Russian hackers burn out Illinois public water system pump

Discuss life, the universe, and everything with other members of this site. Get to know your fellow polywell enthusiasts.

Moderators: tonybarry, MSimon


Skipjack
Posts: 6823
Joined: Sun Sep 28, 2008 2:29 pm

Post by Skipjack »

What idiot connects crucial facilities like these to the internet?

charliem
Posts: 218
Joined: Wed May 28, 2008 8:55 pm

Post by charliem »

Skipjack wrote:What idiot connects crucial facilities like these to the internet?
You'd be surprised.

I teach network systems security and computer forensics, and quite often wonder how public and private sector alike, can be so reckless with their systems.

Looks like too few are able to learn without getting beaten a few times first.
"The problem is not what we don't know, but what we do know [that] isn't so" (Mark Twain)

choff
Posts: 2447
Joined: Thu Nov 08, 2007 5:02 am
Location: Vancouver, Canada

Post by choff »

and when you build the network to restrict access, users will blindly bring in wireless routers to get around security, because they just can't get through the workday without websurfing. Even when they've signed off on not doing so. The worst offenders will often be in management.
CHoff

Skipjack
Posts: 6823
Joined: Sun Sep 28, 2008 2:29 pm

Post by Skipjack »

Then get them a fracking netbook that is not connected to the secure network to do their surfing!
Idiots, gooosh ;)

choff
Posts: 2447
Joined: Thu Nov 08, 2007 5:02 am
Location: Vancouver, Canada

Post by choff »

You're talking way too much common sense now. Most users see network security as an encumbrance to be circumvented. Even when provided with access to a separate unsecured network they'll still want the convenience of not switching over.
CHoff

Skipjack
Posts: 6823
Joined: Sun Sep 28, 2008 2:29 pm

Post by Skipjack »

You're talking way too much common sense now. Most users see network security as an encumbrance to be circumvented. Even when provided with access to a separate unsecured network they'll still want the convenience of not switching over
Well, it is also a matter of not just making this a rule, but also enforcing it.

Diogenes
Posts: 6968
Joined: Mon Jun 15, 2009 3:33 pm

Post by Diogenes »

Skipjack wrote:What idiot connects crucial facilities like these to the internet?
Barack Obama is from Chicago isn't he? Must be something up there that makes people stupid.
‘What all the wise men promised has not happened, and what all the damned fools said would happen has come to pass.’
— Lord Melbourne —

Diogenes
Posts: 6968
Joined: Mon Jun 15, 2009 3:33 pm

Post by Diogenes »

Skipjack wrote:What idiot connects crucial facilities like these to the internet?
Actually, to give you a fair answer, much of the modern day *SCADA system equipment is hooked to the internet for the purpose of allowing an off site expert to fix and resolve problems with it, or to implement other changes to the software. Not too many people on many sites know how to do the programing. They just operate the equipment.



*Supervisory Control and Data Acquisition.
‘What all the wise men promised has not happened, and what all the damned fools said would happen has come to pass.’
— Lord Melbourne —

Diogenes
Posts: 6968
Joined: Mon Jun 15, 2009 3:33 pm

Post by Diogenes »

Image
‘What all the wise men promised has not happened, and what all the damned fools said would happen has come to pass.’
— Lord Melbourne —

ScottL
Posts: 1122
Joined: Thu Jun 02, 2011 11:26 pm

Post by ScottL »

Diogenes wrote:Image
But you support their right to protest correct?

Skipjack
Posts: 6823
Joined: Sun Sep 28, 2008 2:29 pm

Post by Skipjack »

Actually, to give you a fair answer, much of the modern day *SCADA system equipment is hooked to the internet for the purpose of allowing an off site expert to fix and resolve problems with it, or to implement other changes to the software. Not too many people on many sites know how to do the programing. They just operate the equipment.
The do savety by obscurity. Only connect to the internet in the case that it is neede and be offline most of the time. Unless you have hackers wait for months for that short opportunity window to get in there, they wont get in.

ScottL
Posts: 1122
Joined: Thu Jun 02, 2011 11:26 pm

Post by ScottL »

Skipjack wrote:
Actually, to give you a fair answer, much of the modern day *SCADA system equipment is hooked to the internet for the purpose of allowing an off site expert to fix and resolve problems with it, or to implement other changes to the software. Not too many people on many sites know how to do the programing. They just operate the equipment.
The do savety by obscurity. Only connect to the internet in the case that it is neede and be offline most of the time. Unless you have hackers wait for months for that short opportunity window to get in there, they wont get in.
You mean obscurity by security? It's common practice, but really to prevent unauthorized devices on one's network why not implement 802.1x with radius server. This significantly reduces the risk of exploitation.

MSimon
Posts: 14335
Joined: Mon Jul 16, 2007 7:37 pm
Location: Rockford, Illinois
Contact:

Post by MSimon »

Skipjack wrote:What idiot connects crucial facilities like these to the internet?
There appears to be quite a few idiots who think that is a good idea.

http://www.ecnmag.com/Blogs/2011/11/Sma ... Security-/
Engineering is the art of making what you want from what you can get at a profit.

Diogenes
Posts: 6968
Joined: Mon Jun 15, 2009 3:33 pm

Post by Diogenes »

ScottL wrote:
Diogenes wrote:Image
But you support their right to protest correct?
Yes, if that is what they are doing, about which I have some doubts.
‘What all the wise men promised has not happened, and what all the damned fools said would happen has come to pass.’
— Lord Melbourne —

Post Reply