logoalt Hacker News

pudgywalshyesterday at 8:45 PM9 repliesview on HN

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will.

CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration.

Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. You cross a threshold where you're being deliberately careless.

When you are putting more effort into securing your Plex server on your home network then public utilities are taking on machinery that dumps chemicals into the local water, something is not right and finger-pointing isn't going to fix it.


Replies

Avicebronyesterday at 8:55 PM

I think it's less carelessness and more the inability to attract (pay) people who have the technical knowhow to properly secure infrastructure. Even a lot of developers are poor network engineers and treat IT like magic at their own companies.

show 3 replies
andyjohnson0yesterday at 8:51 PM

> Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords.

I work with PLCs. Default passwords of not, the idea that such weakly secure devices are being made accessible from the public internet boggles my mind.

show 2 replies
fathermarzyesterday at 11:08 PM

Not IT malpractice and this where the industry diverges. IT folks usually don’t work on or understand these systems.

Which is one of MANY problems OT faces. IT best practices don’t suffice in OT and even when they do, most of these orgs are too resource hamstrung to do anything about all of the fires they have to put out.

Not to mention all of the OT vendors who flooded the market with tools instead of people being taught the boring process driven work.

lorreyfumyesterday at 9:25 PM

Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.

show 2 replies
dylan604today at 1:52 AM

CISA was formed in 2018, so not quite 15 years but closer to half that. The security industry as a whole has been yelling for longer than 15 years about the vulnerability of utilities. They've been marked as soft targets before the Bush administration restructured the government.

throwaway894345yesterday at 9:56 PM

Yes, utilities shouldn’t be negligent, but national security is 100% the federal government’s responsibility. If the vulnerabilities were so trivial, then it’s even more damning that the federal government was caught with its pants down, particularly since they were the only ones who knew they would be starting a war.

> finger-pointing isn't going to fix it.

Your entire comment was finger pointing…

show 1 reply
idontwantthisyesterday at 9:02 PM

Until the people in charge face jailtime for hurting innocent people, why would they care? The government shouldn’t be warning, it should be ordering and imprisoning. And funding and educating where there are genuine gaps.

cyanydeezyesterday at 9:49 PM

a broken clock, yada yada.

AnimalMuppetyesterday at 10:15 PM

"I blame it on Minnesota because they are grossly incompetent."

"I think Minnesota is behind it."

The first quote makes it the state's responsibility to secure local water systems, which I'm not sure that it is. The second makes it at least sound like the state of Minnesota is the entity running the attack on local water systems within their state, which is off in paranoid conspiracy territory.

Trump was absolutely wrong.