Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

381–390 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#381
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…

> Linux PCs are uncommon for personal use and corporations don't want to train users how to use Linux.

I wonder how quickly that’ll change with the generations. The kids these days use Android and iOS, right?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#382
post #58

Earlier quoted context omitted.

> It's not much effort to just drag and drop a file into … OneDrive … See, there’s the problem. Once you touch anything M365, you’re using SharePoint. People see SharePoint as a document collaboration tool. But, in reality, it’s real use is as a data storage platform.

Which is so funny because it was a pain in the ass on prem to make sharepoint work for that purpose. Silly item restrictions, complaints about database sizes (which stored the files), etc

Most of the restrictions have been dropped. You can ignore the database size. Multi-TiB content databases are fine.

But SPO uses Azure Blob Storage to store content rather than SQL databases.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#383

I have spent far too much of my life on SharePoint. Having it internet facing has never been a good idea. Not really what it is meant for, though the promo verbiage on that has changed over different versions. Some folks wanted SharePoint as their "web server", I would set that installation up entirely separted from all other instances they may have on the network.

Actually it wasn't too long ago, in the early-2010's, that Microsoft was promoting SharePoint for internet sites; I think at one point some Europoean car manufacturer (BMW? Ferrari?) had their global marketing site on SharePoint. Of course that didn't last long, as Microsoft licensed it at a crazy price ($40k per site or something like that).

Well, they would have had to purchase one Client Access License per potential device or user that would access the website. Since there's about 5-6 billion people with internet access, and a CAL is about $50 a pop, that would be roughly two hundred and fifty billion dollars to fully and correctly license a public server.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#384

Earlier quoted context omitted.

> Schleswig-Holstein, one of Germany’s 16 states, on Wednesday confirmed plans to move tens of thousands of systems from Microsoft Windows to Linux. The announcement follows previously established plans to migrate the state government off Microsoft Office in favor of open source LibreOffice. https://arstechnica.com/information-technology/2024/04/germa...

People don't take it seriously because European governments have a history of making announcements like this and then rolling it back in favour of a return to Microsoft.

Lets see what happens when they try to move finance of Excel. If they are successful there, then there might be hope, if not, then they will eventually go back or have 45% of the company on some kind of exception.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#385

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

The issue isn’t Windows vs Linux. It’s an application security exploit and it just so happens that it only runs on Windows.

SharePoint Server is widely used and is a high value target.

Atlassian Server products have had their fair share of 0-day exploits. Atlassian also EOL their server products and forced a cloud migration.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#386

Earlier quoted context omitted.

If every car in your neighborhood that gets broken into is manufactured by Ford, but some people keep saying that their sneakers never get broken into, why don't you just walk everywhere, also they've never driven a car and don't really believe anyone else drives a car and keep implying it's just a status symbol... and then they say "okay what if we consider everyone's sneakers all together, and how rarely they get s…

One should be wary of anyone selling you a solution to your problems they know nothing about. Naturally, the only way to be entirely secure is to shutdown all the applications and decommission all the computers, a solution which the business side tends to finds unreasonable. Thus the tender balance between business needs and business risk emerges as the deciding principle. But the numbers are the numbers in heterogen…

> "a solution which the business side tends to finds unreasonable"

Isn't it odd that "unreasonable" solutions keep being suggested in threads started by people who first push Linux, and second ask what the thing even does anyway.

> "Thus the tender balance between business needs and business risk emerges as the deciding principle."

There is no tender balance and this is nothing like the deciding principle, and again it's illustrative that in a world where big organizations turn to poor quality software with poor UX for reasons like "nobody got fired for buying IBM" and "I look good on the Gartner report" and "the vendor will bend over backwards to make our auditors and legal team approve it" that Linux people go for the only thing they have going and try to suggest it's the most important thing, even though it's demonstrably an afterthought or a never-thought.

> "you are statistically likely to see the same rate of incidents, at whatever cost that comes to the business, indefinitely."

And you see this happening for literally 30 years and the "whatever cost" being written off as a business expense that has never changed anything, but you still call it "the deciding principle" when the evidence shows that the decision makers barel consider this at all?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#387

Earlier quoted context omitted.

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…

This suggests that the main thing Linux needs, for broader enterprise adoption, is a much improved "log into something that quacks like Active Directory" solution. Not actual Active Directory, obviously that just contributes to the lock-in, but what else is even remotely as polished and well integrated? I suspect this is the true moat actually. Nearly every actual business has "log into our company managed authentica…

Even macOS has a ton of goofy workarounds and third-party products required to get that level of ease for logging in with a corporate identity and having everything "just work". It's only finally getting close in Tahoe with the new additions to Platform SSO, but close is not "feature parity" either.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#388

Earlier quoted context omitted.

Nginx doesn’t have the same attack surface. Microsoft’s back office suite is massive. So you’re talking about Nginx + a CMS + online office suite + video conferencing + identity providers and so on and so forth. There isn’t really a direct comparison in the FOSS world. It’s either smaller in scope or smaller in terms of high profile organisation adoption. This is why I think it’s easier to ignore the “Linux” part. No…

If every car in your neighborhood that gets broken into is manufactured by a single manufacturer, it is in your interest in asking why that is, and perhaps considering that fact when shopping for a new car.

That does happen though. Cars worth more are stolen while cards worth less are not.

The common factor there isn’t that 40 year old hatchbacks have better security. It’s that the risk vs reward isn’t there compared to the brand new luxury cars with higher resale value on the black market.

This isn’t something I’ve just made up either. This is what the police told us when my neighbours Merc was stolen while my Skoda, which was accidentally left unlocked, was not.

Thieves target the expensive cars because they’re worth more. It’s really that simple.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#389

Earlier quoted context omitted.

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…

Apple focussed on consumer and even shunned the enterprise. MS for all its flaws, welcomed, targetted and tried to support scale operations in larger business environments (Imaging, AD, GP, SuS, bitlocker, ...). Also, if your only fix a hardware problem option was to "visit the 'genious bar'" and wait 6 weeks for a machine to come back, vs the Dell/HP/... service of "same day onsite repair", what is IT going to prefe…

Apple has changed their tune, in so far as they probably need some level of identity management on the Mac, crypto-key escrow, restrictions, and so on. Their Device Management framework is quite capable.

For large enough businesses Apple will let you do your own self-service repairs too. On-site. Order the part and you're still in warranty.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#390

Earlier quoted context omitted.

Hard to square this with every startup after ~2006 running a substantial, if not majority, Mac fleet. In addition to the major tech companies.

Startups rarely use MDM solutions, that's a thing when you hit >> 1000 users because you need dedicated teams to hand-hold the MDM.

I managed 1000 computers and a few hundred iPads by myself. No team required. HIPAA covered entity.
Post reply on HN