Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

111–120 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#111
post #84
post #64

Earlier quoted context omitted.

Atlassian products are garbage. So why are they so popular? Because Jira is a wet dream for mediocre micro-managers (of all levels), allowing them to manage by ticket, instead of lead by example.

Hit the nail on the head there. New thing? Let’s open a new JIRA project and prefix with some random shit show workflow customised by someone who was clearly asleep or incompetent!

Yup, have been in that exact situation. It was literally mind-boggling.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#112

Earlier quoted context omitted.

Clubhouse (soon to be renamed Shortcut) covers the first two. Github covers the latter two. It's easier to switch than ever.

> Clubhouse (soon to be renamed Shortcut) covers the first two. Even taking the following into account? >> Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement.

Well if your organisation wants crappy project management tools and processes then there's nothing to be done. But there are plenty of alternatives out there for those who seek them.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#113

Earlier quoted context omitted.

How big is your organisation? I know it shouldn’t matter but your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc. I’ve always found government, sensitive customers (banks, payment processors, healthcare) and big spenders get prioritised with phone call notifications. However with a deprecated product, the financial impact is so minuscule - leadership won’t prioriti…

your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc. The only companies that are like those companies are those companies. In most companies, the CS people don't know what anything in that sort of alert means and will discard it thinking that it's a spam or phishing attempt. The problem is not that he doesn't work for a megacorp. The problem is that Atlassian screw…

Where did they screw up? How do you know that the mail wasn't lost/filtered after being sent?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#114
post #83
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> It’s amazing that this company continues to fall up. There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition. Atlassian get a lot of criticism, that's not always justified

> That's why they are still here, their product is still superior to the competition.

No. It's because their products are sticky in nature. The tools are used to hold the current state and historic knowledge of the organisation, and even the thought of replacing one of them gives IT manager types the shakes.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#115

Earlier quoted context omitted.

How big is your organisation? I know it shouldn’t matter but your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc. I’ve always found government, sensitive customers (banks, payment processors, healthcare) and big spenders get prioritised with phone call notifications. However with a deprecated product, the financial impact is so minuscule - leadership won’t prioriti…

It's tiny, I just want them to send me an email if there is a critical vulnerability. Not too much to ask, I think.

Based on the other anecdotes here it seems most likely that they did and you just didn't receive it.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#116

Earlier quoted context omitted.

But why are they not using VPN?

common reasons could be :- - Cost, VPNs and the hardware to run them can be expensive - Single point of failure. If you run all your remote access through a VPN gateway then you run the risk of disruption if it goes down. Of course you can implement redundnt/multiple gateways but that increases cost. - Complexity for B2B setups. If you're exposing an API and you want third party services to access it, it can be more…

If all of these are reasons, then you should use the cloud version. In other words, if your project management solution needs to be hosted for some business reason and you can't afford all of the maintenance required to host it properly, then you aren't charging enough for your product.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#117
post #74
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

This is the primary failing of many tech people/companies. You can't compete by just building a "better" technical product.

Everything from sales to support to customizations and integrations matter to companies, especially as they grow and develop their own teams and management structures which require the software mold into their workflows. Whether the management processes are the best is a different conversation, but being able to support any scenario is why Jira and Confluence are so successful.

It's the same reason why Salesforce has dominated CRMs even with so many "modern" alternatives around.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#118

Atlassian was so kind to update their mailing lists somewhere over the last year or so. Previously, they would email the 'technical contact' of the license about any vulnerabilities. They quietly switched to some other notification system and never informed us about it. Hence we missed the update and got a free Bitcoin miner. Thanks Atlassian, I'll make sure to get your products out of the door as soon as possible. […

Partly related https://news.ycombinator.com/item?id=25590846

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#119

Earlier quoted context omitted.

> Clubhouse (soon to be renamed Shortcut) covers the first two. Even taking the following into account? >> Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement.

Well if your organisation wants crappy project management tools and processes then there's nothing to be done. But there are plenty of alternatives out there for those who seek them.

It is actually possible to want bespoke tools to do certain things. And honestly? Confluence is slow, but at least it has all the features I could want and it works.

People are like”use the shiny thing” forgetting the existing thing has, you know, stuff I actually use.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#120
post #80

Earlier quoted context omitted.

I wish I knew the answer as well. I believe many managers trained in the art of building software without knowing how to build software are too married to doing processes in a very specific way that's very tightly coupled to Jira, and feel safe and at home with the added complexity it provides, so they vouch for it. But that's just a theory from personal experience.

Jira is as complex as you make it and you can't solve people issues with technology. So another solution won't solve your manager problem. That said, the UI is an abomination that will one day summon the elder gods to reap us all.

Taking away configuration options from most Jira project managers I’ve come across would be a very helpful first step.
Post reply on HN