Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

141–150 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#141

I hope they can find what they are looking for, because, with the built-in search, I sure can’t.

It is awful, the worst "search engine" which exists. I absolutely hate it and this is the only thing which wants to make me move away from Confluence. When you need it the most, and this happens often, you know that you definitely cannot rely on it. Any data you put in there is lost, unless you have a good hierarchy and know what to find where without relying on the search.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#142
post #74
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

The thing about products that occupy the kind of niche that Jira does is, the people using the product are not the people making the purchasing decision. They rarely even talk to each other.

If you come to a venue like Hacker News, you'll mostly be getting opinions of the people who actually use the product. These opinions do not reflect the interests and priorities of the people who decide which product to buy.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#143
post #126
post #87

> The vulnerability only affects on-premise servers, not those hosted in the cloud. This is a dangerous statement to make and should be revised to say: > The vulnerability only affects standalone versions of the software, not the managed service of confluence provided directly by Atlassian. The problem with the former is that lesser technical people, especially directors, might assume they're fine because their stand…

99% agreed. Reserving 1% because I'd strike "lesser technical" from your final sentence. The misleading quote is simply not correct. It is misleading because it's not true. It says Confluence hosted in the cloud is not vulnerable. False statement that can mislead anyone regardless of how technical they are.

> regardless of how technical they are

They said "lesser technical people", not "less-technical people". A more technical person might not be able to read between the lines, but a better technical person should.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#144

Earlier quoted context omitted.

Bitbucket recently has shockingly poor reliability. Quite often you see nothing on the status page but see other people having issues on twitter. We've nearly migrated everything to github, plus github has better features and more powerful.

They've been doing a large transformation recently to put it on a new platform. Not saying that's an excuse, but it is an explanation for some of the problems they've had.

Even after this we had issues. Pull requests can take quite a while, diffs not working, git slow or timing out.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#145

Earlier quoted context omitted.

Where did they screw up? How do you know that the mail wasn't lost/filtered after being sent?

If O365 can't find the email and the O365 message tracing does not show anything, it seems likely that the mail was not actually delivered by Atlassian. If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Also, regardless of whether or not I received the mail, the initial mail stated that only authorized users co…

They absolutely do silent drops of email they consider suspect. Anybody who works with email can tell you this. What this metric is nobody knows outside their walls. Google and other big providers do this too, some regard Microsoft a bit more skittish perhaps.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#146
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products.

Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it.

I don't think there is a company out there that hasn't had critical CVEs, nor most major open source projects, either.

Microsoft had a recent vulnerability in their Azure Cosmos DB product that left thousands of customers' data unprotected. Google has released multiple patches to Chrome in the past month.

If you demand you'll only use products from companies or open source projects that have never had a major CVE, you'll be writing a lot of your own software that probably has even worse security.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#147

Earlier quoted context omitted.

If O365 can't find the email and the O365 message tracing does not show anything, it seems likely that the mail was not actually delivered by Atlassian. If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Also, regardless of whether or not I received the mail, the initial mail stated that only authorized users co…

> If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Internet email has never been considered a highly-reliable messaging system; its quite possible an infrequent data loss in a mail server would get misattributed to a failure outside. Heck, even ignoring the unreliability of email generally, in fact, your assum…

In terms of human communication, I consider anything which is only unidirectional to be unreliable.

It's ok for ad emails. But anything that might cost millions if lost should require some kind of human TCP handshake. Whether by email or phone.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#148
post #74
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

The thing about Jira is that it provides much more than just tickets. It's really not even bad at what it does as far as user workflows go, it's just really easy to misconfigure due to lackluster administrative tooling.

I work with a Jira instance that has something like 20 years of history and over half a million tickets. Migrating just the tickets and their comments might be possible, but migrating all the other metadata and every service and automation we've integrated into the workflows (some of which we depend on to be able to work at all) would take months of work if a suitable alternative even exists in the first place.

If it were just tickets and some CI integrations, migrating away from Jira would be trivial, but that's not where all the value is.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#149

Earlier quoted context omitted.

If you’re ok sharing things externally why self-host at all?

> If you’re ok sharing things externally why self-host at all? You're theoretically more in control of the data, which may be a legal requirement in certain jurisdictions and/or industries.

Exactly. Our customers do need to authenticate to read anything in our Confluence installation. Ideally there's nothing critical, just stuff which is considered private.

Legally many of our clients require that their data, all of it, secret or not, reside within the EU.

Currently cloud is not so hot, due to Schrems II. During the last six months we migrate a number of customers on-prem, and only one is building out their stuff in AWS.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#150
post #83

Earlier quoted context omitted.

> It’s amazing that this company continues to fall up. There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition. Atlassian get a lot of criticism, that's not always justified

I suspect that a lot of Atlassian's criticism is a reflection of their dominant market position. Outside of smartphones and video game consoles, people generally don't spend much time complaining about products they don't use. For my part, I've spent enough time using both Atlassian products and competitors to find something to hate in all of them. Familiarity breeds contempt.

A former Rally engineer once told me, "Rally did a better job than Atlassian at making engineers think positive thoughts about Jira."

That said, I can't think of a single feature Atlassian released in the past several years that made the experience of using Jira or Confluence substantially better. (I could at least say markdown support if that was ever ported to Jira Data Center.)

The argument for software subscriptions is that it funds continuous improvement, but most of the top complaints from 2011 are just as relevant in 2021.

Post reply on HN