Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #90186 > unrolled thread

US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em

Started byc186282 <c186282@nnada.net>
First post2026-08-19 22:33 -0400
Last post2026-08-23 12:19 +0100
Articles 20 on this page of 26 — 8 participants

Back to article view | Back to comp.os.linux.misc


Contents

  US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em c186282 <c186282@nnada.net> - 2026-08-19 22:33 -0400
    Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em Richard Kettlewell <invalid@invalid.invalid> - 2026-08-20 09:04 +0100
      Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em c186282 <c186282@nnada.net> - 2026-08-20 12:45 -0400
        Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em "Mr. Chang Man-wai" <toylet.toylet@gmail.com> - 2026-08-21 22:38 +0800
      Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em "Mr. Chang Man-wai" <toylet.toylet@gmail.com> - 2026-08-21 22:37 +0800
    Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em Roger Blake <rogblake@iname.invalid> - 2026-08-21 13:24 +0000
      Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em The Natural Philosopher <tnp@invalid.invalid> - 2026-08-21 14:40 +0100
        Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em "Mr. Chang Man-wai" <toylet.toylet@gmail.com> - 2026-08-21 22:33 +0800
        Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em Roger Blake <rogblake@iname.invalid> - 2026-08-21 23:49 +0000
          Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em The Natural Philosopher <tnp@invalid.invalid> - 2026-08-22 13:22 +0100
            Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em rbowman <bowman@montana.com> - 2026-08-22 18:47 +0000
            Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em c186282 <c186282@nnada.net> - 2026-08-23 02:24 -0400
              Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em The Natural Philosopher <tnp@invalid.invalid> - 2026-08-23 12:29 +0100
        Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em c186282 <c186282@nnada.net> - 2026-08-21 23:11 -0400
      Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em "Mr. Chang Man-wai" <toylet.toylet@gmail.com> - 2026-08-21 22:31 +0800
        Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em Nuno Silva <nunojsilva@invalid.invalid> - 2026-08-21 23:47 +0100
          Re: US Govt Warns .... videos vs words? waste of time? "Mr. Chang Man-wai" <toylet.toylet@gmail.com> - 2026-08-23 23:05 +0800
      Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em c186282 <c186282@nnada.net> - 2026-08-21 23:08 -0400
      Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-08-22 04:17 +0000
        Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em c186282 <c186282@nnada.net> - 2026-08-22 00:57 -0400
        Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em Roger Blake <rogblake@iname.invalid> - 2026-08-22 15:10 +0000
          Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em The Natural Philosopher <tnp@invalid.invalid> - 2026-08-22 16:32 +0100
            Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em rbowman <bowman@montana.com> - 2026-08-22 18:40 +0000
              Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em The Natural Philosopher <tnp@invalid.invalid> - 2026-08-22 23:17 +0100
                Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em rbowman <bowman@montana.com> - 2026-08-23 00:23 +0000
                  Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em The Natural Philosopher <tnp@invalid.invalid> - 2026-08-23 12:19 +0100

Page 1 of 2  [1] 2  Next page →


#90186 — US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em

Fromc186282 <c186282@nnada.net>
Date2026-08-19 22:33 -0400
SubjectUS Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em
Message-ID<7_CcnWTL6ePw-hv3nZ2dnZfqnPednZ2d@giganews.com>
https://www.newsmax.com/world/globaltalk/siemens-devices-water-facilities-cybersecurity/2026/08/19/id/1266642/

Several U.S. government agencies warned that unidentified
hackers are trying to breach devices made by Siemens that
are used to monitor and operate water facilities and ‌other
critical infrastructure systems, according ​to a cybersecurity
advisory published Wednesday.

The warning comes amid widespread cyber incidents targeting
local ⁠water systems in multiple states in recent ​weeks in
attacks cybersecurity experts suspect are linked to ⁠Iran.

The advisory describes an "active threat" to all Siemens S7
Series programmable logic controllers across multiple
critical infrastructure sectors, including ‌manufacturing,
energy, water, and wastewater, chemical, food ​and
agriculture facilities, according ‌to the warning issued by
the National Security Agency, FBI, ‌Department of Energy,
Environmental Protection Agency, and the Department of
Homeland Security's Cybersecurity and Infrastructure
Security ⁠Agency.

. . .

   PLAs are kinda stupid - so really it's likely the
   software kit used to program/check the things.
   LIKELY the affected sites kept all that ONLINE
   so they could over-work ONE geek rather than
   pay to have their own.

