Live data from Hacker News

CISA Alert: Water Sector PLC Targeting

censys.com

71–78 of 78 posts

Re: CISA Alert: Water Sector PLC Targeting

#71

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will. CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration. Yet here we are in 2026 and…

I think it's less carelessness and more the inability to attract (pay) people who have the technical knowhow to properly secure infrastructure. Even a lot of developers are poor network engineers and treat IT like magic at their own companies.

Funny enough I used to work for a water system in the “Information Systems” department - there was far too much of the classic “not my problem” from colleagues.

Our original bill pay (ran from 2006 to 2019) stored passwords in plaintext in flat files. Concerned citizens noticed because our password reset would just email you your own password. Instead of fixing it, they just removed the ability to recover an account without coming into an office. Our CTO knew, he wrote the whole thing!

We had a fun one, Outlook was sending employee passwords to our bill pay system and ending up plaintext in our logs due to some quirky fallback default behaviors around DNS and VPNs. Reported and ignored, of course.

Regarding TFA, we had an insurance requirement to properly air gap our PLCs - which we didn’t do. We (the CTO) just put them on a separate subnet and lied to insurance.

There’s not much you can do to an organization that has no real oversight here, especially once the “coast to retirement” types infest the place. We need something like HIPPA or PCI-DSS with real auditors and real teeth for utilities.

Re: CISA Alert: Water Sector PLC Targeting

#72

Earlier quoted context omitted.

Not really. Just patch and reboot. Pretty simple.

Ouch. You just caused a major outage for . Either you costed your company millions of dollars or you killed someone. OT does not equal IT

Apparently not. IT does security patches, OT neglects them. You get what you get.

Re: CISA Alert: Water Sector PLC Targeting

#73

Earlier quoted context omitted.

National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground? NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so. I agree that in theory this would not be a…

> The issue comes down to actual skilled people hours to do the work and resource constraints to do so. It comes down to incentives. If you want broad security you have to do more than hope that every water utility will both hire good people and also allow them to do their jobs properly. > But what does that fundamentally mean for boots on the ground? How does any regulation look on the ground? How does the federal g…

Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”.

It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.

It needs some real backing and effort to make it happen.

Re: CISA Alert: Water Sector PLC Targeting

#74

Earlier quoted context omitted.

> The issue comes down to actual skilled people hours to do the work and resource constraints to do so. It comes down to incentives. If you want broad security you have to do more than hope that every water utility will both hire good people and also allow them to do their jobs properly. > But what does that fundamentally mean for boots on the ground? How does any regulation look on the ground? How does the federal g…

Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”. It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like. It needs…

> Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”.

Top down regulation drives the systematic change, just like it did with the banking sector.

> It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.

I'm not sure how this analogy works. What's the ATC equivalent to leaving default passwords on critical infrastructure?

Re: CISA Alert: Water Sector PLC Targeting

#75
post #64

Earlier quoted context omitted.

There are 1000x as many tax payers and the government still makes sure every single mom who gets a venmo payment for $60 pays taxes. National security is a federal responsibility, they should absolutely do their jobs.

> There are 1000x as many tax payers and the government still makes sure every single mom who gets a venmo payment for $60 pays taxes. That's a join in an existing database. Where's the database and what's the code for this case?

Is the idea that the federal government of the United States, which created and maintains a database of hundreds of millions of taxpayers, is powerless compile a database of 0.1% that number of water utilities?

> What's the code for this case?

Are you seriously asking me to provide a program?

Re: CISA Alert: Water Sector PLC Targeting

#76

Earlier quoted context omitted.

Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”. It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like. It needs…

> Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”. Top down regulation drives the systematic change, just like it did with the banking sector. > It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air…

> Top down regulation drives the systematic change, just like it did with the banking sector.

Banking is resourced well enough to absorb that regulation and stand up a compliance team. I bring up ATC because of the consequence. Default passwords are a symptom, not the failure mode.

ATC is already federal, with the FAA running that. 20 years of regulation has not fixed the problems that still plague that industry: outdated equipment, short-staffed, a small niche talent and training pipeline, and people dying as a consequence of those systemic problems. That's even closer to my point. Making something regulated doesn't change the inherent problems inside the industry.

Re: CISA Alert: Water Sector PLC Targeting

#77
post #64

Earlier quoted context omitted.

> There are 1000x as many tax payers and the government still makes sure every single mom who gets a venmo payment for $60 pays taxes. That's a join in an existing database. Where's the database and what's the code for this case?

Is the idea that the federal government of the United States, which created and maintains a database of hundreds of millions of taxpayers, is powerless compile a database of 0.1% that number of water utilities? > What's the code for this case? Are you seriously asking me to provide a program?

I believe the comment was to say you can not create a join for data that does not exist. Access to financial records is trivial, but there is likely no such comparable record that one can query on for water/industrial. Maybe metrics like water quality for some of them, but not the other security data exists other than shodan/censys (weak and out of context) which could take months per site to collect.

AFAIK the most robust data they have on industrial sectors is within the national labs, and even then its considered sparse.

Re: CISA Alert: Water Sector PLC Targeting

#78

Earlier quoted context omitted.

Is the idea that the federal government of the United States, which created and maintains a database of hundreds of millions of taxpayers, is powerless compile a database of 0.1% that number of water utilities? > What's the code for this case? Are you seriously asking me to provide a program?

I believe the comment was to say you can not create a join for data that does not exist. Access to financial records is trivial, but there is likely no such comparable record that one can query on for water/industrial. Maybe metrics like water quality for some of them, but not the other security data exists other than shodan/censys (weak and out of context) which could take months per site to collect. AFAIK the most…

How did the federal government create the database of taxpayers? How do they keep it up to date? Why can these mechanisms not work for water utilities?
Post reply on HN