Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

271–280 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#271

Earlier quoted context omitted.

They are all equally crap. I'm convinced the people designing collaboration tools don't have to use them on a daily basis.

I’m sure the people who designed Teams and Meet use their own products on a daily basis. And if those are crap, what’s a better alternative?

Do they? Didn’t Microsoft force all its employees back to the office?

That doesn’t sound like they have faith in Teams themselves.

I use Teams every day and it can’t even do threading in channels properly. The spellchecker is unreliable and even copy and paste is occasionally patchy.

It is not a good product. I’d switch to Slack given the choice.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#272

Earlier quoted context omitted.

Dev tools, sure. Self-selecting yourself out of the office/email toolset used by 90% of companies seems like a weird flex.

Teams is just so much more horrible than Slack and Zoom, and dev teams use Slack and/or Zoom.

My company uses both outlook and slack. Teams is also used for scheduled meetings but never touched for chat. I personally don’t find teams to be significantly worse than zoom but I’d rather never use either.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#273

Earlier quoted context omitted.

I definitely wouldn't call Slack "awesome". Self-hosted tools like Zulip are doing a better job. Slack is however, the smaller evil amongst MS Teams, Zoom, MS Outlook and similarly bad software. Like, if someone told me all communication, including text chat shall happen via MS Teams, I would seriously consider looking for another job. It is a recipe for absolute disaster and completely broken communication. If the s…

What do you do to make Zulip better than Slack? A vanilla installation is not better, and scales worse with more users, more devices per user more mobile users and more integration sources. But, I’ve never been in a situation where I was forced to make Zulip an attractive communication tool to an organization; there must be a lot that is possible. Getting away from a Salesforce product is a good goal.

I’ve never touched a scaling issue with Zulip, how many devices are we talking about here? Maybe I’ve just never touched the walls of scaling it. The architecture seems fine to scale if you self host though.

The only issues I’ve found with Zulip is how it looks and training people to use it right. I’ve had a lot of comments that Zulip has ruined people because they realised how good it is only after they stopped using it, and can tell that everything is so much worse, but the whole time they used it- they hated it.

The other issue, if we can call it as such, is that there’s not that many native third party integrations, we had to write our own bots for some pretty basic things. But writing bots is so much easier in Zulip than Slack (and for Teams its a lesson in genuine masochism) so I give them a pass.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#275
post #222

Earlier quoted context omitted.

It fills a niche. What’s else does? Yes, it’s not great, but so what?

What niche?

The niche of trying to do everything and being good at none of it.

File hosting, web application hosting and integrating with Office.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#276
post #246

If it is that bad why don’t we see it being exploited at scale? I work with many Fortune 500 companies and I would say 9/10 use SharePoint. Also some deployments are much better than others, so I would rather say many implementations of SharePoint are shit but if done right it’s actually pretty solid. There’s really no better alternative unless you want to maintain 5-10 separate tools owned by multiple vendors. I als…

Most people treat Sharepoint for what it is, and only expose it internally.

With Microsoft pushing o365 the “new” Sharepoint is SaaS instead, so Microsoft is exposing it to the internet on your behalf, but then they make a lot of effort to patch it and use WAFs on your behalf instead.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#277

Earlier quoted context omitted.

[flagged]

[flagged]

What a worthwhile contribution to the thread, though an ironic one, considering that you're echoing the very same sentiment - albeit reversed - that the person to whom you're replying did.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#278

Earlier quoted context omitted.

I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount and flagging all from top, implies incompetency at GP's side than at the company side. Like, if a fighter jet pilot came and told all American jets are equally weak and overcomplicated and ineffective, it probably tells more about that pilot than about the jets. I don't know if that's the case, but that w…

> I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount I wouldn't be surprised if many people find that smaller companies are more fun/interesting to work at, so even if this were only filtering out large companies checking for MS could be helpful.

Then it's an overcomplicated company size check.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#279

Earlier quoted context omitted.

Doing research on a potential employer and filtering out opportunities based on preferred toolchains is a green flag not a red flag.

In this economy? This sounds like a fantasy.

OP might not have recently been looking for a job.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#280
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

If a company provides a Mac laptop, that to me is a green flag, if it provides a Windows laptop, that is a red flag. The best company I ever worked at, provided every software engineer both a Mac laptop and a Linux desktop as standard equipment.

Both are a red flag
Post reply on HN