   In an irony - the early Iranian nuke program used
   Siemens controllers on its uranium centrifuges.
   The spooks found a vulnerability and caused the
   devices to destroy themselves. Set 'em back a
   few years.

   For obvious reasons nobody is going to EXACTLY
   identify how the things were hacked. However
   Siemens is a major supplier of industrial
   process controllers, so everybody had better
   keep an eye out.

[toc] | [next] | [standalone]


#90199

FromRichard Kettlewell <invalid@invalid.invalid>
Date2026-08-20 09:04 +0100
Message-ID<wwv33w9nrpg.fsf@LkoBDZeT.terraraq.uk>
In reply to#90186
c186282 <c186282@nnada.net> writes:
>   In an irony - the early Iranian nuke program used
>   Siemens controllers on its uranium centrifuges.
>   The spooks found a vulnerability and caused the
>   devices to destroy themselves. Set 'em back a
>   few years.
>
>   For obvious reasons nobody is going to EXACTLY
>   identify how the things were hacked. However
>   Siemens is a major supplier of industrial
>   process controllers, so everybody had better
>   keep an eye out.

On the contrary, it’s pretty well documented. The exploit code, the
target devices and the identity of the person who inserted it into
Natanz are all public. Search for ‘stuxnet’ and ‘operation olympic
games’.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#90217

Fromc186282 <c186282@nnada.net>
Date2026-08-20 12:45 -0400
Message-ID<Whudne_V5Ou4shr3nZ2dnZfqnPednZ2d@giganews.com>
In reply to#90199
On 8/20/26 04:04, Richard Kettlewell wrote:
> c186282 <c186282@nnada.net> writes:
>>    In an irony - the early Iranian nuke program used
>>    Siemens controllers on its uranium centrifuges.
>>    The spooks found a vulnerability and caused the
>>    devices to destroy themselves. Set 'em back a
>>    few years.
>>
>>    For obvious reasons nobody is going to EXACTLY
>>    identify how the things were hacked. However
>>    Siemens is a major supplier of industrial
>>    process controllers, so everybody had better
>>    keep an eye out.
> 
> On the contrary, it’s pretty well documented. The exploit code, the
> target devices and the identity of the person who inserted it into
> Natanz are all public. Search for ‘stuxnet’ and ‘operation olympic
> games’.

   Careful ... when the spooky people are involved 'leaks'
   may not be entirely accurate info  :-)

[toc] | [prev] | [next] | [standalone]


#90292

From"Mr. Chang Man-wai" <toylet.toylet@gmail.com>
Date2026-08-21 22:38 +0800
Message-ID<1169nu0$d13c$2@toylet.eternal-september.org>
In reply to#90217
On 8/21/2026 12:45 AM, c186282 wrote:
> 
>     Careful ... when the spooky people are involved 'leaks'
>     may not be entirely accurate info  :-)


The source codes are opened to all. UNLESS....

Unless the source codes released to the public
are NOT exactly the same as the ones being
used by Siemens. :)

-- 

    @~@   Simplicity is Beauty! Remain silent! Drink, Blink, Stretch!
   / v \  May the Force and farces be with you! Live long and prosper!!
  /( _ )\ https://sites.google.com/site/changmw/
    ^ ^   https://github.com/changmw/changmw
          The game is afoot... Meow...

[toc] | [prev] | [next] | [standalone]


#90291

From"Mr. Chang Man-wai" <toylet.toylet@gmail.com>
Date2026-08-21 22:37 +0800
Message-ID<1169ns0$d13c$1@toylet.eternal-september.org>
In reply to#90199
On 8/20/2026 4:04 PM, Richard Kettlewell wrote:
> 
> On the contrary, it’s pretty well documented. The exploit code, the
> target devices and the identity of the person who inserted it into
> Natanz are all public. Search for ‘stuxnet’ and ‘operation olympic
> games’.


You talking about Linux including Mint?
And you are using them? :)

-- 

    @~@   Simplicity is Beauty! Remain silent! Drink, Blink, Stretch!
   / v \  May the Force and farces be with you! Live long and prosper!!
  /( _ )\ https://sites.google.com/site/changmw/
    ^ ^   https://github.com/changmw/changmw
          The game is afoot... Meow...

