Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

101–110 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#101

It is instructive that we are seeing the results of DOGE's work: "The process took six hours Saturday night — much longer than it otherwise would have, because the threat-intelligence and incident-response teams have been cut by 65 percent as CISA slashed funding, Rose said."

I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.

The first obvious sign was that the people not holding office or having any access to government data were making unfounded claims about how the government was operating.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#102

Earlier quoted context omitted.

You're assuming their purpose was to find waste, it was not. Their purpose was to be the Chicago boys in DC.

Seems like generally it ended up being a surveillance play, in practice if not original intent. For example, Dog coin has been reported to be passing data taken from other agencies directly to ICE^[1] for law enforcement applications, and there was that other matter of logins apparently from Russia using accounts the Dog coin personnel demanded agencies create on their internal systems with (auditable) logging disabl…

The idea that Musk's intent was to gut all of the agencies that were in a position to regulate any of his companies does seem to suggest that DOGE was an outstanding success.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#103
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

At some point Microsoft tried to sell some automatic DRM system based on SharePoint to some company that I worked for.

The sales pitch was that they could upload documents to SharePoint and when people downloaded the documents SharePoint would automatically apply DRM so the documents could only be opened by that person on authorised machines for a specified number of days.

Well, it turned out depending on how you logged in (using the same account, just different login forms) on the SharePoint server it would either give you the files with DRM applied - or the completely unrestricted files.

We got some senior Microsoft consultant working directly for Microsoft to look at it but in the end they were just as confused as us.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#104

Earlier quoted context omitted.

My boss spent over a year trying to get me to setup Sharepoint. About 6 months into this, I finally looked into it and what it provided and said no. Eventually he hired a second tech and he set it up "in an afternoon." Good for him. Nobody ever used it. He also stole my high speed USB drive.

While Sharepoint might some day die, it will only be replaced by another piece of software that gets launched for nobody to ever use.

Clearly Sharepoint is being used. Otherwise, this would not be a news story. So if every single Sharepoint user switched to another piece of software, it would be more than nobody using it.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#105

Earlier quoted context omitted.

I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.

The first obvious sign was that the people not holding office or having any access to government data were making unfounded claims about how the government was operating.

The move obvious sign is that people making that claim have a proven track record of being compulsive liars.

That anyone gives a word they say the time of day is actually crazy.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#106
post #97
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

As a mid size company that does work with government agencies, it’s near impossible to use anything ‘better’ solution. Cybersecurity requirements are getting so onerous that Sharepoint is too commercially feasible of an option to use anything else for a shared file store between organizations. The fact that Sharepoint sucks* doesn’t matter… because anything else is seen as a risk. * folders with lots of files are har…

It’s not cybersecurity. It’s legal, trust me. For large corporations, eDiscovery is huge. Failing eDiscovery can cost a company millions. Having a bunch of different data sources makes it impossible, so companies stick with M365 as corporate policy and call it a day.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#107

Earlier quoted context omitted.

[flagged]

"Our product is remarkably insecure, let's convince everyone of this by sponsoring an attack so they go and buy our other product." I mean, there are definitely stupid people everywhere, but I'd hope MS leadership isn't that stupid.

I mean, dumber things have happened. Governments have destroyed their own government buildings to blame on the opposition and gain sympathy for their causes.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#108
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

Good news. Teams is actually SharePoint. It ain't going anywhere

My company was using slack and mattermost and consolidated to teams... It is so bad.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#109
post #84

Earlier quoted context omitted.

It’s impossible to stop using M365 while stopping usage of SharePoint (cloud or on-premises). See https://news.ycombinator.com/item?id=44640219 Here’s just one example: Each M365 Teams Team creates an M365 Group which creates a SharePoint site and Exchange mailbox. Teams channel files are stored in that SharePoint site. Teams channel messages are stored in the Exchange mailbox. Private files dropped in Teams are stor…

> Private Teams messages are stored in individual Exchange mailboxes. Good lord. It truly is a layer of dung layered upon more layers of dung.

I don't think this is nearly as crazy as you may think at first glance

Imagine if it was just a hidden (special) folder in an Exchange mailbox.

Voila, you already have a well-known and widely implemented and tested message syncing solution both for content and status (read/unread)

I assume Windows Phone worked the same way with its text message backup. When you'd set up a new phone it would take a while for your Microsoft account to finish syncing during which new messages would trickle into the Messaging app in real time. In fact if your old phone was still on WiFi new messages would show up on both. Still more advanced 15(?!) years ago than my Android today

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#110

Earlier quoted context omitted.

"Our product is remarkably insecure, let's convince everyone of this by sponsoring an attack so they go and buy our other product." I mean, there are definitely stupid people everywhere, but I'd hope MS leadership isn't that stupid.

I mean, dumber things have happened. Governments have destroyed their own government buildings to blame on the opposition and gain sympathy for their causes.

Yes, false flags. That's usually used to motivate people to go attack someone or to garner sympathy or support for a cause. MS's products being subject to attacks because they have numerous vulnerabilities does not encourage anyone to go out and buy other MS products.

You sink one of your own naval vessels (or it sinks due to an accident and you take advantage of the situation) and blame it on an enemy. That enemy is now the target of your military and your population approves.

A shipbuilder hires someone to poke a hole in 1000 of their ships that are so badly designed and manufactured that it only takes a rubber ducky bouncing off the hull to sink them does not encourage anyone to go back to that shipbuilder.

False flags (particularly of the "let's kill or maim hundreds of our own people and other innocent people" variety) push into evil territory. They aren't dumb on their own, they're calculated risks predicated on the willingness of the masses to fall in line after a catastrophe.

Deliberately hurting your own customers by using weaknesses in your own systems in order to motivate them to go buy your other products or services is dumb.

Post reply on HN