Live data from Hacker News

Hackers destroy water pump via SCADA abuse

wired.com

1–10 of 42 posts

Re: Hackers destroy water pump via SCADA abuse

#2
Good. Malicious crackers, please destroy as many non-safety-critical water pumps as it takes for people to take security on these systems seriously. It seems most of the industrial controls industry is used to operating on a proprietary network, and when moving to IP their guess at security is "uh, firewall?".

Re: Hackers destroy water pump via SCADA abuse

#5
post #3

So they stole username/passwords the SCADA vendor kept for the clients. There are better ways to gain access to systems. But even then, you have to prevent access to your own systems first...

I wonder if the glitches were that they remote people couldn't login. So they kept changing the passwords, and restoring them, and then the hackers just went and got the password again, changed it...

Re: Hackers destroy water pump via SCADA abuse

#6

Good. Malicious crackers, please destroy as many non-safety-critical water pumps as it takes for people to take security on these systems seriously. It seems most of the industrial controls industry is used to operating on a proprietary network, and when moving to IP their guess at security is "uh, firewall?".

This is indeed odd. On my home network, I have a firewall at the edge, a firewall on each machine, and every service requires authentication (cryptographic where possible; username+password over SSL otherwise). It took me about a day to set up, and I'm not even a security person.

It's unacceptable that people whose jobs are to secure computer networks do a worse job than I do for the little computer under my TV.

(Yup, all of my machines at home have a public IP address. Convenient!)

Re: Hackers destroy water pump via SCADA abuse

#8
post #5
post #3

So they stole username/passwords the SCADA vendor kept for the clients. There are better ways to gain access to systems. But even then, you have to prevent access to your own systems first...

I wonder if the glitches were that they remote people couldn't login. So they kept changing the passwords, and restoring them, and then the hackers just went and got the password again, changed it...

[deleted]

Re: Hackers destroy water pump via SCADA abuse

#9
post #6

Good. Malicious crackers, please destroy as many non-safety-critical water pumps as it takes for people to take security on these systems seriously. It seems most of the industrial controls industry is used to operating on a proprietary network, and when moving to IP their guess at security is "uh, firewall?".

This is indeed odd. On my home network, I have a firewall at the edge, a firewall on each machine, and every service requires authentication (cryptographic where possible; username+password over SSL otherwise). It took me about a day to set up, and I'm not even a security person. It's unacceptable that people whose jobs are to secure computer networks do a worse job than I do for the little computer under my TV. (Yup…

how many users does your home system have? what is your budget like to support them? what is your pain point for "at this overhead we just go out of business?"

it's a lot more complicated than "just do it right".

I'm not saying we shouldn't take effort to do it right, but right now the market doesn't price for security so ...

Re: Hackers destroy water pump via SCADA abuse

#10
post #6

Good. Malicious crackers, please destroy as many non-safety-critical water pumps as it takes for people to take security on these systems seriously. It seems most of the industrial controls industry is used to operating on a proprietary network, and when moving to IP their guess at security is "uh, firewall?".

This is indeed odd. On my home network, I have a firewall at the edge, a firewall on each machine, and every service requires authentication (cryptographic where possible; username+password over SSL otherwise). It took me about a day to set up, and I'm not even a security person. It's unacceptable that people whose jobs are to secure computer networks do a worse job than I do for the little computer under my TV. (Yup…

That's not even it though? Shouldn't systems like this be air-gapped?
Post reply on HN