Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

301–310 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#301
post #34
post #25

That's one of the selling point of Saas compared to hosted instance honestly. Some company think that having Confluence hosted internally is going to increase the security. But this is wrong. When you rely on a Saas provider. The provider has people who monitor the infrastructure constantly whereas when you hosted on your own server, the confluence instance is just one of the many services that they manage. And even…

If you are running it accessible from the outside maybe. But a big point of hosting it internally is that you don't have to.

There is no “outside” and “inside” anymore. Have you ever had a penetration test on your network?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#302

Earlier quoted context omitted.

> Git repos? One of these things is not like the other, and anybody who uses a real editor and VCS but still has to deal with confluence or the rest of the above knows it. Child poster below going on about markdown etc is absolutely wrong.

You're aware that you can dynamically generate wiki pages from git repos using (you guessed it) confluence, right? The problem is people, not tooling.

How? Does it involve a 3rd party plugin? If so that’s DOA for any org concerned about security.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#303
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

> awful engineering practices that underpin their products

Confluence has become an absolutely disgusting, bloated Javascript beast. The amount of JS that it loads is unbelievable.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#304
post #74

Earlier quoted context omitted.

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

I think it already has been disrupted but no company is going to switch task management software without a really good reason. But I can't imagine and fresh companies are choosing Jira over Clubhouse, Asana, Trello or what I hope to be my company at some point! https://tahsk.com

fwiw Trello is owned by Atlassian.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#305

Earlier quoted context omitted.

I think they’re talking about the front-end, not the server. FWIW both Confluence and Jira are abysmally slow on my machine (new MBP) on the cloud version.

I use both Jira and Confluence (cloud version) on a 6 year old Dell laptop and have no performance issues. Maybe I'm closer to their servers. Or you're using Safari.

Is Safari slow when using Jira?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#306

Earlier quoted context omitted.

> Git repos? One of these things is not like the other, and anybody who uses a real editor and VCS but still has to deal with confluence or the rest of the above knows it. Child poster below going on about markdown etc is absolutely wrong.

You're aware that you can dynamically generate wiki pages from git repos using (you guessed it) confluence, right? The problem is people, not tooling.

How do you do that without yet another third party addon not even supported by Atlassian? (if you say via the api...)

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#307
post #287

Earlier quoted context omitted.

Spolsky’s FogBugz is still out there after a few ownership changes, and is still a hell of a lot less painful to use than Jira.

It was innovative 13 years ago, but never really caught on. Kiln was also a great product and allowed for using both Git and Mercurial. It was way better than anything else at the time, but lost out to Github. I always liked Spolsky's Evidence Based Scheduling that was built into the products. https://fogbugz.com/evidence-based-scheduling/

> Kiln was also a great product and allowed for using both Git and Mercurial. It was way better than anything else at the time, but lost out to Github.

I used both FogBugz and Kiln at a previous employer, and I really liked FogBugz, but we had nothing but problems with Kiln. We had a fairly large team (maybe 75-100 people) and a good sized project (maybe 300k lines), and it was painfully slow to do anything in Kiln and it was down/broken at least once a month. It wasn't so bad early on when we were small, but it didn't scale with us very well.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#308
post #255

Earlier quoted context omitted.

> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))

Is TFS no longer considered a competitor? Feels like it should have been the first mentioned here. Not saying TFS is problem-free, of course.

I've had to use Azure DevOps recently, and it made me long for the speed, simplicity, and stability of Jira...

The most annoying bug was that one could only have around 4-5 tabs open before something went wrong and everything stopped updating.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#309
post #34

Earlier quoted context omitted.

If you are running it accessible from the outside maybe. But a big point of hosting it internally is that you don't have to.

There is no “outside” and “inside” anymore. Have you ever had a penetration test on your network?

The difference then is shifted towards whether it is a targeted attack or not. And that is a huge difference.

That difference would undoubtedly have saved every single company that was affected in the current story.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#310

Earlier quoted context omitted.

He obviously did not understand what his job as a manager is about. Why on earth would a manager be allowed to set tolerances like how you describe, tool or no tool? It makes no sense and is first and foremost a management and cultural issue. Second a work process issue. Solid third, one of competency. Probably ways below numerous other problems lies the tool. You obviously needed to be able to set tight tolerances f…

> He obviously did not understand what his job as a manager is about. > Why on earth would a manager be allowed to set tolerances like how you describe, tool or no tool? He's not the expert in the field, I am. Normally, I would have vetted the work orders and fixed it before hand. This is similar to managers in the software world, where the team lead or senior engineer would say," No, we won't do that, it's a bad ide…

Again: describe a set of work principles explicitly that all agree on - it's a human communication and collaboration issue you were faced with.

A tool is not responsible for this breakdown. Lack of clarity around ownership and responsibilities is, by the look of it.

IM humble O.

Post reply on HN