Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

81–90 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#81
post #41

Earlier quoted context omitted.

> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki . Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but un…

For a non-technical user group you likely want something more WYSIWYG than Dokuwiki.

Maybe. But I have a hunch that we are severely underestimating huge parts of the workforce.

I mean: ux discussions often feels like they assume users are a separate species somewhere between ordinary humans and chimps when it comes to intelligence.

I have some experience with training users and I have only given up once.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#82
post #7

Earlier quoted context omitted.

So that users can be at home or on a mobile device without requiring them to have VPN. But so that you still can ensure data-locality or run a customised instance e.t.c. if you have requirements around that. Plus licensing is approx. 40% of the full SaaS cost at scale so may be cheaper to deploy that way.

But why are they not using VPN?

As well as all the other great reasons listed, you might not want users to have a VPN if for instance they are an external user (e.g. if your client's documentation is on your confluence instance and you want to give them access, it might be a giant pain and bad customer experience to force them to sign into your VPN in order to get access to their documentation).

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#83
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> It’s amazing that this company continues to fall up.

There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition.

Atlassian get a lot of criticism, that's not always justified

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#84
post #64
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

Atlassian products are garbage. So why are they so popular? Because Jira is a wet dream for mediocre micro-managers (of all levels), allowing them to manage by ticket, instead of lead by example.

Hit the nail on the head there.

New thing? Let’s open a new JIRA project and prefix with some random shit show workflow customised by someone who was clearly asleep or incompetent!

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#85
post #74

Earlier quoted context omitted.

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement. You can't easily dump Jira if you are using Jira, confluence, bitbucket, and whatever their CI/CD product is called (bamboo?)

Clubhouse (soon to be renamed Shortcut) covers the first two. Github covers the latter two. It's easier to switch than ever.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#86
post #41

Earlier quoted context omitted.

For a non-technical user group you likely want something more WYSIWYG than Dokuwiki.

Maybe. But I have a hunch that we are severely underestimating huge parts of the workforce. I mean: ux discussions often feels like they assume users are a separate species somewhere between ordinary humans and chimps when it comes to intelligence. I have some experience with training users and I have only given up once.

I fully agree that you can train users for a lot. But the question is if it's worth doing so in the specific case. And wikis often already have trouble with people not using them enough, making them seemingly hard to use doesn't help.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#87
> The vulnerability only affects on-premise servers, not those hosted in the cloud.

This is a dangerous statement to make and should be revised to say:

> The vulnerability only affects standalone versions of the software, not the managed service of confluence provided directly by Atlassian.

The problem with the former is that lesser technical people, especially directors, might assume they're fine because their standalone instances are hosted on GCP/AWS/Azure, which counts to them as "cloud".

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#88
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> awful engineering practices that underpin

And what are these practices?

> assume that there are problems of a similar nature in their cloud service

?

> then everyone around them also started laughing

You know, I'm sure that highly paid dev felt just fine.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#89

Earlier quoted context omitted.

If you’re ok sharing things externally why self-host at all?

> If you’re ok sharing things externally why self-host at all? You're theoretically more in control of the data, which may be a legal requirement in certain jurisdictions and/or industries.

Atlassian is not HIPAA compliant, so many are forced to install their tools on on-prem.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#90

My employer was bit by this on Wednesday. Thankfully we had Crowdstrike on it which blocked any real damage. But it definitely moved our cloud migration from “later this year” to “later this month”. Also, not having confluence for a day exposed just how reliant we were on it for day-to-day activities.

Security is planning to implement here CrowdStrike in the near future... does it run on every single server?

Yes.
Post reply on HN