Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

261–270 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#261
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…

Going Mac in an enterprise environment is a stupid move. Apple is constantly changing how MDM works. One week they'll go all-in on some method of doing things, and tell everyone they must comply or GTFO. The next week they'll completely change their minds and gaslight you, saying that old way is stupid and nobody should have ever used it ever. Then they will put in blocks to prevent it from working. This means all the work and tooling that people poured into it are just dead.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#262

Earlier quoted context omitted.

This though is also true in the private sector.

In the private sector, there's a slightly more direct link between job underperformance and being fired.

And if your strategy fails, you (usually) can't raise taxes to make up for lost revenue. So there is an even more direct link between underperformance and losing money.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#264
post #226

Earlier quoted context omitted.

Makes “zero trust” sound like basic username/password from ancient times.

Think machine certs (stored in a TPM). Plus perimeter-enforced username/password/2FA. Plus additional policy checks, like making sure your machine is up to date on security patches. It doesn’t matter what network you are connecting from, but it does matter that you’re connecting from a company-issued laptop that’s in a trustworthy state.

Sounds like multiple single points of failure to make a security infrastructure so hostile to the end user it would be considered the equivalent of being under persistent attack.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#265
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

I do wonder if the fact that these vulnerabilities get exploited so often is because the customers are the likes of DoD. If DoD used Red Hat, maybe we'd see more large-scale linux/freedesktop exploits being discovered.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#267
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

> when more secure (Linux-based) options are far cheaper and widely deployed

Hold on, we are talking about SharePoint here. I don't know any software that could replace it, that is allowing office suite to collaborate in a way SharePoint Server does it (versioning, concurrent editing, online editing, workflows, customizations, OneDrive, IRM, compliance, search etc.)

Even in a windows environment. Can you name more secure, cheaper and widely deployed alternative?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#268

Earlier quoted context omitted.

They're using Microsoft because all of the alternatives have the same issues. FOSS isn't magically immune to vulnerabilities. It doesn't help that the FOSS community generally prefers the C programming language over more modern and safer alternatives as a cultural thing. The result is just as many vulnerabilities, if not more, per line of code or per feature. Keep in mind that SharePoint is an enormous product with a…

I mean.. people contributing to FOSS generally program in what they know - i.e. I have some time to contribute, I'll spend 10 productive hours in C, because I know what I'm doing, vs. learning Rust only to spend 30 hours and not really getting anything done. I contributed to a Tcl/Tk library that I was using at work that had a specific issue with some image files, so I fixed it internally, and contributed the fix bac…

People working at Microsoft in the SharePoint team also program in a language/framework they know (and they must be masochists if they're working with ASP.NET WebForms). Knowledge of the language doesn't prevent vulnerabilities.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#269
post #249

Earlier quoted context omitted.

"Hardware support for Linux PCs is poor and lacks the manageable of Windows PCs with Active Directory and GPO, or JAMF for Macs. Enterprise software usually doesn't support Linux. Linux PCs are uncommon for personal use and corporations don't want to train users how to use Linux." I would dispute the "hardware support" comment. Linux has pretty good hardware support nowadays. And "enterprise" software is a vague term…

There are still plenty of issues with bluetooth, batteries, microphones, gpus, touchpads etc when doing a clean install of Ubuntu on any random laptop.

[deleted]

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#270
post #249

Earlier quoted context omitted.

"Hardware support for Linux PCs is poor and lacks the manageable of Windows PCs with Active Directory and GPO, or JAMF for Macs. Enterprise software usually doesn't support Linux. Linux PCs are uncommon for personal use and corporations don't want to train users how to use Linux." I would dispute the "hardware support" comment. Linux has pretty good hardware support nowadays. And "enterprise" software is a vague term…

There are still plenty of issues with bluetooth, batteries, microphones, gpus, touchpads etc when doing a clean install of Ubuntu on any random laptop.

Enterprise and government don't use random laptops.
Post reply on HN