Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

221–230 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#221
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows.

But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to overtake Windows enterprise machine usage.

Hardware support for Linux PCs is poor and lacks the manageable of Windows PCs with Active Directory and GPO, or JAMF for Macs. Enterprise software usually doesn't support Linux. Linux PCs are uncommon for personal use and corporations don't want to train users how to use Linux.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#222
post #159

If I am ever on the board of a company, I will always vote no confidence in the dipshit CTO or founder that willingly install/mandate use of Microsoft junk in the company. As a corporate drone that has accidentally opened various Microsoft office suite links inside of Teams. My dislike for anything Microsoft continues to grow. Am I surprised that sharepoint has vulnerabilities? Hell no.

What would you replace it with? Once an org gets to a certain size, they need something like sharepoint, and would they be any more secure?

> they need something like sharepoint

Or probably they don't.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#223

Meanwhile, Citrix has been on fire causing much worse things (you can just grab any session you want and become anyone who's already logged in). Who needs to break into SharePoint when you're becoming someone who's already got access... including to everything else (not just SharePoint) It's patchable, but it's been two times in a row now, and patching is always slow and incomplete.

I wonder how widely this affected all 3 of Citrix customers?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#224
post #7

Another day another vulnerability with Microsoft. I wonder if this will incentivize the countries to move faster with Linux. Probably not since there are so many of these breaches people just ignore them. I miss the old days when a breach involved someone breaking into the computer room and grabbing as many mag tapes as they can carry and run :)

Genuinely asking - is there a Linux alternative to Sharepoint? I couldn't care less if it was lit on metaphorical fire and dumped into the sea, but a lot of orgs using it extensively.

> Genuinely asking - is there a Linux alternative to Sharepoint?

Genuinely asking - is there a Microsoft alternative to eBPF, k8s, nginx?

The answer is NO. Alternative to SharePoint is SharePoint. I would argue such project just not needed in general and therefor there is no 'alternative'.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#225

Earlier quoted context omitted.

Google Docs and Libre Office both produce compatible documents. There's really no reason to force one or the other. It's just conflating needs. Document editing and file storage are two different tasks. It's weird that people want everything integrated. It's not much effort to just drag and drop a file into G-Drive, OneDrive, Dropbox, box.com...

What people want are systems that compose and work well together. That's what MS provides, or at least attempts to provide, with SharePoint. When you start trying to tack on collaborative document editors, workflow management systems, shared storage, and other capabilities from different providers or systems you run into more and more complications (especially because most of these don't offer any kind of standards c…

> What people want are systems that compose and work well together.

Not really, that's managers' speak. All things SharePoint is just a data swamp.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#226

Earlier quoted context omitted.

In zero trust "exposed to the internet" is a bit of a misnomer compared to how traditional security would use the term. A better description might be "you're allowed to form a session to it from over the internet but only after your identity and set of rights have been verified". From this view: "zero trust" < "vpn" < "wide open" (in terms of exposure).

Makes “zero trust” sound like basic username/password from ancient times.

Think machine certs (stored in a TPM). Plus perimeter-enforced username/password/2FA. Plus additional policy checks, like making sure your machine is up to date on security patches.

It doesn’t matter what network you are connecting from, but it does matter that you’re connecting from a company-issued laptop that’s in a trustworthy state.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#227

Earlier quoted context omitted.

I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.

There is waste. A God awful amount of waste, fraud, and abuse. You don't rack up a 1.8 trillion deficit and a debt per capita that is 7x the income per capita without waste, fraud, and abuse. The problem is that while common sense would dictate those nonsensical expenses as such, they were part of the official process, so it was all legalized, so they avoid the FWA labels because the rule writers have made it so.

The problem with your argument is that Social Security (old people income), Medicare (old people healthcare) and interest on the national debt account for fully one half of total federal spending. Add in national defense and you reach two thirds.

Interest is trivially accounted for. We know how much debt is outstanding.

Social Security and Medicare expenditures are well within 5% of what should be expected, given the total population of the US and its age distribution.

Your God Awful amount of waste, fraud and abuse reduces to a fraction of a fraction of the total budget. A tiny fraction of a big number may be a big number, but it simply doesn't matter structurally.

The only way out is to cancel the entire military, slash social security or raise taxes. The rest of the stuff (even if it is purely waste with no useful purpose) simply doesn't add up to enough dollars to fix the budget.

I know this isn't what anyone wants to hear, but numbers are numbers and you can't just wish away unpleasant realities.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#228
post #225

Earlier quoted context omitted.

What people want are systems that compose and work well together. That's what MS provides, or at least attempts to provide, with SharePoint. When you start trying to tack on collaborative document editors, workflow management systems, shared storage, and other capabilities from different providers or systems you run into more and more complications (especially because most of these don't offer any kind of standards c…

> What people want are systems that compose and work well together. Not really, that's managers' speak. All things SharePoint is just a data swamp.

You think people don't want systems that work well together? That they want isolated apps that don't communicate or work with each other?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#229
post #159

If I am ever on the board of a company, I will always vote no confidence in the dipshit CTO or founder that willingly install/mandate use of Microsoft junk in the company. As a corporate drone that has accidentally opened various Microsoft office suite links inside of Teams. My dislike for anything Microsoft continues to grow. Am I surprised that sharepoint has vulnerabilities? Hell no.

What would you replace it with? Once an org gets to a certain size, they need something like sharepoint, and would they be any more secure?

Google Workspace. Yes.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#230
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Could be that Microsoft can navigate all the regulatory bullshit that surrounds anything government. I don't know of anyone doing that for anything Linux.

There's tons of Red Hat in federal IT, that's not the issue. It's just that Microsoft dominates the client-facing software business, and Red Hat has minimal presence there so while you might see RHEL desktops at e.g. NASA you're unlikely to see them anywhere else, and there's no real open source equivalent of SharePoint or Office out there.

Maybe [0] will be one, eventually, but it would take a long long time to replicate the functionality if it were to ever happen. Best case scenario is that the EU were to fund an open source solution.

[0] https://www.techradar.com/pro/mozilla-launching-thundermail-...

Post reply on HN