Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

31–40 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#31
Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge.

Sounds like they need to seriously redesign their security policies.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#32
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

> needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet You want to make everything about a nuclear facility bespoke and subject to air-gapped drift? What about the guard booth that verifies peoples access, the receptionist who schedules meetings, and the janitor who wants to watch YouTube on his break? It seems unrealistic to lump everything that goes on at a nuclear f…

Opening up the internet to a nuclear facility so that the janitor can watch Youtube seems preposterous. People can afford to do things slower for the sake of security. Having things typed out, verifying security via phone calls, etc like it's the 1970s seems reasonable to me. Does it really matter if things aren't fully optimized for speed and convenience in nuclear facilities?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#33
post #27
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Being airgapped didn't help Iran avoid Stuxnet.

That also had a HUMINT element.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#34
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Fine, keep it on the internet. But SharePoint, seriously? A 15 year old version of nginx pointed to the ~/.ssh folder is more secure.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#35

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

Every time I need to touch anything made my Microsoft lately I am met with multiple levels of glitchyness, straight up bugs, most frustratingly it’s so excruciatingly slow.

Recently I tried to configure a new subdomain to handle mail on 365 and even finding their DKIM configuration section was a mission. Once finding it, I learned that their DNS check fails to properly handle subdomains for email, so you have to put their DKIM keys against your root domain. Genius!

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#36
post #29

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

Not defending Microsoft in any way but my guess of what's happening:

* Too few people use Firefox to access Office online, they don't care

* Your organization is too small for them to care

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#37

Earlier quoted context omitted.

> needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet You want to make everything about a nuclear facility bespoke and subject to air-gapped drift? What about the guard booth that verifies peoples access, the receptionist who schedules meetings, and the janitor who wants to watch YouTube on his break? It seems unrealistic to lump everything that goes on at a nuclear f…

Opening up the internet to a nuclear facility so that the janitor can watch Youtube seems preposterous. People can afford to do things slower for the sake of security. Having things typed out, verifying security via phone calls, etc like it's the 1970s seems reasonable to me. Does it really matter if things aren't fully optimized for speed and convenience in nuclear facilities?

> really matter if things aren't fully optimized for speed and convenience in nuclear facilities

For hiring and retaining people, yes. It's understood that the "guts" of what's happening at these facilities needs to be locked down to the max. But, for supporting roles you need to be able to bring people in off the street without 1) a bunch of specialized training on your bespoke way of doing things, and 2) making your employees less attractive on the job market.

Just my opinion, though. Maybe I'm completely off base but it doesn't seem like a good idea to me long-term.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#38
post #27
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Being airgapped didn't help Iran avoid Stuxnet.

No, but it made the attacker's job 10000X more difficult.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#39
post #29

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

I am a social worker and SharePoint is unfortunately widely used by nonprofit agencies for storing client records. It's a real shame, but they can't afford anything better.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#40

Earlier quoted context omitted.

> needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet Why the special treatment for nuclear? Do you really think redlining a dam or storm-levee system would be less damaging? Also, turning off internet connections means less-capable remote shut shut-off. Less-responsive power plants. Fewer eyes on telemetry. We should be mindful of what is and isn't connected to the i…

> Also, turning off internet connections means less-capable remote shut shut-off. Why does it have to be remote what's wrong with it being in-house? Besides a shut-off should never be able to be triggered remotely. The same goes for digital emergency shut off buttons; all should be physical. > Less-responsive power plants. What? How is remote any more responsive than physical workers being in-house? If power-plants o…

> Why does it have to be remote what's wrong with it being in-house?

Nothing wrong with it being in house. But having a back-up is never bad.

> How is remote any more responsive than physical workers being in-house?

If the on-site workers are incapacitated. It's a remote (hehe) risk. But so is foreign hackers doing anything with our nukes.

> If power-plants operated efficiently back in the 50's without internet, they should be able to now without internet

If you're fine paying 50s power prices again, sure, I'm sure a power company would happily run their plants retro style.

Post reply on HN