Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

61–70 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#62
post #58
post #41

As a company that supports OT systems we hate seeing level 5 in the Purdue model with direct write access to level 1 and 0.

Link describing the acronyms in the above comment: https://www.paloaltonetworks.com/cyberpedia/what-is-the-purd...

Thanks CJ, I live with that chart, but forget maybe most don't. And to add 4 to level 2-0 can also be an attack vector, but seeing straight 5 to 1-0 happens more then people want to admit even with the "firewalls"

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#63

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

I'm working on a gov contract right now and they're forcing everyone to migrate off of Slack and into Teams. I somehow have managed to avoid MS corporate products for the better part of two decades. People's tolerance to UX pain seems to be boundless in corporate/fed worlds.

[deleted]

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#64
post #36
post #29

Earlier quoted context omitted.

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

Not defending Microsoft in any way but my guess of what's happening: * Too few people use Firefox to access Office online, they don't care * Your organization is too small for them to care

if they will lose data when you're on a rarely used browser, can you really trust them not to lose data in general?

"yes, your car exploded, but you were driving on a dirt drive way. it works just fine on the highway"

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#65

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

How large are the files?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#66
post #51

Does this kind of thing happen to China + Russia? I don't see news about that much - but to be fair, I am not looking for it.

yes. but it doesn't get covered by western media. much like how NATO airplanes violating Russian airspace is not reported about either.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#67
post #54
post #47

Earlier quoted context omitted.

From the article: > OT cybersecurity specialists interviewed by CSO say that KCNSC’s production systems are likely air-gapped or otherwise isolated from corporate IT networks, significantly reducing the risk of direct crossover. Nevertheless, they caution against assuming such isolation guarantees safety. This was also not a nuclear facility, however. The article says it makes "non-nuclear components". In my experien…

Ah yes, " likely air-gapped", what a high-confidence statement. Any competently designed air-gap must be precisely auditable and demonstrably, positively air-gapped. The only world where "likely" is a reasonable word is in reference to possible physical taps or a precise enumeration of physical access points that went unaudited, but have reliably followed safe access control/configuration procedures. Anything else is…

How do you go about positively demonstrating such a system is air-gapped?

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#68

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

Developed and maintained in China by Chinese nationals, with untechnical escorts overseeing their work.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#69
post #54
post #47

Earlier quoted context omitted.

From the article: > OT cybersecurity specialists interviewed by CSO say that KCNSC’s production systems are likely air-gapped or otherwise isolated from corporate IT networks, significantly reducing the risk of direct crossover. Nevertheless, they caution against assuming such isolation guarantees safety. This was also not a nuclear facility, however. The article says it makes "non-nuclear components". In my experien…

Ah yes, " likely air-gapped", what a high-confidence statement. Any competently designed air-gap must be precisely auditable and demonstrably, positively air-gapped. The only world where "likely" is a reasonable word is in reference to possible physical taps or a precise enumeration of physical access points that went unaudited, but have reliably followed safe access control/configuration procedures. Anything else is…

They have multiple networks. One of them is definitely airgapped (red for RD). The medium security one is protected by annoyingly strict network ACLs (yellow for ITAR). Then there's a low security one for stuff like sharepoint (green).

This article is full of nonsense and speculation.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#70
post #29

Sharepoint is one of the worst, most bug-ridden softwares I've worked with. It has a bug with Solidworks (3D design suite) that sporadically makes files completely un-openable unless you go in and change some metadata. They are aware of this, doesn't seem to be any limitation preventing them from fixing it, and it has sat unfixed for years. Microsoft's cloud storage as a whole is an insane tangle where you never know…

Microsoft Word online deletes text in Firefox Linux (maybe others too) for at least two years now [1]. The one thing you want a text editor to do is be able to write text into a document, and somehow this bug goes unfixed. You would think it would be priority #1 for paying customers of Business Office 365 - and yet nothing. It ended up being easier just to switch to paid Overleaf and teach our non-tech members how to…

That bug has been around for years. I always wondered if that was deliberate. I guess that Microsoft support answer settles the question...

>Sorry for that we may have no enough resources about the Linux environment.

Post reply on HN