Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

61–70 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#61

Wondering if this was a self goal to, you know, get people to use this enshittified product on the cloud?

There are basically two things at play here: MS's hosted version of SharePoint. It's apparently unimpacted by this current round of attacks. DOD (since it's been brought up by other commenters) makes significant use of this. People hosting SharePoint instances themselves. Some on-prem, some with rented computers. These are the impacted ones. It's not about "the cloud", it's about hosted SharePoint having weaknesses t…

[flagged]

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#62
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

As far as I can tell there's two vulnerabilities bundled up here. One is an unauthenticated command injection (!) vulnerability to steal some keys and the other is of course yet another serialization-based RCE in a safe language, mediated by signed cookies (signed with the keys stolen in step 1).

I don't understand how often this design has to blow up in people's faces until they stop doing this and use something dumb and safe instead.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#63
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

My boss spent over a year trying to get me to setup Sharepoint. About 6 months into this, I finally looked into it and what it provided and said no. Eventually he hired a second tech and he set it up "in an afternoon." Good for him. Nobody ever used it. He also stole my high speed USB drive.

While Sharepoint might some day die, it will only be replaced by another piece of software that gets launched for nobody to ever use.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#64

Earlier quoted context omitted.

There are basically two things at play here: MS's hosted version of SharePoint. It's apparently unimpacted by this current round of attacks. DOD (since it's been brought up by other commenters) makes significant use of this. People hosting SharePoint instances themselves. Some on-prem, some with rented computers. These are the impacted ones. It's not about "the cloud", it's about hosted SharePoint having weaknesses t…

[flagged]

"Our product is remarkably insecure, let's convince everyone of this by sponsoring an attack so they go and buy our other product."

I mean, there are definitely stupid people everywhere, but I'd hope MS leadership isn't that stupid.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#65
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

SharePoint is garbage. Even nextcloud is way better and it doesn't exactly have the best reputation. It can't possibly be that hard can it...

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#67
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

SharePoint is garbage. Even nextcloud is way better and it doesn't exactly have the best reputation. It can't possibly be that hard can it...

I have never used SharePoint but I honestly cannot imagine it being worse than Nextcloud + Collabora Office. Which I do use almost every day.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#68

Earlier quoted context omitted.

O365 is a poor amalgamation of like 18 different things. Quite frankly I hope there isn't a true "alternative" to it. The reason orgs use Sharepoint is they are forced to if they use Microsoft. One drive is sharepoint, teams is sharepoint, sharepoint sites is sharepoint, etc... I'm sure all those things have better alternatives, but Microsoft shoves them down your throat when you license with them.

But it's understandable why an org would prefer that to having to maintain and manage the 18 things, right? It's a hard sell. I'm not saying that wouldn't be better, but it makes sense why an org would be reluctant. Again, not a fan of Sharepoint myself, but from an org's viewpoint, moving to Linux raises more problems than it solves.

It's understandable, but it doesn't excuse how poorly everything actually works and how confusing it is to use and administrate.

To some extent I think Microsoft is largely in the business of building solutions for problems that don't exist.

Most orgs are probably perfectly fine with a document management system + desktop word application and then a commercial NAS for bulk storage / backups.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#69
post #25
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

I wonder what drives people using Microsoft and then using more from this company. We didn’t knew it better, back then. We knew it better, now. But migrating is work. So we prefer to suffer! And harm others! This Linux and BSD people are so annoying with their desire for compatibility. They shall suffer, too! And when we buy everything from a Monopoly, we don’t need to think. Somehow. Part of the game is that you’ve…

From what I've seen in my industry? To pass all the liability to Microsoft.

"If something happens, we used enterprise grade industry standard software. We did our due diligence."

This outlook is basically why we can't innovate anymore.

I had to recently sit through a meeting where our CTO quoted all the "blogs" he's been reading as a way to slap down my suggestion for an in-house project.

It's all about CYA.

Post reply on HN