Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

441–450 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#441

Earlier quoted context omitted.

Security is not only Confidentiality, Availability is also a part of the triad.

This is the crux of the issue. The CIA triad (confidentiality, integrity and availability) are the root of all security. However, those goals are often self-contradictory. There will always, for example, be a conflict between availability and confidentiality. Ultimate confidentiality might require that the data be stored in an inaccessible bunker with no outside access. Ultimate availability might involve hosting sen…

The CIA triad comes from an agency that spies on people so I wonder if it truly is a comprehensive philosophy of security. It might be an attempt to confuse those they spy on with the intent to encourage security gaps. Philosophies of any kind are notorious for not being comprehensive or provable. Is there any research that tries to verify this philosophy? I worked on computer security for a few decades and I've never seen a justification for the CIA triad. The security community used to say that advanced persistent threats were "out of scope" because "the cost to defend against them was too high", but today they obviously are not out of scope because APT's are everywhere. Possibly the triad is a false legacy assumption as well. It seemed cool because it came from the CIA, but is it true? Even if it is reasonably true, is it complete?

As an example, diplomacy, open source, shared interests, universal basic income, and education can reduce the desire for attacking. How do these factor into the CIA triad?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#442

Earlier quoted context omitted.

That does happen though. Cars worth more are stolen while cards worth less are not. The common factor there isn’t that 40 year old hatchbacks have better security. It’s that the risk vs reward isn’t there compared to the brand new luxury cars with higher resale value on the black market. This isn’t something I’ve just made up either. This is what the police told us when my neighbours Merc was stolen while my Skoda, w…

> Thieves target the expensive cars because they’re worth more. It’s really that simple. They don't target the expensive cars. The most stolen cars in the US are cheap Hyundais And Kias. Before they claimed the top spot on the list of cars taken most often the winner was pick up trucks and old Toyotas. Thieves target what's easy to take and easy to chop up and sell, not luxury cars with high resale value.

> They don't target the expensive cars.

US != everywhere.

They do target expensive cars in other counties.

As I said earlier, I have firsthand experience of this being the case.

> Thieves target what's easy to take and easy to chop up and sell, not luxury cars with high resale value.

You’re just proving my point here though. Thieves target cars that have the highest resale value.

Whether that’s as a whole, or for parts where the supply chain for genuine parts has become extremely expensive.

Organised crime happens for money.

Yeah there will there will be a subsection of society that steal cars for shits and giggles. But those also aren’t the sort of motives for hackers who’d go after Microsoft Sharepoint. So if we are to compare like-for-like, then you have to discuss organised crime rather than bored teenagers.

———

By the way, I love how your username is accidentally appropriate for this conversation :D

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#443

Earlier quoted context omitted.

Sometimes it looks as if it matters more whether people are good and work in good faith rather than what a particular system is. However, the more extreme the system (be it anarchocapitalism or communism), the higher the requirement to the goodness of people. As is, in current societes I find that the ambient chaos of general democratic capitalism counteracts the threat of small minority making wrong decisions (Mao’s…

> democratic capitalism I don't think I have anything in response to that one.

I was actually on your side in this, oh well!

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#444

Earlier quoted context omitted.

No, as we both know, there are vulnerabilities on Linux, like log4j. And I also did not say that zero days are a once a month thing, I said that vulnerable Microsoft software is a once a month thing.

There are monthly security updates for packages for our Linux systems too.

Can you give me a list? I bet most users are unaffected, but I wonder.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#445

Earlier quoted context omitted.

> democratic capitalism I don't think I have anything in response to that one.

I was actually on your side in this, oh well!

Only liberals could describe our system as "democratic capitalism" with a straight face, its absurd. I'm on the left, I'm not a liberal, so no, we are definitely not on the same side. I believe our intolerable levels of inequality and disparity is caused by systemic issues not some "bad actors".

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#446
post #441

Earlier quoted context omitted.