[toc] | [prev] | [next] | [standalone]


#90285

FromRoger Blake <rogblake@iname.invalid>
Date2026-08-21 13:24 +0000
Message-ID<20260821092000@news.eternal-september.org>
In reply to#90186
On 2026-08-20, c186282 <c186282@nnada.net> wrote:
> https://www.newsmax.com/world/globaltalk/siemens-devices-water-facilities-cybersecurity/2026/08/19/id/1266642/
>
> Several U.S. government agencies warned that unidentified
> hackers are trying to breach devices made by Siemens that
> are used to monitor and operate water facilities and ‌other
> critical infrastructure systems, according ​to a cybersecurity
> advisory published Wednesday.

Surprisingly almost no one asks the question "Why is critical
infrastructure connected to the internet?" (Likely it wasn't
30-40 years ago.) Pull the plug and it can't be hacked.

-- 
  Roger Blake

[toc] | [prev] | [next] | [standalone]


#90286

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2026-08-21 14:40 +0100
Message-ID<1169kgv$9sqa$17@dont-email.me>
In reply to#90285
On 21/08/2026 14:24, Roger Blake wrote:
> On 2026-08-20, c186282 <c186282@nnada.net> wrote:
>> https://www.newsmax.com/world/globaltalk/siemens-devices-water-facilities-cybersecurity/2026/08/19/id/1266642/
>>
>> Several U.S. government agencies warned that unidentified
>> hackers are trying to breach devices made by Siemens that
>> are used to monitor and operate water facilities and ‌other
>> critical infrastructure systems, according ​to a cybersecurity
>> advisory published Wednesday.
> 
> Surprisingly almost no one asks the question "Why is critical
> infrastructure connected to the internet?" (Likely it wasn't
> 30-40 years ago.) Pull the plug and it can't be hacked.
> 
Because its a simple and cheap way to control unmanned installations

I mean here on the UK Fens there are many many sluice gates and pumps 
that should operate automatically on float sensors, but I suspect are 
also monitored and controlled centrally.

No one ever thought anyone would have any interest in  hacking them.

Siemens are a pretty shoddy firm anyway.

One would have thought they had some some form of authentication and 
encryption and indeed firewalling going on. There is no need to expose 
such devices to the whole Internet...


-- 
“It is not the truth of Marxism that explains the willingness of 
intellectuals to believe it, but the power that it confers on 
intellectuals, in their attempts to control the world. And since...it is 
futile to reason someone out of a thing that he was not reasoned into, 
we can conclude that Marxism owes its remarkable power to survive every 
criticism to the fact that it is not a truth-directed but a 
power-directed system of thought.”
Sir Roger Scruton

[toc] | [prev] | [next] | [standalone]


#90290

From"Mr. Chang Man-wai" <toylet.toylet@gmail.com>
Date2026-08-21 22:33 +0800
Message-ID<1169njc$ctbh$2@toylet.eternal-september.org>
In reply to#90286
On 8/21/2026 9:40 PM, The Natural Philosopher wrote:
>
> Because its a simple and cheap way to control unmanned installations
Why do your enemies wanna waste time and
effort hacking electronic signals when
you can just bomb and destroy the hell
of those infrastructure? :)

-- 

    @~@   Simplicity is Beauty! Remain silent! Drink, Blink, Stretch!
   / v \  May the Force and farces be with you! Live long and prosper!!
  /( _ )\ https://sites.google.com/site/changmw/
    ^ ^   https://github.com/changmw/changmw
          The game is afoot... Meow...

[toc] | [prev] | [next] | [standalone]


#90308

FromRoger Blake <rogblake@iname.invalid>
Date2026-08-21 23:49 +0000
Message-ID<20260821193314@news.eternal-september.org>
In reply to#90286
On 2026-08-21, The Natural Philosopher <tnp@invalid.invalid> wrote:
> Because its a simple and cheap way to control unmanned installations

It seems to me that for critical infrastructure the risks outweigh
the benefits. Then again I reject the modern mindset that seems to
want every damned thing down to the last refrigerator, washing
machine, thermostat, light switch, etc. to be connected to the
internet.

> No one ever thought anyone would have any interest in  hacking them.

I remember reading an article years ago where it was stated that
when what came to be known as the internet was under development
it never occurred to anyone that users would attack each other.

-- 
  Roger Blake

[toc] | [prev] | [next] | [standalone]


#90334

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2026-08-22 13:22 +0100
Message-ID<116c4ad$143jr$3@dont-email.me>
In reply to#90308
On 22/08/2026 00:49, Roger Blake wrote:
> I remember reading an article years ago where it was stated that
> when what came to be known as the internet was under development
> it never occurred to anyone that users would attack each other.

