Describe the network security of the industrial automation industry and their customers in a single statement. Lol.
Describe the network security of the industrial automation industry and their customers in a single statement. Lol.
And the problem has actually gotten better over the years:
https://trends.shodan.io/search?query=tag%3Aics+rockwell
The situation used to be worse with things like the Lantronix password recovery service (i.e. a UDP port that would just send you the device password without any auth). It's still not ideal and takings things offline isn't easy (https://blog.shodan.io/taking-things-offline-is-hard/) but it's getting better (slowly).
How do you lockdown something that may have not been taken offline for decades because it will cost downtime or harm. Or something that can’t be locked down without tossing new tech around it that may not be compatible with the protocols etc.
Tunnel your dialup within your obsolete 3g network, and then tunnel that obsolete 3g network within something modern. The obsolete technologies are not the issue here.
Also the thing about dialup is that it's point to point so the attack surface isn't even remotely comparable to exposing a port on the open internet. I should generally be able to trust the link that my phone company provides. Faxes are still used in many secure settings in preference to email.
The dial up part is far more involved, especially when they have auto answering connected directly to PLC or HMI, mostly with shared passwords. Also, you can’t trust the network operator either, insider threats and rogue employees are a threat. Additionally, dial ups are less monitored compared to modern network, and usually you end up with duct tape solutions like jump server to have strong authentication and continuous logging in firewall and such, plus proper encrypted tunnels so even physical wiretapping isn’t possible, and the assumption of air gap isn’t there because it’s reachable through public telephone, and the worst part, these dial ups are usually connected to windows XP Scada developers machines.
To add, obsolete is bad too, when your device cease to have vulnerability patches, you are screwed regardless of whatever configs you put.