

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- I mean, this statement shouldn't be shocking to anyone. Critical infrastructure should be air-gapped if at all practical.by mcfdoesdev
- Another vulnerability is natural gas pipeline compressor stations are all internet-connected, often via wireless because they are in remote locations. Simple DOS attack against one will force it to shutdown flow, causing things like power stations to drop offline.by nacozarina
- >Other countries start securing their water
>nsa: what no, stop that
by Cider9986 - The NSA's job is to collect information, not screw with people's water.by psunavy03
- I sometimes wonder how much damage (and potential damage) to US infrastructure exists simply because intelligence-agencies prioritize being able to exploit it globally over fixing it on defense.by Terr_
- what does belong on the internet in a post-mythos world?
one argument: only services which need to be available to unauthenticated endpoints should be default reachable.
all other services should be default unreachable (no data plane until authorized ...then use internet and other networks to establish the connections).
yes, that is not always easy. it is much more possible than it used to be.
and arguably we now need to commit to the tradeoffs of default unreachable services.
by gz5 - Well yes this is true but air gapping isn't perfect security, it's important to understand that too.
And true air gapping isn't possible because it'll need to be monitored somewhere central so there'll have to be some vpn or mpls whatever. Meaning it can be hacked.
Having it exposed to the public internet is not good practice but should be far from the only layer in its security.
And really, when a PLC is found unfirewalled on the public internet, you can bet that's far from the only security screwup in that infrastructure. If they won't even handle the low hanging fruit.
by wolvoleo - We could say that about a lot of infrastructure that has been recklessly placed on the open Internet because it was cheaper than more secure solutions. I would say the same about home security systems, for instance.by vannevar
- No infrastructure should be on the open internet the potential for abuse is incredible. At a minimum a VPN should be used to tunnel all connections back to what ever command and control server exist, leaving equipment visible on the public IP should be a crime if not a felony.by nik282000
- Don't put your PLCs directly on the internet. In fact most industrial stuff is very not made to be directly connected to the internet. But interpose a firewall+VPN solution and you might be ok, if done competently.
And remote access to hardware definitely makes management and maintenance a lot easier and quicker. (else you need to drive out for every minor issue)
by Kim_Bruning - If we can beat a security-state airgap by sprinkling USB drives in the parking lot, I think the Iranians can beat an "internal" network by getting someone to click on an email attachment or visit the wrong website on their municipal issued Windows machine.
It's very common for the proprietary software for interfacing with ancient, expensive machines to break after OS upgrades, so they're probably unpatched... you might not even need to burn a 0-day.
by closeparen - "If done competently" is a bold assumption unfortunately, not just these days but alwaysby tomsanbear
- He is wrong and right. They should be connected to the Internet when they aren't 30 year old PLCs ripe for abuse. Until then, cut the data lines and do water monitoring the old way.by 1970-01-01
- Things that don’t have a compelling need to be connected to the internet should never be connected to the internet. When there is a need, connectivity should be restricted to the bare minimum required for the task.by bigfatkitten
- A data diode can allow monitoring via the internet without risking ingress of control. Commercial units aren't cheap though.
Obviously we need open source designs.
Perhaps the easiest way would be a Raspberry pi set up with an opto isolated CGA/EGA/VGA/SVGA capture that could be viewed via the internet? (I mean, we're probably talking systems still running MS-DOS or Windows 98 running these systems)
by mikewarot - Rather than "on/off" I think we need to distinguish between at least four things:
1. Connected naively to the internet.
2. Behind a hardened VPN endpoint which is on the internet.
3. Has a separate physical private network.
4. Requires physical access.
I think it's obvious that #1 should be prohibited in favor of #2. After that point we need to ask what the impact is of a Denial of Service attack that prevents anyone from remotely accessing the system.
The difference between #2 and #3 may depend on whether things could be Very Bad if the system is disconnected at a time of the attacker's choosing. For example, disabling access to flood-control valves during a hurricane.
by Terr_ - If it’s connected, it’s compromised. Or will be.
Folly to think otherwise.
by grebc - Disagree. Why connect them to the internet? They should be super hardened against attacks, and should NOT have a physical connection to the internet. Same with electrical infrastructure. Network access? Possibly, however that network should NOT be accessible from the internet.
The only exception I can think of would be for meter reading, which should be a separate, read only device with no ability to do harm altogether.
by eek2121 - At modern population densities, basic infrastructure breaking on down on a large scale can kill millions in a matter of weeks.
The largest threat isn't bombs falling on our heads, it's incompetent fools leaving the door open to their enemies.
These aren't mistakes that can be excused. Failing in one's duty to steward important infrastructure must mean immediate replacement of leadership.
by chmod775 - With coding agents now being used for hacking, there's a decent chance we'll see a 9/11-scale hacking incident as a result of NSA/DHS negligence in securing American internet-connected services. Similar to how the CIA's negligence allowed 9/11 itself.
