Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

361–370 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#361
post #312
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Security aside, what even is an alternative to SharePoint on Linux? There is not one.

There's Liferay:

https://www.liferay.com/resources/l/content-management-syste...

https://hub.docker.com/r/liferay/portal

I haven't played with it in about 5 years but it was substantially less polished than a well-run Sharepoint 2013 instance.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#362

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…

> If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society.

No, this is the same sort of defeatism that prevents us from making progress on security. We could engineer usable systems where actual security is a priority, and not just security theater. We don't because nobody in a position to change anything actually gives a shit.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#363

Earlier quoted context omitted.

Not yet, but I’m planning to roll one out later this week! Are you in cybersecurity or just tracking vulnerabilities for fun/work?

I work both cybersec + fun/research, LOVE this resource and lucky to have come across it here. Subscribed via email & looking forward to RSS. Thanks for sharing it here!

Thanks so much, that really means a lot! I'm actively upgrading the feed right now: more vendors, faster signal (closer to real-time), and smarter triage to cut through the noise.

I’m also shaping a Pro tier and would love your input. Some of the things I’m working on:

Full access to all alerts (not just critical)

Fine-grained filtering (vendor, product, CVSS score, tags)

Delivery via webhooks, Slack, Teams, pagerduty, Splunk, other SIEMs

A “Time Machine” view so you can preview what you would’ve received had you been subscribed earlier

Would love to know what you’d want in a tool like this. Anything missing that would help your day-to-day in cybersec or research?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#364

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…

Security is not only Confidentiality, Availability is also a part of the triad.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#365

Earlier quoted context omitted.

[flagged]

Sometimes it looks as if it matters more whether people are good and work in good faith rather than what a particular system is. However, the more extreme the system (be it anarchocapitalism or communism), the higher the requirement to the goodness of people. As is, in current societes I find that the ambient chaos of general democratic capitalism counteracts the threat of small minority making wrong decisions (Mao’s…

> democratic capitalism

I don't think I have anything in response to that one.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#366

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

with microsoft's history of insecurity, if you pick microsoft (or azure) and get breached, it's totally on you.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#367

Earlier quoted context omitted.

"Why do Microsoft products enjoy a monopoly on the server ...?" They don't. There's plenty, even a majority, of non-Windows servers in gov (I know, some depts are true MS shops). Sharepoint is one of those things that snuck in via the desktop. It was touted by MS as an evolution of shared folders with "Intranet" features included. If you already ran a Windows Server for fileshares, Sharepoint was "free". The initial…

I was involved in a software startup that was aligned with MSFT 18 or so years ago. We built the web app side of our tool in Sharepoint precisely to be a good team player, and make ourselves more attractive to Redmond, even though it gave us no real benefits. The support problems were INSANE. We ended up spending an entire release cycle pulling the web app out of Sharepoint and just doing a proper stand-alone web sit…

Sharepoint’s problem, as parent alluded to, is that it’s three kids in a trenchcoat pretending to be an adult.

At no time did MS seem to say “Here’s our vision for Sharepoint as a complete product.”

Instead, you got coming on 25 years of random big customer feature asks + a home for lost MS product bits.

It would surprise no one that performance of that has been atrocious for most of its life (for those not old enough, think non-functional search and 20s page loads for on-prem instances), salvaged only semi-recently via the cloud managed version (that I’d guess runs on a ground-up backend reimplementation).

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#368

Earlier quoted context omitted.

Microsoft only has a market cap if 3.7 trillion. They can't afford to hire domestically. Anyway, from what I can tell being in this industry, a lot of things need to be explicitly illegal to stop companies from doing it. Edit: The penalities also have to be meaningful. There's a lot of "technically not legal, but sue us lol" going on. "Hey, this is a really really stupid idea." Isn't going to stop a middle manager fr…

Maybe instead of fines, large companies should be forbidden to do any new contracts for some months. That would be a larger incentive and also comprehensible to sales people.

In which magical country do you suspect this would be enforced ?

Microsoft also has a captive market here. Realistically you aren't going to migrate millions of employees and servers to another tech stack, even over something egregiously bad.

Something like storing cleared data really should be handled 100% internally with an open source stack that's regularly audited.

But that sounds really difficult, even if it would be cheaper or the same price in the long run.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#369
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

"Why do Microsoft products enjoy a monopoly on the server ...?" They don't. There's plenty, even a majority, of non-Windows servers in gov (I know, some depts are true MS shops). Sharepoint is one of those things that snuck in via the desktop. It was touted by MS as an evolution of shared folders with "Intranet" features included. If you already ran a Windows Server for fileshares, Sharepoint was "free". The initial…

>> The initial few implementations were of extremely poor quality, even by MS standards, but SP was positioned in the MS channel as the future of MS server side application development. So all of the consultancy/sales channel jumped on the SP wagon for any custom server projects.

The gaslighting around this matter was intense. It destroyed any remaining trust I had at that point.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#370
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

I do wonder if the fact that these vulnerabilities get exploited so often is because the customers are the likes of DoD. If DoD used Red Hat, maybe we'd see more large-scale linux/freedesktop exploits being discovered.

DoD does use Red Hat (a ton). Not for this, apparently, but for plenty of other things.
Post reply on HN