Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

31–40 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#31
post #29
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

Biased but I'm actually building a competitor (V1 is almost ready) to Confluence for medium to big organizations. But I don't understand your requirement for on-prem. That's clearly not an advantage from the security point of view. Apart from Quip, Sharepoint and Confluence (soon stopped) I'm not sure there is any commercial knowledge base tool that are available on-prem. The only thing that you can hope for, is "bri…

>I'm not sure there is any commercial knowledge base tool that are available on-prem.

XWiki?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#32
post #6
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

I am considering going with Bookstack Wiki for my company. But I am not a Fortune500 company.

I would say it is very darn complete, perhaps without the syntactic linking that Confluence has. The only thing missing from it, is a very solid backup and restore method from the admin panel. The authors want users to rely on database backups and file level backups, that must be handled manually. Essentially saying "not my problem".

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#33

Atlassian was so kind to update their mailing lists somewhere over the last year or so. Previously, they would email the 'technical contact' of the license about any vulnerabilities. They quietly switched to some other notification system and never informed us about it. Hence we missed the update and got a free Bitcoin miner. Thanks Atlassian, I'll make sure to get your products out of the door as soon as possible. […

Well, I got it. Maybe you specifically didn't get it, or maybe there is something filtering it.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#34
post #25

That's one of the selling point of Saas compared to hosted instance honestly. Some company think that having Confluence hosted internally is going to increase the security. But this is wrong. When you rely on a Saas provider. The provider has people who monitor the infrastructure constantly whereas when you hosted on your own server, the confluence instance is just one of the many services that they manage. And even…

If you are running it accessible from the outside maybe.

But a big point of hosting it internally is that you don't have to.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#35
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki . Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but un…

[flagged]

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#36
post #31
post #29

Earlier quoted context omitted.

Biased but I'm actually building a competitor (V1 is almost ready) to Confluence for medium to big organizations. But I don't understand your requirement for on-prem. That's clearly not an advantage from the security point of view. Apart from Quip, Sharepoint and Confluence (soon stopped) I'm not sure there is any commercial knowledge base tool that are available on-prem. The only thing that you can hope for, is "bri…

>I'm not sure there is any commercial knowledge base tool that are available on-prem. XWiki?

I personally do not categorize them to equivalent to Confluence, Sharepoint, Notion, Quip, ... but if you do, yeah there are few wiki software which are available on premise.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#37

Atlassian was so kind to update their mailing lists somewhere over the last year or so. Previously, they would email the 'technical contact' of the license about any vulnerabilities. They quietly switched to some other notification system and never informed us about it. Hence we missed the update and got a free Bitcoin miner. Thanks Atlassian, I'll make sure to get your products out of the door as soon as possible. […

Well, I got it. Maybe you specifically didn't get it, or maybe there is something filtering it.

I only got the 'update' from last Saturday, by then it was too late already. Their original advisory was from the 25th, they should have mailed me back then.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#38
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki . Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but un…

I get the sense that there are a few Atlassian employees on HN this morning...

Jira and Confluence are "okay" at what they do, but they're horribly inefficient. I wonder how much energy would be saved if all the JIRA and Confluence server farms were replaced with single servers or redundant setups running something more efficient.

Atlassian seems to be one of the subjects of the 2000's versions of the old line: "nobody got fired for buying IBM".

Anyway the discussion in this thread is interesting to me - just to hear about the alternatives.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#39

Earlier quoted context omitted.

But why are they not using VPN?

common reasons could be :- - Cost, VPNs and the hardware to run them can be expensive - Single point of failure. If you run all your remote access through a VPN gateway then you run the risk of disruption if it goes down. Of course you can implement redundnt/multiple gateways but that increases cost. - Complexity for B2B setups. If you're exposing an API and you want third party services to access it, it can be more…

A pair of openvpn servers will run you about $100/month in AWS. Sure there is some overhead in running them but not anything more than any other server. Maybe I'm just a jaded Sysop but this stuff is networking 101.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#40
post #30
post #28

Earlier quoted context omitted.

This isn't always true. Using a SaaS is outsourcing these concerns, and sometimes you're outsourcing them to someone who will do better than you would and sometimes worse. I've worked on a couple of SaaS where security was absolutely not top priority. Especially in Silicon Valley, organizations often value growth over sound processes, fully staffed security teams, and managing tech debt. Many a SaaS has leaked custom…

I didn't say that it is always the case. The same argument you use can be used to talk about companies who are going to self host Confluence. I agree that a lot of Saas startup are going to neglect security. But here we are talking about Knowledge base tools Saas companies. This is not some standard Saas company. They know they are in charge of company internal secrets. Or at lest I hope

Any time a SaaS gets compromised there's a similar comment here about how obviously this is going to happen when you give someone else your data, and it should have just all been within your own firewall, unexposed directly to the Internet.

I mean right this minute there's a privacy-focused SaaS on the front page for not being as private as everyone thinks. There's also a network hardware vendor on the front page for including back doors. A philosophy like "SaaS vendors know they can't allow security breaches" is really glossing over the need for layers of security and knowing that it's ultimately all on the trustworthiness of specifically who is involved.

Post reply on HN