Water treatment plant hacked, chemical mix changed for tap supplies
theregister.co.uk
theregister.co.uk
There is no mention of what chemical changes were made, but if malicious it sounds more like warfare or terrorism potentially targeting civilians. The subtitle is "Well, that's just a little scary", also quite an understatement.
Yes it does; it's a perfect example of how "activist" (and by extension "hactivist") is being used in modern propaganda. Jacob Appelbaum very recently gave a rather... intense talk[1] that is about[2] this type of propaganda. As he explains:
Let us address this concept of "activism", and it works like this.
"Activism" is used as a pejorative term in order to suggest that
participation in a democratic society is somehow outside of
normal behavior.
> There is no mentionStenographers publishing propaganda are not in the business of revealing facts.
[1] https://www.youtube.com/watch?v=KJValv4YQcY#t=78 (note: Jacob doesn't pull his punches, so this contains some strong language)
[2] It also has some disturbing new information about how The Guardian treated him, Poitras, Greenwald, and others.
Personally, I'm one for trying to keep the personal attacks out of a rational discussion, but I recognize that sometimes going with emotion can work as well or better, depending on the audience. I'm also sure he views quite a bit of what he's talking about as personal attacks on himself as well.
I'm sad now that I didn't see it when you posted it a few days ago, and couldn't do my small bit to nudge it to the front page.
Can someone help me understand why this isn't more popular? Is it because they requirement controls from outside resources? Or maybe there's central places that rely on telemetry?
Another option: outgoing UDP packets only. Outgoing telemetry but nothing comes back in.
I'll add a lesson from software world that it also pays to contract steady fixes over time instead of near-perfect the first time. That might partly be because people in such industries only make sacrifices after shit hits the fan publicly. See Target for example. ;)
"The Bowman Avenue Dam in this low-key suburban village in Westchester County is … about the width of a modest living room, and the 20-foot-tall dam itself essentially keeps a babbling creek, the Blind Brook, from flooding basements and ground floors in houses downstream.
Yet, according to the authorities, it was the computer-guided controls of this dam that seven Iranian computer hackers chose to penetrate on behalf of that country’s Revolutionary Guards Corps, as part of a plot that also breached or paralyzed 46 of the nation’s largest financial institutions and blocked hundreds of thousands of customers from accessing their bank accounts online.
They broke into the Iranian nuclear program without much condemnation, so...
I still find it dismaying that we so casually accept this state of affairs. There is no meaningful difference between attacks like this and a foreign agent setting fire to the bank building or physically sabotaging the dam.
https://en.wikipedia.org/wiki/Stuxnet https://en.wikipedia.org/wiki/Flame_(malware)
Both of these were directed primarily at Iran. And that second one, flame, has been described as "the most complex malware ever found."
War is a big deal. You can't just rely on something meeting an old formal definition of "act of war"; to cause a war, there's got to be a risk of more damage (by some accounting) than we would do to ourselves by going to war.
Don't you remember Stuxnet? That is exactly what the us was doing! Surely it's been deniable, but who do you think did it?
I would go even further.
To air-gap something implies that you are breaking the physical link that it could interact on the network with.
I would suggest that these systems should not have networking capabilities at all. The controllers for a dam, or power plant, or (insert critical infrastructure here) should not have networking hardware or even a networking stack.
If you want someone to be able to adjust the dam, without putting out the physical effort required to make the adjustment, you need to network the dam. That way, the person can send a signal (easy) and a machine that's able to do the work can receive the signal and do the work (hard).
The most you can do is ensure that signals from the internet (or anywhere offsite) can't reach the dam. You need onsite signals.
Yes, that is exactly what it implies.
This brings with it two very important and extremely valuable effects:
First, it means there is a human observing, on a regular basis, the behavior of the system - someone "has a feel" for how things work and can (with the intellect and perception of a human brain) "sense" when something is not right.
Second, it means, in the Taleb sense, that someone has "skin in the game". In the same way that I would be very disturbed if a commercial airliner had remote pilots, I would be similarly disturbed if a dam or a power plant had remote operators.
Finally, this human, locally present operator or operators probably shouldn't have Internet access - even on personal devices. There's no reason for it and it only adds risk and attack vectors. If you run the nuclear plant you can check twitter when you get home.
I am talking about doing it without computers. These things were done prior to computers with relays and switches and even status lights and a monitoring board, etc.
I'm advocating that we take out all of the general purpose capabilities as well as the ability to interoperate. A human being flicks a switch.
No, no ... the "without automation" part is the entire point.
If a system is automated, then nobody has skin in the game - the way the pilot and copilot of your airplane do. The outcomes we want are the outcomes we get when the operator is the first one to go if something goes wrong.
It is in that interaction that we can rely on the (amazing, irreproducible, beautiful) ability of the human brain to recognize patterns and make brilliant deductive leaps.
That's just the very thing we want.
But there are optical routers that guarantee one way only access to networks. My favorite method is a switch, with the power supply connected to a physical timer. Once the time's up, the power supply is cut, and that device no longer is accessible. Quite ingenious really.
There was a recent incident in the UK where too much chlorine was added to the water supply, leaving it unsafe even for washing. I wonder if it's connected?
But Verizon claims the valves were manipulated to "no particular effect" which doesn't seem credible if it required a full system flush and a do-not-use to be posted.
Also Severn Trent has 4.6 million customers, not 2.5 million.
The affected only lost most of their hair.
The whole thing reads like an advertisement for Verizon Security and Splunk.
Remember the recent Ukrainian power outage hack? http://arstechnica.com/security/2016/02/hackers-did-indeed-c...
So it's a kid, not a state.
But even fairly advanced attackers don't necessarily know their way around SCADA systems. nor have the resources to take control of often very tech-specific PLC's
Actually, I'd be interested to know if things like ISO27001 are mandatory for these sorts of facilities. And who gets in trouble if the system fails.
Of course, there also has to be budget and time allowances to actually make it happen.
They're just not applied by most because people paying don't give a shit. Any high-security engineer doing SCADA or site-to-site for big companies will probably tell you so.