Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

171–180 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#171
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

Companies that don't use Outlook? All five of them? I've seen companies with varying levels of MS product integration but Outlook is pretty foundational. Now, if a company says they use SharePoint or Teams to store their documentation, run to the hills. Wikis or bust.

I've been at quite a few places that wouldn't touch the MS ecosystem with a twenty-foot pole, and history has proven that to be a wise decision on their part. It certainly has not cost them any business.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#172
post #8
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Wasn't the internet literally created by the military for military comms? The decentralized routing was in part to ensure that comms could survive some areas being taken out by nuclear weapons.

That's fine, when all the nodes run autonomously and the internet is only used for real information sharing. What we now have is that the nodes are display control servers and all the computation and storage happens externally. That is not how it was designed by the military.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#173

Earlier quoted context omitted.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

Every public IPv4 address is port scanned multiple times a day.

Per day? per minute or second.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#174

Earlier quoted context omitted.

I was running millions of accounts using Postfix/Dovecot on shared-nothing storage with a single MUA-facing endpoint and complex policy options, and that was over a decade ago. Fastmail today would be much bigger again, and they’re on CMU Cyrus. 150k is rookie numbers. Perhaps that was meant ironically to satirise mediocre enterprise thinking?

Cool. I did that with qmail in 1998 on a couple of Ultra 5s. Try managing a calendar or booking resources.

Integrated CalDAV is also available. Not in qmail, however. The patch for that would be large.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#175
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Wasn't it literally designed for that specific task? As a robust C&C system during nuclear war? The fact that we're doing it wrong doesn't mean we need to pull the plug on everything. How else do you survive WWIII? https://ieeexplore.ieee.org/document/5432117

That only works, if the nodes still operate just fine, without the Internet.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#176
post #130
post #84

Earlier quoted context omitted.

Wait until you hear about the guy storing Top Secret Nuclear documents in the public toilet of his resort....

Down voting like it never happened... https://upload.wikimedia.org/wikipedia/commons/5/52/Classifi...

In general you'll get downvoted if you're talking about any politician or political party. You are allowed to shit on (or advocate for) the government doing stuff tho.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#177
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

Too bad Microsoft shops run the world. All the factories and shops, nearly every commercial backoffice runs windows, office/exchange and what not.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#178
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

I’ve definitely noticed a correlation with low regard for labor (h1b abuse). But maybe that’s just a location thing, I’m in California where regard for labor, especially local talent, is non-existent. You know, move fast and break things like nascent tech worker unions and the state itself.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#179

Earlier quoted context omitted.

I'm gonna be honest, you sound like a problem employee. The companies not using Microsoft, are using Google. Which in my experience is equally or measurably worse. Just personal data points, but every avowed Microsoft hater I've ever worked with has been... difficult. Like a-drag-on-the-team-because-he-refuses-to-use-company-tools difficult. Edit: How does an aged post on this site go from +4 to -1 in the span of a f…

Doing research on a potential employer and filtering out opportunities based on preferred toolchains is a green flag not a red flag.

I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount and flagging all from top, implies incompetency at GP's side than at the company side.

Like, if a fighter jet pilot came and told all American jets are equally weak and overcomplicated and ineffective, it probably tells more about that pilot than about the jets.

I don't know if that's the case, but that would be the idea.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#180

Earlier quoted context omitted.

> Also, turning off internet connections means less-capable remote shut shut-off. Why does it have to be remote what's wrong with it being in-house? Besides a shut-off should never be able to be triggered remotely. The same goes for digital emergency shut off buttons; all should be physical. > Less-responsive power plants. What? How is remote any more responsive than physical workers being in-house? If power-plants o…

> Why does it have to be remote what's wrong with it being in-house? Nothing wrong with it being in house. But having a back-up is never bad. > How is remote any more responsive than physical workers being in-house? If the on-site workers are incapacitated. It's a remote (hehe) risk. But so is foreign hackers doing anything with our nukes. > If power-plants operated efficiently back in the 50's without internet, they…

good argument against having nukes
Post reply on HN