Live data from Hacker News

German nuclear plant infected with computer viruses, operator says

reuters.com

61–70 of 101 posts

Re: German nuclear plant infected with computer viruses, operator says

#61

I wonder what scale of disaster will have to occur before information security is placed under the same legal and regulatory scrutiny as physical security?

No disaster necessary. NERC CIP regulations have been in place (and enforced) at electric utilities since 2007:

"In 2007, FERC designated NERC the ERO in accordance with Section 215 of the Federal Power Act, enacted by the Energy Policy Act of 2005. Upon FERC’s approval, NERC’s Reliability Standards became mandatory within the United States. These mandatory Reliability Standards include CIP standards 001 through 009, which address the security of cyber assets essential to the reliable operation of the electric grid."

Source: http://www.nerc.com/pa/CI/Comp/Pages/default.aspx

(Edit: clarification)

Re: German nuclear plant infected with computer viruses, operator says

#62

I wonder what scale of disaster will have to occur before information security is placed under the same legal and regulatory scrutiny as physical security?

I think it won't happen until everyone in society has good "computer literacy".

The number of people who have no idea how their car works, despite them being fairly ubiquitous for nearly 100 years makes be think that that will never happen. There will always be people who know only just enough about the technology around them to get by.

Re: German nuclear plant infected with computer viruses, operator says

#63
post #40
post #36

Earlier quoted context omitted.

Modern nuclear reactor design is such that you cant cause a meltdown without violating the laws of physics.

How does this work? Do you know the reactor-type you are speaking of? I'd like to know more on this...

Wiki has a few examples of such systems/designs: https://en.wikipedia.org/wiki/Passive_nuclear_safety#Example...

Re: German nuclear plant infected with computer viruses, operator says

#64
post #10

Possibly important to note the timing of this admission right on the heels of the announcement of our defense minister that she wants to build a 'cyber' division in the army with 13500 people working there. Thats almost 10% of our armed forces. I could only find decent reporting about this in german: http://www.tagesspiegel.de/politik/plaene-der-verteidigungsm...

Here in Germany that only means that 13000 people print out reports for the minister, while 500 people look at screens. 10 of them program the stuff that happens on the screens.

Classic joke: "Wow, that's a huge building. How many people work here?" - "Maybe half of them."

Re: German nuclear plant infected with computer viruses, operator says

#65
post #3

Earlier quoted context omitted.

What....? Seriously, wtf? Is it really that hard to provide outlets to charge your phone?

Or alternatively, how about WTF are you doing plugging your phone into this fucking cockpit? You're here to do your job and if you want to carry your phone around with you in the factory all day that's up to you, but plugging your phone into the fucking cockpit you're meant to be working on will result in demotions, suspensions and unemployment all round. More politely put, I see no obligation on employers to provide…

> More politely put, I see no obligation on employers to provide employees with the means to recharge their personal phones :)

This is a classic "design a better human" problem - sure, you can try to 'persuade' people by threatening them with demotions, suspensions and unemployment. And then you can hope that this will work in every single instance. Or ... you can provide a few usb ports in a convenient location, so people use these instead of the usb port in your multi million dollar cockpit to charge their phones. Take your pick.

For another example decide if it's easier to provide waste bins or to threaten people who litter streets.

Re: German nuclear plant infected with computer viruses, operator says

#66

Earlier quoted context omitted.

Here in Germany that only means that 13000 people print out reports for the minister, while 500 people look at screens. 10 of them program the stuff that happens on the screens.

You have that many Australians working in Germany?

I don't get the reference.

Re: German nuclear plant infected with computer viruses, operator says

#67
We have to be more concerned about the things that are not reported. And why is it even technically possible to infect the control system of a power plant at all, or was this just a virus in some auxilliary sytem like, say, the machines only connected to another network, totally decoupled from the control system? Without details, this is just fear mongering on the heels of recent media outbreak regarding Belgian reactors.

Re: German nuclear plant infected with computer viruses, operator says

#68
post #10

Possibly important to note the timing of this admission right on the heels of the announcement of our defense minister that she wants to build a 'cyber' division in the army with 13500 people working there. Thats almost 10% of our armed forces. I could only find decent reporting about this in german: http://www.tagesspiegel.de/politik/plaene-der-verteidigungsm...

Yeah, totally agree. They also have aggressive print advertising everywhere (here in Munich) for this campaign. I wonder if they can attract any real talent though? Only people I know willingly wanted to work for the Bundeswehr eiter did not have the grades to study elsewhere or went to Afghanistan for the money.

I'm glad somebody joins them, though, or they would make up a law to legalize what drug cartels are doing with IT (and other) talent. Laws can be passed in parliament and be in use and need to go through trial at supreme court to be ruled invalid. I really wish passing laws was super had, super laborious, and took a very long time (at least 5 years). Then, the government, which needs to be reelected every 4 years, cannot pass all kinds of stupidity.

Re: German nuclear plant infected with computer viruses, operator says

#69

I found that part much more .. interesting: > As an example, Hypponen said he had recently spoken to a European aircraft maker that said it cleans the cockpits of its planes every week of malware designed for Android phones. The malware spread to the planes only because factory employees were charging their phones with the USB port in the cockpit.

Yeah, it's sad that so many people actually use USB ports at airports to charge their devices, without knowing what they are connecting their devices to. I don't expect them to know better, but all their data could be copied, stuff could be modified. Isn't there an adapter which limits the active lines to just what's needed to pass power, no data, or is charging without some data exchange impossible?

Re: German nuclear plant infected with computer viruses, operator says

#70

I wonder what scale of disaster will have to occur before information security is placed under the same legal and regulatory scrutiny as physical security?

I think it won't happen until everyone in society has good "computer literacy".

That's not a reasonable requirement, it's just that there is no consequence for people administrating (installing, maintaining) systems and the software writers. If fines were involved, how long do you guess would it take for people to stop writing in C or system integrator setting up random software. Critical systems may only use software written and certified years ago, not be constantly updated.
Post reply on HN