Remember the Internet was devised initially (DARPANET) as a weapons 
grade military network that could withstand a nuclear attack and still 
allow someone to push the red button.
Which is why IP packets have no field representing 'cost' embedded in them

Imagine if any website could charge you for access seamlessly, with your 
ISP charging you the picocents for each packet downloaded via them and 
reimbursing the sites owners.

NO advertising needed

But the point remains TCP/IP was optimised cor reliability diverse 
routing and connectivity.
Any security was to be provided either at a physical level - cables 
inside locked locations - or at a higher level by firewalls, encryption 
and network virtualisation.

It is not the fault of the Internet that people do not routinely employ 
these to protect their networks.


-- 
“People believe certain stories because everyone important tells them, 
and people tell those stories because everyone important believes them. 
Indeed, when a conventional wisdom is at its fullest strength, one’s 
agreement with that conventional wisdom becomes almost a litmus test of 
one’s suitability to be taken seriously.”

Paul Krugman

[toc] | [prev] | [next] | [standalone]


#90346

Fromrbowman <bowman@montana.com>
Date2026-08-22 18:47 +0000
Message-ID<neu95kF5rktU2@mid.individual.net>
In reply to#90334
On Sat, 22 Aug 2026 13:22:37 +0100, The Natural Philosopher wrote:

> It is not the fault of the Internet that people do not routinely employ
> these to protect their networks.

Some people are more interested than others.

https://en.wikipedia.org/wiki/Mix_network

The problem with Tor is if you can monitor both ends of the rabbit hole 
eventually you can correlate what time time rabbit went in and came out, 
making the rabbit identifiable. 

[toc] | [prev] | [next] | [standalone]


#90372

Fromc186282 <c186282@nnada.net>
Date2026-08-23 02:24 -0400
Message-ID<kl6dnS7_fs2MDxf3nZ2dnZfqn_udnZ2d@giganews.com>
In reply to#90334
On 8/22/26 08:22, The Natural Philosopher wrote:
> On 22/08/2026 00:49, Roger Blake wrote:
>> I remember reading an article years ago where it was stated that
>> when what came to be known as the internet was under development
>> it never occurred to anyone that users would attack each other.
> 
> Remember the Internet was devised initially (DARPANET) as a weapons 
> grade military network that could withstand a nuclear attack and still 
> allow someone to push the red button.
> Which is why IP packets have no field representing 'cost' embedded in them

   "Cost" ? What exact def did you have in mind ?

> Imagine if any website could charge you for access seamlessly, with your 
> ISP charging you the picocents for each packet downloaded via them and 
> reimbursing the sites owners.
> 
> NO advertising needed

   Constant rip-offs ... that's pretty standard now.
   Client/mainframe became "PCs"/Net and has now
   drifted back to the old model. Cash-extraction
   for every byte, even if they try to hide that.

> But the point remains TCP/IP was optimised cor reliability diverse 
> routing and connectivity.

   Correct. It's pretty strong if used correctly.

   But it was also designed with a MUCH MUCH simpler
   environment in mind. The packet-routing equation
   alone these days is just insane.

   Ye and me are old enough to remember when there
   was no 'internet', no DARPA-net. A Big Box somewhere
   and low-speed direct serial connections, maybe over
   horribly low-speed modems. The old IBM and DEC
   systems were made for international collaboration
   and commerce - over those SLOW SLOW connections.
   Better condense yer data intelligently, and no
   flashing ads for gambling and porn sites ! :-)

> Any security was to be provided either at a physical level - cables 
> inside locked locations - or at a higher level by firewalls, encryption 
> and network virtualisation.
> 
> It is not the fault of the Internet that people do not routinely employ 
> these to protect their networks.

   Employing ENOUGH, and "enough" is harder and harder
   to achieve every day now, is very DIFFICULT. Pretty
   soon you are drowned by your own 'security' measures
   and remember each 'measure' may have it's OWN flaws
   someone can exploit.

   Basically you have to analyze YOUR risks - who/what/why
   might want to get at YOUR stuff. For Joe Average, not
   many are particularly interested except MAYBE stealing
   his bank routing number or Amazon acct password if you
   make it super-easy.

