Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

211–220 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#211
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

I can assure you, the DoD isn't a bunch of windows servers hosting sharepoint for the public. Federal government IT in general is a RHEL shop, at least serverside.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#212

Earlier quoted context omitted.

Actually it wasn't too long ago, in the early-2010's, that Microsoft was promoting SharePoint for internet sites; I think at one point some Europoean car manufacturer (BMW? Ferrari?) had their global marketing site on SharePoint. Of course that didn't last long, as Microsoft licensed it at a crazy price ($40k per site or something like that).

I worked on a couple of public facing SharePoint 2010 sites for large, well known companies before while it was in RC and immediately after - MS had a big marketing push to get people to build more than Intranet portals on it at the time. It seems like that died off entirely once Office 365 came around, and it was never a good idea in the first place, but it was definitely a thing.

2013 literally came with a tool to built a theme from your html and css and other features for hosting web sites.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#213

Wasn’t Microsoft just recently using Chinese people living in China to administer DOD servers? I would guess they use Sharepoint inside the DOD?

Says this in the article: > A programming flaw in its cloud services also allowed China-backed hackers to steal email from federal officials. On Friday, Microsoft said it would stop using China-based engineers to support Defense Department cloud-computing programs after a report by investigative outlet ProPublica revealed the practice, prompting Defense Secretary Pete Hegseth to order a review of Pentagon cloud deals…

Absolutely insane. Especially in light of their layoffs. Should be criminal. According to another comment in the thread, it is?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#214
Something to understand about the word “leak” is that it implies at some point it was keeping things in. Microsoft security is so underfunded and garbage, it is fundamentally making technology as a whole unsafe.

Example: if Kroger or whatever your supermarket of choice distributed meat that was infected they would get sued to bits. Microsoft distributes thousands of malicious NPM dependencies and underfund the NPM security team - if there is such a thing - resulting in an entire industry of supplychain security companies to exist. No other registry has the issue of malicious packages as badly as NPM since Microsoft acquired Github.

Microsoft just does not know how to handle security, which is why so many security companies exist to fill their gaps. I don’t trust their security practices one bit tbh.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#215

Earlier quoted context omitted.

Best practice is to assume the network is compromised - a VPN doesn't provide as much guarantee as people would like. In large fleets, devices are regularly lost, damaged, retired, etc. In organizations with high target value, physical penetration through any number of means should be assumed. So you don't do that. You use zero trust and don't care that things are exposed to the internet. Working from anywhere (remot…

Microsoft’s version of “Zero Trust” doesn’t care if things are reachable from the public internet. They have been preaching “identity is the new perimeter” [1] for years, and it doesn’t wash. The NIST Zero Trust Architecture (ZTA) implementation guides (SP 1800-35) [2] cut through the nonsense and AI generated marketing smoke. In ZTA, ALL network locations are untrusted. Network connections are created by a Policy En…

> Network connections are created by a Policy Engine that creates and tears down tunnels to each resource dynamically using attribute-based-access-controls (ABAC). Per request.

What does it mean in technical terms? What kind of tunnels are whose and what is their purpose?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#216
post #203
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Microsoft invested in making integrated Windows-based business software and a big closed-source ecosystem and/or bought other tech companies that previously developed similar tech. Some of them older than Red Hat even Microsoft. Where is the equivalent tech on the Linux side that Red Hat developed? They simply didn't have a competitive enough alternative. Usually anything outside of cloud/web server space, you'd find…

Most government IT is using RHEL. You are correct, it is because of the thankless work they put into long term enterprise support. Microsoft doesn't do anything like that.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#217
post #174

Earlier quoted context omitted.

Zero trust is when every session with every service is like its own VPN, independently authenticated and encrypted. Consider the way an HTTPS session between a server and a browser is created anew every time the browser accesses a domain, and ends after a short flurry of requests needed to load a page.

Almost sounds like “zero trust” is classic HTTPS authentication with extra marketing added…

There's a significant difference which my original message hints at and is subsequently clarified: there's still an intermediary. If there's an exploit in the service, like this case, it's still not directly exposed. The intermediary device is still sitting in between and won't allow any old traffic through without separate authorization

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#218
post #58

Earlier quoted context omitted.

Google Docs and Libre Office both produce compatible documents. There's really no reason to force one or the other. It's just conflating needs. Document editing and file storage are two different tasks. It's weird that people want everything integrated. It's not much effort to just drag and drop a file into G-Drive, OneDrive, Dropbox, box.com...

> It's not much effort to just drag and drop a file into … OneDrive … See, there’s the problem. Once you touch anything M365, you’re using SharePoint. People see SharePoint as a document collaboration tool. But, in reality, it’s real use is as a data storage platform.

Which is so funny because it was a pain in the ass on prem to make sharepoint work for that purpose. Silly item restrictions, complaints about database sizes (which stored the files), etc

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#219

Earlier quoted context omitted.

Clearly Sharepoint is being used. Otherwise, this would not be a news story. So if every single Sharepoint user switched to another piece of software, it would be more than nobody using it.

I think you missed the joke here, being that Sharepoint is installed in many of orgs, but never used after installation. I have worked at an org that did the same. We already had Confluence. Somebody decided we needed Sharepoint. We licensed and installed it. Six months later we migrated the handful of documents and files and decommissioned it.

> I think you missed the joke here,

probably so. every corp I've worked for that had Sharepoint used it religiously. that is a whopping 3 different companies, but > 1 anecdotal experience. to be fair though, 2 of the 3 companies used it because the same person was at both companies and was responsible for using it at both companies during their tenure.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#220

Earlier quoted context omitted.

This vuln might have existed before Copilot received that title bump. It could have been introduced while Copilot was just an intern

It's safe to say at this point. The more Microsoft relies on Copilot to solve its security problems, the more problems Microsoft will have.

Sounds like job security for Copilot!
Post reply on HN