Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

371–380 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#371

Earlier quoted context omitted.

If every car in your neighborhood that gets broken into is manufactured by a single manufacturer, it is in your interest in asking why that is, and perhaps considering that fact when shopping for a new car.

If every car in your neighborhood that gets broken into is manufactured by Ford, but some people keep saying that their sneakers never get broken into, why don't you just walk everywhere, also they've never driven a car and don't really believe anyone else drives a car and keep implying it's just a status symbol... and then they say "okay what if we consider everyone's sneakers all together, and how rarely they get s…

One should be wary of anyone selling you a solution to your problems they know nothing about. Naturally, the only way to be entirely secure is to shutdown all the applications and decommission all the computers, a solution which the business side tends to finds unreasonable. Thus the tender balance between business needs and business risk emerges as the deciding principle.

But the numbers are the numbers in heterogenous environments, regarding security problems by platform. And if it rains perpetual Windows-based incidents on your security staff, and you don't consider the numbers when evaluating what you will and will not do, compute/services-wise, then you are statistically likely to see the same rate of incidents, at whatever cost that comes to the business, indefinitely.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#372

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

> SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE”

In what world has SharePoint Server and SharePoint Standard + Enterprise User CALs ever been "FREE"?

> Security honestly feels like a service for a lot of giants.

While code security is on Microsoft, infrastructure security is on the organization deploying SharePoint Server.

Remember, the topic you're commenting on is about SharePoint Server. Not M365. Not SPO.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#373
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

> Why do Microsoft products enjoy a monopoly on the server in these sectors when more secure (Linux-based) options are far cheaper and widely deployed already? Because there is no FOSS solution even coming close to the level of out-of-the-box integration of Office 365. Thunderbird has zero integration with LibreOffice, LibreOffice has zero integration with Owncloud (or whatever else one might use), neither has integr…

You are very close. But Office isn't the secret to Microsoft's unassailable dominance in enterprise. I could remove Office at work and we'd be okay.

Active Directory is the key. A unified management of users, devices, groups, and policies that everything else is built on. Nothing outside of the Windows world even comes close. There's Linux tools to impersonate or talk to Active Directory, but no alternative to it.

Group Policy lets me set up any number of tens of thousands of configuration changes and apply it easily to any group of users or computers with a few clicks, regardless of device manufacturer. Linux distributions aren't even consistent enough about which system tools are onboard, much less what policies can be configured on them. Web browsers all have Group Policy plugins, so everyone's web browser is configured by Active Directory too.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#374
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Unpopular opinion but I don't think this solves anything. The exploit wasn't an OS exploit but a userland app exploit (Sharepoint Server/App). These attacks will always be developed until we're able to write perfect exploitation free software.

If the government was running Red Hat with 'open source SharePoint alternative' the headline would be 'open source SharePoint on-prem solution exploited'.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#375

Earlier quoted context omitted.

Maybe instead of fines, large companies should be forbidden to do any new contracts for some months. That would be a larger incentive and also comprehensible to sales people.

In which magical country do you suspect this would be enforced ? Microsoft also has a captive market here. Realistically you aren't going to migrate millions of employees and servers to another tech stack, even over something egregiously bad. Something like storing cleared data really should be handled 100% internally with an open source stack that's regularly audited. But that sounds really difficult, even if it wou…

One can dream.

I didn't suggested preventing the fulfillment of existing contracts. Nobody would change for all costumers. They just wouldn't get any new contractors.

Sanctions already exist.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#377

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

> Right now, Windows gets a lot of attention because it’s everywhere.

I disagree with this take. Linux dominates in the server market.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#378

Earlier quoted context omitted.

True. But larger orgs don't buy "random laptops". The trick is to just buy laptops where you know everything works, and the company making them has a commitment to Linux. Buy your linux laptop fleet from Framework, System76, Starlabs etc and you won't have any problems like that. You might have OTHER problems, but not that one.

None of those companies have a logistics chain which would at all be suitable for the US federal government. Even in corporate, there's basically two vendors - Dell, and a distant second Lenovo, with Apple having a foothold in niche usecases.

You used to be able to buy Dells with Linux pre-installed, quite a while ago. Did they stop?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#379

Earlier quoted context omitted.

> Private Teams messages are stored in individual Exchange mailboxes. Good lord. It truly is a layer of dung layered upon more layers of dung.

To be fair exchange works quite well for mail and calendar, it syncs very fast, is easy to set up and the cloud version is easy to administer (i never had to admin an on-prem exchange but ive heard its not fun). Using this infra for teams makes sense since it already works well. As one poster said, its probably via some hidden folder. I wonder what they did with skype, did they actually integrate any of it into teams…

On-prem Exchange is usually fine. Migration is a pain, but for a mid-size org you can mostly just install it and use it. If you have multiple servers distributed globally and database availability groups and such, yeah, it gets to be its own thing, but that's because at that point you're huge and you're going to feel the pain no matter what platform you run.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#380

I have spent far too much of my life on SharePoint. Having it internet facing has never been a good idea. Not really what it is meant for, though the promo verbiage on that has changed over different versions. Some folks wanted SharePoint as their "web server", I would set that installation up entirely separted from all other instances they may have on the network.

Microsoft.com and Office.com used to be entirely built upon SharePoint, as SharePoint solutions. It was to prove it out as possible, eat your own dogfood.

I think the shift away started in 2013 or 2014, but you can imagine the throw away effort spent on it.

Not sure about microsoft.com, but office.com frontend "rendering" SharePoint instances were read-only, not plain SharePoint exposed as-is.

Post reply on HN