6 ms·
It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo). If you work in IT, this
by sanskarix 1y ago
It’s kind of wild how we end up here over and over, a big government breach, angry headlines, but the tech never seems to change (imo).
If you work in IT, this whole SharePoint story is probably a deja vu,
A few real-world points that stood out to me:
- SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” and nobody got fired for rolling it out in the 2000s. Once you’re deep into the Microsoft ecosystem, the cost and pain of replaccing is huge!
- Security honestly feels like a service for a lot of giants. When someone asks if it’s the number one priority, the answer from experiencem, is “no.”
Cost, compliance available support, and how easy it is to blame a vendor if things fail tend to matter more.
- When people say Linux would be more secure in these environments, maybe. But if Linux or Red Hat took over everywhere, you can bet it would become the juiciest target immediately. Right now, Windows gets a lot of attention because it’s everywhere. And obviously, attackers like to go where the odds of a big payoff are highest.
- A lot of giants aren’t making decisions based only on security or technical merit. It’s about familiarity, employee training costs, consulting partners, and “safe” bets. If you pick Microsoft and get breached, it’s an industry problem. If you pick something niche and get breached... it’s 100% your fault.
- Resistance to change is real. Swapping out platforms isn’t just a technical lift. Management, end users, even IT staff get pretty set in their ways.
Honestly, unless there’s enough public backlash or a relgulation hammer, I don’t see the inertia breaking any time soon. For most companies, “patch and carry on” still beats “burn it all down and start fresh.”
- jon-wood 1y agoWhile I agree with you on most points, security is never the number one priority. If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. Security is always weighed against many other priorities such as authorised users being able to access data, and ease of use. A unique 128 character password for each document would have high security, but be widely considered unacceptable even in a system handling classified material.
- kibwen 1y ago> If it were we'd all destroy our computers, never write anything down, and simply accept the collapse of society. No, this is the same sort of defeatism that prevents us from making progress on security. We could engineer usable systems where actual security is a priority, and not just security theater. We don't because nobody in a position to change anything actually gives a shit.
- mpyne 1y ago> We could engineer usable systems where actual security is a priority, Security is a priority. But it's not the only priority. It would be difficult engineering even if it was the only priority, but given that there's little point to security for a system you never deploy, it's not likely to ever completely monopolize focus, either for users or implementers.
- autoexec 1y agoAt this point i don't think security is a priority at all for companies like MS. Marketing themselves has having security is a priority. Doing the bare minimum to avoid lawsuits is their priority. Ultimately though, they know that no matter how many times their failure to invest in security results in their customer's data being compromised or destroyed they'll keep making money. Their customers are corporations who have insurance to cover their expenses when Microsoft's failure to make security a priority inevitably leads to a breech and those corporations are able to avoid all accountability for their decision to use Microsoft products no matter who else gets hurt as a result. Dealing with yet another security issue caused by Microsoft is just another cost of doing business. It's still cheaper and/or easier for the corporations to keep MS and deal with the endless vulnerability/patch cycle than it is to move to something else and pay people who know what they're doing to manage those new systems so nothing changes.
- jon-wood 1y agoYou can engineer systems where security is a priority. You can't engineer useful systems where security is the priority.
- arccy 1y agowith microsoft's history of insecurity, if you pick microsoft (or azure) and get breached, it's totally on you.
- p_ing 1y ago> SharePoint (and a lot of other MS stuff) didn’t win because it was bulletproof, just because it was bundled “FREE” In what world has SharePoint Server and SharePoint Standard + Enterprise User CALs ever been "FREE"? > Security honestly feels like a service for a lot of giants. While code security is on Microsoft, infrastructure security is on the organization deploying SharePoint Server. Remember, the topic you're commenting on is about SharePoint Server. Not M365. Not SPO.
- eddythompson80 1y ago> In what world has SharePoint Server and SharePoint Standard + Enterprise User CALs ever been "FREE"? Yeah.. I think people say "bundled FREE" when they really referring to MS enterprise packages. It's similar to how Comcast will sell you TV for $100, land line for $20, internet for $100, but you can get a TV/land line package for $90? or a TV/internet for $130. You can "bundle FREE" phone on your TV/internet package for an extra $5. (And yes, I heard support before tell me "For $10 more a month, you get a free upgrade to 1Gbps". ???? How is that free? They will say "It's the same package, but one level up for $10 more. It comes with free 1Gbps upgrade. what doesn't make sense?"
- p_ing 1y agoGenerally EA licensing didn't work like that. You still picked individual SKUs (Windows client, Windows Server, SQL Standard, etc), you simply got some level of discount, maybe eval licenses, some level of support, a TAM(CSAM), and paid when you tru-up (was three years, may be different now). There wasn't, as far as I recall, "buy SQL Server Enterprise, get SharePoint Server Enterprise SKU for free" type licensing deals.
- eddythompson80 1y ago> There wasn't, as far as I recall, "buy SQL Server Enterprise, get SharePoint Server Enterprise SKU for free" type licensing deals. Yes, I didn't mean to say it was like that. More that you get discounts, credits, etc. Every EA agreement I heard of seemed custom and different for that enterprise needs. Throwing in Azure credits or a discount on a product if you get another product or increase volume, etc seemed to be typical.
- skeeterbug 1y ago> Right now, Windows gets a lot of attention because it’s everywhere. I disagree with this take. Linux dominates in the server market.
- gjsman-1000 1y agoYeah... but mostly external services. Meanwhile, Windows is running the crown jewels for operations inside the company, like SharePoint and Active Directory.
- kuhsaft 1y agoThe issue isn’t Windows vs Linux. It’s an application security exploit and it just so happens that it only runs on Windows. SharePoint Server is widely used and is a high value target. Atlassian Server products have had their fair share of 0-day exploits. Atlassian also EOL their server products and forced a cloud migration.
- graemep 1y ago> When people say Linux would be more secure in these environments, maybe. But if Linux or Red Hat took over everywhere, you can bet it would become the juiciest target immediately. I do not think that is the only difference between Windows and Linux though. For one thing Linux has multiple distros, some very varied. Its less of a monoculture. If Linux was more widely used it would also get grater usage for BSDs because a lot of things that run on Linux will run on them too. Linux IS very widely used on servers, and on Chromebooks, and embedded. The kernel and a few other bits are widely used on phones too.
- sirjaz 1y agoLook at Android. It is more of a leaky sive than Windows now.
- autoexec 1y agoAndroid was designed from day one specifically to be a leaky sieve that funnels as much of your personal and private data to Google and their partners as possible. They're left with the impossible task of making it harder for third parties to gain access to the data they're collecting without making it too hard for them to collect it for themselves.
- mixdup 1y agoSomething to understand here is that Sharepoint is not Windows. Sure it runs on Windows, but the vulnerability here was the application. Are we going to argue that applications that run on Linux cannot have security vulnerabilities? Especially large archaic enterprisey things like this? I bet Oracle and SAP have similar types of things happen to their application suites but no one runs public websites on Oracle eApplications (yeah, plenty of companies have that exposed to the internet, but it's not The Company's Website)