Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

351–360 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#351
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

If a company provides a Mac laptop, that to me is a green flag, if it provides a Windows laptop, that is a red flag. The best company I ever worked at, provided every software engineer both a Mac laptop and a Linux desktop as standard equipment.

My workplace let's me choose Mac or Dell laptops.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#352

Earlier quoted context omitted.

> Microsoft Office usage is highly predictive of lots and lots of other choices. Job sites could do with this as a filter. Even more specifically, ‘Teams’.

I don't mind teams but really do hate outlook.

But you can ‘thumbs up’ an email!

Do you even read your ‘weekly digest’?

/s

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#353

Earlier quoted context omitted.

Comparing postfix/dovecot to exchange is grossly misunderstanding what’s happening If you’re using exchange/outlook, you’re using Active Directory. The only real “altetnative” is the reimplementation in samba v4.. calling that an alternative is a bit of a stretch. And it barely scales to one user let alone millions like AD can

You can trivially set up Postfix/Dovecot with LDAP.

There’s nothing trivial about running or scaling an ldap server.

Ldap is also not Active Directory. Ldap is one very small part of it

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#354

Earlier quoted context omitted.

What do you do to make Zulip better than Slack? A vanilla installation is not better, and scales worse with more users, more devices per user more mobile users and more integration sources. But, I’ve never been in a situation where I was forced to make Zulip an attractive communication tool to an organization; there must be a lot that is possible. Getting away from a Salesforce product is a good goal.

What I would do if hosting Zulip for a company, is: (1) host an up to date Zulip version (2) setup or rent a Jitsi Meet or other open source / free software voice + video chat solution. Jitsi Meet might be a bit difficult to properly set up, compared to Zulip, because of extra things needed, like TURN server and in general the complexities of web RTC. Maybe renting that for some (3) Configure Zulip to have for exampl…

Literally did that at my last company, but the google meet link was “meet:” where the friendly URL of the meet-link was inserted.

It worked pretty well, I do wish Zulip had better ability to generate links from the video call button, it works really well with Jitsi this way.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#355
post #193

Earlier quoted context omitted.

the software is so bad it's literally a national security risk.

While I may agree on Sharepoint, not everything from Microsoft is bad. Often the alternatives are even worse.

Really?

Libreoffice Calc and Excel are probably your strongest argument, Excel runs the world after all.

But, if it wasn’t for incompatibility and fear of incompatibility- I have a hard time thinking Calc is materially worse; I doubt theres a single workflow not possible in Calc- and if O365 utils get worse looking then Calc will win there too soon enough.

For everything else in the microsoft stack, either its “this thing does many things thus is incomparable to any one thing!” or its simply worse.

Even the best tools that I would actively defend (MSSQL) are only equivalent to other solutions (PGSQL) and almost never better than everything offered elsewhere.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#356

Earlier quoted context omitted.

I'm gonna be honest, you sound like a problem employee. The companies not using Microsoft, are using Google. Which in my experience is equally or measurably worse. Just personal data points, but every avowed Microsoft hater I've ever worked with has been... difficult. Like a-drag-on-the-team-because-he-refuses-to-use-company-tools difficult. Edit: How does an aged post on this site go from +4 to -1 in the span of a f…

How can OP be a problematic employee when he's specifically decided never to become an employee of a company which uses such tools?

It seems like a sour grapes thing. "I can't have you as an employee? Well you must be a problem so I don't want you anyway."

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#357
post #89

Earlier quoted context omitted.

How oh how did these nuclear weapons facilities manage to function in the days before Exchange and Sharepoint?

They paid lots of secretaries lots of money and had a whole department called "the mailroom". No one wants to go back to that.

When they're managing nuclear bombs, I think some inefficiency shouldn't be a deal breaker.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#358
post #94

One of the first things I do after getting an inquiry from a recruiter or friend referral is lookup the MX record for the company’s email domain. It is an anonymous one-command check to see if they’re a Microsoft shop. If they are, it’s enormous personal red flag. MSFT is very popular so I’m only speaking about my own experience, but I have learned over the course of 20 years that an MSFT IT stack is highly correlate…

I'm gonna be honest, you sound like a problem employee. The companies not using Microsoft, are using Google. Which in my experience is equally or measurably worse. Just personal data points, but every avowed Microsoft hater I've ever worked with has been... difficult. Like a-drag-on-the-team-because-he-refuses-to-use-company-tools difficult. Edit: How does an aged post on this site go from +4 to -1 in the span of a f…

[dead]

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#359
post #278

Earlier quoted context omitted.

> I think the point is that GP red flagging all MS shops, which is more or less just sorting companies by headcount I wouldn't be surprised if many people find that smaller companies are more fun/interesting to work at, so even if this were only filtering out large companies checking for MS could be helpful.

Then it's an overcomplicated company size check.

[dead]

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#360
post #324

Earlier quoted context omitted.

Until one needs to reach out to support.

Google's support for their business clients is considered pretty top of class. The "Google lacks support" chorus we hear frequently is more associated with their free tier.

Where I am we're kind of Dual Stack for various reasons with GCP and Azure.

Microsoft support has been very good. Google support was abysmal and very "you're dumb, we're smart because we're Google" style.

And we pay money for support to both organizations.

Post reply on HN