   For bigger biz and banking and govt/defense however the
   risk is MUCH greater. Such systems attract the worst
   of the worst and they WILL put major time/resources
   into their evils.

   But, theoretically, the 'big' players OUGHT to be able
   to afford a squad of their OWN in-house geeks who can
   find and fix such evil efforts. But is seems fewer
   and fewer DO - they just turn it over to "Company-X"
   which promises everything and rarely delivers. In the
   small print somewhere C-X be held harmless or be able
   to SWEAR it was YOU who screwed their 'perfect'
   protection scheme.

   Employ Company-X and, if all goes to hell, YOU can't
   be blamed. It's all THEIR fault !!!

[toc] | [prev] | [next] | [standalone]


#90382

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2026-08-23 12:29 +0100
Message-ID<116elig$1sako$2@dont-email.me>
In reply to#90372
On 23/08/2026 07:24, c186282 wrote:
> On 8/22/26 08:22, The Natural Philosopher wrote:
>> On 22/08/2026 00:49, Roger Blake wrote:
>>> I remember reading an article years ago where it was stated that
>>> when what came to be known as the internet was under development
>>> it never occurred to anyone that users would attack each other.
>>
>> Remember the Internet was devised initially (DARPANET) as a weapons 
>> grade military network that could withstand a nuclear attack and still 
>> allow someone to push the red button.
>> Which is why IP packets have no field representing 'cost' embedded in 
>> them
> 
>    "Cost" ? What exact def did you have in mind ?

  Lets say you contact a server. You could embed a cost field along with 
the source address. That being the cost of 'serving' that packet. 
Routers would [optionally] add intermediate fields to it so a total cost 
of delivering that packet to the end user would accrue. The far end ISP 
would add their charges and deliver the packet billing the customer for 
the total charges.

Online tables of cost centres  would tick up the costs between internet 
entities and the accounting be adjusted with actual cash transfers once 
a month or so.
The whole internet would be PAYG.

>> But the point remains TCP/IP was optimised cor reliability diverse 
>> routing and connectivity.
> 
>    Correct. It's pretty strong if used correctly.
> 
>    But it was also designed with a MUCH MUCH simpler
>    environment in mind. The packet-routing equation
>    alone these days is just insane.
> 
I don't think it is. Not on the traditional backbone. Its still BGP
Satellite is another matter, but that's a private protocol inside the 
satellite network


>    Ye and me are old enough to remember when there
>    was no 'internet', no DARPA-net. A Big Box somewhere
>    and low-speed direct serial connections, maybe over
>    horribly low-speed modems. The old IBM and DEC
>    systems were made for international collaboration
>    and commerce - over those SLOW SLOW connections.
>    Better condense yer data intelligently, and no
>    flashing ads for gambling and porn sites ! :-)
> 
Yup.

>> Any security was to be provided either at a physical level - cables 
>> inside locked locations - or at a higher level by firewalls, 
>> encryption and network virtualisation.
>>
>> It is not the fault of the Internet that people do not routinely 
>> employ these to protect their networks.
> 
>    Employing ENOUGH, and "enough" is harder and harder
>    to achieve every day now, is very DIFFICULT. Pretty
>    soon you are drowned by your own 'security' measures
>    and remember each 'measure' may have it's OWN flaws
>    someone can exploit.
> 
>    Basically you have to analyze YOUR risks - who/what/why
>    might want to get at YOUR stuff. For Joe Average, not
>    many are particularly interested except MAYBE stealing
>    his bank routing number or Amazon acct password if you
>    make it super-easy.
> 
>    For bigger biz and banking and govt/defense however the
>    risk is MUCH greater. Such systems attract the worst
>    of the worst and they WILL put major time/resources
>    into their evils.
> 
You would hope so, wouldn't you...

>    But, theoretically, the 'big' players OUGHT to be able
>    to afford a squad of their OWN in-house geeks who can
>    find and fix such evil efforts. But is seems fewer
>    and fewer DO - they just turn it over to "Company-X"
>    which promises everything and rarely delivers. In the
>    small print somewhere C-X be held harmless or be able
>    to SWEAR it was YOU who screwed their 'perfect'
>    protection scheme.
> 
Yup. Lets have a single point of failure called 'cloudflare'

>    Employ Company-X and, if all goes to hell, YOU can't
>    be blamed. It's all THEIR fault !!!
> 
But it doesn't matter, because they have made you dependent on them

-- 
The biggest threat to humanity comes from socialism, which has utterly 
diverted our attention away from what really matters to our existential 
survival, to indulging in navel gazing and faux moral investigations 
into what the world ought to be, whilst we fail utterly to deal with 
what it actually is.

