Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

271–280 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#271
post #94

Earlier quoted context omitted.

What can confluence do what XWiki cannot? But i understand that you try to promote your cloud offering ;)

Confluence can take text and turn it into a black box format shoved inside a database that you can't edit with a real editor, then shove that text into a black box unstandardized version control system shoved inside a database! Take that, other tools!

> black box format shoved inside a database

Are you drunk? Who tf ever wants that?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#272

Earlier quoted context omitted.

Is there a way to quickly mark a block as code? Because whatever nice feature it has are completely rendered irrelevant by this lack.

In Confluence you use the {code} macro.

Confluence's code blocks are hot garbage:

* Selecting a language on one code block changes the languages for other code blocks on the same page, sometimes. (I've not figured out the exact conditions on this one yet.)

* Whitespace is not preserved / rendered the same as the editor; we have several Confluence pages with YAML where the rendered version won't parse, but it looks fine in the editor.

Give me Markdown in git any day.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#274

I look up to Atlassian. Somehow they continue to easily sell even though so many hates it. I don't know what the secret sauce is... but I want it.

This is the power of meeting the "needs" of business side suits who don't know how to use git or a real editor. So many times I've gotten pushback about writing docs in git instead of in confluence because "what about the non-technical people, what if they need to edit something?". So the lesson learned is that if you can use your proprietary vendor lock in to trap a bunch of C-levels via stockholm syndrome you can j…

What's ironic...is instead of educating and offering a workable alternative, you actually made the problem worse and the sale easier for Atlassian!

No, the rest of the company shouldn't be required to enter the complex and esoteric world of Git and fire up a terminal + a bloated code editor and deal with merge conflicts just so they can collaborate on a simple text doc.

This reads like a horror story I'd find on the landing page of some Saas tool under a heading that reads, "The Problem"

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#275
post #271

Earlier quoted context omitted.

Confluence can take text and turn it into a black box format shoved inside a database that you can't edit with a real editor, then shove that text into a black box unstandardized version control system shoved inside a database! Take that, other tools!

> black box format shoved inside a database Are you drunk? Who tf ever wants that?

Sorry, must have lost some context... nobody wants that if they know what they are doing. I don't want it. I'm saying this is the reality behind confluence. (and I don't like it either!)

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#276
post #255

Earlier quoted context omitted.

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))

Is TFS no longer considered a competitor? Feels like it should have been the first mentioned here. Not saying TFS is problem-free, of course.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#277

Earlier quoted context omitted.

This is the power of meeting the "needs" of business side suits who don't know how to use git or a real editor. So many times I've gotten pushback about writing docs in git instead of in confluence because "what about the non-technical people, what if they need to edit something?". So the lesson learned is that if you can use your proprietary vendor lock in to trap a bunch of C-levels via stockholm syndrome you can j…

What's ironic...is instead of educating and offering a workable alternative, you actually made the problem worse and the sale easier for Atlassian! No, the rest of the company shouldn't be required to enter the complex and esoteric world of Git and fire up a terminal + a bloated code editor and deal with merge conflicts just so they can collaborate on a simple text doc. This reads like a horror story I'd find on the…

> No, the rest of the company shouldn't be required to enter the complex and esoteric world of Git and fire up a terminal + a bloated code editor and deal with merge conflicts just so they can collaborate on a simple text doc.

Instead, they just won't update the doc at all and will pester the kind of person who does know how to use git until they do it for them. Then the doc will sit there dormant and un-updated until the process repeats.

> a bloated code editor

Have you ever used Confluence? SMH.

All those defending Atlassian need to go read this other current front page hn article: https://news.ycombinator.com/item?id=28414308 and probably lots of other articles about good documentation.

To be fair, I understand what you are saying, but the problem is you are trying to meet the needs of suits, while I'm trying to meet the needs of technical teams. I can acknowledge that git can be daunting for suits, and probably not the correct method for them to write docs, (e.g., I'm not saying force the suits to use git, even though, with a web interface like GHE or gitlab etc, this is actually quite easy and visually intuitive, no terminal or (laughing) "bloated code editor" required) but it seems the "suits side" of this argument doesn't want to acknowledge that the needs of technical teams aren't being met when they force their lowest common denominator tool on the entire org.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#279

I hope they can find what they are looking for, because, with the built-in search, I sure can’t.

I use this browser extension which seems OK https://chrome.google.com/webstore/detail/confluence-quick-s...

We have an internal search engine. It made Confluence usable.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#280

Earlier quoted context omitted.

I think they’re talking about the front-end, not the server. FWIW both Confluence and Jira are abysmally slow on my machine (new MBP) on the cloud version.

I use both Jira and Confluence (cloud version) on a 6 year old Dell laptop and have no performance issues. Maybe I'm closer to their servers. Or you're using Safari.

Nope, I’m using Chrome / Firefox and it’s a common enough problem that Atlassian sluggishness has been a running joke on multiple teams I’ve been on.

Maybe I should measure it and post somewhere, I thought it was a well-known problem but maybe there’s something different about our setups.

Post reply on HN