Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

181–190 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#182

Earlier quoted context omitted.

So yes or no were a bunch of Microsoft products hacked?

Definitively no. It was not a hack at all. It was misconfigured software running inside the kernel. The issue was this misconfiguration was "urgently pushed" from Crowdstrike and depending on who you believe it overrode customer testing policies.

So a bunch of Linux systems were compromised or a bunch of Widows?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#183

Earlier quoted context omitted.

I mean, dumber things have happened. Governments have destroyed their own government buildings to blame on the opposition and gain sympathy for their causes.

Yes, false flags. That's usually used to motivate people to go attack someone or to garner sympathy or support for a cause. MS's products being subject to attacks because they have numerous vulnerabilities does not encourage anyone to go out and buy other MS products. You sink one of your own naval vessels (or it sinks due to an accident and you take advantage of the situation) and blame it on an enemy. That enemy is…

What you say is true everywhere but in a monopoly, and on that I've got bad news for you.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#185

Wasn’t Microsoft just recently using Chinese people living in China to administer DOD servers? I would guess they use Sharepoint inside the DOD?

Says this in the article: > A programming flaw in its cloud services also allowed China-backed hackers to steal email from federal officials. On Friday, Microsoft said it would stop using China-based engineers to support Defense Department cloud-computing programs after a report by investigative outlet ProPublica revealed the practice, prompting Defense Secretary Pete Hegseth to order a review of Pentagon cloud deals…

Excuse me??

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#187
post #84
post #24

At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…

It’s impossible to stop using M365 while stopping usage of SharePoint (cloud or on-premises). See https://news.ycombinator.com/item?id=44640219 Here’s just one example: Each M365 Teams Team creates an M365 Group which creates a SharePoint site and Exchange mailbox. Teams channel files are stored in that SharePoint site. Teams channel messages are stored in the Exchange mailbox. Private files dropped in Teams are stor…

CORRECTION: Chats are only journaled to Exchange mailboxes for data compliance. Messages are actually stored in Cosmos DB. https://youtu.be/V6B4KraD-FM?feature=shared&t=319

Contacts and voicemail are stored in Exchange.

Diagram of data storage locations: https://youtu.be/V6B4KraD-FM?feature=shared&t=454

M365 Groups are still SharePoint + Exchange.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#188
post #177
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

> Isn't security the number one priority in those spaces? Money changing hands between suitable people who pop up together at the right social occasions is the priority.

This though is also true in the private sector.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#189

Earlier quoted context omitted.

Best practice is to assume the network is compromised - a VPN doesn't provide as much guarantee as people would like. In large fleets, devices are regularly lost, damaged, retired, etc. In organizations with high target value, physical penetration through any number of means should be assumed. So you don't do that. You use zero trust and don't care that things are exposed to the internet. Working from anywhere (remot…

Microsoft’s version of “Zero Trust” doesn’t care if things are reachable from the public internet. They have been preaching “identity is the new perimeter” [1] for years, and it doesn’t wash. The NIST Zero Trust Architecture (ZTA) implementation guides (SP 1800-35) [2] cut through the nonsense and AI generated marketing smoke. In ZTA, ALL network locations are untrusted. Network connections are created by a Policy En…

> several pillars are missing from their “Zero Trust” marketing materials.

TBH several pillars are missing from their entire security posture.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#190

I have spent far too much of my life on SharePoint. Having it internet facing has never been a good idea. Not really what it is meant for, though the promo verbiage on that has changed over different versions. Some folks wanted SharePoint as their "web server", I would set that installation up entirely separted from all other instances they may have on the network.

Actually it wasn't too long ago, in the early-2010's, that Microsoft was promoting SharePoint for internet sites; I think at one point some Europoean car manufacturer (BMW? Ferrari?) had their global marketing site on SharePoint. Of course that didn't last long, as Microsoft licensed it at a crazy price ($40k per site or something like that).

And it probably needed a very hefty bunch of servers, even after caching, if you needed just a little bit of dynamic content or interaction with the site.
Post reply on HN