Earlier quoted context omitted.
Google Workspace
This is SharePoint on-premise, so Google Workspace isn’t a good comparison? Also, even if we do look at cloud: Workspace isn’t bad (exception: sheets vs Excel), but SharePoint is the center of Teams, Power Platform, PowerBI… to replace M365 with Workspace means a lot of research, setup and testing of 3rd party alternatives to the above. If you’ve ever worked in a well configured Microsoft stack, nothing beats the int…
Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
311–320 of 456 posts
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#312We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#313Earlier quoted context omitted.
There are still plenty of issues with bluetooth, batteries, microphones, gpus, touchpads etc when doing a clean install of Ubuntu on any random laptop.
True. But larger orgs don't buy "random laptops". The trick is to just buy laptops where you know everything works, and the company making them has a commitment to Linux. Buy your linux laptop fleet from Framework, System76, Starlabs etc and you won't have any problems like that. You might have OTHER problems, but not that one.
There’s a reason why corporations use HP and Dell machines. And there’s a reason why HP/Dell/etc don’t have Linux OSes on their corporate client machines. Well, they do, but companies don’t care to order them for the other reasons people have listed here.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#314Earlier quoted context omitted.
I wonder what drives people using Microsoft and then using more from this company. We didn’t knew it better, back then. We knew it better, now. But migrating is work. So we prefer to suffer! And harm others! This Linux and BSD people are so annoying with their desire for compatibility. They shall suffer, too! And when we buy everything from a Monopoly, we don’t need to think. Somehow. Part of the game is that you’ve…
They're using Microsoft because all of the alternatives have the same issues. FOSS isn't magically immune to vulnerabilities. It doesn't help that the FOSS community generally prefers the C programming language over more modern and safer alternatives as a cultural thing. The result is just as many vulnerabilities, if not more, per line of code or per feature. Keep in mind that SharePoint is an enormous product with a…
Valid point about the image size. A possible sign for bloat? Bloat is danger.
Second:
C, C++ or Rust are our tools. Everyone prefers another for technical and personal reasons. A religious believe in salvation by the next programming language is not helpful and causing harm. I hope sanitizers for C/C++ improve further - which improved safety a lot. For C++28 or C++3x we can hope for further safety improvements. Which we need.
Most bugs are logic errors. SharePoint is - according to my knowledge - implemented in C#. The CVEs mention deserialization of untrusted data, improper limitation of a pathname to a restricted directory ('path traversal'), improper control of generation of code ('code injection') and so on.
I'm rather careful about people requiring another language and claiming it will fix everything. Reliability needs hard work (design, code, review, testing...more review) even with well selected tools. I guess Microsoft does that. And I guess Microsoft works like the rest of the industry, focus on time-to-market and building a monopoly in every area. That's why we see rapid updates in a lot areas and - worse - enforced updates. And why software is known for it's low quality in comparsion to other industries?
Examples:
GNOME opted to use JavaScript in the hype back in 2010:
* JavaScript reduced compatibility compared to C/C++.
* They suffered a lot from memory-leaks. Due to JavaScript.
* The run-time modification seems not to be a big benefit.
* Extra dependencies for JavaScript. More memory usage.
The code matured and it works now rather well. I didn't liked the decision back then. I don't like it now. But I also don't request a rewrite in C, C++, Rust or Python. Without good reasons (plural) it doesn't benefit the project.Java also suffered. This rewrite of C++ to Java with JRE is a example, why rewrites for the sake of rewrites aren't a solution:
https://neilmadden.blog/2022/04/19/psychic-signatures-in-jav...
There is no magic. Only thorough work.
We will always suffer from security issues and we shall be always careful.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#315Earlier quoted context omitted.
> Why do Microsoft products enjoy a monopoly on the server in these sectors when more secure (Linux-based) options are far cheaper and widely deployed already? Because there is no FOSS solution even coming close to the level of out-of-the-box integration of Office 365. Thunderbird has zero integration with LibreOffice, LibreOffice has zero integration with Owncloud (or whatever else one might use), neither has integr…
OTOH that is a plus for security. When everything is interconnected/integrated, everything is usually pwned at the same time.
And on top of that, many data exchange formats are not just "old", they're "fossil" and don't even come close to meeting the demands that people have come to expect.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#316Earlier quoted context omitted.
This suggests that the main thing Linux needs, for broader enterprise adoption, is a much improved "log into something that quacks like Active Directory" solution. Not actual Active Directory, obviously that just contributes to the lock-in, but what else is even remotely as polished and well integrated? I suspect this is the true moat actually. Nearly every actual business has "log into our company managed authentica…
Amen .. and this has been the case for a very long time. I remember transitioning my startup employer to "small business server" (Active Directory+Exchange) over 20 years ago. Why? Email and calendaring, especially - remember this? - Blackberry integration. Everyone above middle-manager level lives in meetings, which means that the calendar is a critical piece of productivity software for them, and they want the comf…
Absolutely. A company isn’t going to create a GitHub issue and wait around. You can’t make service agreements with FOSS. There needs to be market forces to sell this software to corporations and it’s a hard sell.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#317We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…
I do wonder if the fact that these vulnerabilities get exploited so often is because the customers are the likes of DoD. If DoD used Red Hat, maybe we'd see more large-scale linux/freedesktop exploits being discovered.
A huge portion of the desktop and server market are running Windows. It used to be almost all Windows, at least on the desktop. Nowadays mobile computing has become far more important so Windows doesn't have the end user dominance it once did, but there are still a huge portion of end user devices running Windows.
Same on the back end: it's just a big juicy target, and the bang for buck that hackers get from it is huge given how prevalent it remains in corporate and government environments.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#318Earlier quoted context omitted.
True. But larger orgs don't buy "random laptops". The trick is to just buy laptops where you know everything works, and the company making them has a commitment to Linux. Buy your linux laptop fleet from Framework, System76, Starlabs etc and you won't have any problems like that. You might have OTHER problems, but not that one.
Do these companies support Net 30/60/90 payment? Do they provide enterprise support? There’s a reason why corporations use HP and Dell machines. And there’s a reason why HP/Dell/etc don’t have Linux OSes on their corporate client machines. Well, they do, but companies don’t care to order them for the other reasons people have listed here.
You are right that not all devices don't work perfectly, but the Bluetooth headsets, Bluetooth mouses, conference rooms etc. that the company supports are tested for compatibility before being bought by our IT department.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#319Earlier quoted context omitted.
Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…
Going Mac in an enterprise environment is a stupid move. Apple is constantly changing how MDM works. One week they'll go all-in on some method of doing things, and tell everyone they must comply or GTFO. The next week they'll completely change their minds and gaslight you, saying that old way is stupid and nobody should have ever used it ever. Then they will put in blocks to prevent it from working. This means all th…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#320Earlier quoted context omitted.
This though is also true in the private sector.
In the private sector, there's a slightly more direct link between job underperformance and being fired.