Live data from Hacker News

Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

nytimes.com

51–60 of 96 posts

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#51

People use 1000x more water than they need to drink. If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted. Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope. It wouldn't cause t…

Who exactly is this "we" in 2026 ?

The only thing I can see is some political crony company getting a big payment from the federal budget to take on the "burden" of doing so. But then not actually distributing enough water so they can still price-gouge individuals because we wouldn't want people to become entitled, right?

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#52
post #3

The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and…

Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!

When will the public figure out that many IT exploits are the result of malpractice by developers and network adminstrators, and the businesses employing them? We're building and operating bridges that we know will collapse. Our products are nearly indefensible, literally - they can't realistically be secured except at great expense. We talk about the imbalance between costs of attack and defense; we made that imbalance.

The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.

The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#53
post #20
post #12

Wasn't there a Defcon or Derby talk about this years back? (The insecurity, not the Persian angle) Struggling for a source. Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?

Not sure about defcon, but Buckminster Fuller wrote waay back in the sixties about the New York's vulnerability to a fresh water supply attack. If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books. https://archive.org/details/operatingmanualforspaceshipearth...

I'll throw it on my list, I've got a pretty big backlog right now.

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#54

People use 1000x more water than they need to drink. If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted. Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope. It wouldn't cause t…

Iran doesn't need to cause mass casualties. They just need to make US citizens hate the war in Iran.

Trouble is, there's a good chance that a large portion of the population will then be in favour of ending the war by escalating it to the point of flattening Iran. And that portion of the population has somewhat of a correlation with the political base of the current administration.

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#55

Where does all the money go? Not to cyber apparently.

DOGE eliminated 1/3 of CISA staff in 2025. Trump reduced the 2026 CISA budget by $491 million (17%). Trump intends to slash their budget by an additional $707 million in 2027. The ICE budget was just increased by $70 BILLION, bringing its total to >$200 billion.

CISA staff doesn’t do security patches and updates on local water supplies. You’re mixing a lot of stuff around there, none of it relevant to the discussion.

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#57

People use 1000x more water than they need to drink. If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted. Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope. It wouldn't cause t…

It's actually insane to me that the nation convulsed over the inability to get water to flint Michigan and people are still over here doing "no one actually deserves water, you use too much of it anyway"

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#58

Earlier quoted context omitted.

DOGE eliminated 1/3 of CISA staff in 2025. Trump reduced the 2026 CISA budget by $491 million (17%). Trump intends to slash their budget by an additional $707 million in 2027. The ICE budget was just increased by $70 BILLION, bringing its total to >$200 billion.

CISA staff doesn’t do security patches and updates on local water supplies. You’re mixing a lot of stuff around there, none of it relevant to the discussion.

CISA is the one who mandates these controls and who manages the public/private relationship. Who issues the active exploration warnings. Who suggests legislation to prevent this in the future, including mandatory software updates.

If your question was only a trite recitation of the fact that private enterprise consistently refuses to practice cybersecurity then you've added nothing.

If your question was about who watches the watchers and what we're doing about the fact that private enterprise refuses to practice cybersecurity then it was an incredibly relevant statement.

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#59
>state and local officials throughout the country were on high alert for potential problems in vulnerable computers that are commonly used to monitor and adjust water quality, including chemical-treatment levels and water pressure.

You don't need a full bidirectional internet connection for remote monitoring, and data diodes are a relatively cheap way to monitor them in complete safety.

Completely stopping ingress of control (using above mentioned data diodes) is relatively easy, and should be legislated into being the norm.

Re: Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran

#60
post #43
post #26

Earlier quoted context omitted.

I mean Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas… It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level. These…

Who connected the systems to the Internet in the first place? Why ?

Most likely to cut costs and have one person remote-admin all pumps, valves, etc. instead of a crew for each location.

Why didn't they have firewalls, admin accounts, access rights, you know, proper security? They were glad it barely worked at all.

Post reply on HN