Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

241–250 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#241
post #159

Earlier quoted context omitted.

That's basically WSL. My work laptop is Windows, and the only native applications I run on it are a web browser, Zoom, and the company's VPN software. Everything else runs inside WSL. I greatly prefer Debian to Homebrew, so if I can't run actual Linux, this is (to me) superior to trying to develop on a Mac.

I agree that Debian beats Homebrew. But wouldn’t a persistent Debian container on Mac be better? WSL is nothing more than a container on the system, no? The Mac hardware is vastly superior to most Windows laptops, especially enterprise Windows laptops.

You can do that at least for CLI apps with OrbStack. Not sure if it has X or Wayland support.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#242
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

I'm gonna be honest, you sound like a problem employee. The companies not using Microsoft, are using Google. Which in my experience is equally or measurably worse. Just personal data points, but every avowed Microsoft hater I've ever worked with has been... difficult. Like a-drag-on-the-team-because-he-refuses-to-use-company-tools difficult. Edit: How does an aged post on this site go from +4 to -1 in the span of a f…

Well, in my experience every Microsoft shop I've ever interacted with has been a problem employer. Why do you feel your angle has greater moral defensibility?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#243
post #223

Earlier quoted context omitted.

WTF is this even supposed to mean? H1Bs use Microsoft products more than others? Or they do it because they have to…or what?? Please explain yourself.

Companies more likely to want to save money on labor costs (employing many h1bs) are also likely to want to save money on Tooling costs, by using safe options like MSFT stuff, rather than finding better tools. Also yes, due to availability and various other reasons, H1bs, particularly from India, seem more likely to use a MSFT stack.

MSFT tools aren't even cheap - they're very expensive. Many FOSS tools are just better and cheaper. End of the day, even RHEL is cheaper.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#245

Earlier quoted context omitted.

> Why does it have to be remote what's wrong with it being in-house? Nothing wrong with it being in house. But having a back-up is never bad. > How is remote any more responsive than physical workers being in-house? If the on-site workers are incapacitated. It's a remote (hehe) risk. But so is foreign hackers doing anything with our nukes. > If power-plants operated efficiently back in the 50's without internet, they…

> When expressed in constant 2019 dollars, the average price of electricity in the United States fell from $4.79 per kilowatt-hour in 1902 (the first year for which the national mean is available) to 32 cents in 1950. https://spectrum.ieee.org/electricity-its-wonderfully-afford... $0.32 is $0.41 accoreit BLS, which is less than I'm paying today (I live somewhere with expensive electricity), so I'd enjoy the discount…

> $0.32 is $0.41 accoreit BLS, which is less than I'm paying today

Out of curiosity, what was the real power price where you live in the 60s?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#246
If it is that bad why don’t we see it being exploited at scale? I work with many Fortune 500 companies and I would say 9/10 use SharePoint. Also some deployments are much better than others, so I would rather say many implementations of SharePoint are shit but if done right it’s actually pretty solid. There’s really no better alternative unless you want to maintain 5-10 separate tools owned by multiple vendors. I also don’t get the hate for Teams. I use Zoom, Slack even Discord for work and don’t have strong feelings for Teams. I can take calls, join meetings from my calendar, record them and summarize them with Copilot. I don’t need anything else and Teams does that just fine. I do like Discord ability to share multiple screens and jump into a channel to collaborate, particularly useful when debugging or pair programming.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#247

Earlier quoted context omitted.

Most customers of both use O365. The zoom fascination is pretty weird. It’s literally Webex 3.0 without Cisco bullshit. Slack is pretty awesome. It wouldn’t factor in selecting an employer, but that’s just me.

I definitely wouldn't call Slack "awesome". Self-hosted tools like Zulip are doing a better job. Slack is however, the smaller evil amongst MS Teams, Zoom, MS Outlook and similarly bad software. Like, if someone told me all communication, including text chat shall happen via MS Teams, I would seriously consider looking for another job. It is a recipe for absolute disaster and completely broken communication. If the s…

What do you do to make Zulip better than Slack? A vanilla installation is not better, and scales worse with more users, more devices per user more mobile users and more integration sources. But, I’ve never been in a situation where I was forced to make Zulip an attractive communication tool to an organization; there must be a lot that is possible. Getting away from a Salesforce product is a good goal.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#248
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

I'm gonna be honest, you sound like a problem employee. The companies not using Microsoft, are using Google. Which in my experience is equally or measurably worse. Just personal data points, but every avowed Microsoft hater I've ever worked with has been... difficult. Like a-drag-on-the-team-because-he-refuses-to-use-company-tools difficult. Edit: How does an aged post on this site go from +4 to -1 in the span of a f…

> How does an aged post on this site go from +4 to -1 in the span of a few minutes?

I just down-voted you, so I contributed to that.

OP bent over backwards to make it clear that he didn't mean any offense, and you opened with "you sound like a problem employee."

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#249
post #248

Earlier quoted context omitted.

I'm gonna be honest, you sound like a problem employee. The companies not using Microsoft, are using Google. Which in my experience is equally or measurably worse. Just personal data points, but every avowed Microsoft hater I've ever worked with has been... difficult. Like a-drag-on-the-team-because-he-refuses-to-use-company-tools difficult. Edit: How does an aged post on this site go from +4 to -1 in the span of a f…

> How does an aged post on this site go from +4 to -1 in the span of a few minutes? I just down-voted you, so I contributed to that. OP bent over backwards to make it clear that he didn't mean any offense, and you opened with "you sound like a problem employee."

But, he truly does. That is not because they have caused any offence, it's just that this pattern of behaviour may indicate similar tendencies in other parts of the tech stack.

For example, if OP for some reason stops liking a maintainer of, say, RabbitMQ or PostgreSQL, they might be penetrant about switching a finished project to a different stack without any tangible reason, causing completely unnecessary headaches for the team.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#250

Earlier quoted context omitted.

Doing research on a potential employer and filtering out opportunities based on preferred toolchains is a green flag not a red flag.

I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount and flagging all from top, implies incompetency at GP's side than at the company side. Like, if a fighter jet pilot came and told all American jets are equally weak and overcomplicated and ineffective, it probably tells more about that pilot than about the jets. I don't know if that's the case, but that w…

> I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount

I wouldn't be surprised if many people find that smaller companies are more fun/interesting to work at, so even if this were only filtering out large companies checking for MS could be helpful.

Post reply on HN