Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

111–120 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#111

Earlier quoted context omitted.

Best practice is to assume the network is compromised - a VPN doesn't provide as much guarantee as people would like. In large fleets, devices are regularly lost, damaged, retired, etc. In organizations with high target value, physical penetration through any number of means should be assumed. So you don't do that. You use zero trust and don't care that things are exposed to the internet. Working from anywhere (remot…

Maybe I'm missing something but doesn't this very story cut your assertion off at the knees? With a VPN the attack surface of this vulnerability would have been miniscule compared to a publicly accessible zero-day RCE (And it's not like you have to allow carte-blanche access behind the wall) Defense in depth!

In zero trust "exposed to the internet" is a bit of a misnomer compared to how traditional security would use the term. A better description might be "you're allowed to form a session to it from over the internet but only after your identity and set of rights have been verified". From this view: "zero trust" < "vpn" < "wide open" (in terms of exposure).

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#112
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

>At the risk of massive downvotes,

The only reason to get downvotes is nonsense of prefacing the post with the 'worry'. Sharepoint would be far from a first choice under normal circumstances (e.g. not bundled with excel and friends)

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#113

It is instructive that we are seeing the results of DOGE's work: "The process took six hours Saturday night — much longer than it otherwise would have, because the threat-intelligence and incident-response teams have been cut by 65 percent as CISA slashed funding, Rose said."

I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.

How about the fact that Elon and most of his cronies weren’t even born here and seem to feel that the people who were born here are stupid and/or lazy. Maybe only Vivek said that quiet part out loud, but they very much agreed on the solution.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#114

Earlier quoted context omitted.

Seems like generally it ended up being a surveillance play, in practice if not original intent. For example, Dog coin has been reported to be passing data taken from other agencies directly to ICE^[1] for law enforcement applications, and there was that other matter of logins apparently from Russia using accounts the Dog coin personnel demanded agencies create on their internal systems with (auditable) logging disabl…

The idea that Musk's intent was to gut all of the agencies that were in a position to regulate any of his companies does seem to suggest that DOGE was an outstanding success.

Good point!

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#116

Earlier quoted context omitted.

The same people will tell you GIMP is a serious competitor to Photoshop.

And it will be true for 99% of use cases.

GIMP is falling behind because GenAI doesn't work out of the box.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#118

Earlier quoted context omitted.

CrowdStrike is not made or owned by Microsoft.

Giving OP the benefit of the doubt, there were issues with how the Windows kernel had little guardrails and restrictions. That said, that was the EU's fault, as the EU in 2009 forced Microsoft to fully expose their OS internals to outside vendors during an anti-trust settlement, and with little ability to enforce vendor standards: ""Microsoft shall make available to interested undertakings Interoperability Informatio…

The EU defense is something they claim to shirk responsibility, best left to their PR team. Nothing prevented Microsoft from following Apple’s lead in having safer APIs to perform filtering. Note how it refers to “equal footing”? That means that they have to let other people do what Defender does, not that they can’t secure Windows at all.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#119

I have spent far too much of my life on SharePoint. Having it internet facing has never been a good idea. Not really what it is meant for, though the promo verbiage on that has changed over different versions. Some folks wanted SharePoint as their "web server", I would set that installation up entirely separted from all other instances they may have on the network.

Actually it wasn't too long ago, in the early-2010's, that Microsoft was promoting SharePoint for internet sites; I think at one point some Europoean car manufacturer (BMW? Ferrari?) had their global marketing site on SharePoint. Of course that didn't last long, as Microsoft licensed it at a crazy price ($40k per site or something like that).

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#120

> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.

> It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing.

Once upon a time Microsoft marketed it as, and a lot of Orgs adopted SharePoint as their Intranet. With SharePoint 2019 being sunset, a lot of Orgs are scrambling to implement replacements.

Post reply on HN