The USG should be deploying thousands of security engineers armed with the latest coding models and agents, in attempt to secure systems before they're hacked. A few billion dollars spent here could save us trillions.
by jacobgold - https://www.nsa.gov/Cybersecurity/Cybersecurity-Advisories-G...
While that’s not the job of the NSA, they do produce a lot of good cybersecurity guides.
- Unlike the CIA and/or FBI being in charge of preventing attacks like 9/11, NSA and DHS aren't in charge of each state's or city's infrastructure. They could run some opt-in program that local governments could then engage with, but "negligence" is a bit strong for systems they're not in charge of and have no access to.by bjt
- How is it NSA/DHS negligence? Neither is responsible for securing the infrastructure of state and local governments nor private companies.
They should provide guidance, but I’m not sure we really want the NSA inside of networks more than they already are.
If voters and CEOs don’t want to spend the money required to secure their infrastructure, that’s on them.
by pigbearpig - There are many wireless pump-and-reservoir systems that while not internet connected, use insecure RF links. These local RF (and casting a wider net, Bluetooth) interfaces are also ripe for abuse.by clbrmbr
- Wouldn't the physical facilities themselves have security?by Wowfunhappy
- If that means you need to at least be physically present then I'd say that's a lot of protection already. Means someone in a foreign country can't simply get lucky fuzzing.by barbazoo
- Part of my career encapsulates a period where I was a PLC programmer, installer, commissioner, and troubleshooter for massive build outs (sky scrapers, data centers, laboratories, factories). Interestingly, this was after years of teaching myself software engineering, eventually participating in large open source projects. The clash of entering the PLC world was _extremely_ harsh.
Let me give an example: I once worked with an integrator who was working on an AHU feeding an extremely critical portion of a datacenter (I was a lead by this point and mostly played babysitter). During certain points of the day you couldn't open the door to this room due to negative pressure because the logic was over-ramping the exhaust fans. As I watched this contractor work, I saw him open his laptop, with Windows on it (because Microsoft has had a death grip on this industry for decades now), and proceed to backup the PLC program into a massive folder with God knows how many other "customer projects" he was carrying around in this thing. He then proceeded to go do some physical checks in the field, came back, and prepared to upload the fixed program. As I watched, I noticed he _grabbed a backup from ANOTHER customer_ and I immediately had to intervene. Who knows what untold damage I saved from that single move.
I tell this story to demonstrate just how far into the dark ages this industry is. I vividly recall coming into the data center for a fortune 50 company, one everyone here would know, and being astonished that they had never heard of Network Attached Storage or RAID and why they might want to consider a disaster recovery plan for their multi-million dollar mechanical plant.
This industry is in _desperate_ need of strong technical help, but unfortunately the "higher ups" tend to be the same people who are "comfortable" with the way thing are and refuse to move. I literally tried for a decade before giving up and moving into software engineering proper.
So, anyways, just imagine the most archaic and barbaric set of IT software, controls, and procedures, dumb that down even further, and you've landed on the infrastructure/teams that operate probably half of critical infrastructure.
by aliasxneo - The worst part -as I mentioned in another comment few days earlier- is most of the network is ancient, dialup, poor architecture designed by people who barely touched a computer, very old OSes, one utility had windows 3.1 a couple years ago! For them as long as it’s working, don’t touch it, because a downtime is far more costly and it will bring many eyes and attention to them than just sit and hope nothing will happen. Physical security is a major gap too, I have been to many locations where the field server panels are just behind the door, the RTUs are just closed with panel keys, even the whole facility are using some old HID cards that you can unlock in few seconds, this is even in R&D that beyond automation but also in robotic ones.by tamimio
- Sounds like we have a similar development path. People fail to understand how complex some of these systems can be, especially since you have to have the project to understand what registers/variables are what. Some when Joe the contractor does a job and walks away, you better make sure they give you the project and you store it in a nice safe place.
A good system integrator is worth their weight in gold. Sure they cost more, but getting a whole package turned over to you is worth a million more than 5 years into the lifecycle of a factory when someone wants to make mods/fix a bug/etc and has to reinvent the whole car, not just the wheel.
This industry is always 10-20 years in the past. My company’s preferred vendor only just started supporting virtualization (this is for a DCS) in the past 10 years. I still have to tell my sales people to provide A/V and minimalistic backup and recovery on every project (they essentially cost nothing compared to the rest of any project).
by procarch2019 - > So, anyways, just imagine the most archaic and barbaric set of IT software, controls, and procedures, dumb that down even further, and you've landed on the infrastructure/teams that operate probably half of critical infrastructure.
Same with SCADA: just as bad as what you describe.