Earlier quoted context omitted.
How oh how did these nuclear weapons facilities manage to function in the days before Exchange and Sharepoint?
Just like everyone else before invention of Email and Document sharing? However, like every other business, no one is willing to slow down velocity for security reasons so now we are here. Unless you have a fix for "Line must go up", market pressures will always cause this.
Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
121–130 of 404 posts
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#122Earlier quoted context omitted.
I was running millions of accounts using Postfix/Dovecot on shared-nothing storage with a single MUA-facing endpoint and complex policy options, and that was over a decade ago. Fastmail today would be much bigger again, and they’re on CMU Cyrus. 150k is rookie numbers. Perhaps that was meant ironically to satirise mediocre enterprise thinking?
Cool, you got a blog article detailing how that works with Postfix/Dovecot? All clustering articles I'm seeing for those involved shared storage. Fastmail is not very specific how that works. In any case, Exchange is not just email, it has Calendaring/Contacts stuff going on as well.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#123Earlier quoted context omitted.
You can use hosted versions of Google Workplace or Office365 if you can’t figure out how to secure software (places like this typically can’t clearly). Additionally it enforces a separation of concerns where a compromise of your email server doesn’t lead to a compromise of the plant itself (again - clearly IT didn’t know how to partition the network into different parts).
Sure, this business should have converted to either of those and let someone else take over administration since they were clearly negligent. This is stuff that FedRAMP or it's replacement was supposed to fix but didn't.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#124As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…
I see you build a case for traditional MS product in Exchange, yet this issue is about Sharepoint. Just like with Windows, Microsoft has built a moat with Exchange, but the question is why do all the companies buy into their full ecosystem, especially for anything relating to web technologies (you even bring up Exchange Web Services), because this they do really badly, and Sharepoint seems to be the worst. However, I…
Old manager I had one told me: "I wish Microsoft made all the software in the world because it works so well together!" He was the guy who bought our company a one-way ticket to O365. He was also woefully tech ignorant and could barley drive software outside of office programs.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#125That guy who jumped the office chair will be the end of us all
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#126Earlier quoted context omitted.
From the article: > OT cybersecurity specialists interviewed by CSO say that KCNSC’s production systems are likely air-gapped or otherwise isolated from corporate IT networks, significantly reducing the risk of direct crossover. Nevertheless, they caution against assuming such isolation guarantees safety. This was also not a nuclear facility, however. The article says it makes "non-nuclear components". In my experien…
Ah yes, " likely air-gapped", what a high-confidence statement. Any competently designed air-gap must be precisely auditable and demonstrably, positively air-gapped. The only world where "likely" is a reasonable word is in reference to possible physical taps or a precise enumeration of physical access points that went unaudited, but have reliably followed safe access control/configuration procedures. Anything else is…
The root fault with this article, and the resulting discussion, is the extent to which it generalizes over one of the larger organizations in a very complex part of the defense industrial complex. Many parts of KCNSC's operations are absolutely not exposed by this incident. Other parts absolutely are. Determining which fall into which category, and to what extent that is acceptable, keeps quite a few people employed.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#127One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…
Companies that don't use Outlook? All five of them? I've seen companies with varying levels of MS product integration but Outlook is pretty foundational. Now, if a company says they use SharePoint or Teams to store their documentation, run to the hills. Wikis or bust.
Teams macOS client? Crashes on startup, even after clearing all of my user data.
Teams iOS client? You can join a call by a link, but you can't see the call UI because it's behind the login window.
Teams on Firefox? No video support for years, and most recently just glitches out and shows an empty page when trying to join.
Teams on Chrome? Tried joining a meeting, and was told by the organizers that they couldn't admit me because the button wasn't doing anything.
I've had all four of these things happen within the last month, and it's made me want to tear my hair out. I get that none of these are "Microsoft Edge/native Windows client", but they could at least pretend to care about other platforms...
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#128I'm sitting here with a very performant computer running its native web browser.
It's ridiculous that I kept losing my place in that article because the page kept getting shifted to fit yet another damn ad (there were at least three in-view at all times as I was looking at it) onto the screen.
Either make the ads fast and don't load the page until they're all there, or better yet, admit that online content isn't a way to make your private equity group even more obscenely rich, and cut back on the monetization that you put on it.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#129Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge. Sounds like they need to seriously redesign their security policies.
What would you recommend instead?
Decisions like these need to be done from first principles. SharePoint shouldn't even have been a contender here if looked at seriously. Do your own homework.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#130Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge. Sounds like they need to seriously redesign their security policies.
Wait until you hear about the guy storing Top Secret Nuclear documents in the public toilet of his resort....