Live data from Hacker News

German nuclear plant infected with computer viruses, operator says

reuters.com

51–60 of 101 posts

Re: German nuclear plant infected with computer viruses, operator says

#51
post #36
post #31

Earlier quoted context omitted.

"Nuclear is safe", they said. I'd rather have my local solar power plant infected with viruses or hit by cyberattacks.

Modern nuclear reactor design is such that you cant cause a meltdown without violating the laws of physics.

I wouldn't be so sure - you know the joke about fool proof designs and nature inventing bigger fools ;).

Few years ago, Westinghouse tried to kick out Rosatom from VVER power plants in Eastern Europe as a supplier of the fuel. They pulled very heavy levers to do that, but in the end, they were still refused due to their pellets not being up to the task and being a security hazard.

And yet they still try that in Ukraine...

Re: German nuclear plant infected with computer viruses, operator says

#53
post #39

Earlier quoted context omitted.

Unfortunately most nuclear reactors aren't modern.

As far as I know there isn't even a single one of those designs which was successfully built somewhere yet (as in: Is able to generate more power than it uses).

The being able to generate more power than it uses is a problem for nuclear fusion reactors.

The problem with modern nuclear reactor designs is that they're just that, designs. Great ideas people in comment sections love to mentally masturbate about. In reality almost all nuclear reactors are decades old.

Politics alone ensure nuclear reactors with the exception of maybe fusion (which will be way too late for climate change) will never get off the ground. In the meantime renewables, solar especially, get cheaper and more efficient every day, not designs but actual installations.

Re: German nuclear plant infected with computer viruses, operator says

#54

I wonder what scale of disaster will have to occur before information security is placed under the same legal and regulatory scrutiny as physical security?

Developing and maintaining software with a sufficiently large focus on information security will almost certainly cost so much money, that people will reconsider whether the investment is worth it.

It probably takes several relatively large and frequent disasters not just to put the issue on the map politically but also to show that it's worth investing in information security besides the cost.

Re: German nuclear plant infected with computer viruses, operator says

#55
post #36
post #31

Earlier quoted context omitted.

"Nuclear is safe", they said. I'd rather have my local solar power plant infected with viruses or hit by cyberattacks.

Modern nuclear reactor design is such that you cant cause a meltdown without violating the laws of physics.

you can melt down any reactor. Perhaps you mean it can't create a nuclear explosion? in that you are right.

Re: German nuclear plant infected with computer viruses, operator says

#56
post #4

I found that part much more .. interesting: > As an example, Hypponen said he had recently spoken to a European aircraft maker that said it cleans the cockpits of its planes every week of malware designed for Android phones. The malware spread to the planes only because factory employees were charging their phones with the USB port in the cockpit.

The next sentence pretty much confirms my impression that this claim is almost certainly bullshit: > Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger. That's just...not how computers work.

See the recent BadUSB attack [1][2] for how this sort of attack can work; the firmware of the USB microcontroller itself can be infected.

[1] https://srlabs.de/badusb/ [2] http://www.wired.com/2014/07/usb-security/

Re: German nuclear plant infected with computer viruses, operator says

#57
post #4

Earlier quoted context omitted.

The next sentence pretty much confirms my impression that this claim is almost certainly bullshit: > Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger. That's just...not how computers work.

nice catch. can't help but think of Independence Day when Jeff Goldblum and Will Smith infect alien mothership with a mac virus from a 3.5 floppy which specifically disabled its protective shield. "will give it a cold" Edit: corrected it's its

There's a deleted scene that explains that all of our computer technology has been covertly based on the results of the Area 51 research into the crashed ship. It makes that bit a little less silly.

Re: German nuclear plant infected with computer viruses, operator says

#58
post #3

I found that part much more .. interesting: > As an example, Hypponen said he had recently spoken to a European aircraft maker that said it cleans the cockpits of its planes every week of malware designed for Android phones. The malware spread to the planes only because factory employees were charging their phones with the USB port in the cockpit.

What....? Seriously, wtf? Is it really that hard to provide outlets to charge your phone?

Anything installed in an aircraft is subject to a regulatory avalanche of paperwork, testing, and approvals.

Re: German nuclear plant infected with computer viruses, operator says

#59
post #45

Let's just say it's not new. Operators mostly watch the plant during the weekend while the engineers are not there. It is a security job: check if something turns red and pick up the phone if it goes bonkers. The operator has a limited access to the core process. Boring, and they get busy by going to the Internet and downloading random stuff. And yes they do have access to the Internet...

Remember saw a job ads for PDP11 programmer to work on Nuclear power related project a few months ago. One thing for sure: you can't infect a PDP11 system with Windows or Dos Virus, nor can one plug in an USB.

I wonder if the new hire raises eyebrows constantly talking about "core memory", "dumping core", etc.

Re: German nuclear plant infected with computer viruses, operator says

#60
post #38

It's more alarming to me that, apparently, critical infrastructure in a nuclear plant is running old versions of Windows.

There are Windows computers in there. They are not connected to any outside network "to be safe". Therefore they are protected, even protected from updates. Software that runs on them is validated for that specific OS version with a specific state of updates applied. Regulations say you can't just ran any random device (including software) there, that's unsafe. Unfortunately regulations weren't being made with PCs in…

They shouldn't be using Windows at all. Whoever had that idea should be thrown in jail for attempted mass murder. Keeping Windows off a network doesn't make it safe: Stuxnet proved that.

Windows has no business being used in any application that is life or safety critical. Its license even says so. Doing so should be a crime. There are much better OSes out there for this kind of thing: just ask anyone who builds jet aircraft.

Post reply on HN