Live data from Hacker News

CISA Alert: Water Sector PLC Targeting

censys.com

31–40 of 78 posts

Re: CISA Alert: Water Sector PLC Targeting

#31

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will. CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration. Yet here we are in 2026 and…

Yes, utilities shouldn’t be negligent, but national security is 100% the federal government’s responsibility. If the vulnerabilities were so trivial, then it’s even more damning that the federal government was caught with its pants down, particularly since they were the only ones who knew they would be starting a war. > finger-pointing isn't going to fix it. Your entire comment was finger pointing…

There are over 150k water utilities alone in the US.

Passing the buck to the Federal Government is not understanding the problem.

Re: CISA Alert: Water Sector PLC Targeting

#32

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will. CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration. Yet here we are in 2026 and…

> Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. I work with PLCs. Default passwords of not, the idea that such weakly secure devices are being made accessible from the public internet boggles my mind.

What industry? Very relevant.

Re: CISA Alert: Water Sector PLC Targeting

#33

Earlier quoted context omitted.

Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

I will repeat a comment from below. There are over 150k water utilities alone in the US.

Passing the buck to the Federal Government is not understanding the problem.

Re: CISA Alert: Water Sector PLC Targeting

#34
post #17

Earlier quoted context omitted.

It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..

I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)

Well I think it speaks to the age of the equipment they are speaking of in the industrial sector.

How do you lockdown something that may have not been taken offline for decades because it will cost downtime or harm. Or something that can’t be locked down without tossing new tech around it that may not be compatible with the protocols etc.

Re: CISA Alert: Water Sector PLC Targeting

#35
post #17

Earlier quoted context omitted.

It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..

I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)

It is an issue, dial up lacks tunnel encryption and if you managed to make it, it will be useless in real scenarios, and 3g is being phased out and obsolete

Re: CISA Alert: Water Sector PLC Targeting

#36

Earlier quoted context omitted.

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota? > failed to anticipate not only these infrastructure breach They've been warning them for close to two decades. Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.

The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.

Re: CISA Alert: Water Sector PLC Targeting

#39

Earlier quoted context omitted.

Your comments show, beyond a shadow of a doubt, that you have never worked for the federal government and likely have never worked in state or local government. >In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing. Federal employment is merit based. Advances are earned, not doled out to the tea…

I don't think your attitude here is in keeping with the guidelines (or constructive discourse for that matter). You've made a number of uncharitable assumptions about the other party on the back of which you then launched into baseless personal attacks. Notably everything in the comment you replied to applies equally to the public and private sector. They are neutral observations about systemic motives and the associ…

>I don't think your attitude here is in keeping with the guidelines (or constructive discourse for that matter).

I'll make a note of that. Any comment that I make on this site is made in the hopes that there will be discussion generated. Sometimes that happens and other times it doesn't. I don't spend any part of my life wondering why people choose to or choose not to engage. Most of us have busy lives and this (HN) for us is an opportunity to catch up on interesting things.

>You've made a number of uncharitable assumptions about the other party on the back of which you then launched into baseless personal attacks.

I am not sure that noting that a poster has no experience in a subject and has no idea how it really works in practice becomes an uncharitable assumption. It may look like a personal attack but it is based entirely on the content of the user's own posts, which support the conclusion that I reached.

>They are neutral observations about systemic motives and the associated perverse incentives.

From /u/moscoe original comment in the thread:

>Incentives and performance management are fundamental problem in civil service. The incentives to set high standards and hold individuals accountable simply do not exist.

These two sentences here demonstrate that /u/moscoe does not have any experience working in the public sector for federal, state, or local government entities yet somehow they feel qualified to speak confidently (incorrectly) that those who have worked in that capacity are ham-strung by the system and disincentivized to make waves. That is false.

I mentioned federal employees specifically because they are civil servants (referenced by /u/moscoe above) and someone close to me has worked a long career in the federal government under several administrations from both political parties.

I think you have your opinions and you are entitled to those opinions. I am also sure that you are wrong about the content of my post. It was not uncharitable nor were there any assumptions. The conclusions that I drew were supported by the statements made by /u/moscoe. If it ends up looking like a personal attack then there was a basis for that personal attack.

It's possible that you read my comment without reading the full thread so some of the context was missing.

Re: CISA Alert: Water Sector PLC Targeting

#40

Earlier quoted context omitted.

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

I will repeat a comment from below. There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.

There are 150 million taxpayers and the federal government regulates all of them. I don’t see why they can’t audit 0.1% of that. If there are 150,000 utilities then absent some regulation, some of them will fuck up. If we want fewer fuckups, you need regulation.
Post reply on HN