Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

321–330 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#321

Earlier quoted context omitted.

> Git repos? One of these things is not like the other, and anybody who uses a real editor and VCS but still has to deal with confluence or the rest of the above knows it. Child poster below going on about markdown etc is absolutely wrong.

You're aware that you can dynamically generate wiki pages from git repos using (you guessed it) confluence, right? The problem is people, not tooling.

If you dynamically generate confluence pages from a git repo, what do you need confluence for? That’s a lot of money you can save.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#322

Earlier quoted context omitted.

Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement. You can't easily dump Jira if you are using Jira, confluence, bitbucket, and whatever their CI/CD product is called (bamboo?)

How many PMs actually use those features? In my organization, for example, I don't see any reason why we should prefer Atlassian over Taiga, other than familiarity and inertia.

I think that the larger and more dystopian organisations cannot do better than Jira to fulfill their needs.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#323
post #74

Earlier quoted context omitted.

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

This is the primary failing of many tech people/companies. You can't compete by just building a "better" technical product. Everything from sales to support to customizations and integrations matter to companies, especially as they grow and develop their own teams and management structures which require the software mold into their workflows. Whether the management processes are the best is a different conversation,…

> being able to support any scenario is why Jira and Confluence are so successful

It’s incidentally also exactly why they’re often horrid to work with.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#324
post #247
post #209

Earlier quoted context omitted.

One of the companies I know use it for HR, payroll and account receivables. If you hack into that, you can get a lot of information.

How would that information be useful?

Everything from identify theft, to phishing to industrial espionage.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#325
post #281

Earlier quoted context omitted.

So... you do not, in fact, have an answer to the question?

Lacking humor I see. My point is that it is experience acquired from managing these for a decade. If you wish to acquire this experience you need to run it, which is now even costlier than it used to be.

Actually using these products suffices. Especially confluence, which regularly reduces me to a stream of particularly foul profanity.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#326
post #255

Earlier quoted context omitted.

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))

I would prefer to use anything but JIRA,I fucking loathe it.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#327
post #178
post #155

Earlier quoted context omitted.

A far stretch to conclude that this event can equate to awful engineering. The rest of this your comment reads like you continue to be naive to Atlassian’s success. I have to think many people do find unique value in their products (myself included), some people don’t laugh rudely when they hear what folks are working on, and I think that shows in the overall achievements of the Atlassian team and product. I’ve witne…

And I've witnessed first hand the truly garbage nothing changes after adopting Jira and Confluence - a wasteland of process management through bad automation and forgotten wiki articles with Write Once Read Never behavior. Nothing Atlassian does is that much better than past tooling, it all comes down to how you want to run your org, what discipline you apply, and where you apply it.

Agreed, it’s a total waste of time, I’d say our managements love for JIRA is the things that’s really holding us back from really being productive and enjoying our work. It’s such a horrible horrible time suck and offers nothing of real value.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#328

Earlier quoted context omitted.

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

Where may I learn more about exactly how they are "garbage fires on the inside"? Thanks

find or create an installation and examine how the database is put together

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#329
I spent years "working on" (battling) our own company-hosted Atlassian suite. I'm a software engineer / architect and was thrown admin powers to get a project up and running.

It was constant a battle of "the critical basic feature you need in this micro version is broken" and other critical functions being hidden in random places.

I applied to their engineering team citing my experience and ability to help with a lot of these things, but never even heard a response.

Current alternative software suites I've seen are beyond terrible or generally non-existent / missing major features. I'm sure there's some "pretty SaaS solutions" out there from a startup that charges exorbitant prices, but I don't believe their back end or security are going to be any better.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#330
post #255

Earlier quoted context omitted.

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))

Pivotal Tracker. I've found it to be a much more productive tool, and teams using it typically move alot faster and are far happier than those using Jira.
Post reply on HN