Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

61–70 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#61

Earlier quoted context omitted.

But jira is only a tool right? Blaming Atlassian for a poorly led organization seems slightly misguided. At some project size, measured either by software complexity/interoperability or user base, you will need a tool to manage issues and tasks. What you're talking about is an organization where developers are not empowered - but even empowered developers need an issue tracker or a board of some description. A "manag…

A good tool cannot guarantee good results, but a bad tool can shape its user's behavior in bad ways. The same individual without that tool might have behaved differently. I have seen this in what I call design-by-ticket where all the why and how for a design decision, including design by committee meeting notes, get put in jira tickets.

Totally agree with your first two sentences.

However, the final part has nothing to do with jira IMO. You would have the same behavior in these organizations regardless of tool.

The dysfunction you describe goes way beyond a single or set of tools.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#62

Atlassian was so kind to update their mailing lists somewhere over the last year or so. Previously, they would email the 'technical contact' of the license about any vulnerabilities. They quietly switched to some other notification system and never informed us about it. Hence we missed the update and got a free Bitcoin miner. Thanks Atlassian, I'll make sure to get your products out of the door as soon as possible. […

Did you check your spam folder? Just saying emails can slip through the cracks.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#63

Earlier quoted context omitted.

Because you might need it to share documentation with customers. Confluence isn't just for external documentation. Confluence, at it's core, is just a wiki. Sometimes it needs to be available online, sometimes it really doesn't.

If you’re ok sharing things externally why self-host at all?

> If you’re ok sharing things externally why self-host at all?

You're theoretically more in control of the data, which may be a legal requirement in certain jurisdictions and/or industries.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#64
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

Atlassian products are garbage.

So why are they so popular? Because Jira is a wet dream for mediocre micro-managers (of all levels), allowing them to manage by ticket, instead of lead by example.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#65
post #29
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

Biased but I'm actually building a competitor (V1 is almost ready) to Confluence for medium to big organizations. But I don't understand your requirement for on-prem. That's clearly not an advantage from the security point of view. Apart from Quip, Sharepoint and Confluence (soon stopped) I'm not sure there is any commercial knowledge base tool that are available on-prem. The only thing that you can hope for, is "bri…

Plenty of deployments will continue to be on-prem, cloud is not perfect for 100% of use cases.

Example: If you are a semiconductor manufacturer, you probably are not going to be storing all the documentation about your bleeding edge fabs on a cloud provider.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#66

Atlassian was so kind to update their mailing lists somewhere over the last year or so. Previously, they would email the 'technical contact' of the license about any vulnerabilities. They quietly switched to some other notification system and never informed us about it. Hence we missed the update and got a free Bitcoin miner. Thanks Atlassian, I'll make sure to get your products out of the door as soon as possible. […

Did you check your spam folder? Just saying emails can slip through the cracks.

Yes, I did. I also ran an Exchange Message Trace (this is just standard Office 365, nothing fancy) and there was only 1 message from Atlassian in the last 15 days which was the update email that was too late to prevent exploitation. So they did not email me in time.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#67

Earlier quoted context omitted.

I only got the 'update' from last Saturday, by then it was too late already. Their original advisory was from the 25th, they should have mailed me back then.

How big is your organisation? I know it shouldn’t matter but your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc. I’ve always found government, sensitive customers (banks, payment processors, healthcare) and big spenders get prioritised with phone call notifications. However with a deprecated product, the financial impact is so minuscule - leadership won’t prioriti…

It's tiny, I just want them to send me an email if there is a critical vulnerability. Not too much to ask, I think.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#68
post #29
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

Biased but I'm actually building a competitor (V1 is almost ready) to Confluence for medium to big organizations. But I don't understand your requirement for on-prem. That's clearly not an advantage from the security point of view. Apart from Quip, Sharepoint and Confluence (soon stopped) I'm not sure there is any commercial knowledge base tool that are available on-prem. The only thing that you can hope for, is "bri…

Being able to self-host is a hard requirement for many organizations. Especially for tools like a wiki, which may contain proprietary/secret business information.

The last time we reviewed the Atlassian Cloud hosted products, they did not meet our security needs (requirements include isolated tenant from other customers, customer managed keys, etc) though they were much closer than a few years earlier. We also review the general security practices of the company (for example to make sure they implement a secure SDLC and follow other security best-practices).

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#69

Earlier quoted context omitted.

If you’re ok sharing things externally why self-host at all?

> If you’re ok sharing things externally why self-host at all? You're theoretically more in control of the data, which may be a legal requirement in certain jurisdictions and/or industries.

Due to the "TOLA" Australian law, all Atlassian products should be avoided if you care about being in control of the data.

https://www.zdnet.com/article/whats-actually-in-australias-e...

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#70

Earlier quoted context omitted.

A good tool cannot guarantee good results, but a bad tool can shape its user's behavior in bad ways. The same individual without that tool might have behaved differently. I have seen this in what I call design-by-ticket where all the why and how for a design decision, including design by committee meeting notes, get put in jira tickets.

Totally agree with your first two sentences. However, the final part has nothing to do with jira IMO. You would have the same behavior in these organizations regardless of tool. The dysfunction you describe goes way beyond a single or set of tools.

It is hard to say for sure, but this organization used configuration controlled documents for design documentation before atlassian came along. When they made the switch (and hired oodles of graduates) suddenly about half of them ignore confluence or latex for design, because "jira has markdown". Oh hurray, we have a bad typesetting language mixed in with our bug tracker, lets shove our entire design in there! It is possible this is the influence of the graduates we hired, but it felt like everyone got there together while playing with the new toy.
Post reply on HN