Hacked Texan Water Infrastructure Had a 3 Character Password
threatpost.com
threatpost.com
(I'm a developer at one of the smaller SCADA software companies.)
But I'm guessing it's mostly because system integrators are qualified in a way a software company isn't. The scope of a project that an integrator might take on can be vast and the SCADA software is generally only one piece of the equation.
For smaller, "one-off" jobs, the integration work is done by distributors or by 3rd party integrators. Distributors will often do the integration for free and cover the integration cost and their profit from the discount the manufacturer gives them from list price. Most integrators do fixed-price bids for work, and may also make money from equipment markups. In both cases, there is a lot of incentive to do the minimum possible, especially since the projects tend to be poorly specified.
This is all made worse by the fact that the customers tend to be technically unsophisticated. That makes it hard for them to effectively manage projects, and hard for them to make informed judgements when selecting suppliers. Suppliers are usually picked based on personal relationships with the sales team (manufacturer's or distributor's) and the in-house engineer's familiarity with a given supplier.
Finally, the whole industrial automation industry isn't terribly glamorous. The typical problems being solved on any given job have been solved thousands of times before. The technology is often old and clunky (the most common language is called ladder logic... look it up, it's good for a laugh). Being successful requires a mixture of software, electrical engineering, mechanical engineering, and sales skills. Since most distributors and integrators live almost hand-to-mouth, sales skills tend to be emphasized, even among the engineers. The engineers who are good at sales find they can make more money doing sales. The ones who aren't salesy find there isn't much room for advancement and move on. I'm over-generalizing, but the overall trends don't encourage high-quality software engineering.
But yeah, the real world kind of stinks.
The kind of shit I've seen in SCADA comms rooms blows my mind -- bare, homebrew breadboards screwed into 19" racks; SparcStations caked with dirt and grime; passwd files containing active accounts for people who are now dead.
The only thing I find surprising about any of this is that it doesn't happen every single day.
Given that, and given weird laws about "providing help to terrorists"[2] I'm amazed that someone putting a 3 character password on something so important, and then letting it face the Internet, is not going to see jail time.
[1] See, for example, flooding in Gloucestershire, England, a few years ago. That was troublesome, but only got really bad when a local water treatment plant was flooded.
[2] At least, in the UK.
(Unfortunately, this reads just as valid sarcastically as seriously).
http://www.bmo.com/home/about/banking/privacy-security/prote...
Maybe your the victim of a Phishing attack or something, for example maybe a fake site told you you had to use 4 digits.
Honestly I've heard of a lot worse then this:
http://www.bmo.com/home/about/banking/privacy-security/how-w...
What i dont understand is now all bank cards in Canada have a smartcard embedded, why cant they just hand out $5 card readers and use that for ebanking, every major browser and OS supports this stuff right out of the box.
"Yeah but don't forget God. System operators love to use God. It's that whole male ego thing." ;-)
Also I think somebody ought to pass some tougher laws about leaving national infrastructure open to simple attacks. We can start with "3 years in prison for default passwords."