Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

211–220 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#211

Earlier quoted context omitted.

The thing I've found is that Jira has so many fields on its tickets that beg to be filled in, that PMs start filling them in, and before you know it they're all mandatory and must be filled in. And organising that much state in the tickets becomes a full-time job, and so the PM ends up doing that - managing the state of Jira rather than managing the state of the project. The two become synonymous when they're not. Wh…

So basically you are describing an organization of people that don't really understand what they should be doing. People led by a tool and not the other way around - and you blame the tool? I hear what you are saying, and I've seen the very symptoms you're describing - I've just stopped chalking it down to the tools. It's a symptom of something entirely different and much more challenging to deal with than a change i…

If you provide a tool that let's managers easily and arbitrarily increase the requirements on their employees, over time they'll continue to do so, because it's a management tool and their job is to manage.

I experienced this phenomenon when I was a designer / CNC programmer. We had a form for requesting a part to be designed and machined. It had a box for tolerance allowance, where the person requesting a part could specify how tight all the tolerances should be, and we had recently added in 0.0005 inches to the options, at the request of a customer. I left for a month to do training at another location and came back to find a ridiculously long backlog of work. The manager who'd stepped in for me had decided that tighter tolerances would make better products, so was selecting 0.0005" tolerance for every feature on every part.

To make up for how ridiculously slow that made the machining process, he tried to micro-optimize work flows, readjust hours, push machine operators to "work harder". He wasn't a bad person, was an okay manager, we'd just given him the option of doing something stupid, and he'd done it then tried to use his managing skills to make it work.

If you give someone the tool to do their job, make sure that misusing it feels hard.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#213

I look up to Atlassian. Somehow they continue to easily sell even though so many hates it. I don't know what the secret sauce is... but I want it.

It's like Microsoft in the 90s, everyone wants to hate on the company but their sales department just laughs and pens another huge contract

Atlassian doesn't have a sales department (or at least this was the case for well over a decade, perhaps it could have changed now).

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#214

Earlier quoted context omitted.

> There aren’t good integrated replacements I think even that would be a good attack vector against Atlassian: For them, "integration" means adding links from one product to the other. If I were to pay for an integrated suite of tools, the least I would expect is that their bloody markup languages are consistent. But because Atlassian just buys random products and then doesn't seem to ever change a single thing about…

That’s false: Confluence went from Wikimarkup in 2008 to wysiwyg in 2010 (to big uproars); and they are uniformizing all their cloud products under the new ADF editor.

Thanks, that's good to hear. A quick Google search makes it sound like it will finally be possible to use `backticks` for code everywhere.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#215
post #74

Earlier quoted context omitted.

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement. You can't easily dump Jira if you are using Jira, confluence, bitbucket, and whatever their CI/CD product is called (bamboo?)

GitLab has wikis, CI/CD and sprint / issue / project management features. We use it at $DAY_JOB and while not perfect it's a pretty great offering.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#217
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

I can see how you jumped to the conclusion this CVE means Atlassian is nonsense, but it’s not the only take on the comment. The discussion arising from a

I’m not really sure what the point of the rant is. It’s not as if such a comment conclusion is as big of deal to reality as an idiot staying unvaccinated.

But I get it; someone is “wrong”* on the internet.

* where wrong is defined very specifically to one or a handful of particular readers but the error doesn’t rise to being a real problem for humanity

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#218

Earlier quoted context omitted.

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

Where may I learn more about exactly how they are "garbage fires on the inside"?

Thanks

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#220
post #111
post #84

Earlier quoted context omitted.

Hit the nail on the head there. New thing? Let’s open a new JIRA project and prefix with some random shit show workflow customised by someone who was clearly asleep or incompetent!

Yup, have been in that exact situation. It was literally mind-boggling.

Ow.
Post reply on HN