Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

71–80 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#71
post #67

Earlier quoted context omitted.

SharePoint is garbage. Even nextcloud is way better and it doesn't exactly have the best reputation. It can't possibly be that hard can it...

I have never used SharePoint but I honestly cannot imagine it being worse than Nextcloud + Collabora Office. Which I do use almost every day.

You have no idea how good you have it.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#73

It's not right to victim blame but it's also not wrong. Akin to investing lots of money in a stock. If you took the risks of maintaining a public SharePoint server in 2025, here's your very bad day.

It's perfectly fine to victim blame corporations that keep kneecapping themselves. That's a hill I'm willing to day on.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#74
post #54

Earlier quoted context omitted.

I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.

This is what happens when Chesterton's fence is ignored...

not just ignored but purposefully burnt down

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#75

[flagged]

CrowdStrike is not made or owned by Microsoft.

Giving OP the benefit of the doubt, there were issues with how the Windows kernel had little guardrails and restrictions.

That said, that was the EU's fault, as the EU in 2009 forced Microsoft to fully expose their OS internals to outside vendors during an anti-trust settlement, and with little ability to enforce vendor standards:

""Microsoft shall make available to interested undertakings Interoperability Information that enables non-Microsoft server Software Products to interoperate with Windows Server Operating System on an equal footing with other Microsoft Server Software Products.

"Microsoft shall ensure on an ongoing basis and in a Timely Manner that the APIs in the Windows Client PC Operating System and the Windows Server Operating System that are called on by Microsoft Security Software Products are documented and available for use by third-party security software products that run on the Windows Client PC Operating System and/or the Windows Server Operating System.

These APIs will be documented on the Microsoft Developer Network, unless open publication would create security risks. In such circumstances, Microsoft will provide third-party security vendors with access to such APIs pursuant to a royalty-free license and on fair, reasonable and non-discriminatory terms." [0]

This meant that by offering Microsoft Defender for Endpoint, Microsoft needs to give similar access to the underlying kernel to competing vendors like CRWD and S1.

[0] - https://news.microsoft.com/download/archived/presskits/eu-ms...

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#76

Earlier quoted context omitted.

I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.

You're assuming their purpose was to find waste, it was not. Their purpose was to be the Chicago boys in DC.

Seems like generally it ended up being a surveillance play, in practice if not original intent. For example, Dog coin has been reported to be passing data taken from other agencies directly to ICE^[1] for law enforcement applications, and there was that other matter of logins apparently from Russia using accounts the Dog coin personnel demanded agencies create on their internal systems with (auditable) logging disabled^[2]. And probably more that I'm forgetting.

One does wonder whether this was all part of Musk's vision, or more thanks to the scum he hired to staff Dog coin and/or other lawless opportunists in the Trump administration.

[1] https://www.washingtonpost.com/immigration/2025/04/16/medica...

[2] https://www.reuters.com/technology/cybersecurity/whistleblow...

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#77

It is instructive that we are seeing the results of DOGE's work: "The process took six hours Saturday night — much longer than it otherwise would have, because the threat-intelligence and incident-response teams have been cut by 65 percent as CISA slashed funding, Rose said."

I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.

I'll tell you what pisses me off: Having to be subjected to low security services because one political party wants to run a reality TV show instead of caring for people. The consequences are all for us to bear.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#78
post #16
post #9

Earlier quoted context omitted.

I operate under the assumption that open source projects are compromised by states. If you espouse unpopular ideas or are yourself a state don’t rely on it.

Lets pretend what you are saying is true, which it is not. Who would you want to access your data ? The State or the "underworld". Many countries have laws on how to access your data. The underworld, you may wake up dead. Granted there are countries that act like a Criminal Org., but if you live there you have more issues than your data. With proprietary software, it is a much larger chance that backdoors exist than…

It is true. Denying trivial truths with the purpose of not giving an inch does not add to one's argument, it weakens it.

Plenty of closed source products will happily backdoor their products on request, without a warrant, if they are confident they will never be found out. That's the point. Not that FOSS source is somehow inviolable to nation-states with virtually infinite resources, many of which sponsor or contribute to the finance of a huge percentage of the development of FOSS themselves.

It's easier to find backdoors in FOSS if you're looking, because you're allowed to look. But somebody has to be looking.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#79
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

Good news.

Teams is actually SharePoint.

It ain't going anywhere

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#80
> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available.

It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.

Post reply on HN