Live data from Hacker News

CISA Alert: Water Sector PLC Targeting

censys.com

21–30 of 78 posts

Re: CISA Alert: Water Sector PLC Targeting

#21

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will. CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration. Yet here we are in 2026 and…

I think it's less carelessness and more the inability to attract (pay) people who have the technical knowhow to properly secure infrastructure. Even a lot of developers are poor network engineers and treat IT like magic at their own companies.

[flagged]

Re: CISA Alert: Water Sector PLC Targeting

#22

Earlier quoted context omitted.

Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota?

> failed to anticipate not only these infrastructure breach

They've been warning them for close to two decades.

Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.

Re: CISA Alert: Water Sector PLC Targeting

#23
post #17

> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts). Describe the network security of the industrial automation industry and their customers in a single statement. Lol.

It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..

I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)

Re: CISA Alert: Water Sector PLC Targeting

#24

Earlier quoted context omitted.

I think it's less carelessness and more the inability to attract (pay) people who have the technical knowhow to properly secure infrastructure. Even a lot of developers are poor network engineers and treat IT like magic at their own companies.

I've met info-sec / vulnerability researcher types that were egregiously reckless, like plugging Raspberry Pi's into the production network kind of thing. Public sector has always paid low. But the problem is widespread, almost universal, and they've had a 15 year head start of the federal government telling them to get their shit together. At some point it just became standard industry practice is my guess.

In all things when it fails in a drastic way the system will be corrected. People will die, it will suck, changes will be made.

Government is supposed to respond to these things and create incentives to correct. Telling a small municipality to do something without a carrot ir stick does nothing.

In this instance someone else will be providing the stick.

Re: CISA Alert: Water Sector PLC Targeting

#25

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will. CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration. Yet here we are in 2026 and…

Not IT malpractice and this where the industry diverges. IT folks usually don’t work on or understand these systems.

Which is one of MANY problems OT faces. IT best practices don’t suffice in OT and even when they do, most of these orgs are too resource hamstrung to do anything about all of the fires they have to put out.

Not to mention all of the OT vendors who flooded the market with tools instead of people being taught the boring process driven work.

Re: CISA Alert: Water Sector PLC Targeting

#26
post #11

Earlier quoted context omitted.

In an environment without accountability, higher pay is just more incentive to lay low and not take any personal risk. Why do anything other than the bare minimum when there is no upside? In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing. The people who climb to the top aren’t the ones who to…

Your comments show, beyond a shadow of a doubt, that you have never worked for the federal government and likely have never worked in state or local government. >In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing. Federal employment is merit based. Advances are earned, not doled out to the tea…

I don't think your attitude here is in keeping with the guidelines (or constructive discourse for that matter). You've made a number of uncharitable assumptions about the other party on the back of which you then launched into baseless personal attacks.

Notably everything in the comment you replied to applies equally to the public and private sector. They are neutral observations about systemic motives and the associated perverse incentives.

Also it's not clear to me that any of the utilities in question have anything to do with the federal government so I'm not sure why you dragged them into this.

Re: CISA Alert: Water Sector PLC Targeting

#27
post #8

Earlier quoted context omitted.

You’re on the right track, I think. But, I wouldn’t say it’s about the pay to attract competent workers. I think it has more to do with the incentive structures once you’re in. Incentives and performance management are fundamental problem in civil service. The incentives to set high standards and hold individuals accountable simply do not exist. The one and only exception is the military, because lives are literally…

We just started replacing our PLCs. They absolutely were setup with default passwords, but weren't put on the public internet.

What policies do y’all have in place for this? Is there a program in place or the beginnings of one at least?

Re: CISA Alert: Water Sector PLC Targeting

#28
post #8

Earlier quoted context omitted.

You’re on the right track, I think. But, I wouldn’t say it’s about the pay to attract competent workers. I think it has more to do with the incentive structures once you’re in. Incentives and performance management are fundamental problem in civil service. The incentives to set high standards and hold individuals accountable simply do not exist. The one and only exception is the military, because lives are literally…

Usually when people say this they are dog whistling privatization. Which is the exact opposite thing people need in infrastructure, ask anyone who has to deal with PG&E. Paying skilled people highly does actually incentivize people to do better work, especially if they are actually embedded into the community they are essentially working for. If being a civil servant was as "glorious" as being a techie is SF there wo…

Why do you assume that PG&E has a good incentive structure, or that the public sector must necessarily have a bad one? My only objection to the preceding comment would be that struggling with perverse incentives isn't limited to civil service. Incentive structures are a core struggle of approximately all large groups of people.

Re: CISA Alert: Water Sector PLC Targeting

#29

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will. CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration. Yet here we are in 2026 and…

Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.

“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.

Re: CISA Alert: Water Sector PLC Targeting

#30
post #8

Earlier quoted context omitted.

You’re on the right track, I think. But, I wouldn’t say it’s about the pay to attract competent workers. I think it has more to do with the incentive structures once you’re in. Incentives and performance management are fundamental problem in civil service. The incentives to set high standards and hold individuals accountable simply do not exist. The one and only exception is the military, because lives are literally…

Usually when people say this they are dog whistling privatization. Which is the exact opposite thing people need in infrastructure, ask anyone who has to deal with PG&E. Paying skilled people highly does actually incentivize people to do better work, especially if they are actually embedded into the community they are essentially working for. If being a civil servant was as "glorious" as being a techie is SF there wo…

I think the big problem is administrative capacity.

There are better run governments than we have in the US.

The contempt for the state is a self-fulfilling prophecy. The state is incompetent because many of us believe it is inevitable that it will be. Compensation is just a part of it; coherent administration with continuity is even more important.

Post reply on HN