Earlier quoted context omitted.
Where may I learn more about exactly how they are "garbage fires on the inside"? Thanks
First you need a fire starter, which in this case must be made out of bills valued 100 USD each or greater. It'll take quite a few to light the Datacenter licenses that are the now the only on-prem tier on fire...
US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
281–290 of 344 posts
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#282Earlier quoted context omitted.
In Confluence you use the {code} macro.
Confluence's code blocks are hot garbage: * Selecting a language on one code block changes the languages for other code blocks on the same page, sometimes. (I've not figured out the exact conditions on this one yet.) * Whitespace is not preserved / rendered the same as the editor; we have several Confluence pages with YAML where the rendered version won't parse, but it looks fine in the editor. Give me Markdown in gi…
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#283The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…
That might be the most disconnected-from-reality statement in this entire discussion.
Whatever you think about the quality of Atlassian's products, they are ridiculously entrenched and about as easy to "disrupt" as Microsoft Windows.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#284Admittedly low-value comment: Can we appreciate the amazing vulnerability name? Confluenza. https://censys.io/blog/cve-2021-26084-confluenza/
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#285Earlier quoted context omitted.
FYI: Shodan also does monthly hostname-based scans of the Internet where we set the "Host"/ SNI headers. We use our own DNS DB to grab a list of hostnames/ IPs to launch scans of: https://www.shodan.io/domain/ycombinator.com At the moment, I think we're checking around 600 million hostnames.
Is that DNS DB publicly accessible?
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#286Earlier quoted context omitted.
However, one does not conclude from the other as is insinuated in the comment.
If all products have CVEs, and CVEs are a form of defect, then it follows quite naturally that highly defective products will have CVEs, likely more than less defective products. So yes. Yes it does. Unless you meant that CVEs imply garbage code, in which case I think you read the comment wrong.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#287Earlier quoted context omitted.
> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))
Spolsky’s FogBugz is still out there after a few ownership changes, and is still a hell of a lot less painful to use than Jira.
Kiln was also a great product and allowed for using both Git and Mercurial. It was way better than anything else at the time, but lost out to Github.
I always liked Spolsky's Evidence Based Scheduling that was built into the products.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#288Earlier quoted context omitted.
> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…
I don’t disagree with what you’re saying about software having ongoing vulnerability issues. But, that’s exactly what the problem is with communications-centric solutions that don’t offer strong data security protections such as end-to-end encryption: you’re always one CVE away from having your company’s data exposed. And, in this specific case, there is a MAJOR difference between Chrome getting owned, and the progra…
Imagine being so naive as to think that documentation would be improved by e2e encryption. It's not bad enough convincing developers to write things down, now we need to explicitly share those things with every new person who joins the team?
"Sorry, we can't fix your bug for 6 weeks, Bob's on paternity and the fix is documented on his page".
> MAJOR difference between Chrome getting owned, and the program that hosts all of a company’s internal communications
There's at best 0 difference between these things. Pop chrome, harvest tokens, access Jira. Think about that for a second. What critical company information is not accessible to someone who has arbitrary code execution in your browser.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#289Earlier quoted context omitted.
I use both Jira and Confluence (cloud version) on a 6 year old Dell laptop and have no performance issues. Maybe I'm closer to their servers. Or you're using Safari.
Nope, I’m using Chrome / Firefox and it’s a common enough problem that Atlassian sluggishness has been a running joke on multiple teams I’ve been on. Maybe I should measure it and post somewhere, I thought it was a well-known problem but maybe there’s something different about our setups.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#290Earlier quoted context omitted.
> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…
I don't remember a company like whatsapp having this kind of problems.
Perhaps you should consider that not knowing a thing is very, very different than that thing not being true...