Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

401–410 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#401

I have spent far too much of my life on SharePoint. Having it internet facing has never been a good idea. Not really what it is meant for, though the promo verbiage on that has changed over different versions. Some folks wanted SharePoint as their "web server", I would set that installation up entirely separted from all other instances they may have on the network.

Actually it wasn't too long ago, in the early-2010's, that Microsoft was promoting SharePoint for internet sites; I think at one point some Europoean car manufacturer (BMW? Ferrari?) had their global marketing site on SharePoint. Of course that didn't last long, as Microsoft licensed it at a crazy price ($40k per site or something like that).

The Navy still runs more than a few web servers using Sharepoint, albeit behind dedicated network firewall appliances.

The Secretary of the Navy's page (at https://www.secnav.navy.mil/Pages/default.aspx) for instance, is a Sharepoint site. I used to maintain a Navy website hosted under there, and had a bunch of Hugo-specific scripts to convert a Hugo static site into something I could upload to the Sharepoint and have it mostly still work (which involved things like rewriting links and renaming files to end in .aspx).

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#402

Earlier quoted context omitted.

Teams was built from Skype. The fundamental infra for communication (chat, video call) was pulled out of Skype as a separate component and integrated into both. Skype the client is completely sunset, but a part of its back-end will continue to be used.

Skype Skype or Lync that was rebranded Skype Business?

Teams came from Skype. Skype Lync was just a client (so far as I know). Don't take my word for it though, I was not there during the transition, this is just my understanding from talking to the ones that were.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#403

Earlier quoted context omitted.

While I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considere…

Security is not only Confidentiality, Availability is also a part of the triad.

This is the crux of the issue. The CIA triad (confidentiality, integrity and availability) are the root of all security. However, those goals are often self-contradictory.

There will always, for example, be a conflict between availability and confidentiality. Ultimate confidentiality might require that the data be stored in an inaccessible bunker with no outside access. Ultimate availability might involve hosting sensitive data on a publicly accessible server with no access controls.

In the real world we must always balance these needs carefully, and triage available resources to achieve an "ideal" outcome. This means that security will never, and can never, be a solved problem.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#406

Earlier quoted context omitted.

In which magical country do you suspect this would be enforced ? Microsoft also has a captive market here. Realistically you aren't going to migrate millions of employees and servers to another tech stack, even over something egregiously bad. Something like storing cleared data really should be handled 100% internally with an open source stack that's regularly audited. But that sounds really difficult, even if it wou…

One can dream. I didn't suggested preventing the fulfillment of existing contracts. Nobody would change for all costumers. They just wouldn't get any new contractors. Sanctions already exist.

Ok.

So after the current contract do you switch stacks, or just have a 3rd partner Microsoft shop maintain your existing stack?

Regardless, I don't think our current legal system has any real ability to hold a company like Microsoft accountable.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#407
post #382

Earlier quoted context omitted.

Most of the restrictions have been dropped. You can ignore the database size. Multi-TiB content databases are fine. But SPO uses Azure Blob Storage to store content rather than SQL databases.

Sure. Just saying when that first was brought up in 2007+ and I had to admin it and people loved their folders and searching and such wouldn’t work because if the view sizes.

...That's a completely different complaint. And also solved long ago.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#408
post #329

Earlier quoted context omitted.

I hate Microsoft products as much as the next person, but I don’t think your statement is entirely fair: SharePoint isn’t Windows. It’s a Microsoft product that’s only available for Windows Server. But it’s not Windows. The reason I make that distinction is because if you widen the scope of services available on Linux then you might come a lot closer to the same volume of issues. For example, take a look at how frequ…

Sure, I get the point, a more apt comparison might actually be RedHat though, since they're doing E2E packaging for a product suite. I mean, Linux isn't even Linux - At the risk of invoking a meme: Linux is actually GNU + Linux; and even then there's a web-server on top, and software that it runs. So, a working comparison might be Wikipedia? As far as I understand it; that's the largest CMS on the planet.

The closest comparison to SharePoint is probably a combination of Zoho Connect, Zoho WorkDrive, and Zoho Flow. Zoho's office suite also integrates with WorkDrive and has collaborative editing. They even have a desktop app for Writer.

Even then, SharePoint is more of a platform. You can build SharePoint apps and extend it.

There isn't a comparison for SharePoint Server. There really isn't any single thing like it for on-premise.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#409

Earlier quoted context omitted.

Absolutely insane. Especially in light of their layoffs. Should be criminal. According to another comment in the thread, it is?

Microsoft only has a market cap if 3.7 trillion. They can't afford to hire domestically. Anyway, from what I can tell being in this industry, a lot of things need to be explicitly illegal to stop companies from doing it. Edit: The penalities also have to be meaningful. There's a lot of "technically not legal, but sue us lol" going on. "Hey, this is a really really stupid idea." Isn't going to stop a middle manager fr…

> "Hey, this is a really really stupid idea." Isn't going to stop a middle manager from trying to come in under budget.

Neither is "you can go to jail" when it comes to export controls training

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#410

Earlier quoted context omitted.

One can dream. I didn't suggested preventing the fulfillment of existing contracts. Nobody would change for all costumers. They just wouldn't get any new contractors. Sanctions already exist.

Ok. So after the current contract do you switch stacks, or just have a 3rd partner Microsoft shop maintain your existing stack? Regardless, I don't think our current legal system has any real ability to hold a company like Microsoft accountable.

If you happen to be unlucky and Microsoft just got convicted, you either need to wait some months or go to a competitor. The state shouldn't care about that, when your mechanic just went to prison, what you're gonna do?

But yeah I don't know any party who has such ideas.

Post reply on HN