Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

191–200 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#191
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

it's generally pretty remarkably bad. i think i agree. it sets a sort of psychological baseline culture that computers and their software should be shit, which is a pretty bad influence for people making software to be engaging with day in and day out.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#192

Earlier quoted context omitted.

Companies that don't use Outlook? All five of them? I've seen companies with varying levels of MS product integration but Outlook is pretty foundational. Now, if a company says they use SharePoint or Teams to store their documentation, run to the hills. Wikis or bust.

This varies widely by niche. My experience is that a solid majority of West Coast tech companies / startups use Gmail or other non-MS hosted solutions. Outlook or MS365 are a good indicator that the codebase may be older than some of the people writing it.

Silicon Valley in particular uses Google Workspace at a much higher rate than the rest of the world. If you count every one- or two-person startup as a company, Google probably does have a solid majority. If you count mailboxes, Microsoft still easily wins.

Note that MX records are misleading here. They have no false positives, but are full of false negatives --- daisy-chaining MTAs is common, and since Microsoft owns the mailbox, it's invariably last in the chain. So the MX record will show something like Proofpoint (pphosted) or Mimecast or an internal company host, when really it's Microsoft in the end.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#193
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

Too bad Microsoft shops run the world. All the factories and shops, nearly every commercial backoffice runs windows, office/exchange and what not.

the software is so bad it's literally a national security risk.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#194
post #141

Earlier quoted context omitted.

Um, email was invented, like in the last millenium, well before Microsoft was a thing (only slightly sarky)

Microsoft was a thing before email. Microsoft was founded in 1975. The standard for SMTP wasn't published in 1981. Most early predecessors were the late 70s.

https://en.wikipedia.org/wiki/History_of_email

In 1971 Ray Tomlinson sent the first mail message between two computers on the ARPANET, introducing the now-familiar address syntax with the '@' symbol designating the user's system address.[2][3][4][5] Over a series of RFCs, conventions were refined for sending mail messages over the File Transfer Protocol. Several other email networks developed in the 1970s and expanded subsequently.

Proprietary electronic mail systems began to emerge in the 1970s and early 1980s. IBM developed a primitive in-house solution for office automation over the period 1970–1972, and replaced it with OFS (Office System), providing mail transfer between individuals, in 1974.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#195

Earlier quoted context omitted.

Teams is just so much more horrible than Slack and Zoom, and dev teams use Slack and/or Zoom.

Most customers of both use O365. The zoom fascination is pretty weird. It’s literally Webex 3.0 without Cisco bullshit. Slack is pretty awesome. It wouldn’t factor in selecting an employer, but that’s just me.

I definitely wouldn't call Slack "awesome". Self-hosted tools like Zulip are doing a better job. Slack is however, the smaller evil amongst MS Teams, Zoom, MS Outlook and similarly bad software. Like, if someone told me all communication, including text chat shall happen via MS Teams, I would seriously consider looking for another job. It is a recipe for absolute disaster and completely broken communication. If the same happened with Slack, I would dislike it, but I guess it is at least usable. Still garbage, but not as much garbage, as MS Teams.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#196

Earlier quoted context omitted.

> Why does it have to be remote what's wrong with it being in-house? Nothing wrong with it being in house. But having a back-up is never bad. > How is remote any more responsive than physical workers being in-house? If the on-site workers are incapacitated. It's a remote (hehe) risk. But so is foreign hackers doing anything with our nukes. > If power-plants operated efficiently back in the 50's without internet, they…

good argument against having nukes

One can paraphrase the joke about democracy for nukes. Having nukes is the worst, other than every situation where you don’t have nukes and the other guy does.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#197

Whoever puts a nuclear fission facility on the internet should be put behind bars.

It is not a nuclear fission facility, it is "a plant that produces the vast majority of critical non-nuclear components for US nuclear weapons".

The also targeted the IT side, not the operational side, which, according to the article is likely to be airgapped. Even sensitive production facilities need some internet access, people work there and like everyone else, they need food, office supplies, toilet paper, etc... they can't be cut off the rest of the world completely.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#198

Earlier quoted context omitted.

Doing research on a potential employer and filtering out opportunities based on preferred toolchains is a green flag not a red flag.

I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount and flagging all from top, implies incompetency at GP's side than at the company side. Like, if a fighter jet pilot came and told all American jets are equally weak and overcomplicated and ineffective, it probably tells more about that pilot than about the jets. I don't know if that's the case, but that w…

SharePoint really is that bad though (and I say this as someone who used to develop for it as a platform).

The fact that it's so widespread in our corporate culture is more indicative of how enshittified it is. Now, realistically, we might not be able to avoid it because of that, but let's not pretend that it's not shit.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#199

Earlier quoted context omitted.

They are all equally crap. I'm convinced the people designing collaboration tools don't have to use them on a daily basis.

I’m sure the people who designed Teams and Meet use their own products on a daily basis. And if those are crap, what’s a better alternative?

It is funny, that even a Slack Huddle, something that's not even the core of Slack's function, is better than anything one gets with MS Teams. MS Teams is so laughably bad, I think I have never used a worse chat/voice chat/video chat program. Probably not even Skype in its single core days was worse, even though it ate one third of my single core CPU, just to have a call back then.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#200

Earlier quoted context omitted.

I'm gonna be honest, you sound like a problem employee. The companies not using Microsoft, are using Google. Which in my experience is equally or measurably worse. Just personal data points, but every avowed Microsoft hater I've ever worked with has been... difficult. Like a-drag-on-the-team-because-he-refuses-to-use-company-tools difficult. Edit: How does an aged post on this site go from +4 to -1 in the span of a f…

"using the biggest software suite tailored for offices/IT environments is a red flag" honestly the things i read here sometimes hahaha

If this is "tailored", then I don't even want to know what how bad other MS products are. Oh wait, we can see that in Windows in general. But then again MS Teams is worse. It's almost as if the more MS has its fingers on something, the worse it gets.
Post reply on HN