Earlier quoted context omitted.
How many PMs actually use those features? In my organization, for example, I don't see any reason why we should prefer Atlassian over Taiga, other than familiarity and inertia.
> How many PMs actually use those features? It isn't the set of features that makes them sticky. It is the 10% of features the lead PM can't live without, and the slightly-overlapping-but-different 10% of features the team PM's can't live without, and the slightly-overlapping-but-different 10% of features the developers can't live without, and the roll-up report features the leadership team can't live without... Ther…
US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
331–340 of 344 posts
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#332Earlier quoted context omitted.
> He obviously did not understand what his job as a manager is about. > Why on earth would a manager be allowed to set tolerances like how you describe, tool or no tool? He's not the expert in the field, I am. Normally, I would have vetted the work orders and fixed it before hand. This is similar to managers in the software world, where the team lead or senior engineer would say," No, we won't do that, it's a bad ide…
Again: describe a set of work principles explicitly that all agree on - it's a human communication and collaboration issue you were faced with. A tool is not responsible for this breakdown. Lack of clarity around ownership and responsibilities is, by the look of it. IM humble O.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#333Earlier quoted context omitted.
> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))
Spolsky’s FogBugz is still out there after a few ownership changes, and is still a hell of a lot less painful to use than Jira.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#334Earlier quoted context omitted.
You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.
> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#335Earlier quoted context omitted.
Again: describe a set of work principles explicitly that all agree on - it's a human communication and collaboration issue you were faced with. A tool is not responsible for this breakdown. Lack of clarity around ownership and responsibilities is, by the look of it. IM humble O.
I'm willing to entertain that the teams using Jira are just making worse choices about the work principles they agree on than our teams using gitlab issues, and that it is coincidental and unrelated to the tool. Surely you agree though, that in general a tool can adversely affect user behavior? The agile manifesto said to value tools and process es less than individuals and interactions, not to discount their impact…
I’ve been places with many different tools and people.
Guess what, it’s ALWAYS about the people.
If a team is following principles derived from or resembling the manifesto, the tool will be shaped accordingly.
Jira, as an example, sure can be shaped, and I’ve done it myself several times - remove cruft, keep it simple, change if needed.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#336Earlier quoted context omitted.
> It’s amazing that this company continues to fall up. There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition. Atlassian get a lot of criticism, that's not always justified
The search function is atrocious. Some of the most visited, highly important pages will not be found with exact title matches.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#337Earlier quoted context omitted.
Confluence's code blocks are hot garbage: * Selecting a language on one code block changes the languages for other code blocks on the same page, sometimes. (I've not figured out the exact conditions on this one yet.) * Whitespace is not preserved / rendered the same as the editor; we have several Confluence pages with YAML where the rendered version won't parse, but it looks fine in the editor. Give me Markdown in gi…
Dunno about all that but it doesn't support inline code snippets. You've gotta use formatted text, which doesn't look good. Seems like an intern project at best.
Ordinary text blah blah {{interspersed code snippet}} some more ordinary blah blah text
working, or haven't you tried it?
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#338Earlier quoted context omitted.
If O365 can't find the email and the O365 message tracing does not show anything, it seems likely that the mail was not actually delivered by Atlassian. If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Also, regardless of whether or not I received the mail, the initial mail stated that only authorized users co…
> If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Internet email has never been considered a highly-reliable messaging system; its quite possible an infrequent data loss in a mail server would get misattributed to a failure outside. Heck, even ignoring the unreliability of email generally, in fact, your assum…
While that may be true, it seems vastly less likely to be the cause for the GP not receiving precisely this mail... Given that several other commenters only on this page mention not being able to find any evidence of having received this particular missive, William of Ockham would fall over with laughter at the idea that they all just happened to have email system glitches at the exact same mail.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#339Earlier quoted context omitted.
Arbitrary code execution in an on-premise server? You can basically stage an attack on any other internal resources (core infrastructure, databases, endpoints) that are visible from there, with the benefit of already being behind at least one layer of firewall/security.
> Arbitrary code execution in an on-premise server? That doesn’t explain what the benefit of the attack is. It just explains that it’s an effective attack.
Access the janitor's account on the facilities Jira, which is all that runs on an old Pentium II in the broom cupboard and you get one set of benefits; access the CFO's on the Big Money Server and you get something else entirely. How on Earth did you manage not to realise this by yourself?
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#340Earlier quoted context omitted.
It's like Microsoft in the 90s, everyone wants to hate on the company but their sales department just laughs and pens another huge contract
Atlassian doesn't have a sales department (or at least this was the case for well over a decade, perhaps it could have changed now).