Live data from Hacker News

CISA Alert: Water Sector PLC Targeting

censys.com

41–50 of 78 posts

Re: CISA Alert: Water Sector PLC Targeting

#41
post #35

Earlier quoted context omitted.

I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)

It is an issue, dial up lacks tunnel encryption and if you managed to make it, it will be useless in real scenarios, and 3g is being phased out and obsolete

Secure the contents of the tunnel and it doesn't matter. Provide a secure backbone and it doesn't matter. Realize that dialup is so slow that you can transparently tunnel it across ~any modern network (for which you can encrypt the tunnel) and it doesn't matter.

Tunnel your dialup within your obsolete 3g network, and then tunnel that obsolete 3g network within something modern. The obsolete technologies are not the issue here.

Also the thing about dialup is that it's point to point so the attack surface isn't even remotely comparable to exposing a port on the open internet. I should generally be able to trust the link that my phone company provides. Faxes are still used in many secure settings in preference to email.

Re: CISA Alert: Water Sector PLC Targeting

#42
post #35

Earlier quoted context omitted.

It is an issue, dial up lacks tunnel encryption and if you managed to make it, it will be useless in real scenarios, and 3g is being phased out and obsolete

Secure the contents of the tunnel and it doesn't matter. Provide a secure backbone and it doesn't matter. Realize that dialup is so slow that you can transparently tunnel it across ~any modern network (for which you can encrypt the tunnel) and it doesn't matter. Tunnel your dialup within your obsolete 3g network, and then tunnel that obsolete 3g network within something modern. The obsolete technologies are not the i…

For 3G, it’s phased out, so the bands will be gone, you have to upgrade it.

The dial up part is far more involved, especially when they have auto answering connected directly to PLC or HMI, mostly with shared passwords. Also, you can’t trust the network operator either, insider threats and rogue employees are a threat. Additionally, dial ups are less monitored compared to modern network, and usually you end up with duct tape solutions like jump server to have strong authentication and continuous logging in firewall and such, plus proper encrypted tunnels so even physical wiretapping isn’t possible, and the assumption of air gap isn’t there because it’s reachable through public telephone, and the worst part, these dial ups are usually connected to windows XP Scada developers machines.

To add, obsolete is bad too, when your device cease to have vulnerability patches, you are screwed regardless of whatever configs you put.

Re: CISA Alert: Water Sector PLC Targeting

#43
post #11

Earlier quoted context omitted.

Usually when people say this they are dog whistling privatization. Which is the exact opposite thing people need in infrastructure, ask anyone who has to deal with PG&E. Paying skilled people highly does actually incentivize people to do better work, especially if they are actually embedded into the community they are essentially working for. If being a civil servant was as "glorious" as being a techie is SF there wo…

In an environment without accountability, higher pay is just more incentive to lay low and not take any personal risk. Why do anything other than the bare minimum when there is no upside? In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing. The people who climb to the top aren’t the ones who to…

Corporations have even less accountability to the public than public utility districts. If you don’t like what the organization is doing, vote in different commissioners and make them aware of your concerns. But if you don’t like what your water service is doing, good luck drilling a well to get away from them.

Re: CISA Alert: Water Sector PLC Targeting

#44

Earlier quoted context omitted.

I will repeat a comment from below. There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.

There are 150 million taxpayers and the federal government regulates all of them. I don’t see why they can’t audit 0.1% of that. If there are 150,000 utilities then absent some regulation, some of them will fuck up. If we want fewer fuckups, you need regulation.

What’s the penalty you would impose on a rural water system that has under 10 employees that services thousands of people for water and/or wastewater?

What does that audit look like and how frequent does that happen? It’s a security assessment? A quality assessment? A risk assessment?

I’m open to the idea, but I will repeat, I don’t think the problem is well enough understood for a “make the feds do it” type of comment.

Re: CISA Alert: Water Sector PLC Targeting

#45
post #17

Earlier quoted context omitted.

It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..

I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)

Dial up into an air gapped network defeats the purpose of being air gapped. I would think the bare minimum standard is that there is no way to change anything in the control systems without being physically present at the facility, past it's physical security boundary.

Re: CISA Alert: Water Sector PLC Targeting

#46

Earlier quoted context omitted.

There are 150 million taxpayers and the federal government regulates all of them. I don’t see why they can’t audit 0.1% of that. If there are 150,000 utilities then absent some regulation, some of them will fuck up. If we want fewer fuckups, you need regulation.

What’s the penalty you would impose on a rural water system that has under 10 employees that services thousands of people for water and/or wastewater? What does that audit look like and how frequent does that happen? It’s a security assessment? A quality assessment? A risk assessment? I’m open to the idea, but I will repeat, I don’t think the problem is well enough understood for a “make the feds do it” type of comme…

It’s the same regulatory/incentive toolbox as any industry, including possibly accepting lower security standards for tiny treatment plants just like we accept less security for podunk airports.

> make the feds do it

National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a war with another country they’re absolutely responsible for minimizing by collateral damage at a fucking minimum.

Re: CISA Alert: Water Sector PLC Targeting

#47

Earlier quoted context omitted.

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota? > failed to anticipate not only these infrastructure breach They've been warning them for close to two decades. Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.

The federal government could potentially oversee the most populous areas of the state and those near a military installation pretty easily. They don’t have to look at every one.

Re: CISA Alert: Water Sector PLC Targeting

#48

Earlier quoted context omitted.

Yes, utilities shouldn’t be negligent, but national security is 100% the federal government’s responsibility. If the vulnerabilities were so trivial, then it’s even more damning that the federal government was caught with its pants down, particularly since they were the only ones who knew they would be starting a war. > finger-pointing isn't going to fix it. Your entire comment was finger pointing…

There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.

There are 1000x as many tax payers and the government still makes sure every single mom who gets a venmo payment for $60 pays taxes. National security is a federal responsibility, they should absolutely do their jobs.

Re: CISA Alert: Water Sector PLC Targeting

#49

Earlier quoted context omitted.

What’s the penalty you would impose on a rural water system that has under 10 employees that services thousands of people for water and/or wastewater? What does that audit look like and how frequent does that happen? It’s a security assessment? A quality assessment? A risk assessment? I’m open to the idea, but I will repeat, I don’t think the problem is well enough understood for a “make the feds do it” type of comme…

It’s the same regulatory/incentive toolbox as any industry, including possibly accepting lower security standards for tiny treatment plants just like we accept less security for podunk airports. > make the feds do it National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a w…

National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground?

NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so.

I agree that in theory this would not be a stretch if the stars aligned, but these are for the most part, not federal government funded entities nor government controlled even at a state level. They are usually clooged together by 100 years of paper maché. And that’s just water. What about Energy? Data Centers? Pharma? Regulation is way too far behind to just instantly drop a silver bullet.

And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI.

Re: CISA Alert: Water Sector PLC Targeting

#50

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will. CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration. Yet here we are in 2026 and…

CISA was formed in 2018, so not quite 15 years but closer to half that. The security industry as a whole has been yelling for longer than 15 years about the vulnerability of utilities. They've been marked as soft targets before the Bush administration restructured the government.
Post reply on HN