Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

11–20 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#13
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

Oh, don't worry, there's plenty of known, unpatched vulnerabilities in FOSS, too.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#14
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

Genuinely asking - is there a Linux alternative to Sharepoint? I couldn't care less if it was lit on metaphorical fire and dumped into the sea, but a lot of orgs using it extensively.

O365 is a poor amalgamation of like 18 different things. Quite frankly I hope there isn't a true "alternative" to it.

The reason orgs use Sharepoint is they are forced to if they use Microsoft. One drive is sharepoint, teams is sharepoint, sharepoint sites is sharepoint, etc...

I'm sure all those things have better alternatives, but Microsoft shoves them down your throat when you license with them.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#15
post #6

Earlier quoted context omitted.

I was not sure if this was mere speculation on your part, but I think you might be onto something here. https://www.muellershewrote.com/p/the-epstein-cover-up-at-th... | https://archive.is/RZqU0 > The process of reviewing the Epstein and Maxwell files was chaotic, and the orders were constantly changing - sometimes daily. One person I spoke to on the condition of anonymity said that many agents spent more time waitin…

So how does this work for someone to know what server to use the exploit? Do companies make their Sharepoint servers accessible to WWW? Do hackers need to use this on a network they've already pwnd? Finding out the FBI put something like this on a server open to the WWW would be classic. That much larger group just got a wee bit larger than they previously thought on their previously thought number.

> Do companies make their Sharepoint servers accessible to WWW?

Microsoft was pushing companies to use its Azure cloud services. Now everything is in the cloud. And accessible to WWW.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#16
post #9
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

I operate under the assumption that open source projects are compromised by states. If you espouse unpopular ideas or are yourself a state don’t rely on it.

Lets pretend what you are saying is true, which it is not. Who would you want to access your data ? The State or the "underworld". Many countries have laws on how to access your data. The underworld, you may wake up dead.

Granted there are countries that act like a Criminal Org., but if you live there you have more issues than your data.

With proprietary software, it is a much larger chance that backdoors exist than in Open Source. Many of us heard of 1 issue where it was claimed a project had a Gov sponsored BH in it. They did a long audit and found that was false.

Eventually Open Source backdoors will found in Open Systems. Proprietary you are SOL unless you do very expensive and very hard testing. Even then it is doubtful you will find a backdoor.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#17
post #9
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

I operate under the assumption that open source projects are compromised by states. If you espouse unpopular ideas or are yourself a state don’t rely on it.

Interesting, I'd more likely assume the same for closed source projects as there is less transparency into the supply chain

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#18

Earlier quoted context omitted.

Genuinely asking - is there a Linux alternative to Sharepoint? I couldn't care less if it was lit on metaphorical fire and dumped into the sea, but a lot of orgs using it extensively.

O365 is a poor amalgamation of like 18 different things. Quite frankly I hope there isn't a true "alternative" to it. The reason orgs use Sharepoint is they are forced to if they use Microsoft. One drive is sharepoint, teams is sharepoint, sharepoint sites is sharepoint, etc... I'm sure all those things have better alternatives, but Microsoft shoves them down your throat when you license with them.

But it's understandable why an org would prefer that to having to maintain and manage the 18 things, right? It's a hard sell.

I'm not saying that wouldn't be better, but it makes sense why an org would be reluctant. Again, not a fan of Sharepoint myself, but from an org's viewpoint, moving to Linux raises more problems than it solves.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#20
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

Genuinely asking - is there a Linux alternative to Sharepoint? I couldn't care less if it was lit on metaphorical fire and dumped into the sea, but a lot of orgs using it extensively.

git repo hosted on a secure server behind several layers of VPN? I'm sure I could probably come up with something more secure than freaking sharepoint
Post reply on HN