CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

  • Duamerthrax@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    2 days ago

    Remote monitoring? Sure. Remote managing? Fuck that. These facilities shouldn’t be unstaffed for days at a time.

    • BrianTheeBiscuiteer@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      It’s called paying people to watch the systems during off-hours. It’s often way cheaper than setting up firewalls, setting up alerts, maintaining patches, paying a VPN company to manage connections, paying another company to handle authentication, and so on. Security constraints are getting so bad at my office I’m seriously thinking of how we can do more things with pen and paper.

      • Bytemeister@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        The things you mentioned probably aren’t the problem. It’s not hard or expensive to setup secure remote access for systems.

        The real problem is that a lot of this very expensive and very specific infrastructure equipment is also very old, and frequently does not support newer and more secure protocols.

        Source : I’ve been trying to get gas generators to fire off email alerts using modern authentication with conditional access for about a week now.

        • BrianTheeBiscuiteer@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          Changing tech is usually a lot harder than adoption. Better methods and protocols will keep emerging to fight new digital threats but with physical threats usually don’t change. Only exception is social engineering (e.g. attacking a locked door by tricking someone into opening it). Even then a physical presence is required and someone can’t enter a locked room from 2000 miles away.

    • Doomsider@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      2 days ago

      Oh for sure, air gapped sensors that relay information are going to be necessary. We should be building these systems with absolute security because they are critical to infrastructure.

      • Duamerthrax@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        Some people will say it’s too hard to retrofit onto legacy equipment, but all it really means is adding a secondary system on top of the legacy system. Just a sensor array that has no interaction with existing systems.

        • SanicHegehog@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          2 days ago

          Yup. Fancy architecture diagram:

                            One Way Radio
                             Transmitter
          [Nuclear Reactor] ------------> [Internet connected receiver] -> tHe ClOUd