Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

51–60 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#53

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

I'm working on a gov contract right now and they're forcing everyone to migrate off of Slack and into Teams. I somehow have managed to avoid MS corporate products for the better part of two decades. People's tolerance to UX pain seems to be boundless in corporate/fed worlds.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#54
post #47
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

From the article: > OT cybersecurity specialists interviewed by CSO say that KCNSC’s production systems are likely air-gapped or otherwise isolated from corporate IT networks, significantly reducing the risk of direct crossover. Nevertheless, they caution against assuming such isolation guarantees safety. This was also not a nuclear facility, however. The article says it makes "non-nuclear components". In my experien…

Ah yes, "likely air-gapped", what a high-confidence statement. Any competently designed air-gap must be precisely auditable and demonstrably, positively air-gapped.

The only world where "likely" is a reasonable word is in reference to possible physical taps or a precise enumeration of physical access points that went unaudited, but have reliably followed safe access control/configuration procedures. Anything else is plain incompetence.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#55
post #44

Earlier quoted context omitted.

As the effect of yesterday's AWS event demonstrates, the major Amazon, Microsoft, and Google data centers are surely top tier targets in every adversary's war plans. The decentralized internet is less of a reality today than it was years ago.

Don't we have more internet submarine cables and less single points of failure in our internet infrastructure today than years ago? If so, shouldn't that make it easier to route around failures? The web though I agree isn't very decentralized.

Maybe yes in that regard. But in the past, most organizations ran their own mail and web servers. Software supporting the business ran on-prem. Now they use Google or Azure or AWS. So business and civilian usage, at least, seem more vulnerable now.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#56

Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge. Sounds like they need to seriously redesign their security policies.

But, look at everything we get for free! /s

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#57
post #36
post #29

Earlier quoted context omitted.

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

Not defending Microsoft in any way but my guess of what's happening: * Too few people use Firefox to access Office online, they don't care * Your organization is too small for them to care

Firefox is the only browser other than Chrome (and derivatives) on their OS. The web is supposed to be multi-platform. I guess it isn’t that surprising that modern MS is happy to just live in Google’s ecosystem though.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#58
post #41

As a company that supports OT systems we hate seeing level 5 in the Purdue model with direct write access to level 1 and 0.

Link describing the acronyms in the above comment:

https://www.paloaltonetworks.com/cyberpedia/what-is-the-purd...

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#59
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

It is funny to read this kind of comment knowing at the same time this kind of stuff was happening while the launch codes were 0000000 or some such non-secure code. At same time, the computers in the nuclear launch facilities were still using 5.25" floppies. I did wonder how often they were loading updates from those, if ever.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#60
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Wasn't it literally designed for that specific task? As a robust C&C system during nuclear war? The fact that we're doing it wrong doesn't mean we need to pull the plug on everything. How else do you survive WWIII? https://ieeexplore.ieee.org/document/5432117

You don't. Internet or not.
Post reply on HN