This is the crux of the issue. The CIA triad (confidentiality, integrity and availability) are the root of all security. However, those goals are often self-contradictory. There will always, for example, be a conflict between availability and confidentiality. Ultimate confidentiality might require that the data be stored in an inaccessible bunker with no outside access. Ultimate availability might involve hosting sen…

The CIA triad comes from an agency that spies on people so I wonder if it truly is a comprehensive philosophy of security. It might be an attempt to confuse those they spy on with the intent to encourage security gaps. Philosophies of any kind are notorious for not being comprehensive or provable. Is there any research that tries to verify this philosophy? I worked on computer security for a few decades and I've neve…

I would argue that all models are inherently incomplete because they are models (IE - they are the map not the territory). Rather than worrying about completeness, it's better to ask if the model is useful, and if anything would change about the requirement for tradeoffs in security if we used a more complete model?

I would answer that the triad IS useful in this scenario and further that if we used an alternative model (The 7-C's maybe?) we would still find inherently contradictory requirements for almost every security scenario. In fact, we would just MORE more of those trade-offs, further proving that security can never be "perfect."

For example, I can think of several fundamentals the triad doesn't cover directly. Privacy and non-repudiation spring to mind as concepts that don't neatly fit into the CIA triad, but they are the antithesis of each other!

Perfect privacy would require that nobody (including data-owners) can identify the user, and perfect non-repudiation would require that no access be granted without 100% proof of the current user. Again, you are forced to choose and this means that some aspect will always be less than perfect.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#447
post #435

Earlier quoted context omitted.

Generally EA licensing didn't work like that. You still picked individual SKUs (Windows client, Windows Server, SQL Standard, etc), you simply got some level of discount, maybe eval licenses, some level of support, a TAM(CSAM), and paid when you tru-up (was three years, may be different now). There wasn't, as far as I recall, "buy SQL Server Enterprise, get SharePoint Server Enterprise SKU for free" type licensing de…

> There wasn't, as far as I recall, "buy SQL Server Enterprise, get SharePoint Server Enterprise SKU for free" type licensing deals. Yes, I didn't mean to say it was like that. More that you get discounts, credits, etc. Every EA agreement I heard of seemed custom and different for that enterprise needs. Throwing in Azure credits or a discount on a product if you get another product or increase volume, etc seemed to b…

Yes, you're correct, especially now in the days of Azure, credits are typical there, though they often require you to migrate (or create) some amount of workload to qualify, i.e., Microsoft knows they'll make that money back long term.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#448

Earlier quoted context omitted.

So a bunch of Linux systems were compromised or a bunch of Widows?

Nothing was compromised. A bunch of Windows systems were unable to boot. https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_ou...

So a bunch of windows systems experienced a denial of service?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#449
post #159

If I am ever on the board of a company, I will always vote no confidence in the dipshit CTO or founder that willingly install/mandate use of Microsoft junk in the company. As a corporate drone that has accidentally opened various Microsoft office suite links inside of Teams. My dislike for anything Microsoft continues to grow. Am I surprised that sharepoint has vulnerabilities? Hell no.

What would you replace it with? Once an org gets to a certain size, they need something like sharepoint, and would they be any more secure?

In the places I work is either Sharepoint or Alfresco.

I dont know what is worse.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#450

Earlier quoted context omitted.

One should be wary of anyone selling you a solution to your problems they know nothing about. Naturally, the only way to be entirely secure is to shutdown all the applications and decommission all the computers, a solution which the business side tends to finds unreasonable. Thus the tender balance between business needs and business risk emerges as the deciding principle. But the numbers are the numbers in heterogen…

> "a solution which the business side tends to finds unreasonable" Isn't it odd that "unreasonable" solutions keep being suggested in threads started by people who first push Linux, and second ask what the thing even does anyway. > " Thus the tender balance between business needs and business risk emerges as the deciding principle. " There is no tender balance and this is nothing like the deciding principle, and agai…

Whoops. I used hyperbole, and it went undetected. Here: s/the deciding factor/a deciding factor/g. We're good now.
Post reply on HN