Earlier quoted context omitted.
Definitively no. It was not a hack at all. It was misconfigured software running inside the kernel. The issue was this misconfiguration was "urgently pushed" from Crowdstrike and depending on who you believe it overrode customer testing policies.
So a bunch of Linux systems were compromised or a bunch of Widows?
Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
391–400 of 456 posts
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#392It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…
While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#393These recommendations followed a review of MS practices following the Exchange online compromise. I highly doubt anything changed at MS since then.
source: https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewO...
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#394It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…
> Right now, Windows gets a lot of attention because it’s everywhere. I disagree with this take. Linux dominates in the server market.
Meanwhile, Windows is running the crown jewels for operations inside the company, like SharePoint and Active Directory.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#395It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this whole SharePoint story is probably a deja vu, A few real-world points that stood out to me: - SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000…
While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#396Earlier quoted context omitted.
While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…
> If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. No, this is the same sort of defeatism that prevents us from making progress on security. We could engineer usable systems where actual security is a priority, and not just security theater. We don't because nobody in a position to change anything actually gives a shit.
Security is a priority. But it's not the only priority.
It would be difficult engineering even if it was the only priority, but given that there's little point to security for a system you never deploy, it's not likely to ever completely monopolize focus, either for users or implementers.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#397Earlier quoted context omitted.
While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…
> If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. No, this is the same sort of defeatism that prevents us from making progress on security. We could engineer usable systems where actual security is a priority, and not just security theater. We don't because nobody in a position to change anything actually gives a shit.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#398Earlier quoted context omitted.
Did you already forget about log4j?
log4j is a once in a decade event, while vulnerable Microsoft software is more like once a month.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#399Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#400Earlier quoted context omitted.
Which is so funny because it was a pain in the ass on prem to make sharepoint work for that purpose. Silly item restrictions, complaints about database sizes (which stored the files), etc
Most of the restrictions have been dropped. You can ignore the database size. Multi-TiB content databases are fine. But SPO uses Azure Blob Storage to store content rather than SQL databases.