Mysterious safety-tampering malware infects a second site
arstechnica.com
arstechnica.com
I was involved in a project a few years ago delivering a series of monitoring systems running Windows XP to a brand new 700 million dollar oil rig. This was at the request of the client, they had software they needed that would only run on Windows XP. They had a fit when we had trouble sourcing Windows XP licenses. The expectation is that these systems will have a 20 - 30 year life.
It used to be that keeping every air gapped was enough, but organizations want easier monitoring, so more systems are being networked in an ad-hoc way without a lot of thought about security.
I expect we are going to see more things like this happening in the future until we start taking security in systems / embedded space more seriously. And even then there will be exploits of older systems for years afterwords since the replacement cycle is so long.
I wonder what a secure embedded system even looks like when I think about it. The environment isn't suitable to the kind of continuous patching that is done in the web world, but exploits will be found and dependencies will need to be updated. How do you square keeping things up to date with stringent testing requirements in systems that can kill people. Many of these systems / plants are unique, there is only one plant like it in the world, so testing becomes very hard.
In my mind, we'll start treating silicon the same way... formal verification, rigorous real-world testing, trusted suppliers, and an expectation that change is slow, expensive, and risky.
In most places a rubber stamp of 'yep, definitely secure because we have a password (over http, oh by the way everyone uses the default which is in the manual)' is good enough. Then when something goes wrong there's a general shrug and they change the password.
I've friends who work as instrument technicians/engineers on embedded systems in manufacturing and have worked in Europe, UK and Australia in food manufacturing, mechanical, water collection and water processing.
The one constant I've heard is that all of their hardware is almost or is out of support, when it breaks, they expect band aid fixes and ironically none or very little of them can accept any downtime. There's no hardware redundancy for their production lines and when anything breaks, it's all hands on deck. Yet there's no funding going back into the production lines to pro-actively repair or minimise their risks. Manufacturing it seems to me is 100% a reactive industry.
The industries above work on incredibly small margins of profit and the sheer expense to outfit and refit these aging, decrepit (but still working!) production lines are quite honestly, massive.
These manufacturers won't invest in these engineering faults (whether it's security or production focused) until they've been fucked.
NB: This might be with the exception of Lego, my cousin who got employed by Lego after finishing his masters in Industrial Design & CS, and after reading and watching some articles on Lego. I'm convinced Lego's margins are a lot larger than most. They might be the closest thing to a FAANG company when it comes to investment in phu7sical engineering and manufacturing.
I wonder if the way to get your foot in the door would be to partner with an insurer who would provide discounts to the client if they installed security technology meeting a certain standard. You could come up with some kind of bump on the wire type Linux device that proxied access to the old insecure system bringing them up to the standard. Then sell it as a return on investment through savings on industrial accident insurance premiums.
Check out the DEFCON 2018 talk "Through the Eyes of the Attacker" to see to what lengths the TRITON attackers went. These guys were dumping eeproms from boards running obscure MIPS processors and were looking at raw ethernet packets in Wireshark and flipping bits in the packets to see what would happen. That their command&control was running on Windows was just coincidence.
Very few adversaries have enough resources to break anything. The threshold for roughing up a Windows setup is the lowest in the industry.
Also, a better comparison would be with RHEL, which has a lifetime of 10 years or more.
https://www.shodan.io/search?query=inventory+port%3A%2210001...
They take commands to change certain values.
Also, all water meters are being replaced so they can be read remotely without a human physically using an electronic meter reader.
Those are extremely widespread already. And they're pretty open. I wouldn't personally be too worried about any potential exploits since they're simply broadcast only systems and the worst that could probably happen is your'd get a jacked up water bill.
You have unpaid WATER BILL of -2147483648 dollars.
Report immediately to INCINERATOR145 for processing.
Please have a kindly day,
ROBOTOVERLORD69420
Worst case you can tamper with the readings, but you can't actually cause damaging effects.
Article spends too much time FUDing "plant explosions" for my taste
Because hacking systems to cause explosions would be unheard of?
https://www.telegraph.co.uk/news/worldnews/northamerica/usa/...
It’s just not worth the risk exposure. The worst case failure modes must be expected to occur, and they must be economically and ecologically acceptable when they do.
The idea that “this can theoretically happen but we promise it won’t” is simply not acceptable. Versus, “this is extremely unlikely to occur because of these numerous counter-measures, but when it does here’s what we do and what it will cost us.”
If you can do the later analysis on a nuclear plant and come away satisfied, then build baby build.
Note: this only describes cases I'm familiar with, in the US. I bet that some countries with more experience on the receiving end of cyber-warfare (e.g. Ukraine) are better.
The main line of defense is these days is "layers of an onion" network with (physical) controls such that data easily can get out to a higher layer but that it is very difficult to get in from a higher layer back down into a deeper layer.
A completely airgapped network is not practical anymore because the alternative is even worse: nobody wants to have dozens or 100ths of operators, maintenance engineers and 3rd party contractors running around the facility with usb sticks because there is no network to move stuff around. If you have a network then you can control where the data comes into your network, who copies the data to where and what data is visible for which user.
Let data flow one way from the secure industrial equipment out to the general use network for monitoring, but you'd still have to go to a machine on the secure side to make any changes.