Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

91–100 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#91

Earlier quoted context omitted.

Because you might need it to share documentation with customers. Confluence isn't just for external documentation. Confluence, at it's core, is just a wiki. Sometimes it needs to be available online, sometimes it really doesn't.

If you’re ok sharing things externally why self-host at all?

Cost? Availability of oodles of storage? Integration with other on-prem systems (such as Active Directory) which maybe you don't want to directly expose by itself.

There's a fair few reasons other than this, it's not unthinkable to host servers yourself if you already have other servers on-prem anyway.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#92
post #83
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> It’s amazing that this company continues to fall up. There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition. Atlassian get a lot of criticism, that's not always justified

> Atlassian get a lot of criticism

Yeah, I think that perception used to be pretty hardcore years ago.

I eventually realised that so many, many companies use this software as a backbone to their company and operations. And for the majority of those, the companies like it. So much so that instead of migrating to a competitor, they move to the new cloud offering.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#93
post #74
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

Because Jira is flexible and has the needed features and integrates with most things you care about. To the point where everyone in the org can tolerate it. Alternatives tend to focus on one group of users and the rest HATE the product.

I've tried a lot of these products and in the end come back to Jira because it works better on average for everyone.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#94
post #36
post #31

Earlier quoted context omitted.

>I'm not sure there is any commercial knowledge base tool that are available on-prem. XWiki?

I personally do not categorize them to equivalent to Confluence, Sharepoint, Notion, Quip, ... but if you do, yeah there are few wiki software which are available on premise.

What can confluence do what XWiki cannot? But i understand that you try to promote your cloud offering ;)

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#95
post #80
post #74

Earlier quoted context omitted.

There are many jira alternatives out there, from what I can tell. Why are they not disrupted already, if it’s such a low hanging fruit? (Honest question - I don’t have any personal preference)

I wish I knew the answer as well. I believe many managers trained in the art of building software without knowing how to build software are too married to doing processes in a very specific way that's very tightly coupled to Jira, and feel safe and at home with the added complexity it provides, so they vouch for it. But that's just a theory from personal experience.

Jira is as complex as you make it and you can't solve people issues with technology. So another solution won't solve your manager problem. That said, the UI is an abomination that will one day summon the elder gods to reap us all.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#96
post #80

Earlier quoted context omitted.

I wish I knew the answer as well. I believe many managers trained in the art of building software without knowing how to build software are too married to doing processes in a very specific way that's very tightly coupled to Jira, and feel safe and at home with the added complexity it provides, so they vouch for it. But that's just a theory from personal experience.

Jira is as complex as you make it and you can't solve people issues with technology. So another solution won't solve your manager problem. That said, the UI is an abomination that will one day summon the elder gods to reap us all.

Yeah, I've never seen the Jira code, but I've dealt with the API. It is VERY clear the software is a chaotic mess based on the API.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#97
post #41

Earlier quoted context omitted.

For a non-technical user group you likely want something more WYSIWYG than Dokuwiki.

Maybe. But I have a hunch that we are severely underestimating huge parts of the workforce. I mean: ux discussions often feels like they assume users are a separate species somewhere between ordinary humans and chimps when it comes to intelligence. I have some experience with training users and I have only given up once.

In my experience, it depends on the industry and company how competent their users will be. I've been a training (back when thinngs were in person) where a user started getting irate because their login wouldn't work to our software. The trainer walked over to see what was going on, and the user was trying to put their login credentials into their bank website instead of ours.

These were sales people.

So often, somewhere right above a chimp is where some of your users are.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#98
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

I once said this too.

Then I tried a bunch of their competitors. Still stuck with some of them.

Sadly, some of Atlassian's products - namely Confluence and Jira - are the best in the business.

Those complaining below about PMs staring at JIRA all day... well, this is a problem with PMs, not JIRA, and it happens even if they are using other work management tools. We created a middleman position in our business to deal with the stuff we didn't want to - tracking work, getting requirements, etc - and we must reap what we've sown. They become obsessed with the management stuff because that's why they exist, and they will fill their time to justify their existence.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#99

Earlier quoted context omitted.

common reasons could be :- - Cost, VPNs and the hardware to run them can be expensive - Single point of failure. If you run all your remote access through a VPN gateway then you run the risk of disruption if it goes down. Of course you can implement redundnt/multiple gateways but that increases cost. - Complexity for B2B setups. If you're exposing an API and you want third party services to access it, it can be more…

A pair of openvpn servers will run you about $100/month in AWS. Sure there is some overhead in running them but not anything more than any other server. Maybe I'm just a jaded Sysop but this stuff is networking 101.

Sure and if you're on AWS you can use their managed offerings. There's a variety of ways of solving it, but it depends on people seeing it as an issue to be solved.

I think, unfortunately, what a lot of people take away from "zero trust networks" as a concept is get rid of all bastions/VPNs and firewalls, but that ultimately leads to the topic of this article...

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#100

Earlier quoted context omitted.

I only got the 'update' from last Saturday, by then it was too late already. Their original advisory was from the 25th, they should have mailed me back then.

How big is your organisation? I know it shouldn’t matter but your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc. I’ve always found government, sensitive customers (banks, payment processors, healthcare) and big spenders get prioritised with phone call notifications. However with a deprecated product, the financial impact is so minuscule - leadership won’t prioriti…

your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc.

The only companies that are like those companies are those companies.

In most companies, the CS people don't know what anything in that sort of alert means and will discard it thinking that it's a spam or phishing attempt.

The problem is not that he doesn't work for a megacorp. The problem is that Atlassian screwed up.

Post reply on HN