Live data from Hacker News

Water system controllers don't belong on the internet, says ex-NSA chief

theregister.com

11–20 of 164 posts

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#11
post #8

Earlier quoted context omitted.

Keeping things up to date and holding critical infrastructure to higher standards than consumer tech is not a bad idea. Taking things offline and properly airgapped can also work, but wouldn't the cost of that exceed making specialized things and maintaining them? We got into this situation due to cost, not ignorance. Both choices are higher cost than putting ancient devices on the internet.

You can't have both secure infrastructure and Internet exposed infrastructure. I don't know if I'd frame it as incompetence, but it does seem firmly outside the capabilities of current engineering practice. If you need a computer system to be actually secure, rule #0 is absolutely ensure it cannot receive unauthorized inputs of any kind (airgapped, big Faraday cage, JB Weld all the ports, big scary guys with guns, re…

Right, enclose it in meters thick reinforced concrete walls and let no one near it.

While that works for Chernobyl, if you have a real world systems you might want somewhat more practical access.

Of course exposing industrial hardware directly on the internet is the other extreme, and you get what you're asking for.

Do something in between, if you even just apply normal network security you'll be ahead of the pack.

Problem is, a lot of these systems are not built by IT people. While they have a lot of quite admirable skills, it's just not their primary job, and thus they tend to lack the necessary paranoia at times.

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#12

He is wrong and right. They should be connected to the Internet when they aren't 30 year old PLCs ripe for abuse. Until then, cut the data lines and do water monitoring the old way.

Disagree. Why connect them to the internet? They should be super hardened against attacks, and should NOT have a physical connection to the internet. Same with electrical infrastructure. Network access? Possibly, however that network should NOT be accessible from the internet.

The only exception I can think of would be for meter reading, which should be a separate, read only device with no ability to do harm altogether.

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#13
post #8

Earlier quoted context omitted.

Keeping things up to date and holding critical infrastructure to higher standards than consumer tech is not a bad idea. Taking things offline and properly airgapped can also work, but wouldn't the cost of that exceed making specialized things and maintaining them? We got into this situation due to cost, not ignorance. Both choices are higher cost than putting ancient devices on the internet.

You can't have both secure infrastructure and Internet exposed infrastructure. I don't know if I'd frame it as incompetence, but it does seem firmly outside the capabilities of current engineering practice. If you need a computer system to be actually secure, rule #0 is absolutely ensure it cannot receive unauthorized inputs of any kind (airgapped, big Faraday cage, JB Weld all the ports, big scary guys with guns, re…

[deleted]

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#14

>Other countries start securing their water >nsa: what no, stop that

I sometimes wonder how much damage (and potential damage) to US infrastructure exists simply because intelligence-agencies prioritize being able to exploit it globally over fixing it on defense.

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#15
post #12

He is wrong and right. They should be connected to the Internet when they aren't 30 year old PLCs ripe for abuse. Until then, cut the data lines and do water monitoring the old way.

Disagree. Why connect them to the internet? They should be super hardened against attacks, and should NOT have a physical connection to the internet. Same with electrical infrastructure. Network access? Possibly, however that network should NOT be accessible from the internet. The only exception I can think of would be for meter reading, which should be a separate, read only device with no ability to do harm altogeth…

People start freaking out at the costs of dedicated fibers to every monitored facility. Hence even 'private' networks still run over the same actual lines as the internet.

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#16
post #8

Earlier quoted context omitted.

You can't have both secure infrastructure and Internet exposed infrastructure. I don't know if I'd frame it as incompetence, but it does seem firmly outside the capabilities of current engineering practice. If you need a computer system to be actually secure, rule #0 is absolutely ensure it cannot receive unauthorized inputs of any kind (airgapped, big Faraday cage, JB Weld all the ports, big scary guys with guns, re…

Right, enclose it in meters thick reinforced concrete walls and let no one near it. While that works for Chernobyl, if you have a real world systems you might want somewhat more practical access. Of course exposing industrial hardware directly on the internet is the other extreme, and you get what you're asking for. Do something in between, if you even just apply normal network security you'll be ahead of the pack. P…

> normal network security

The problem is there's no good way to actually enforce this. Every organization has their own idea of what is "good enough". The NSA has some pretty good advice[0]. But as far as I know there's no written-in-stone engineering standard organizations have to meet, just "best practices". If the building inspector finds fault with the construction of your facility, it gets evacuated and shut down until the defect is remedied. There's no inspector for your network security. That's the problem.

[0] https://media.defense.gov/2022/Jun/15/2003018261/-1/-1/0/CTR...

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#17

He is wrong and right. They should be connected to the Internet when they aren't 30 year old PLCs ripe for abuse. Until then, cut the data lines and do water monitoring the old way.

Rather than "on/off" I think we need to distinguish between at least four things:

1. Connected naively to the internet.

2. Behind a hardened VPN endpoint which is on the internet.

3. Has a separate physical private network.

4. Requires physical access.

I think it's obvious that #1 should be prohibited in favor of #2. After that point we need to ask what the impact is of a Denial of Service attack that prevents anyone from remotely accessing the system.

The difference between #2 and #3 may depend on whether things could be Very Bad if the system is disconnected at a time of the attacker's choosing. For example, disabling access to flood-control valves during a hurricane.

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#18
post #5

There are many wireless pump-and-reservoir systems that while not internet connected, use insecure RF links. These local RF (and casting a wider net, Bluetooth) interfaces are also ripe for abuse.

Wouldn't the physical facilities themselves have security?

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#19

Don't put your PLCs directly on the internet. In fact most industrial stuff is very not made to be directly connected to the internet. But interpose a firewall+VPN solution and you might be ok, if done competently. And remote access to hardware definitely makes management and maintenance a lot easier and quicker. (else you need to drive out for every minor issue)

"If done competently" is a bold assumption unfortunately, not just these days but always

Re: Water system controllers don't belong on the internet, says ex-NSA chief

#20
post #4

Earlier quoted context omitted.

If it’s connected, it’s compromised. Or will be. Folly to think otherwise.

Keeping things up to date and holding critical infrastructure to higher standards than consumer tech is not a bad idea. Taking things offline and properly airgapped can also work, but wouldn't the cost of that exceed making specialized things and maintaining them? We got into this situation due to cost, not ignorance. Both choices are higher cost than putting ancient devices on the internet.

> Keeping things up to date and holding critical infrastructure to higher standards than consumer tech is not a bad idea.

This is a great theory, but practice (over centuries now if not millennia) tells us that critical infrastructure is rarely properly maintained. "If it ain't broke, don't fix it" is the motto of governments and large organizations everywhere when it comes to proper maintenance. As opposed to improper (keep the existing thing running) maintenance, proper maintenance requires being proactive and is expensive, often requiring partial or full replacements of systems while also keeping the old system running until a hand-off time. In order to get a government or corporation to be proactive, they have to see a problem.

No problem, no worry. That it can be hacked is not a problem from their perspective. That it has been hacked might be a problem to them, but only if their constituents find out. More likely, they'll make it the poor engineer's problem, the engineer who had no budget and no staff to address it beforehand.

When it's time to cut costs, proper maintenance is one of the first places organizations look to because it's not a present problem. Then it becomes normal to not do the work, from an organizational perspective, and all those engineers and technicians are just a bunch of Cassandras.

Post reply on HN