Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

351–360 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#351
It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu,

A few real-world points that stood out to me:

- SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000s. Once you’re deep into the Microsoft ecosystem, the cost and pain of replaccing is huge!

- Security honestly feels like a service for a lot of giants. When someone asks if it’s the number one priority, the answer from experiencem, is “no.” Cost, compliance available support, and how easy it is to blame a vendor if things fail tend to matter more.

- When people say Linux would be more secure in these environments, maybe. But if Linux or Red Hat took over everywhere, you can bet it would become the juiciest target immediately. Right now, Windows gets a lot of attention because it’s everywhere. And obviously, attackers like to go where the odds of a big payoff are highest.

- A lot of giants aren’t making decisions based only on security or technical merit. It’s about familiarity, employee training costs, consulting partners, and “safe” bets. If you pick Microsoft and get breached, it’s an industry problem. If you pick something niche and get breached... it’s 100% your fault.

- Resistance to change is real. Swapping out platforms isn’t just a technical lift. Management, end users, even IT staff get pretty set in their ways.

Honestly, unless there’s enough public backlash or a relgulation hammer, I don’t see the inertia breaking any time soon. For most companies, “patch and carry on” still beats “burn it all down and start fresh.”

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#352
If Sharepoint was an animal it would be a Duck-billed Platypus. I never understood why it got the degree of use that it did, even as a free product it was always best avoided. Everything seemed to be tacked on at a different angle from the normal one with broken interfaces in between.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#353

Earlier quoted context omitted.

In the private sector, there's a slightly more direct link between job underperformance and being fired.

> In the private sector, there's a slightly more direct link between job underperformance and being fired. Not in my experience. Connections are most important than competence in big corporations. The bigger the company the most is works like the old Soviet Union.

I've been working in major famous corps most my professional 45 years, and this is what I have observed.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#354
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Only because Microsoft offers “certified professional” badges and the MSCP’s are pushing the only thing they are certified for, and the corporations buy into the whole “certified” thing.

I have a ton of customers where the admins are constantly reminding everyone about the certifications they have, all while their basic security is below average.

… but they are certified!

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#355

Earlier quoted context omitted.

> Document editing and file storage are two different tasks. Not if you want to enable multiple users to be live editing the document at the same time.

I've never been able to properly work on a Word document together with a colleague. Not even once. There's always some kind of bug or sync problem. Google Docs, on the other hand, works great when you're working together on a document. Too bad they don't have a native client.

> I've never been able to properly work on a Word document together with a colleague. Not even once

Many millions of others seem to do it all the time without issue. I've done it practically every day for many years now and haven't run into sync issues for a long time.

It's not made to sync if two people are trying to open the file off a NAS, it's made for people editing files stored in OneDrive/SharePoint.

But as both examples show, you need to have your document editing and document storage closely working together for multi-user live editing to work. That's something that so far practically only integrated editors/storage platforms offer.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#356

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considered unacceptable even in a system handling classified material.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#357

I have spent far too much of my life on SharePoint. Having it internet facing has never been a good idea. Not really what it is meant for, though the promo verbiage on that has changed over different versions. Some folks wanted SharePoint as their "web server", I would set that installation up entirely separted from all other instances they may have on the network.

Isn't Office365 an online sharepoint?

Yes, as is OneDrive and Teams file sharing. Those, however, are part of SharePoint Online. SPO is distinct from this CVE, which only applies to the standalone SharePoint Server.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#358

Earlier quoted context omitted.

CrowdStrike is not made or owned by Microsoft.

Giving OP the benefit of the doubt, there were issues with how the Windows kernel had little guardrails and restrictions. That said, that was the EU's fault, as the EU in 2009 forced Microsoft to fully expose their OS internals to outside vendors during an anti-trust settlement, and with little ability to enforce vendor standards: ""Microsoft shall make available to interested undertakings Interoperability Informatio…

so its EUs fault that microsoft cant make proper software? ok. Guess we are back to security by obscurity

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#359
post #357

Earlier quoted context omitted.

Isn't Office365 an online sharepoint?

Yes, as is OneDrive and Teams file sharing. Those, however, are part of SharePoint Online. SPO is distinct from this CVE, which only applies to the standalone SharePoint Server.

Yes I know.

What I was kind of implying is that if the codebase is not that different maybe there has been a complete breach of office365 and Microsoft has stayed quiet about that.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#360

Earlier quoted context omitted.

Nginx doesn’t have the same attack surface. Microsoft’s back office suite is massive. So you’re talking about Nginx + a CMS + online office suite + video conferencing + identity providers and so on and so forth. There isn’t really a direct comparison in the FOSS world. It’s either smaller in scope or smaller in terms of high profile organisation adoption. This is why I think it’s easier to ignore the “Linux” part. No…

If every car in your neighborhood that gets broken into is manufactured by a single manufacturer, it is in your interest in asking why that is, and perhaps considering that fact when shopping for a new car.

If every car in your neighborhood that gets broken into is manufactured by Ford, but some people keep saying that their sneakers never get broken into, why don't you just walk everywhere, also they've never driven a car and don't really believe anyone else drives a car and keep implying it's just a status symbol...

and then they say "okay what if we consider everyone's sneakers all together, and how rarely they get stolen compared to cars" as if they've come up with a sensible comparison in complexity...

and then someone suggests "RedHat Linux" as an alternative to your car. Apparently they don't know what section of the world a car fits into, to suggest an alternative - but they're still convinced that you don't need a car and they are genuinely puzzled why more people aren't using "RedHat Linux" instead of cars...

... also only Ford make cars and the only real alternative is something completely different and then pay consultants to customise it and retrain your entire workforce at great cost and upheaval for little to no return, except hoping for an increase in security but not being able to prove same, or even clearly nail down what that means precisely.

Post reply on HN