Earlier quoted context omitted.
> If you’re ok sharing things externally why self-host at all? You're theoretically more in control of the data, which may be a legal requirement in certain jurisdictions and/or industries.
Atlassian is not HIPAA compliant, so many are forced to install their tools on on-prem.
US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
151–160 of 344 posts
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#152Earlier quoted context omitted.
Clubhouse (soon to be renamed Shortcut) covers the first two. Github covers the latter two. It's easier to switch than ever.
No it's not easy to switch. Engineeting Organisations have invested a lot in the Jira eco system, that includes custom workflows that are understood only by a few to be able to alter them, users are productive right now with jira and nobody wants them less productive even just for a while learning another task manager. Here again the integration effort to migrate would scare any leader who would be blame for the impa…
Except that confluence and JIRA are both so slow that you'll still be there 2 minutes later waiting for it to load. Perhaps not everybody's experience is so bad? I don't understand how anyone could consider these products convenient given how ridiculously slow they were.
We used to do refinement meetings over video call (I guess everyone is these days) inputting into JIRA, and we'd literally spend 3/4's of the call waiting for JIRA to catch up with the words I'd typed. There's bad engineering, and then there's making writing a sentence text box lag with times measures in seconds.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#153I hope they can find what they are looking for, because, with the built-in search, I sure can’t.
It is awful, the worst "search engine" which exists. I absolutely hate it and this is the only thing which wants to make me move away from Confluence. When you need it the most, and this happens often, you know that you definitely cannot rely on it. Any data you put in there is lost, unless you have a good hierarchy and know what to find where without relying on the search.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#154I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.
Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#155The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…
The rest of this your comment reads like you continue to be naive to Atlassian’s success. I have to think many people do find unique value in their products (myself included), some people don’t laugh rudely when they hear what folks are working on, and I think that shows in the overall achievements of the Atlassian team and product.
I’ve witnessed first hand truly fantastic organizational changes after adopting Jira, Confluence, etc., and I wouldn’t continue to write them off so easily.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#156> The vulnerability only affects on-premise servers, not those hosted in the cloud. This is a dangerous statement to make and should be revised to say: > The vulnerability only affects standalone versions of the software, not the managed service of confluence provided directly by Atlassian. The problem with the former is that lesser technical people, especially directors, might assume they're fine because their stand…
99% agreed. Reserving 1% because I'd strike "lesser technical" from your final sentence. The misleading quote is simply not correct. It is misleading because it's not true. It says Confluence hosted in the cloud is not vulnerable. False statement that can mislead anyone regardless of how technical they are.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#157Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#158I hope they can find what they are looking for, because, with the built-in search, I sure can’t.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#159Twitter link to a case of the vulnerability being exploited: https://twitter.com/th3_protoCOL/status/1433414685299142660 NIST Link to issue: https://nvd.nist.gov/vuln/detail/CVE-2021-26084 Tweet from USCYBERCOM urging users to patch: https://twitter.com/CNMF_CyberAlert/status/14337876717851852... Tweet from BadPackets showing where the bad actors are originating from: https://twitter.com/bad_packets/status/1433157632…
But on the “attacks coming from”, I’ve never understood putting stock in these. Aren’t these all going to be proxies and botnets?
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#160My employer was bit by this on Wednesday. Thankfully we had Crowdstrike on it which blocked any real damage. But it definitely moved our cloud migration from “later this year” to “later this month”. Also, not having confluence for a day exposed just how reliant we were on it for day-to-day activities.
> Thankfully we had Crowdstrike on it which blocked any real damage For someone not familiar with their products, what did they do for you specifically?
FWIW, we dumped crowdstrike for Cisco AMP and have been happy.