Live data from Hacker News

Microsoft Teams: 1 feature, 4 vulnerabilities

positive.security

101–110 of 264 posts

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#101

Earlier quoted context omitted.

One day they just completely fucked the ability to paste code. It worked flawlessly before and then suddenly it removes indenting, bugs out and doesn't let you exit the preformatted code block. It's so bugged, it's like they didn't even test it. They couldn't have, one day it literally worked fine and the next it was unusable and could be replicated every single time. And why there isn't the ability to just delete th…

I like playing the "can I paste an image in today or not?" game - sometimes it works, sometimes it doesn't, sometimes I have to open the web version to do it, other times not ...

For a six month five people in our office couldn’t use the desktop client. Video meetings just didn’t work on the Mac.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#103
post #51

Earlier quoted context omitted.

I agree so much! It is baffling to me that so many companies/schools/individuals are actively using it. It is _so_ _bad_. Messages are lost, it reboots spontaneously, it crashes, one cannot turn off emoticons (I think (the UI doesn't help)), etc. It does not even take security seriously. What is good about that software? And then when I talk about this with colleagues, they seem to be just fine with it... Anyway, sor…

The reason people use it is because either they don’t have a say in it or they legitimately never used anything better (such as Slack or the lesser-known competitors like Mattermost). If your benchmark is Skype for Business or email then I guess Teams is indeed an upgrade, and Microsoft is betting on that.

> If your benchmark is Skype for Business or email then I guess Teams is indeed an upgrade

No it really isn't! At least shouldn't be forced as a replacement for Skype.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#104
Reading through these vulnerabilities, it feels like a handful of these are low priority or non-issues. This might be a controversial opinion, but it’s not clear to me why these issues ought to be prioritized and fixed expediently.

For example, it’s not clear to me why an IP address leak is considered problematic. And breaking chat or crashing on reload seems more akin to a bug a la iMessage link bugs like https://www.theverge.com/2018/1/18/16904774/ios-iphone-bug-c.... That type of issue should be fixed, but it’s not a vulnerability that’s meaningfully exploitable for either remote code execution, stealing client credentials, or stealing client data.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#105
post #38

MS Teams is the worst software I've ever used. This is not hyperbole. A room full of monkeys on a typewriter would never create something as bad as teams.

> A room full of monkeys on a typewriter would never create something as bad as teams. Monkeys could barely create software if at all. That means you have set a low badness bar for Teams to surpass.

What if they were using GitHub copilot?

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#106

Earlier quoted context omitted.

One day they just completely fucked the ability to paste code. It worked flawlessly before and then suddenly it removes indenting, bugs out and doesn't let you exit the preformatted code block. It's so bugged, it's like they didn't even test it. They couldn't have, one day it literally worked fine and the next it was unusable and could be replicated every single time. And why there isn't the ability to just delete th…

The latest Teams bug I've encountered is an inability to write a bulleted list with more than one bullet. Each newline splits the list into a new message. No combination of Shift/Ctrl/Alt + Enter worked. This changed, as in broke, around a week ago. At least for me, on Win 11. Edit: Just remembered another Teams bug from a few days ago: cut text from the middle of paragraph, paste it back in earlier in the same parag…

For the list-bug, there is a workaround I think, if you go into the "Edit-mode" (or whatever it's called) where Enter won't immediately send the message, having multiple bullet points (by using Enter) still works.

But yeah, it's really silly how they manage to break things like this. One would think they have a test-suite specifically for their shitty editor to prevent things like this - apparently not the case. Welp.

It's not yet skype-levels of bad, where doing _anything_ beyond simple text was impossible, but it seems they're slowly getting their, update by update.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#107
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

> a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft Zoom had and continues to have a significant developer presence in China. Those individuals are subject to CCP coercion. There was also a time when they routed American calls through the mainland [1]. That has been fixed. But it remains excessive to cast all past criticism of Zoom as Microsoft's work. [1] https://techcrunch.com/2020/04/0…

Don't forget about the time a Zoom software engineer conspired with China's intelligence service to identify and harass dissidents residing in the US. The engineer is currently wanted by the FBI: https://www.justice.gov/opa/pr/china-based-executive-us-tele...

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#108
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

As an anecdote I know of a certain top-100 company that ditched their in-house competitor to Teams because MS made them a sweeter O365 deal. For a time management forced them to use Teams even though they were still developing AND licensing the in-house competitor to other companies. MS is really aggressive with Teams marketing (specially for large bureaucratic enterprise) and I could totally see them doing what you…

The problem is that Slack (paid for) is hard to argue for vs. Teams when Teams is basically free if you already use o365. Management just see that chat app X is costing us XXk/year when Teams is "free". Easy savings.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#109
post #94
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

Honestly I fail to understand why Zoom seems to have so many fans. I find the UI confusing, on my Linux machine having a call with video will lead to the CPU cooler going into overdrive, I often have to leave and re-enter calls because audio output isn't working, etc. etc.

I think people like(d) Zoom because its core features were pretty simple to use. Yes, they do really weird stuff like having app settings that you can change in the app but account settings that you have to log in to your web account to change, but most of those features are more marginal.

Google Meet, and this may have changed recently, lacked basic features like being able to quickly identify what window you are sharing. I've also seen far more call issues with Google and Teams than I have Zoom.

As for Teams, I don't have a ton of quarrels with the video meeting system itself but it's desire to jam 20 other critical workflow pieces into the software made it a huge mess, at least from my experience with it on Mac:

1) The calendar sort of works, but not really, and most features you'd expect to accomplish with a calendar actually need to be done in Outlook and not teams.

2) The chat UI is really cumbersome compared to Slack and it quickly becomes difficult to find anything if you interact with a lot of people

3) The document file system is a total cluster. Let's say someone chats me a file to look at. I click the link and the file opens in my Teams window. I review it partially and have a question for the person who sent it. I go back to chat, send a message, and then try and go back to my document. Guess what? It's gone and I have to load it again. What fun! You just have to get into the habit of forcing the files to open in their native app or load them in a browser. I'm sure there is a way to prevent this from happening but what I've found with Microsoft applications (at least on Mac) is that basic functionality like this is completely unintuitive compared to any other productivity software I've seen.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#110

Earlier quoted context omitted.

One day they just completely fucked the ability to paste code. It worked flawlessly before and then suddenly it removes indenting, bugs out and doesn't let you exit the preformatted code block. It's so bugged, it's like they didn't even test it. They couldn't have, one day it literally worked fine and the next it was unusable and could be replicated every single time. And why there isn't the ability to just delete th…

Oh ye a code snippet I sent in Teams made me wreck our deployment system. Teams put a nobreak space or something in the code that looked like a ordinary space in the diff. I am still abit mad :)

Oh Teams started doing this too now? This was that one thing that made me absolutely hate Skype (other than being utter garbage in general) and that at least worked so far in Teams...

Looks like all commercial chat-software is destined to become terrible garbage, one A/B-test at a time.

Post reply on HN