NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: Ghost of IT mistakes past visits again

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
14 Dec, 2021 04:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Photo / 123RF

Photo / 123RF

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

OPINION:

A catastrophic cyber security incident causing panic everywhere has become the new Christmas tradition and 2021 is no exception.

This time it's a doozy, a piece of logging software for the very popular Java programming language. The utility writes information into log files on computers so that developers and power users know what's going on.

Unfortunately, a feature added in 2013 inadvertently made it possible for anyone to easily run whatever code they like on other people's computers, a hair-raising prospect on today's very hostile internet. It's a spectacular mis-feature and not a bug per se.

Advertisement
Advertise with NZME.

We have been lucky, as it took eight years for intrepid Minecraft gamers and Alibaba security experts to blow the Log4j/Log4Shell vulnerability wide open.

How bad is the vulnerability? Security experts such as CyberCx executive director of cyber security and assurance testing Adam Boileau were taken aback by the severity of Log4Shell. It couldn't really be any worse.

There are vulnerable versions of the Log4js Java code running on countless business systems everywhere.

"It is pretty unprecedented; I am struggling to think of anything quite like this in my career," Boileau said.

Advertisement
Advertise with NZME.

The situation is serious as they come, but explaining what it means to laypeople who have no idea what "remote code execution" is, or how it lets attackers take full control over a computer, is very difficult. That in turn means it's hard for people to grasp the impact of the vulnerability, Boileau added.

Boileau might be a tad too pessimistic here. This is 2021, and Log4Shell/Log4j hit front pages in general media. While few would delve into the deep geek details, there's now a need to know because of the economic hit the flaw could lead to if our IT systems are attacked.

IT systems are in fact already under attack. Ransomware and cryptocurrency miners are being planted through Log4Shell, and there's worse to come. The experience of the past few years shows that this kind of disruption can kill businesses and cost millions for remediation and recovery.

If you understand what's happening, take heart in the tech community's fast and exemplary response. Log4Shell is fixable.

That is, if you know the vulnerable component is there. It's not unusual for applications to be developed with unlisted components that nobody pays much attention to, security-wise.

Not knowing how an application is cobbled together makes life harder for security professionals, but this may be sorted out soon, Boileau noted.

In response to earlier security breaches, the Biden administration has published a requirement for companies that wish to sell software or devices to the United States government to provide a Software Bill of Materials (SBOM). This lists the components used for applications, and all dependencies (other code) they might require.

"With this, we could identify everything with log4j in it in an environment, and rapidly make good decisions about isolation, or remediation, or patching, or even who to talk to," Boileau said.

Advertisement
Advertise with NZME.

Clearly, it's not a good thing to have these regular cataclysmic vulnerabilities. Despite increased awareness of them, and small but important improvements in how we code, security for devices that we happily outsource our cognitive capability and information storage to remains elusive.

Suggestions have popped up that open source developers whose unpaid work trillion-dollar tech titans exploit should become professionalised. Instead of relying on donations, developers should send out big invoices to ensure their clearly valuable work is properly funded.

That, Boileau points out, misses the psychology behind open source: for many developers, publishing code is a social thing, allowing them to connect with users. Increased popularity for the code, and new features that are well-received is the reward rather than money.

Besides, when even Big Invoice software houses get it wrong and ship code with security holes large enough to drive a horse and carriage through, it suggests the problem lies elsewhere.

Despite what "the market will sort it out" ideologues say, just like with burning enormous amounts of fossil fuels without a care, our entire economy is predicated on not paying the real cost of anything, Boileau said.

Software is no different for kicking it down the line when it comes to the cost of maintenance, security or privacy. Now we're paying for that faulty thinking and there's no easy solution on the horizon. It's deemed easier to patch nigh-inscrutable application code rather than deleting the lot and starting again with a clean slate.

Case in point: Java has a very chequered history when it comes to security, but still operates something like three billion devices. Many of those won't ever receive updates because nobody knows quite what the code does, or it's simply not feasible to patch it due to lack of access, or an important feature ceasing to work.

"I think there's probably no practical way to have prevented this from happening," Boileau suggests, and he's right. The IT revolution has run away with us, and we're in for a wild ride.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Markets with Madison

Why $73.5b DataDog is going all in on AI

19 Jun 07:47 PM
World

Trump's policies are reshaping global financial dynamics

19 Jun 07:44 PM
Premium
Media Insider

Court writer: Polkinghorne pitches his own book; TVNZ v Sky in Olympics showdown

19 Jun 06:14 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Why $73.5b DataDog is going all in on AI

Why $73.5b DataDog is going all in on AI

19 Jun 07:47 PM

Hear from four of the company's executives in this episode of Markets with Madison.

Trump's policies are reshaping global financial dynamics

Trump's policies are reshaping global financial dynamics

19 Jun 07:44 PM
Premium
Court writer: Polkinghorne pitches his own book; TVNZ v Sky in Olympics showdown

Court writer: Polkinghorne pitches his own book; TVNZ v Sky in Olympics showdown

19 Jun 06:14 PM
Trump gives TikTok 90 more days to find buyer, again delayed ban

Trump gives TikTok 90 more days to find buyer, again delayed ban

19 Jun 05:53 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP