Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

281–290 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#281
post #239

Earlier quoted context omitted.

[flagged]

[flagged]

Sometimes it looks as if it matters more whether people are good and work in good faith rather than what a particular system is.

However, the more extreme the system (be it anarchocapitalism or communism), the higher the requirement to the goodness of people.

As is, in current societes I find that the ambient chaos of general democratic capitalism counteracts the threat of small minority making wrong decisions (Mao’s famine, etc.) while strategic regulations help curb bad actors abusing the system (like selling people poison or dumping toxic waste into rivers).

Both are needed, and I usually suspect that people who call for one extreme or the other either have an agenda or have not thought it through. (In the West it is often pro-capitalist tendencies, though I encountered both.)

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#282
The root cause might less be whether an entity uses Linux or Windows but whether they use cloud or on-prem. No matter how skilled, the on-prem stuff getting maintained by IT/SOC (often external contractors) are unlikely to deliver the same level of diligence as one of the big cloud vendors.

Things are so complex we have critical bugs everywhere that can not be patched without major breakage. So what does a diligent org do? they make a risk-assessment to explain things away for legal & compliance purposes.

check your SCA/SBOM in any/most stacks if you think this is untrue ...

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#283
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…

This suggests that the main thing Linux needs, for broader enterprise adoption, is a much improved "log into something that quacks like Active Directory" solution. Not actual Active Directory, obviously that just contributes to the lock-in, but what else is even remotely as polished and well integrated? I suspect this is the true moat actually. Nearly every actual business has "log into our company managed authentication system and have our communication and basic productivity apps just work" woven throughout the core of onboarding.

Microsoft sure has a lot of warts, but even as a Linux enthusiast, I cannot deny that Outlook "Just Works" with a frankly shocking set of basic stuff. Login for the first time, check your email, hey there's your meeting with your manager on your calendar, and now we can add new events just by putting you in this group, etc etc. There's dozens of little integrations baked in here that a tech enthusiast could feasibly replace in isolation, all of which vanish the moment you turn off the Exchange server or whatever it is. It's way more complex under the hood than most people realize, which is why "ditching Microsoft" so often turns into "Adopting Google Apps", as they have a similar turnkey solution to most of the same problems.

Not meaning to be a big ball of negativity, but as I haven't really explored here... in the FOSS space, what is the equivalent? Which tools are the most polished, and what server backends could be hosted on-prem to gain the same basic integrations with login, email, calendar, chat, and video conferencing?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#284

Earlier quoted context omitted.

This though is also true in the private sector.

In the private sector, there's a slightly more direct link between job underperformance and being fired.

> In the private sector, there's a slightly more direct link between job underperformance and being fired.

Not in my experience. Connections are most important than competence in big corporations. The bigger the company the most is works like the old Soviet Union.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#285
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

> Why do Microsoft products enjoy a monopoly on the server in these sectors when more secure (Linux-based) options are far cheaper and widely deployed already?

Because there is no FOSS solution even coming close to the level of out-of-the-box integration of Office 365. Thunderbird has zero integration with LibreOffice, LibreOffice has zero integration with Owncloud (or whatever else one might use), neither has integration with a softphone software, much less a backend like Asterisk. And some software like Sharepoint or MS Access doesn't have anything on the FOSS side.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#286

Earlier quoted context omitted.

Did you already forget about log4j?

log4j is a once in a decade event, while vulnerable Microsoft software is more like once a month.

Log4j is a Java thing divorced from the operating system running it.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#287

Earlier quoted context omitted.

Hard to square this with every startup after ~2006 running a substantial, if not majority, Mac fleet. In addition to the major tech companies.

Startups rarely use MDM solutions, that's a thing when you hit >> 1000 users because you need dedicated teams to hand-hold the MDM.

I've worked in two 5k-10k companies in the past 10 years with 80+% of MacBooks in the fleet, all managed through MDM and as an end-user I never experienced issues. Unsure how the IT folks felt about it but they managed it pretty well if I didn't experience any problems for so long.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#288

Earlier quoted context omitted.

There are still plenty of issues with bluetooth, batteries, microphones, gpus, touchpads etc when doing a clean install of Ubuntu on any random laptop.

True. But larger orgs don't buy "random laptops". The trick is to just buy laptops where you know everything works, and the company making them has a commitment to Linux. Buy your linux laptop fleet from Framework, System76, Starlabs etc and you won't have any problems like that. You might have OTHER problems, but not that one.

None of those companies have a logistics chain which would at all be suitable for the US federal government.

Even in corporate, there's basically two vendors - Dell, and a distant second Lenovo, with Apple having a foothold in niche usecases.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#289
post #267

Earlier quoted context omitted.

> when more secure (Linux-based) options are far cheaper and widely deployed Hold on, we are talking about SharePoint here. I don't know any software that could replace it, that is allowing office suite to collaborate in a way SharePoint Server does it (versioning, concurrent editing, online editing, workflows, customizations, OneDrive, IRM, compliance, search etc.) Even in a windows environment. Can you name more se…

Google Workspace

That's actually good point, thank you. However not something that one can install on-premises or is "far cheaper".

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#290
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

"Why do Microsoft products enjoy a monopoly on the server ...?"

They don't. There's plenty, even a majority, of non-Windows servers in gov (I know, some depts are true MS shops).

Sharepoint is one of those things that snuck in via the desktop. It was touted by MS as an evolution of shared folders with "Intranet" features included. If you already ran a Windows Server for fileshares, Sharepoint was "free".

The initial few implementations were of extremely poor quality, even by MS standards, but SP was positioned in the MS channel as the future of MS server side application development. So all of the consultancy/sales channel jumped on the SP wagon for any custom server projects.

For developers, it was a nightmare. Underneat the platform was a frankensteinian horror of bits and pieces of resurected code from many departments and projects across MS crudely bolted together with chewing gum scraped of a park bench and bits of string recovered from old fish guts. Lists (SP's core structure for file directories with exposed metadata properties) could not work reliably, the system fell over under even light load, latency was totaly unaceptable even for basic operations, files did not rountrip through the server unchanged ...

Over the years MS cut it down from "the future platform for custom backoffice apps" to "out of the box Intranet with mainly cosmetic configuration options" to "cloud hosted office 365 shared folders".

" Isn't security the number one priority in those spaces?"

No. It's exacly like every other IT environment of comparable size. Security is considered important, but does not drive sales. Features and cost, but also available expertise from the supplier/channel partners dominates the choice. Security is covered by promises and certifications, but more often than not left to operations to patch up.

Post reply on HN