Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > “I think Minnesota is behind it,” Mr. Trump said on Friday in response to a reporter’s question about Iran’s possible involvement,

    What a coward and a traitor to the American people.

  • It was probably the same (imaginary) people who damaged the lining of the Reflecting Pool.

    I think we should think about making blatant lies by politicians a crime.

  • Context: He said the state was “behind it” because of gross incompetence and that he doesn’t buy the Iran attribution
  • He knows he brought these attacks with his war, but he doesn’t take the blame for anything.
  • Where does all the money go? Not to cyber apparently.
  • DOGE eliminated 1/3 of CISA staff in 2025. Trump reduced the 2026 CISA budget by $491 million (17%). Trump intends to slash their budget by an additional $707 million in 2027.

    The ICE budget was just increased by $70 BILLION, bringing its total to >$200 billion.

  • Is this the true reason for the cyclosporasis outbreaks?
  • Taco Bell is secretly funded by Iran and North Korea and invented covid…
  • Can we still blame Mexico, Taylor Farms and Taco Bell as well?
  • Nah. Cyclospora is a parasite, not a virus.

    [Riffing on the gag, not an actual misunderstanding, just to be clear.]

  • If I was in a power position, I could theoretically channel this water into my own private reservoirs and locations like private land, bunkers, etc to weather a disruption, and blame Iran and it would be really hard to validate.

    I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.

    I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!

  • You know water is kind of big right?
  • I understand being mad, I also get mad.

    This is a bit unhinged.

  • In this war initiated by USA and Israel, it isn't Iran who's attacking civil targets.
  • They always point to a state actor to skirt liability for their own shitty IT work. Then the dim evil journalists swallow it whole, later regurgitating it for their eager little baby bird subscribers.

    If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.

  • <adjustsTinFoilHat> The Trump plan in Iran is not working. Gotta make them look like the evil bogeyman to get people to support further action.
  • >state and local officials throughout the country were on high alert for potential problems in vulnerable computers that are commonly used to monitor and adjust water quality, including chemical-treatment levels and water pressure.

    You don't need a full bidirectional internet connection for remote monitoring, and data diodes are a relatively cheap way to monitor them in complete safety.

    Completely stopping ingress of control (using above mentioned data diodes) is relatively easy, and should be legislated into being the norm.

  • Please expound upon this "data diodes are a relatively cheap way to monitor them in complete safety". I'm familiar with the concept, but do not know they are in widespread use, and off-the-shelfish enough to be considered "cheap". To me, the fundamental problem is that our protocol stacks are all built on an assumption of bidirectional interaction, making "data diodes" require bespoke engineering to define the correct data structures of a type that can be thrown over a wall. Like sure it's easy to cut one ethernet pair, or one serial line wire, but building up a software stack that can use that for one-way communication still seems like a hassle.
  • Why are water systems still on the internet? They should be completely cut off. If necessary, remote access must be from dedicated devices only, only to a mirrored view, and never for remote control.
  • People use 1000x more water than they need to drink.

    If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted.

    Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope.

    It wouldn't cause the mass casualties an enemy might assume.

  • Exactly how big do you think those bottles would be?
  • Who exactly is this "we" in 2026 ?

    The only thing I can see is some political crony company getting a big payment from the federal budget to take on the "burden" of doing so. But then not actually distributing enough water so they can still price-gouge individuals because we wouldn't want people to become entitled, right?

  • Iran doesn't need to cause mass casualties. They just need to make US citizens hate the war in Iran.
  • It's actually insane to me that the nation convulsed over the inability to get water to flint Michigan and people are still over here doing "no one actually deserves water, you use too much of it anyway"
  • Wasn't there a Defcon or Derby talk about this years back? (The insecurity, not the Persian angle)

    Struggling for a source.

    Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?

  • Not sure about defcon, but Buckminster Fuller wrote waay back in the sixties about the New York's vulnerability to a fresh water supply attack.

    If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books.

    https://archive.org/details/operatingmanualforspaceshipearth...

  • The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.

    After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.

    https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...

  • Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!