Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

321–330 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#321

Earlier quoted context omitted.

Do these companies support Net 30/60/90 payment? Do they provide enterprise support? There’s a reason why corporations use HP and Dell machines. And there’s a reason why HP/Dell/etc don’t have Linux OSes on their corporate client machines. Well, they do, but companies don’t care to order them for the other reasons people have listed here.

I work for a company with 1000+ people in RnD doing software development. 80% of those use Ubuntu and have one desktop and one laptop (HP EliteBooks) and that works fine. You are right that not all devices don't work perfectly, but the Bluetooth headsets, Bluetooth mouses, conference rooms etc. that the company supports are tested for compatibility before being bought by our IT department.

Canonical and Red Hat have certified hardware. Most corporate workers aren’t software developers. They just want their productivity suite for email, scheduling, messaging, documents, spreadsheets, and presentations.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#322

Earlier quoted context omitted.

And if your strategy fails, you (usually) can't raise taxes to make up for lost revenue. So there is an even more direct link between underperformance and losing money.

I don't get such incomplete, selective, comparisons. The country can't go bankrupt and you just found another one. Yes, when a country messes up they have to actually fix things, there is no way around it. Except getting merged into another country - like my birth country, the GDR, ended up as West Germany's problem (but its people still had to do the work). Also, if big enough companies (and banks) fail, it is the s…

Oh boy. Haven't watched much US news since, like, Reagan, have we? Dumping the debt of your failures on future generations has become somewhat of a competitive sport in politics. Can't really do that in the private sector.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#324

Earlier quoted context omitted.

I do wonder if the fact that these vulnerabilities get exploited so often is because the customers are the likes of DoD. If DoD used Red Hat, maybe we'd see more large-scale linux/freedesktop exploits being discovered.

I think there's certainly an element of tall poppy syndrome here. Windows, for example, used to be targeted because its security was a complete joke until quite late in the XP era (SP3 IIRC). But there's always been, and still is, and element that it's targeted because it's a big, juicy target. A huge portion of the desktop and server market are running Windows. It used to be almost all Windows, at least on the deskt…

yet nearly all internet facing servers are linux; and we don't see the same volume of issues.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#325
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

It all started with Novell Netware. It was a great product and companies would buy it to have centralized management. Microsoft noticed this and decided to use their power position to drive Novell out of the market by offering a similar service and have it built in in their server product line. Novell tried to fight but it didn't last long. The protocol was proprietary and an open source implementation in Samba was v…

> Active directory, or Entra or however they call it these days, is basically a standard way to manage users everywhere. And until a strong entity (EU?) comes up with strong backup towards an alternative solutions (we have plenty of them now), the situation will not change.

You still have Active Directory on premise and now you have EntraID (formerly Azure AD) in the Azure cloud.

For Windows devices, it is the only mechanism supported to have a centralized management system.

For other systems, such as MacOS, you have alternatives that don't require any centralized user database.

Most cloud-native companies today rely on Okta or Amazon Cognito for their applications. Google Workspace supports this too, but it is incredibly basic at what it can do.

I don't think there's nothing that anyone can do to make this different.

And just to nitpick a little, it's like saying the smartphone reduced the camera market because of its dominant position. It didn't, it just provided convenience when there was none (a phone, a camera, a video recorder...).

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#326

Earlier quoted context omitted.

Absolutely insane. Especially in light of their layoffs. Should be criminal. According to another comment in the thread, it is?

Microsoft only has a market cap if 3.7 trillion. They can't afford to hire domestically. Anyway, from what I can tell being in this industry, a lot of things need to be explicitly illegal to stop companies from doing it. Edit: The penalities also have to be meaningful. There's a lot of "technically not legal, but sue us lol" going on. "Hey, this is a really really stupid idea." Isn't going to stop a middle manager fr…

Maybe instead of fines, large companies should be forbidden to do any new contracts for some months. That would be a larger incentive and also comprehensible to sales people.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#327

Earlier quoted context omitted.

OTOH that is a plus for security. When everything is interconnected/integrated, everything is usually pwned at the same time.

The problem is, decision-makers will not go for the "secure" way, they want a solution out of "one mold" - and so do users. It is a common complaint when trying to set up a FOSS solution, users complain that they have to learn and memorize different ways of doing the same thing across different application... and made worse by many FOSS projects not having UI/UX designers at all that care about consistency even in th…

In the non FOSS world it still ends up the same.

In every single company I have been working in the last 15 years, information was spread across so many different tools that integration was a moot point: Office365, Jira, Confluence, a separate ticketing tool, some mkdocs or single markdown files in repositories, spreadsheets, dedicated HR web portal, intranet, internal blog/comm/social media... Even within Office365 information is stored randomly as office files in sharepoint, teams channels, personnal onedrive, emails, copy/paste in teams, teams channel onedrive synched drivees, onenotes...[1] Also RBAC makes sure that whenever you came across one doc containing link to other stuff, you end up having no access to half of the links

Bottom line the tightest integration doesn't reduce any friction because there is not a single toolsuite that fits every use case and people end up making a mess of everything. You never know where you can find the information and every single teams wiki ends up being a collection of links to a myriad of different places. Also half of the people still email people documents instead of the links because they don't understand anything else.

[1] yes it is in the background the same product but people access them and more importantly know or search the information in totally different ways.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#328
post #324

Earlier quoted context omitted.

I think there's certainly an element of tall poppy syndrome here. Windows, for example, used to be targeted because its security was a complete joke until quite late in the XP era (SP3 IIRC). But there's always been, and still is, and element that it's targeted because it's a big, juicy target. A huge portion of the desktop and server market are running Windows. It used to be almost all Windows, at least on the deskt…

yet nearly all internet facing servers are linux; and we don't see the same volume of issues.

I hate Microsoft products as much as the next person, but I don’t think your statement is entirely fair:

SharePoint isn’t Windows. It’s a Microsoft product that’s only available for Windows Server. But it’s not Windows.

The reason I make that distinction is because if you widen the scope of services available on Linux then you might come a lot closer to the same volume of issues.

For example, take a look at how frequently CVEs are raised against popular CMSs.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#329
post #324

Earlier quoted context omitted.

yet nearly all internet facing servers are linux; and we don't see the same volume of issues.

I hate Microsoft products as much as the next person, but I don’t think your statement is entirely fair: SharePoint isn’t Windows. It’s a Microsoft product that’s only available for Windows Server. But it’s not Windows. The reason I make that distinction is because if you widen the scope of services available on Linux then you might come a lot closer to the same volume of issues. For example, take a look at how frequ…

Sure, I get the point, a more apt comparison might actually be RedHat though, since they're doing E2E packaging for a product suite.

I mean, Linux isn't even Linux - At the risk of invoking a meme: Linux is actually GNU + Linux; and even then there's a web-server on top, and software that it runs.

So, a working comparison might be Wikipedia? As far as I understand it; that's the largest CMS on the planet.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#330
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…

> corporations don't want to train users how to use Linux

This is a huge factor. There are a lot of people who’ll curl up into a ball if you try and get them to use something new.

Post reply on HN