Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

391–400 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#391

Earlier quoted context omitted.

Definitively no. It was not a hack at all. It was misconfigured software running inside the kernel. The issue was this misconfiguration was "urgently pushed" from Crowdstrike and depending on who you believe it overrode customer testing policies.

So a bunch of Linux systems were compromised or a bunch of Widows?

Nothing was compromised. A bunch of Windows systems were unable to boot. https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_ou...

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#392

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…

"Sorry, you can’t use that password to encrypt this email. It’s already being used on NUCLEAR_CODES_2 (final) (2).docx. Please try another password."

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#393
this is barely one year after the CSRB recommended: "...Microsoft leadership should consider directing internal Microsoft teams to deprioritize feature developments across the company’s cloud infrastructure and product suite until substantial security improvements have been made in order to preclude competition for resources. In all instances, security risks should be fully and appropriately assessed and addressed before new features are deployed."

These recommendations followed a review of MS practices following the Exchange online compromise. I highly doubt anything changed at MS since then.

source: https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewO...

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#394

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

> Right now, Windows gets a lot of attention because it’s everywhere. I disagree with this take. Linux dominates in the server market.

Yeah... but mostly external services.

Meanwhile, Windows is running the crown jewels for operations inside the company, like SharePoint and Active Directory.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#395

It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…

[deleted]

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#396
post #362

Earlier quoted context omitted.

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…

> If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. No, this is the same sort of defeatism that prevents us from making progress on security. We could engineer usable systems where actual security is a priority, and not just security theater. We don't because nobody in a position to change anything actually gives a shit.

> We could engineer usable systems where actual security is a priority,

Security is a priority. But it's not the only priority.

It would be difficult engineering even if it was the only priority, but given that there's little point to security for a system you never deploy, it's not likely to ever completely monopolize focus, either for users or implementers.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#397
post #362

Earlier quoted context omitted.

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…

> If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. No, this is the same sort of defeatism that prevents us from making progress on security. We could engineer usable systems where actual security is a priority, and not just security theater. We don't because nobody in a position to change anything actually gives a shit.

You can engineer systems where security is a priority. You can't engineer useful systems where security is the priority.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#398

Earlier quoted context omitted.

Did you already forget about log4j?

log4j is a once in a decade event, while vulnerable Microsoft software is more like once a month.

Zero day actively explored events are not a once a month thing. Are you trying to argue there’s no Linux vulnerabilities monthly??

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#399
post #286

Earlier quoted context omitted.

log4j is a once in a decade event, while vulnerable Microsoft software is more like once a month.

Log4j is a Java thing divorced from the operating system running it.

This was about open source. Not Linux.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#400
post #382

Earlier quoted context omitted.

Which is so funny because it was a pain in the ass on prem to make sharepoint work for that purpose. Silly item restrictions, complaints about database sizes (which stored the files), etc

Most of the restrictions have been dropped. You can ignore the database size. Multi-TiB content databases are fine. But SPO uses Azure Blob Storage to store content rather than SQL databases.

Sure. Just saying when that first was brought up in 2007+ and I had to admin it and people loved their folders and searching and such wouldn’t work because if the view sizes.
Post reply on HN