Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

91–100 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#91
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

While we're at it "and not use Microsoft products". Literally every time a story like this surfaces...

> While we're at it "and not use Microsoft products".

I'm not sure if Oracle would be better.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#92
post #54
post #47

Earlier quoted context omitted.

From the article: > OT cybersecurity specialists interviewed by CSO say that KCNSC’s production systems are likely air-gapped or otherwise isolated from corporate IT networks, significantly reducing the risk of direct crossover. Nevertheless, they caution against assuming such isolation guarantees safety. This was also not a nuclear facility, however. The article says it makes "non-nuclear components". In my experien…

Ah yes, " likely air-gapped", what a high-confidence statement. Any competently designed air-gap must be precisely auditable and demonstrably, positively air-gapped. The only world where "likely" is a reasonable word is in reference to possible physical taps or a precise enumeration of physical access points that went unaudited, but have reliably followed safe access control/configuration procedures. Anything else is…

> Anything else is plain incompetence.

It's an answer from talking heads, not from people from the facility.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#93
post #8
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Wasn't the internet literally created by the military for military comms? The decentralized routing was in part to ensure that comms could survive some areas being taken out by nuclear weapons.

The very very earliest form of some of the protocols involved it were, yes. But not really now at all. That "internet" would not be worth using.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#94
One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop.

If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlated with me hating the engineering culture of an organization.

I know I am excluding a lot of companies with great engineering culture where I would thrive and who just happen to use Outlook/Sharepoint/Teams, etc. but it has had such better predictive power of rotten tech culture than any line of questioning I have come up with during interviews that I still use it.

I don’t mean any disrespect to MSFT-centric engineers out there - it’s not you it’s me.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#95

As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…

I see you build a case for traditional MS product in Exchange, yet this issue is about Sharepoint.

Just like with Windows, Microsoft has built a moat with Exchange, but the question is why do all the companies buy into their full ecosystem, especially for anything relating to web technologies (you even bring up Exchange Web Services), because this they do really badly, and Sharepoint seems to be the worst.

However, I am certain there are big Postfix/Dovecot installations scaling easily to 150k people, but we probably wouldn't know about them. Eg. here a couple of accounts of people doing that: https://www.reddit.com/r/linuxadmin/comments/32fq67/how_woul...

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#96
post #27

Earlier quoted context omitted.

Being airgapped didn't help Iran avoid Stuxnet.

That also had a HUMINT element.

It’s possible that the (un)timely demise of the individual involved also had a HUMINT element as well.

https://en.wikipedia.org/wiki/Operation_Olympic_Games#Histor...

> Dutch engineer Erik van Sabben allegedly infiltrated the Natanz nuclear facility on behalf of Dutch intelligence and installed equipment infected with Stuxnet. He died two weeks after the Stuxnet attack at age 36 in an apparent single-vehicle motorcycle accident in Dubai.

https://en.wikipedia.org/wiki/Erik_van_Sabben

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#97

As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…

Why is this comment glowing? \s

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#98

As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…

You can use hosted versions of Google Workplace or Office365 if you can’t figure out how to secure software (places like this typically can’t clearly). Additionally it enforces a separation of concerns where a compromise of your email server doesn’t lead to a compromise of the plant itself (again - clearly IT didn’t know how to partition the network into different parts).

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#99

As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…

[deleted]

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#100

Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge. Sounds like they need to seriously redesign their security policies.

What would you recommend instead?
Post reply on HN