Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

11–20 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#11
post #8
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Wasn't the internet literally created by the military for military comms? The decentralized routing was in part to ensure that comms could survive some areas being taken out by nuclear weapons.

As the effect of yesterday's AWS event demonstrates, the major Amazon, Microsoft, and Google data centers are surely top tier targets in every adversary's war plans.

The decentralized internet is less of a reality today than it was years ago.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#12
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

You mean its a bad idea to slap a Starlink dish in the same building as the nuclear football?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#13
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

> needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet

Why the special treatment for nuclear? Do you really think redlining a dam or storm-levee system would be less damaging?

Also, turning off internet connections means less-capable remote shut shut-off. Less-responsive power plants. Fewer eyes on telemetry.

We should be mindful of what is and isn't connected to the internet, and how it's firewalled and--if necessary--air gapped. That doesn't mean sprinting straight for the end zone.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#14
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#15
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Wasn't it literally designed for that specific task? As a robust C&C system during nuclear war? The fact that we're doing it wrong doesn't mean we need to pull the plug on everything. How else do you survive WWIII?

https://ieeexplore.ieee.org/document/5432117

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#16
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

Every public IPv4 address is port scanned multiple times a day.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#17
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

> needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet Why the special treatment for nuclear? Do you really think redlining a dam or storm-levee system would be less damaging? Also, turning off internet connections means less-capable remote shut shut-off. Less-responsive power plants. Fewer eyes on telemetry. We should be mindful of what is and isn't connected to the i…

> Also, turning off internet connections means less-capable remote shut shut-off.

Why does it have to be remote what's wrong with it being in-house? Besides a shut-off should never be able to be triggered remotely.

The same goes for digital emergency shut off buttons; all should be physical.

> Less-responsive power plants.

What? How is remote any more responsive than physical workers being in-house?

If power-plants operated efficiently back in the 50's without internet, they should be able to now without internet.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#18

Earlier quoted context omitted.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

Every public IPv4 address is port scanned multiple times a day.

Which really isn't a problem, unless you're being scanned so much your bandwidth is being overwhelmed. Certainly not the case for me, despite having port 80 and 443 open

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#19
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

Back in the day, I made the mistake of hooking up a fresh Windows XP (at least I think it was; pre-SP2) install directly to the internet. There was no firewall or NAT to protect me. The machine got pwned almost immediately.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#20

Earlier quoted context omitted.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

Every public IPv4 address is port scanned multiple times a day.

Watching my website's firewall and ssh logs show all the various hacking attempts is calming in the same way that watching waves crash on to the shore is.
Post reply on HN