Live data from Hacker News

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

csoonline.com

81–90 of 404 posts

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#81

Earlier quoted context omitted.

> needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet You want to make everything about a nuclear facility bespoke and subject to air-gapped drift? What about the guard booth that verifies peoples access, the receptionist who schedules meetings, and the janitor who wants to watch YouTube on his break? It seems unrealistic to lump everything that goes on at a nuclear f…

Opening up the internet to a nuclear facility so that the janitor can watch Youtube seems preposterous. People can afford to do things slower for the sake of security. Having things typed out, verifying security via phone calls, etc like it's the 1970s seems reasonable to me. Does it really matter if things aren't fully optimized for speed and convenience in nuclear facilities?

IRL the way we do it is separating the business network (Youtube, finance people, HR, etc.) from the operational network (relays and sensors). You use data diodes to send business-critical data from the operational network to the business network.

Also, the Kansas City Plant is like a watchmaker's factory, not a power plant. They make widgets and gewgaws, not literally split atoms.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#82
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

I heard that once you put up a website on the public internet, it would immediately gets attacked by all kinds of scanners or other worse things. Not sure if it's true as I'm not a web guy.

IIRC Carnegie Mellon did a study years ago which showed that you could not unbox a new Windows machine, connect it "directly" to the Internet, and get it fully patched before it was pwned.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#83

Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge. Sounds like they need to seriously redesign their security policies.

I have some reaallllly bad news for you on that front.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#84

Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge. Sounds like they need to seriously redesign their security policies.

Wait until you hear about the guy storing Top Secret Nuclear documents in the public toilet of his resort....

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#85
post #84

Hahaha, how stupid must anyone be to deploy SharePoint anywhere near anything of national security relevance! How can it still be a thing, that anyone entrusted with such sensitive matter dates to even touch MS products of the kind of SharePoint? That includes the complete MS Office 365 disaster suite, MS Teams and Edge. Sounds like they need to seriously redesign their security policies.

Wait until you hear about the guy storing Top Secret Nuclear documents in the public toilet of his resort....

Or the one that invites journalist to Signal group during combat mission.

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#87
post #27
post #5

There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.

Being airgapped didn't help Iran avoid Stuxnet.

To be fair, it didn’t help the rest of us avoid Stuxnet, either.

https://en.wikipedia.org/wiki/Operation_Olympic_Games#Histor...

> A programming error later caused the worm to spread to computers outside of Natanz. When an engineer "left Natanz and connected [his] computer to the Internet, the American- and Israeli-made bug failed to recognize that its environment had changed." The code replicated on the Internet and was subsequently exposed for public dissemination. IT security firms Symantec and Kaspersky Lab have since examined Stuxnet. It is unclear whether the United States or Israel introduced the programming error.

Also bearing mention is Flame, which is often left out when Stuxnet comes up, but which was allegedly part of the wider operation.

https://en.wikipedia.org/wiki/Operation_Olympic_Games#Signif...

> The Washington Post reported that Flame malware was also part of Olympic Games.

https://www.washingtonpost.com/world/national-security/us-is... | https://web.archive.org/web/20220322045917/https://www.washi... | https://archive.is/6hRl7

> “We are now 100 percent sure that the Stuxnet and Flame groups worked together,” said Roel Schouwenberg, a Boston-based senior researcher with Kaspersky Lab.

> The firm also determined that the Flame malware predates Stuxnet. “It looks like the Flame platform was used as a kickstarter of sorts to get the Stuxnet project going,” Schouwenberg said.

https://en.wikipedia.org/wiki/Flame_(malware)

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#88

As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…

> Few Open Source Developers want to work on this stuff which I get because it's tedious work interfacing with computer illiterate end users. I'd rather chug sewage then do this work for free.

Or the government could pay people to work on said open source software, providing a benefit to the public along the way. The US government started something like this called "18F" under the Obama administration. It was so effective at making software that was useful to the American public that Trump promptly shut it down 2 months into his second term, in no small part because they had the temerity to develop free-to-use tax filing software.

See

https://handbook.tts.gsa.gov/18f/history-and-values/ https://web.archive.org/web/20250000000000*/https://handbook... https://archive.is/CIXG1

and

https://www.lawfaremedia.org/article/learning-from-the-legac... https://web.archive.org/web/20250000000000*/https://www.lawf... https://archive.is/fmaf6

Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

#89

As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…

How oh how did these nuclear weapons facilities manage to function in the days before Exchange and Sharepoint?
Post reply on HN