[toc] | [prev] | [next] | [standalone]


#90316

Fromc186282 <c186282@nnada.net>
Date2026-08-21 23:11 -0400
Message-ID<36ucneVaq_rIjhT3nZ2dnZfqnPednZ2d@giganews.com>
In reply to#90286
On 8/21/26 09:40, The Natural Philosopher wrote:
> On 21/08/2026 14:24, Roger Blake wrote:
>> On 2026-08-20, c186282 <c186282@nnada.net> wrote:
>>> https://www.newsmax.com/world/globaltalk/siemens-devices-water- 
>>> facilities-cybersecurity/2026/08/19/id/1266642/
>>>
>>> Several U.S. government agencies warned that unidentified
>>> hackers are trying to breach devices made by Siemens that
>>> are used to monitor and operate water facilities and ‌other
>>> critical infrastructure systems, according ​to a cybersecurity
>>> advisory published Wednesday.
>>
>> Surprisingly almost no one asks the question "Why is critical
>> infrastructure connected to the internet?" (Likely it wasn't
>> 30-40 years ago.) Pull the plug and it can't be hacked.
>>

> Because its a simple and cheap way to control unmanned installations

   Yep. And simple/cheap for evil people to GET AT.

> I mean here on the UK Fens there are many many sluice gates and pumps 
> that should operate automatically on float sensors, but I suspect are 
> also monitored and controlled centrally.
> 
> No one ever thought anyone would have any interest in  hacking them.

   Last-century thinking.

> Siemens are a pretty shoddy firm anyway.

   Well, their stuff WORKS and is AFFORDABLE and
   thus using it makes you the low-bidder for
   contract jobs.

> One would have thought they had some some form of authentication and 
> encryption and indeed firewalling going on. There is no need to expose 
> such devices to the whole Internet...

   Sure there is ... CHEAPNESS. Just ONE over-worked
   inexpert geek to rule 100 things rather than hiring
   yer OWN on-site geek.

[toc] | [prev] | [next] | [standalone]


#90289

From"Mr. Chang Man-wai" <toylet.toylet@gmail.com>
Date2026-08-21 22:31 +0800
Message-ID<1169ngv$ctbh$1@toylet.eternal-september.org>
In reply to#90285
On 8/21/2026 9:24 PM, Roger Blake wrote:
> 
> Surprisingly almost no one asks the question "Why is critical
> infrastructure connected to the internet?" (Likely it wasn't
> 30-40 years ago.) Pull the plug and it can't be hacked.

"Pull the plug" usually refers only to
the electricity supply, that is, the
power plug. It's an old word.

As things go wireless and virtual,
there are no plugs to pull. :)

And if you watch Mission Impossible
and James Bond, spies can infiltrate
infrastructure companies and implant
spy gadgets that could take over
the control rooms. I dunno whether
it's fact or fiction.



-- 

    @~@   Simplicity is Beauty! Remain silent! Drink, Blink, Stretch!
   / v \  May the Force and farces be with you! Live long and prosper!!
  /( _ )\ https://sites.google.com/site/changmw/
    ^ ^   https://github.com/changmw/changmw
          The game is afoot... Meow...

[toc] | [prev] | [next] | [standalone]


#90301

FromNuno Silva <nunojsilva@invalid.invalid>
Date2026-08-21 23:47 +0100
Message-ID<116aki3$lv5j$1@dont-email.me>
In reply to#90289
On 2026-08-21, Mr. Chang Man-wai wrote:

> On 8/21/2026 9:24 PM, Roger Blake wrote:
>>
>> Surprisingly almost no one asks the question "Why is critical
>> infrastructure connected to the internet?" (Likely it wasn't
>> 30-40 years ago.) Pull the plug and it can't be hacked.
>
> "Pull the plug" usually refers only to
> the electricity supply, that is, the
> power plug. It's an old word.
>
> As things go wireless and virtual,
> there are no plugs to pull. :)
>
> And if you watch Mission Impossible
> and James Bond, spies can infiltrate
> infrastructure companies and implant
> spy gadgets that could take over
> the control rooms. I dunno whether
> it's fact or fiction.

