Live data from Hacker News

CISA Alert: Water Sector PLC Targeting

censys.com

61–70 of 78 posts

Re: CISA Alert: Water Sector PLC Targeting

#61

Earlier quoted context omitted.

It’s the same regulatory/incentive toolbox as any industry, including possibly accepting lower security standards for tiny treatment plants just like we accept less security for podunk airports. > make the feds do it National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a w…

National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground? NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so. I agree that in theory this would not be a…

> The issue comes down to actual skilled people hours to do the work and resource constraints to do so.

It comes down to incentives. If you want broad security you have to do more than hope that every water utility will both hire good people and also allow them to do their jobs properly.

> But what does that fundamentally mean for boots on the ground?

How does any regulation look on the ground? How does the federal government regulate banks and airports?

> these are for the most part, not federal government funded entities nor government controlled even at a state level

Neither are banks or airports

> What about Energy? Data Centers? Pharma?

Energy and pharma are already regulated. Maybe data centers will be eventually if they are deemed sufficiently critical.

> Regulation is way too far behind to just instantly drop a silver bullet.

I don’t know what this even means in the context of securing our water system. Do you mean to say that regulation can’t ensure that these software systems don’t use default passwords and so on?

> And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI

What is new is that we started a war with a country with a respectable technology competency without doing anything to shore up our defenses.

Re: CISA Alert: Water Sector PLC Targeting

#62
There can be surprisingly few critical components and processes in a water and sewerage network due to gravity-fed designs (far more cost efficient), large buffers (water reservoirs, sewage sumps, etc) allowing intermittent operation of otherwise critical components, retained ability for humans to manually operate equipment, and also the fields of availability and safety engineering which typically prefer elimination of software failure modes by designing equipment to not rely upon software.

The aim of a water network is to:

1. Take water from a water source (elevated dam -- strongly preferred, river, ocean) and as much as possible, gravity feed it to a treatment plant.

2. Treat the water using processes that are simplified/fail-safe as much as possible and could be operated manually by humans if necessary. This is where availability and safety engineers would design equipment to not be dependent on software and instead use mechanical or analogue electronics control.

3. Pre-position treated water as much as possible at ~50-90m hydraulic head (~500-900kPA) above the water faucets where people want to use the treated water and provide a buffer for X days of usage. Any pumps between the treatment plant and elevated storage therefore only need to operate intermittently to refill the buffer.

Sewerage networks have similar aims:

1. Let sewage flow as much as possible downhill to the treatment plant via gravity. Where a rising main (elevation gain) is required, place a large enough sump for X hours/days of usage and pump up to higher elevation from the sump.

2. Treat the sewage using processes that are simplified/fail-safe as much as possible and could be operated manually by humans if necessary. For example, a compressor used for aeration can be manually switched on/off with a mechanical switch and plugged into a diesel generator, and not require someone logging in with multi-factor authentication to a laptop to issue a command to a PLC to turn on the compressor.

3. Design overflows into the system for emergency release of partially or untreated sewage, and practice this process as part of disaster recovery exercises. This is generally an aim arising due to risk assessment process that says building a $1bn sump with 8 independent pumps is cost prohibitive versus the 1-in-200 year chance of untreated sewage messing up a downstream river for a few weeks.

Ultimately a lot of the cybersecurity risk comes down to government appetite to accept 1-in-1000 (or whatever) year failure modes. Is it worth investing now in triple modular redundant automated control systems (mostly used in safety-critical sectors such as aviation and space), or installing a just-in-case diesel generator at every one of 500 pumping stations across a region, or building $10bn of sewage sumps to hold sewage for up to a month, or building 2 treatment plants instead of 1 and using different technology for each, or hiring and training more humans to regularly exercise manual control and operation of a network, etc? Or just accept that once every 1000 years, some water rationing may be required, or a downstream river will be polluted for a few weeks?

Re: CISA Alert: Water Sector PLC Targeting

#63

Earlier quoted context omitted.

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

I will repeat a comment from below. There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.

Usually these commenters are not from the US but get energized by US topics and misunderstand scale of things. E.g., they come from countries with a single nationalized entity for many things.

Re: CISA Alert: Water Sector PLC Targeting

#64

Earlier quoted context omitted.

There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.

There are 1000x as many tax payers and the government still makes sure every single mom who gets a venmo payment for $60 pays taxes. National security is a federal responsibility, they should absolutely do their jobs.

> There are 1000x as many tax payers and the government still makes sure every single mom who gets a venmo payment for $60 pays taxes.

That's a join in an existing database.

Where's the database and what's the code for this case?

Re: CISA Alert: Water Sector PLC Targeting

#65

> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts). Describe the network security of the industrial automation industry and their customers in a single statement. Lol.

The numbers are a bit lower if you exclude honeypots (~2k hosts): https://www.shodan.io/search/report?query=rockwell+port%3A44...

And the problem has actually gotten better over the years:

https://trends.shodan.io/search?query=tag%3Aics+rockwell

The situation used to be worse with things like the Lantronix password recovery service (i.e. a UDP port that would just send you the device password without any auth). It's still not ideal and takings things offline isn't easy (https://blog.shodan.io/taking-things-offline-is-hard/) but it's getting better (slowly).

Re: CISA Alert: Water Sector PLC Targeting

#66

Earlier quoted context omitted.

> Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. I work with PLCs. Default passwords of not, the idea that such weakly secure devices are being made accessible from the public internet boggles my mind.

What industry? Very relevant.

Not utilities. And none of the PLCs I work with are internet-connected or unsecured.

Re: CISA Alert: Water Sector PLC Targeting

#67

Earlier quoted context omitted.

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

I will repeat a comment from below. There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.

The US government does meat inspections, that seems like a much broader scope than auditing the security of a couple hundred thousand utilities every few years. At the very least they could send them a set of best practices and require them to certify compliance. Larger ones could get random on-site inspections.

Re: CISA Alert: Water Sector PLC Targeting

#68
The playbook, per federal officials, was crude but effective: attackers remotely accessed internet-facing operational technology, changed device IP addresses and passwords, and locked utility operators out of their own monitoring and control systems, NBC News reported. The PSA is now pleading with utilities to do the bare minimum - pull programmable logic controllers off the open internet and put them behind gateways and firewalls, use actual passwords, and restrict which devices are allowed to talk to one another.

Re: CISA Alert: Water Sector PLC Targeting

#69

Earlier quoted context omitted.

“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.

Not really. Just patch and reboot. Pretty simple.

Ouch. You just caused a major outage for . Either you costed your company millions of dollars or you killed someone.

OT does not equal IT

Re: CISA Alert: Water Sector PLC Targeting

#70

Earlier quoted context omitted.

I've met info-sec / vulnerability researcher types that were egregiously reckless, like plugging Raspberry Pi's into the production network kind of thing. Public sector has always paid low. But the problem is widespread, almost universal, and they've had a 15 year head start of the federal government telling them to get their shit together. At some point it just became standard industry practice is my guess.

Upgrades to waste water are project based. Lowest bidder will not provide security for free. Security may be mentioned in spec but in hand waved language that can be hand waved away. That company doing the improvement project will have next to no documentation from the previous engineering effort. Just do bare minimum and move on to next job, because no one is getting paid enough to do put in more effort.

Depends on the firm. Quite many water companies handle their own engineering and only outsource when absolutely necessary, think speciality tunnel boring companies.
Post reply on HN