Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

281–290 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#281

Earlier quoted context omitted.

Where may I learn more about exactly how they are "garbage fires on the inside"? Thanks

First you need a fire starter, which in this case must be made out of bills valued 100 USD each or greater. It'll take quite a few to light the Datacenter licenses that are the now the only on-prem tier on fire...

So... you do not, in fact, have an answer to the question?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#282

Earlier quoted context omitted.

In Confluence you use the {code} macro.

Confluence's code blocks are hot garbage: * Selecting a language on one code block changes the languages for other code blocks on the same page, sometimes. (I've not figured out the exact conditions on this one yet.) * Whitespace is not preserved / rendered the same as the editor; we have several Confluence pages with YAML where the rendered version won't parse, but it looks fine in the editor. Give me Markdown in gi…

Dunno about all that but it doesn't support inline code snippets. You've gotta use formatted text, which doesn't look good. Seems like an intern project at best.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#283
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

>It’s only a matter of time before this product suite is disrupted, and it might represent one of the most obvious low-hanging opportunities in our entire industry.

That might be the most disconnected-from-reality statement in this entire discussion.

Whatever you think about the quality of Atlassian's products, they are ridiculously entrenched and about as easy to "disrupt" as Microsoft Windows.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#285

Earlier quoted context omitted.

FYI: Shodan also does monthly hostname-based scans of the Internet where we set the "Host"/ SNI headers. We use our own DNS DB to grab a list of hostnames/ IPs to launch scans of: https://www.shodan.io/domain/ycombinator.com At the moment, I think we're checking around 600 million hostnames.

Is that DNS DB publicly accessible?

Yes, via the API. Btw all of our websites are entirely built on the same public Shodan API that everybody else has access to.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#286

Earlier quoted context omitted.

However, one does not conclude from the other as is insinuated in the comment.

If all products have CVEs, and CVEs are a form of defect, then it follows quite naturally that highly defective products will have CVEs, likely more than less defective products. So yes. Yes it does. Unless you meant that CVEs imply garbage code, in which case I think you read the comment wrong.

It follows in theory but may not in practice. Certain software may have lots of defects that are not CVEs.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#287
post #255

Earlier quoted context omitted.

> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))

Spolsky’s FogBugz is still out there after a few ownership changes, and is still a hell of a lot less painful to use than Jira.

It was innovative 13 years ago, but never really caught on.

Kiln was also a great product and allowed for using both Git and Mercurial. It was way better than anything else at the time, but lost out to Github.

I always liked Spolsky's Evidence Based Scheduling that was built into the products.

https://fogbugz.com/evidence-based-scheduling/

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#288
post #179

Earlier quoted context omitted.

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

I don’t disagree with what you’re saying about software having ongoing vulnerability issues. But, that’s exactly what the problem is with communications-centric solutions that don’t offer strong data security protections such as end-to-end encryption: you’re always one CVE away from having your company’s data exposed. And, in this specific case, there is a MAJOR difference between Chrome getting owned, and the progra…

> don’t offer strong data security protections such as end-to-end encryption

Imagine being so naive as to think that documentation would be improved by e2e encryption. It's not bad enough convincing developers to write things down, now we need to explicitly share those things with every new person who joins the team?

"Sorry, we can't fix your bug for 6 weeks, Bob's on paternity and the fix is documented on his page".

> MAJOR difference between Chrome getting owned, and the program that hosts all of a company’s internal communications

There's at best 0 difference between these things. Pop chrome, harvest tokens, access Jira. Think about that for a second. What critical company information is not accessible to someone who has arbitrary code execution in your browser.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#289

Earlier quoted context omitted.

I use both Jira and Confluence (cloud version) on a 6 year old Dell laptop and have no performance issues. Maybe I'm closer to their servers. Or you're using Safari.

Nope, I’m using Chrome / Firefox and it’s a common enough problem that Atlassian sluggishness has been a running joke on multiple teams I’ve been on. Maybe I should measure it and post somewhere, I thought it was a well-known problem but maybe there’s something different about our setups.

I have seen on premise issues , infrastructure can be the problem, or config. Jira cloud can also be a problem,but nothing one can do about it other than sending a ticket. I think they know what they are doing wrong with certain "low value" subscriptions.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#290
post #207

Earlier quoted context omitted.

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

I don't remember a company like whatsapp having this kind of problems.

(note that this is not a complete list) CVE-2021-24026 CVE-2021-24027 CVE-2020-1891 CVE-2020-1909 CVE-2019-11933

Perhaps you should consider that not knowing a thing is very, very different than that thing not being true...

Post reply on HN