Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

221–230 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#221

Earlier quoted context omitted.

Most customers of both use O365. The zoom fascination is pretty weird. It’s literally Webex 3.0 without Cisco bullshit. Slack is pretty awesome. It wouldn’t factor in selecting an employer, but that’s just me.

I definitely wouldn't call Slack "awesome". Self-hosted tools like Zulip are doing a better job. Slack is however, the smaller evil amongst MS Teams, Zoom, MS Outlook and similarly bad software. Like, if someone told me all communication, including text chat shall happen via MS Teams, I would seriously consider looking for another job. It is a recipe for absolute disaster and completely broken communication. If the s…

[flagged]

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#222

Earlier quoted context omitted.

I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount and flagging all from top, implies incompetency at GP's side than at the company side. Like, if a fighter jet pilot came and told all American jets are equally weak and overcomplicated and ineffective, it probably tells more about that pilot than about the jets. I don't know if that's the case, but that w…

SharePoint really is that bad though (and I say this as someone who used to develop for it as a platform). The fact that it's so widespread in our corporate culture is more indicative of how enshittified it is. Now, realistically, we might not be able to avoid it because of that, but let's not pretend that it's not shit.

It fills a niche. What’s else does?

Yes, it’s not great, but so what?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#223
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

I’ve definitely noticed a correlation with low regard for labor (h1b abuse). But maybe that’s just a location thing, I’m in California where regard for labor, especially local talent, is non-existent. You know, move fast and break things like nascent tech worker unions and the state itself.

WTF is this even supposed to mean?

H1Bs use Microsoft products more than others? Or they do it because they have to…or what??

Please explain yourself.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#225
post #197

Whoever puts a nuclear fission facility on the internet should be put behind bars.

It is not a nuclear fission facility, it is "a plant that produces the vast majority of critical non-nuclear components for US nuclear weapons". The also targeted the IT side, not the operational side, which, according to the article is likely to be airgapped. Even sensitive production facilities need some internet access, people work there and like everyone else, they need food, office supplies, toilet paper, etc...…

[deleted]

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#226
post #197

Whoever puts a nuclear fission facility on the internet should be put behind bars.

It is not a nuclear fission facility, it is "a plant that produces the vast majority of critical non-nuclear components for US nuclear weapons". The also targeted the IT side, not the operational side, which, according to the article is likely to be airgapped. Even sensitive production facilities need some internet access, people work there and like everyone else, they need food, office supplies, toilet paper, etc...…

Something tells me they also use it to order operational side materials, including nuclear gear and materials, from the IT side. To expose this on the internet screams of idiocy.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#227

Earlier quoted context omitted.

Wild to see the different experiences here. I haven't worked for a company that uses Outlook in 20+ years. Recently it's all been gmail/google workspaces.

Similar experience; I haven’t had to use Outlook since the late 90s, and even then only for about a year. Every company I worked for before or since just used IMAP.

What did you have as the IMAP client?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#228
post #222

Earlier quoted context omitted.

SharePoint really is that bad though (and I say this as someone who used to develop for it as a platform). The fact that it's so widespread in our corporate culture is more indicative of how enshittified it is. Now, realistically, we might not be able to avoid it because of that, but let's not pretend that it's not shit.

It fills a niche. What’s else does? Yes, it’s not great, but so what?

What else? LaTeX Beamer, for one; Libre Office Impress for another.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#229

Earlier quoted context omitted.

Dev tools, sure. Self-selecting yourself out of the office/email toolset used by 90% of companies seems like a weird flex.

Teams is just so much more horrible than Slack and Zoom, and dev teams use Slack and/or Zoom.

Just because someone uses Outlook doesn’t mean they use Teams too. I’ve seen Zoom or Slack with Outlook/Office suite for the remainder at companies.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#230
post #129

Earlier quoted context omitted.

What would you recommend instead?

For security-critical or sensitive situations, auditability should be a requirement. That implies access to source code and capabilty to build it. Decisions like these need to be done from first principles. SharePoint shouldn't even have been a contender here if looked at seriously. Do your own homework.

Think you answered just about everything except the question asked
Post reply on HN