It is instructive that we are seeing the results of DOGE's work: "The process took six hours Saturday night — much longer than it otherwise would have, because the threat-intelligence and incident-response teams have been cut by 65 percent as CISA slashed funding, Rose said."
I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.
Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
101–110 of 456 posts
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#102Earlier quoted context omitted.
You're assuming their purpose was to find waste, it was not. Their purpose was to be the Chicago boys in DC.
Seems like generally it ended up being a surveillance play, in practice if not original intent. For example, Dog coin has been reported to be passing data taken from other agencies directly to ICE^[1] for law enforcement applications, and there was that other matter of logins apparently from Russia using accounts the Dog coin personnel demanded agencies create on their internal systems with (auditable) logging disabl…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#103At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…
The sales pitch was that they could upload documents to SharePoint and when people downloaded the documents SharePoint would automatically apply DRM so the documents could only be opened by that person on authorised machines for a specified number of days.
Well, it turned out depending on how you logged in (using the same account, just different login forms) on the SharePoint server it would either give you the files with DRM applied - or the completely unrestricted files.
We got some senior Microsoft consultant working directly for Microsoft to look at it but in the end they were just as confused as us.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#104Earlier quoted context omitted.
My boss spent over a year trying to get me to setup Sharepoint. About 6 months into this, I finally looked into it and what it provided and said no. Eventually he hired a second tech and he set it up "in an afternoon." Good for him. Nobody ever used it. He also stole my high speed USB drive.
While Sharepoint might some day die, it will only be replaced by another piece of software that gets launched for nobody to ever use.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#105Earlier quoted context omitted.
I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.
The first obvious sign was that the people not holding office or having any access to government data were making unfounded claims about how the government was operating.
That anyone gives a word they say the time of day is actually crazy.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#106At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…
As a mid size company that does work with government agencies, it’s near impossible to use anything ‘better’ solution. Cybersecurity requirements are getting so onerous that Sharepoint is too commercially feasible of an option to use anything else for a shared file store between organizations. The fact that Sharepoint sucks* doesn’t matter… because anything else is seen as a risk. * folders with lots of files are har…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#107Earlier quoted context omitted.
[flagged]
"Our product is remarkably insecure, let's convince everyone of this by sponsoring an attack so they go and buy our other product." I mean, there are definitely stupid people everywhere, but I'd hope MS leadership isn't that stupid.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#108At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…
Good news. Teams is actually SharePoint. It ain't going anywhere
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#109Earlier quoted context omitted.
It’s impossible to stop using M365 while stopping usage of SharePoint (cloud or on-premises). See https://news.ycombinator.com/item?id=44640219 Here’s just one example: Each M365 Teams Team creates an M365 Group which creates a SharePoint site and Exchange mailbox. Teams channel files are stored in that SharePoint site. Teams channel messages are stored in the Exchange mailbox. Private files dropped in Teams are stor…
> Private Teams messages are stored in individual Exchange mailboxes. Good lord. It truly is a layer of dung layered upon more layers of dung.
Imagine if it was just a hidden (special) folder in an Exchange mailbox.
Voila, you already have a well-known and widely implemented and tested message syncing solution both for content and status (read/unread)
I assume Windows Phone worked the same way with its text message backup. When you'd set up a new phone it would take a while for your Microsoft account to finish syncing during which new messages would trickle into the Messaging app in real time. In fact if your old phone was still on WiFi new messages would show up on both. Still more advanced 15(?!) years ago than my Android today
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#110Earlier quoted context omitted.
"Our product is remarkably insecure, let's convince everyone of this by sponsoring an attack so they go and buy our other product." I mean, there are definitely stupid people everywhere, but I'd hope MS leadership isn't that stupid.
I mean, dumber things have happened. Governments have destroyed their own government buildings to blame on the opposition and gain sympathy for their causes.
You sink one of your own naval vessels (or it sinks due to an accident and you take advantage of the situation) and blame it on an enemy. That enemy is now the target of your military and your population approves.
A shipbuilder hires someone to poke a hole in 1000 of their ships that are so badly designed and manufactured that it only takes a rubber ducky bouncing off the hull to sink them does not encourage anyone to go back to that shipbuilder.
False flags (particularly of the "let's kill or maim hundreds of our own people and other innocent people" variety) push into evil territory. They aren't dumb on their own, they're calculated risks predicated on the willingness of the masses to fall in line after a catastrophe.
Deliberately hurting your own customers by using weaknesses in your own systems in order to motivate them to go buy your other products or services is dumb.