Hack at German steel works.

There must be some very well funded hackers about. Plenty of candidates for those who would like to disrupt things.
The dangerous ones are the ones which haven't been noticed of which I am sure there are quite a few .
 
i think security is just a fail, unless you have huge money to throw at it... proper big dont care money... and have nazzi style inforcment staff...

long passwords, changed all the time? look under the keyboard... in the desk draw... just ring someone, say you are from support ask them for the password, or ring the help desk and say you forgot your password.

systems super locked down? too hard to make anything work someone will dual home a server or open a firewall...

I feel the best solution is just DO NOT PLUG INTO INTERNET...
 
IIRC the centrifuge controllers attacked by stuxnet were entirely disconnected from internet.

We had a funny one at work once - IT guy who was always going on about security practises, etc. and not having stuff exposed to the internet - one day connects his personal laptop to the closed production system to install a printer driver and infected the network that way :S
 
But we could imagine that some plants in our industry could be damaged but it would probably require inside knowledge of the industry to choose the appropriate parameters the right amount to cause damage without it being noticed or tripping.

I believe this is largely how stuxnet managed to be so effective. Avoided obvious failures but instead focused on a general degrading of equipment caused by subtle tweaks to firmware parameters.
 
Back
Top Bottom