Page 1 of 2

Russian hackers burn out Illinois public water system pump

Posted: Sat Nov 19, 2011 9:25 pm
by DeltaV

Posted: Sat Nov 19, 2011 9:44 pm
by Skipjack
What idiot connects crucial facilities like these to the internet?

Posted: Sat Nov 19, 2011 10:20 pm
by charliem
Skipjack wrote:What idiot connects crucial facilities like these to the internet?
You'd be surprised.

I teach network systems security and computer forensics, and quite often wonder how public and private sector alike, can be so reckless with their systems.

Looks like too few are able to learn without getting beaten a few times first.

Posted: Sun Nov 20, 2011 8:40 am
by choff
and when you build the network to restrict access, users will blindly bring in wireless routers to get around security, because they just can't get through the workday without websurfing. Even when they've signed off on not doing so. The worst offenders will often be in management.

Posted: Sun Nov 20, 2011 6:39 pm
by Skipjack
Then get them a fracking netbook that is not connected to the secure network to do their surfing!
Idiots, gooosh ;)

Posted: Sun Nov 20, 2011 7:28 pm
by choff
You're talking way too much common sense now. Most users see network security as an encumbrance to be circumvented. Even when provided with access to a separate unsecured network they'll still want the convenience of not switching over.

Posted: Sun Nov 20, 2011 8:25 pm
by Skipjack
You're talking way too much common sense now. Most users see network security as an encumbrance to be circumvented. Even when provided with access to a separate unsecured network they'll still want the convenience of not switching over
Well, it is also a matter of not just making this a rule, but also enforcing it.

Posted: Mon Nov 21, 2011 1:27 am
by Diogenes
Skipjack wrote:What idiot connects crucial facilities like these to the internet?
Barack Obama is from Chicago isn't he? Must be something up there that makes people stupid.

Posted: Mon Nov 21, 2011 1:31 am
by Diogenes
Skipjack wrote:What idiot connects crucial facilities like these to the internet?
Actually, to give you a fair answer, much of the modern day *SCADA system equipment is hooked to the internet for the purpose of allowing an off site expert to fix and resolve problems with it, or to implement other changes to the software. Not too many people on many sites know how to do the programing. They just operate the equipment.



*Supervisory Control and Data Acquisition.

Posted: Mon Nov 21, 2011 1:47 am
by Diogenes
Image

Posted: Mon Nov 21, 2011 2:56 am
by ScottL
Diogenes wrote:Image
But you support their right to protest correct?

Posted: Mon Nov 21, 2011 4:05 am
by Skipjack
Actually, to give you a fair answer, much of the modern day *SCADA system equipment is hooked to the internet for the purpose of allowing an off site expert to fix and resolve problems with it, or to implement other changes to the software. Not too many people on many sites know how to do the programing. They just operate the equipment.
The do savety by obscurity. Only connect to the internet in the case that it is neede and be offline most of the time. Unless you have hackers wait for months for that short opportunity window to get in there, they wont get in.

Posted: Mon Nov 21, 2011 4:14 am
by ScottL
Skipjack wrote:
Actually, to give you a fair answer, much of the modern day *SCADA system equipment is hooked to the internet for the purpose of allowing an off site expert to fix and resolve problems with it, or to implement other changes to the software. Not too many people on many sites know how to do the programing. They just operate the equipment.
The do savety by obscurity. Only connect to the internet in the case that it is neede and be offline most of the time. Unless you have hackers wait for months for that short opportunity window to get in there, they wont get in.
You mean obscurity by security? It's common practice, but really to prevent unauthorized devices on one's network why not implement 802.1x with radius server. This significantly reduces the risk of exploitation.

Posted: Mon Nov 21, 2011 5:13 am
by MSimon
Skipjack wrote:What idiot connects crucial facilities like these to the internet?
There appears to be quite a few idiots who think that is a good idea.

http://www.ecnmag.com/Blogs/2011/11/Sma ... Security-/

Posted: Mon Nov 21, 2011 5:07 pm
by Diogenes
ScottL wrote:
Diogenes wrote:Image
But you support their right to protest correct?
Yes, if that is what they are doing, about which I have some doubts.