Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

101–110 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#101

Earlier quoted context omitted.

Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement. You can't easily dump Jira if you are using Jira, confluence, bitbucket, and whatever their CI/CD product is called (bamboo?)

Clubhouse (soon to be renamed Shortcut) covers the first two. Github covers the latter two. It's easier to switch than ever.

> Clubhouse (soon to be renamed Shortcut) covers the first two.

Even taking the following into account?

>> Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#102

Earlier quoted context omitted.

It is hard to say for sure, but this organization used configuration controlled documents for design documentation before atlassian came along. When they made the switch (and hired oodles of graduates) suddenly about half of them ignore confluence or latex for design, because "jira has markdown". Oh hurray, we have a bad typesetting language mixed in with our bug tracker, lets shove our entire design in there! It is…

Can't but help to feel that what you describe is a breakdown of both organization and work process. It wasn't atlassian that "came along" - someone penned down an agreement and, from what it sounds, there was a lack of clarity both in regards to current and future principles of work and collaboration. What we can do, as devs, to protect ourselves from the madness you describe is to be explicit about our work processe…

The thing I've found is that Jira has so many fields on its tickets that beg to be filled in, that PMs start filling them in, and before you know it they're all mandatory and must be filled in. And organising that much state in the tickets becomes a full-time job, and so the PM ends up doing that - managing the state of Jira rather than managing the state of the project. The two become synonymous when they're not. When they inevitably diverge all the usual problems of project management get exacerbated horribly (in part because what should happen is all the state in Jira gets thrown away as it doesn't reflect reality, but that's a huge sunk cost so no-one does it).

So yeah, I have found that the tool shapes the process, not the other way around.

It would probably work the other way around if every organisation built their own project management tooling around their own processes. But that would be insane.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#104
post #74
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

I think it already has been disrupted but no company is going to switch task management software without a really good reason. But I can't imagine and fresh companies are choosing Jira over Clubhouse, Asana, Trello or what I hope to be my company at some point! https://tahsk.com

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#105
post #83
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> It’s amazing that this company continues to fall up. There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition. Atlassian get a lot of criticism, that's not always justified

I suspect that a lot of Atlassian's criticism is a reflection of their dominant market position. Outside of smartphones and video game consoles, people generally don't spend much time complaining about products they don't use.

For my part, I've spent enough time using both Atlassian products and competitors to find something to hate in all of them. Familiarity breeds contempt.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#106
post #80

Earlier quoted context omitted.

I wish I knew the answer as well. I believe many managers trained in the art of building software without knowing how to build software are too married to doing processes in a very specific way that's very tightly coupled to Jira, and feel safe and at home with the added complexity it provides, so they vouch for it. But that's just a theory from personal experience.

Jira is as complex as you make it and you can't solve people issues with technology. So another solution won't solve your manager problem. That said, the UI is an abomination that will one day summon the elder gods to reap us all.

I mean, if the problem you have is that Jira lets you set up overly complex workflows, then a more limited solution that forces a simpler way of working could have a positive effect? I do agree that you don’t HAVE to make things more complicated than necessary in Jira, but obviously some do that anyway.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#107

Earlier quoted context omitted.

Totally agree with your first two sentences. However, the final part has nothing to do with jira IMO. You would have the same behavior in these organizations regardless of tool. The dysfunction you describe goes way beyond a single or set of tools.

It is hard to say for sure, but this organization used configuration controlled documents for design documentation before atlassian came along. When they made the switch (and hired oodles of graduates) suddenly about half of them ignore confluence or latex for design, because "jira has markdown". Oh hurray, we have a bad typesetting language mixed in with our bug tracker, lets shove our entire design in there! It is…

many organizations are overwhelmed with inexperienced new graduates; they end up doing what they want or how they did things in college projects.

then they get promoted, and may never learn / experience why a task / defect tracker is not where you store requirements / design.

(note: the above comments are for long lived software only. it you rewrite your web site from first principles every you, do whatever. it doesn't matter)

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#108
post #83
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> It’s amazing that this company continues to fall up. There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition. Atlassian get a lot of criticism, that's not always justified

Is there a way to quickly mark a block as code? Because whatever nice feature it has are completely rendered irrelevant by this lack.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#110

Earlier quoted context omitted.

Well, I got it. Maybe you specifically didn't get it, or maybe there is something filtering it.

I only got the 'update' from last Saturday, by then it was too late already. Their original advisory was from the 25th, they should have mailed me back then.

If you got the one from Sep 4, you definitely should have gotten the one from Aug 25.

This is unrelated to any mailing-list change, since both were sent from/to the 10991049.xt.local mailing list.

Search for the header entry `List-ID: ` in your Sep 4 email. If it came from that list, the one from Aug 25 will very likely have been lost during transit.

I use their products in the 10-user license program since 2016 and got automatically subscribed to their mailing list back then, and never made some change to the subscription. I'm receiving emails from that list since 2020-10-17.

On the 2020-07-10 I got a mail from them telling me:

```

Subject: Please double-check your contact details for Atlassian

Making sure you don't miss important emails

Hi,

When you purchased your Atlassian products, we asked for the contact information for two types of people in your organization:

Billing contact - A person we contact with invoice and billing information

Technical contact - A person we contact about product changes, security advisories, etc.

We don't want your company to miss out on important information from Atlassian, so please take a minute to make sure your contact information is current. Here's what we have in our system:

```

Post reply on HN