We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…
Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
211–220 of 456 posts
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#212Earlier quoted context omitted.
Actually it wasn't too long ago, in the early-2010's, that Microsoft was promoting SharePoint for internet sites; I think at one point some Europoean car manufacturer (BMW? Ferrari?) had their global marketing site on SharePoint. Of course that didn't last long, as Microsoft licensed it at a crazy price ($40k per site or something like that).
I worked on a couple of public facing SharePoint 2010 sites for large, well known companies before while it was in RC and immediately after - MS had a big marketing push to get people to build more than Intranet portals on it at the time. It seems like that died off entirely once Office 365 came around, and it was never a good idea in the first place, but it was definitely a thing.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#213Wasn’t Microsoft just recently using Chinese people living in China to administer DOD servers? I would guess they use Sharepoint inside the DOD?
Says this in the article: > A programming flaw in its cloud services also allowed China-backed hackers to steal email from federal officials. On Friday, Microsoft said it would stop using China-based engineers to support Defense Department cloud-computing programs after a report by investigative outlet ProPublica revealed the practice, prompting Defense Secretary Pete Hegseth to order a review of Pentagon cloud deals…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#214Example: if Kroger or whatever your supermarket of choice distributed meat that was infected they would get sued to bits. Microsoft distributes thousands of malicious NPM dependencies and underfund the NPM security team - if there is such a thing - resulting in an entire industry of supplychain security companies to exist. No other registry has the issue of malicious packages as badly as NPM since Microsoft acquired Github.
Microsoft just does not know how to handle security, which is why so many security companies exist to fill their gaps. I don’t trust their security practices one bit tbh.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#215Earlier quoted context omitted.
Best practice is to assume the network is compromised - a VPN doesn't provide as much guarantee as people would like. In large fleets, devices are regularly lost, damaged, retired, etc. In organizations with high target value, physical penetration through any number of means should be assumed. So you don't do that. You use zero trust and don't care that things are exposed to the internet. Working from anywhere (remot…
Microsoft’s version of “Zero Trust” doesn’t care if things are reachable from the public internet. They have been preaching “identity is the new perimeter” [1] for years, and it doesn’t wash. The NIST Zero Trust Architecture (ZTA) implementation guides (SP 1800-35) [2] cut through the nonsense and AI generated marketing smoke. In ZTA, ALL network locations are untrusted. Network connections are created by a Policy En…
What does it mean in technical terms? What kind of tunnels are whose and what is their purpose?
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#216We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…
Microsoft invested in making integrated Windows-based business software and a big closed-source ecosystem and/or bought other tech companies that previously developed similar tech. Some of them older than Red Hat even Microsoft. Where is the equivalent tech on the Linux side that Red Hat developed? They simply didn't have a competitive enough alternative. Usually anything outside of cloud/web server space, you'd find…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#217Earlier quoted context omitted.
Zero trust is when every session with every service is like its own VPN, independently authenticated and encrypted. Consider the way an HTTPS session between a server and a browser is created anew every time the browser accesses a domain, and ends after a short flurry of requests needed to load a page.
Almost sounds like “zero trust” is classic HTTPS authentication with extra marketing added…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#218Earlier quoted context omitted.
Google Docs and Libre Office both produce compatible documents. There's really no reason to force one or the other. It's just conflating needs. Document editing and file storage are two different tasks. It's weird that people want everything integrated. It's not much effort to just drag and drop a file into G-Drive, OneDrive, Dropbox, box.com...
> It's not much effort to just drag and drop a file into … OneDrive … See, there’s the problem. Once you touch anything M365, you’re using SharePoint. People see SharePoint as a document collaboration tool. But, in reality, it’s real use is as a data storage platform.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#219Earlier quoted context omitted.
Clearly Sharepoint is being used. Otherwise, this would not be a news story. So if every single Sharepoint user switched to another piece of software, it would be more than nobody using it.
I think you missed the joke here, being that Sharepoint is installed in many of orgs, but never used after installation. I have worked at an org that did the same. We already had Confluence. Somebody decided we needed Sharepoint. We licensed and installed it. Six months later we migrated the handful of documents and files and decommissioned it.
probably so. every corp I've worked for that had Sharepoint used it religiously. that is a whopping 3 different companies, but > 1 anecdotal experience. to be fair though, 2 of the 3 companies used it because the same person was at both companies and was responsible for using it at both companies during their tenure.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#220Earlier quoted context omitted.
This vuln might have existed before Copilot received that title bump. It could have been introduced while Copilot was just an intern
It's safe to say at this point. The more Microsoft relies on Copilot to solve its security problems, the more problems Microsoft will have.