Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

241–250 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#241
post #181
post #178

Earlier quoted context omitted.

And I've witnessed first hand the truly garbage nothing changes after adopting Jira and Confluence - a wasteland of process management through bad automation and forgotten wiki articles with Write Once Read Never behavior. Nothing Atlassian does is that much better than past tooling, it all comes down to how you want to run your org, what discipline you apply, and where you apply it.

I'm no fan of Jira or Confluence but you'll get forgotten wiki articles, for example, no matter what tech you choose. Confluence? Forgotten Git repos? Forgotten Notion? New hotness, still forgotten Google Docs / Office 365 ? Forgotten This is just a difficult problem to solve, especially for organisations growing at speed.

Agree, that's why I post that the discipline and management is required, not some specific tool - no tool solves the people problems adequately.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#242

Earlier quoted context omitted.

Atlassian has a reputation for poor engineering/backend practices. It's a great (to use) product though.

Interestingly I assumed (due to personal and anecdotal experience fro colleagues) it’s not a good experience and that was part of what the parent was referring to.

Coming from ClearQuest, Jira was a breathe of fresh air some years ago. We can run projects with several hundred to thousand people with it (the on prem version) without problems and UX is ok IMHO. Maybe it's easy to screw up the config?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#243
post #221

Earlier quoted context omitted.

Try to use one

Try using two of them connected together.

In order to do that, one would have to try to connect one to the other, which is usually sufficient.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#244
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

>overhearing someone ask a developer, “where do you work?” When the developer responded with “HipChat,” the other person immediately chuckled and said, “oh — Atlassian... I’m sorry” — and then everyone around them also started laughing.

Wow, This is incredibly mean.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#245

Earlier quoted context omitted.

Interestingly I assumed (due to personal and anecdotal experience fro colleagues) it’s not a good experience and that was part of what the parent was referring to.

Coming from ClearQuest, Jira was a breathe of fresh air some years ago. We can run projects with several hundred to thousand people with it (the on prem version) without problems and UX is ok IMHO. Maybe it's easy to screw up the config?

It's slow, but so long as you don't do anything “out of the ordinary” (i.e. try to act like the average sort of person who would use Jira), it's decent enough to use. I've personally had no workflow issues, though I could tell there was something deeply wrong with the internals.

Then again, if you're only using the “ordinary” features, Jira doesn't have much advantage over any other bug tracker; Gitea can integrate with Jira just as well as with any other bug tracker, and well enough that the Jira / Confluence integration isn't necessary.

The Atlassian softwares are okay, but (from my limited experience) worse than their alternatives. On several occasions, I expected a bug, but it refreshed or redirected, and there wasn't a bug. I have found no bugs while using Jira, and not unusably many while using Confluence… but I can say the same for Gitea, GitHub, Gitlab and even Bugzilla. (Gitea's native issue tracker is actually good enough – and therefore better than Jira – for everything I ever used Jira for.)

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#246
post #192

Can anyone comment on what the value of this attack is to the attackers?

Arbitrary code execution in an on-premise server? You can basically stage an attack on any other internal resources (core infrastructure, databases, endpoints) that are visible from there, with the benefit of already being behind at least one layer of firewall/security.

> Arbitrary code execution in an on-premise server?

That doesn’t explain what the benefit of the attack is. It just explains that it’s an effective attack.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#247
post #209
post #192

Can anyone comment on what the value of this attack is to the attackers?

One of the companies I know use it for HR, payroll and account receivables. If you hack into that, you can get a lot of information.

How would that information be useful?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#248
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

Downloading 20MB of javascript to view a wiki page is all I needed to know that Atlassian is a garbage fire of acquired products stitched together. Well that and spending any amount of time using it and feeling the crustiness.

Mixed frontend and backend rendering = horrific slowness and impact on productivity

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#249
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

On prem is gone and with this so is my faith in their slow cloud solution.
Post reply on HN