logoalt Hacker News

1970-01-01yesterday at 9:49 PM4 repliesview on HN

He is wrong and right. They should be connected to the Internet when they aren't 30 year old PLCs ripe for abuse. Until then, cut the data lines and do water monitoring the old way.


Replies

eek2121yesterday at 10:21 PM

Disagree. Why connect them to the internet? They should be super hardened against attacks, and should NOT have a physical connection to the internet. Same with electrical infrastructure. Network access? Possibly, however that network should NOT be accessible from the internet.

The only exception I can think of would be for meter reading, which should be a separate, read only device with no ability to do harm altogether.

show 2 replies
grebcyesterday at 9:55 PM

If it’s connected, it’s compromised. Or will be.

Folly to think otherwise.

show 2 replies
Terr_yesterday at 10:28 PM

Rather than "on/off" I think we need to distinguish between at least four things:

1. Connected naively to the internet.

2. Behind a hardened VPN endpoint which is on the internet.

3. Has a separate physical private network.

4. Requires physical access.

I think it's obvious that #1 should be prohibited in favor of #2. After that point we need to ask what the impact is of a Denial of Service attack that prevents anyone from remotely accessing the system.

The difference between #2 and #3 may depend on whether things could be Very Bad if the system is disconnected at a time of the attacker's choosing. For example, disabling access to flood-control valves during a hurricane.

show 1 reply
mikewarottoday at 12:47 AM

A data diode can allow monitoring via the internet without risking ingress of control. Commercial units aren't cheap though.

Obviously we need open source designs.

Perhaps the easiest way would be a Raspberry pi set up with an opto isolated CGA/EGA/VGA/SVGA capture that could be viewed via the internet? (I mean, we're probably talking systems still running MS-DOS or Windows 98 running these systems)

show 1 reply