Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

231–240 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#231
post #137
post #94

Earlier quoted context omitted.

What can confluence do what XWiki cannot? But i understand that you try to promote your cloud offering ;)

I'm not trying to promote my cloud offering. I would like to be able to offer self hosting, but we still haven't found a way to do it. This is too much hassle for everyone. There is a tradeoff between ease of use of a software and the security process. A collaboration tool which is difficult to update and thus will not evolve quickly is an issue for its adoption and for its benefits. Well first its interface, if a no…

>I don't have the time to do a full comparison of other features

That should be your first prio before anyone locks one's information into your system...XWiki can import and export confluence and even wikimedia data, i never use a system when in cant import/export to the the next best product.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#232

Earlier quoted context omitted.

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

Where may I learn more about exactly how they are "garbage fires on the inside"? Thanks

First you need a fire starter, which in this case must be made out of bills valued 100 USD each or greater. It'll take quite a few to light the Datacenter licenses that are the now the only on-prem tier on fire...

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#233

Earlier quoted context omitted.

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

However, one does not conclude from the other as is insinuated in the comment.

If all products have CVEs, and CVEs are a form of defect, then it follows quite naturally that highly defective products will have CVEs, likely more than less defective products.

So yes. Yes it does. Unless you meant that CVEs imply garbage code, in which case I think you read the comment wrong.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#234

I look up to Atlassian. Somehow they continue to easily sell even though so many hates it. I don't know what the secret sauce is... but I want it.

And look at the stock. If someone told me it would ever reach $180, would have been shocked. It’s now $384. And it’s outperforming the expectations all the time. All the people who claim it is awful software, they ignore how many people love the Atlassian suite.

Not that many people “love” it, that’s why it’s always surprising how well it does. It’s pretty unpleasant to use but there isn’t really anything else out there that’s so well integrated so they keep winning despite the pain.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#235
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

On the other hand, cloud-hosted services can have a CVE patched for all users within a matter of hours (or less). Consider the alternative of frantically trying to get in contact with thousands (or tens of thousands) of companies running your on-prem version and urging each one to install your patch.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#236
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

Atlassian has a reputation for poor engineering/backend practices. It's a great (to use) product though.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#237

I look up to Atlassian. Somehow they continue to easily sell even though so many hates it. I don't know what the secret sauce is... but I want it.

They have pretty much everything in the package. You don't really have a lot of alternatives out there that are in the package.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#238

Earlier quoted context omitted.

Because you might need it to share documentation with customers. Confluence isn't just for external documentation. Confluence, at it's core, is just a wiki. Sometimes it needs to be available online, sometimes it really doesn't.

If you’re ok sharing things externally why self-host at all?

Because it’s still cheaper than cloud, it’s still not putting your data on someone else’s servers, and it’s still not being beholden to the cloud provider’s planned and unplanned outages.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#239

Earlier quoted context omitted.

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

Atlassian has a reputation for poor engineering/backend practices. It's a great (to use) product though.

Interestingly I assumed (due to personal and anecdotal experience fro colleagues) it’s not a good experience and that was part of what the parent was referring to.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#240
post #205
post #87

> The vulnerability only affects on-premise servers, not those hosted in the cloud. This is a dangerous statement to make and should be revised to say: > The vulnerability only affects standalone versions of the software, not the managed service of confluence provided directly by Atlassian. The problem with the former is that lesser technical people, especially directors, might assume they're fine because their stand…

Why do people say "on-premise" instead of "on-premises"? Here follows the definitions I am familiar with: "premise" - a house or building, together with its land and outbuildings, occupied by a business or considered in an official context. "premise" - a previous statement or proposition from which another is inferred or follows as a conclusion. (I have the privilege of worrying about this because my company uses Con…

Just say on-prem. Problem solved!

Really though, "self-hosted" would make even more sense, as companies often deploy such applications in one or more "off prem" environments anyway. I'd hardly consider my company's multi-region/multi-AZ AWS VPC to be my "premise".

Post reply on HN