Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

291–300 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#291
post #129

Earlier quoted context omitted.

What would you recommend instead?

For security-critical or sensitive situations, auditability should be a requirement. That implies access to source code and capabilty to build it. Decisions like these need to be done from first principles. SharePoint shouldn't even have been a contender here if looked at seriously. Do your own homework.

> For security-critical or sensitive situations, auditability should be a requirement. That implies access to source code and capabilty to build it.

Vendors can be accountable without providing source code, for example through contracts specifying performance.

I don't know how large Sharepoint's source is, though it has many components and I assume there is quite a bit of code. Auditing the source code of something like Microsoft Office seems almost impossible.

> first principles.

What does that mean in this context?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#292
post #29

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

> teach our non-tech members how to write LaTeX

How did that go? :)

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#293
post #39
post #29

Earlier quoted context omitted.

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

I am a social worker and SharePoint is unfortunately widely used by nonprofit agencies for storing client records. It's a real shame, but they can't afford anything better.

Why not use a file server and/or a simple database, even a CRM database (there must be FOSS ones)? What do you mean by "client records"?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#294
post #292
post #29

Earlier quoted context omitted.

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

> teach our non-tech members how to write LaTeX How did that go? :)

It's one of those semantic riddles. Because, once they know LaTeX they aren't non-tech anymore. :)

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#295
post #51

Does this kind of thing happen to China + Russia? I don't see news about that much - but to be fair, I am not looking for it.

yes. but it doesn't get covered by western media. much like how NATO airplanes violating Russian airspace is not reported about either.

> much like how NATO airplanes violating Russian airspace is not reported about either.

How do you know it's happening?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#296
post #234

Earlier quoted context omitted.

Dev tools, sure. Self-selecting yourself out of the office/email toolset used by 90% of companies seems like a weird flex.

Companies that use Microsoft for one thing invariably use it for another, and then another, and then another, because they're "already paying for it". Their business model has always been like this. Microsoft Office usage is highly predictive of lots and lots of other choices.

> Microsoft Office usage is highly predictive of lots and lots of other choices.

Job sites could do with this as a filter. Even more specifically, ‘Teams’.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#297
Looking at the comments, it seems like everyone is just busy arguing about Microsoft versus other companies. Does anyone actually care about how this SharePoint vulnerability was exploited?

If Microsoft had just contacted ZAST.AI earlier, I believe this security incident wouldn't even have happened.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#298

Earlier quoted context omitted.

Dev tools, sure. Self-selecting yourself out of the office/email toolset used by 90% of companies seems like a weird flex.

Teams is just so much more horrible than Slack and Zoom, and dev teams use Slack and/or Zoom.

When it was introduced Teams was pretty bad but these days it works just fine. I don't see that it being a decider really more than just historical preference.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#299

Earlier quoted context omitted.

I’m sure the people who designed Teams and Meet use their own products on a daily basis. And if those are crap, what’s a better alternative?

It is funny, that even a Slack Huddle, something that's not even the core of Slack's function, is better than anything one gets with MS Teams. MS Teams is so laughably bad, I think I have never used a worse chat/voice chat/video chat program. Probably not even Skype in its single core days was worse, even though it ate one third of my single core CPU, just to have a call back then.

What is it that is bad about it these days?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#300

Earlier quoted context omitted.

Teams is just so much more horrible than Slack and Zoom, and dev teams use Slack and/or Zoom.

Just because someone uses Outlook doesn’t mean they use Teams too. I’ve seen Zoom or Slack with Outlook/Office suite for the remainder at companies.

Yes - agreed. I'm just saying that in my experience dev teams do care about some tools that Office is trying to replace.
Post reply on HN