You should watch NCIS too.

<https://www.youtube.com/watch?v=u8qgehH3kEQ>

[toc] | [prev] | [next] | [standalone]


#90399 — Re: US Govt Warns .... videos vs words? waste of time?

From"Mr. Chang Man-wai" <toylet.toylet@gmail.com>
Date2026-08-23 23:05 +0800
SubjectRe: US Govt Warns .... videos vs words? waste of time?
Message-ID<116f27p$20pug$1@toylet.eternal-september.org>
In reply to#90301
On 8/22/2026 6:47 AM, Nuno Silva wrote:
> 
> You should watch NCIS too.
> 
> h+t+t+ps://www.youtube.com/watch?v=u8qgehH3kEQ


You got a plain-text version of
the video? I don't need voices
nor pictures when reading. :)

-- 

    @~@   Simplicity is Beauty! Remain silent! Drink, Blink, Stretch!
   / v \  May the Force and farces be with you! Live long and prosper!!
  /( _ )\ https://sites.google.com/site/changmw/
    ^ ^   https://github.com/changmw/changmw
          The game is afoot... Meow...

[toc] | [prev] | [next] | [standalone]


#90315

Fromc186282 <c186282@nnada.net>
Date2026-08-21 23:08 -0400
Message-ID<Nd-dnZMOl67sjxT3nZ2dnZfqnPudnZ2d@giganews.com>
In reply to#90285
On 8/21/26 09:24, Roger Blake wrote:
> On 2026-08-20, c186282 <c186282@nnada.net> wrote:
>> https://www.newsmax.com/world/globaltalk/siemens-devices-water-facilities-cybersecurity/2026/08/19/id/1266642/
>>
>> Several U.S. government agencies warned that unidentified
>> hackers are trying to breach devices made by Siemens that
>> are used to monitor and operate water facilities and ‌other
>> critical infrastructure systems, according ​to a cybersecurity
>> advisory published Wednesday.
> 
> Surprisingly almost no one asks the question "Why is critical
> infrastructure connected to the internet?" (Likely it wasn't
> 30-40 years ago.) Pull the plug and it can't be hacked.


   I ask that ALL THE TIME ... NO sane answers.

   MOSTLY seems to be so they over-work ONE poor
   contracted geek instead of hiring their OWN geeks.

   However esp for 'critical infrastructure' and
   'dangerous' things like chem plants, nuke plants,
   refineries and such - BAD BAD BAD IDEA these days.

   If the hacks can't bust the password app they will
   go after the lower-level stuff that RUNS the
   password app. China is nefarious here - has gotten
   deep into all kinds of top companies. "AI" approaches
   have just made all this MUCH worse.

[toc] | [prev] | [next] | [standalone]


#90325

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-08-22 04:17 +0000
Message-ID<116b7sv$r3ve$1@dont-email.me>
In reply to#90285
On Fri, 21 Aug 2026 13:24:28 -0000 (UTC), Roger Blake wrote:

> Surprisingly almost no one asks the question "Why is critical
> infrastructure connected to the internet?" (Likely it wasn't 30-40
> years ago.) Pull the plug and it can't be hacked.

That didn’t protect against Stuxnet though, did it ...

[toc] | [prev] | [next] | [standalone]


#90326

Fromc186282 <c186282@nnada.net>
Date2026-08-22 00:57 -0400
Message-ID<36ucnedaq_qosRT3nZ2dnZfqnPcAAAAA@giganews.com>
In reply to#90325
On 8/22/26 00:17, Lawrence D’Oliveiro wrote:
> On Fri, 21 Aug 2026 13:24:28 -0000 (UTC), Roger Blake wrote:
> 
>> Surprisingly almost no one asks the question "Why is critical
>> infrastructure connected to the internet?" (Likely it wasn't 30-40
>> years ago.) Pull the plug and it can't be hacked.
> 
> That didn’t protect against Stuxnet though, did it ...

   Infiltrator/spy.

   CAN happen.

   NOT so likely at yer local water plant though.

   Bigger facilities, maybe yes. Nobody knows all
   their co-workers, people coming and going all
   the time. Shit, you could probably run a hardwire
   in from next door and nobody would notice anything
   unusual. Jihad Jamal dressed like the FedEx guy.

   I'm more worried about industrial facilities -
   chem plants, refineries, power plants - things
   that can go BOOM.

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.os.linux.misc


csiph-web