Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

231–240 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#231
post #223

Earlier quoted context omitted.

I’ve definitely noticed a correlation with low regard for labor (h1b abuse). But maybe that’s just a location thing, I’m in California where regard for labor, especially local talent, is non-existent. You know, move fast and break things like nascent tech worker unions and the state itself.

WTF is this even supposed to mean? H1Bs use Microsoft products more than others? Or they do it because they have to…or what?? Please explain yourself.

Companies more likely to want to save money on labor costs (employing many h1bs) are also likely to want to save money on Tooling costs, by using safe options like MSFT stuff, rather than finding better tools.

Also yes, due to availability and various other reasons, H1bs, particularly from India, seem more likely to use a MSFT stack.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#232

Earlier quoted context omitted.

I don't know man, you're gonna have a very tough crowd if you're gonna try and convince anyone that Teams is as good as Google Meet.

They are all equally crap. I'm convinced the people designing collaboration tools don't have to use them on a daily basis.

IME the call quality varies quite widely between video calling software. And being able to reliably hear and be heard with reasonable latency is pretty important!

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#233

Earlier quoted context omitted.

If a company provides a Mac laptop, that to me is a green flag, if it provides a Windows laptop, that is a red flag. The best company I ever worked at, provided every software engineer both a Mac laptop and a Linux desktop as standard equipment.

My employer provides a Mac laptop with the Office suite. Red flag, green flag, or yellow?

Word, Excel, and arguably PowerPoint are still the best tools im their respective classes, so if you mean those then very much a green flag.

If they're also making you use Outlook or especially Teams then they're going to start losing "points".

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#234

Earlier quoted context omitted.

Doing research on a potential employer and filtering out opportunities based on preferred toolchains is a green flag not a red flag.

Dev tools, sure. Self-selecting yourself out of the office/email toolset used by 90% of companies seems like a weird flex.

Companies that use Microsoft for one thing invariably use it for another, and then another, and then another, because they're "already paying for it". Their business model has always been like this.

Microsoft Office usage is highly predictive of lots and lots of other choices.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#235
post #19

Earlier quoted context omitted.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

Back in the day, I made the mistake of hooking up a fresh Windows XP (at least I think it was; pre-SP2) install directly to the internet. There was no firewall or NAT to protect me. The machine got pwned almost immediately.

It's still true!

> What happens if you connect Windows XP to the Internet in 2024?

https://youtu.be/6uSVVCmOH5w

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#236
post #48
post #28

Earlier quoted context omitted.

I have a server that has a slow (5s) response to unknown pages, returns it as 200, and makes the next failing request even slower (for unauthenticated users). That seems to keep the number of requests limited. Perhaps I should just drop the connection after a certain number of requests. BTW, quite a few of these port scanners are companies that offer to scan your ports for vulnerabilities. Temu pen testing, so to spe…

Do you configure this in your firewall? How can I replicate this?

what firewall do you use?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#237

Earlier quoted context omitted.

> Also, turning off internet connections means less-capable remote shut shut-off. Why does it have to be remote what's wrong with it being in-house? Besides a shut-off should never be able to be triggered remotely. The same goes for digital emergency shut off buttons; all should be physical. > Less-responsive power plants. What? How is remote any more responsive than physical workers being in-house? If power-plants o…

> Why does it have to be remote what's wrong with it being in-house? Nothing wrong with it being in house. But having a back-up is never bad. > How is remote any more responsive than physical workers being in-house? If the on-site workers are incapacitated. It's a remote (hehe) risk. But so is foreign hackers doing anything with our nukes. > If power-plants operated efficiently back in the 50's without internet, they…

> When expressed in constant 2019 dollars, the average price of electricity in the United States fell from $4.79 per kilowatt-hour in 1902 (the first year for which the national mean is available) to 32 cents in 1950.

https://spectrum.ieee.org/electricity-its-wonderfully-afford...

$0.32 is $0.41 accoreit BLS, which is less than I'm paying today (I live somewhere with expensive electricity), so I'd enjoy the discount if they did!

https://data.bls.gov/cgi-bin/cpicalc.pl?cost1=0.32&year1=201...

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#240
post #222

Earlier quoted context omitted.

It fills a niche. What’s else does? Yes, it’s not great, but so what?

What else? LaTeX Beamer, for one; Libre Office Impress for another.

You are confusing SharePoint with PowerPoint.
Post reply on HN