Why older tech is sometimes safer from hackers
bbc.com
bbc.com
Our water and power utilities need to re-watch the pilot.
You could absolutely make the case that it isn't worth the risk, but that isn't the same as not having benefits.
Remote management has clear benefits, don’t be obtuse. I totally agree on the security risks, but the benefits are obvious.
a virtual network built upon the regular internet is much easier.
And yes, mostly done wrong
I asked because of books I had read about the bad ones, where unsecured industrial control protocols were exposed wirelessly , or via vpns. And I’ve been curious if any good ones are out there .
The water and power utilities are themselves large distributed systems. They need communications between elements just to function properly. They don't exist in a single location where people can go locally manage them in some air-gapped, offline fashion.
There is no option of not having a communication network to monitor and manage these geographically distributed elements. The question is which communication network you would use, and how you would secure it. Whether it is telephones, radio links, or people running around as messengers, it is still a communications network.
Will some "dedicated" network be any safer? If anything, I imagine the fantasy of a private network will lead to even less security. You cannot physically secure the entire signal path. You really need to treat it as untrusted and build your security on top with encryption, authentication, authorization, etc.
The problem of secure networking has been solved long ago but there is no incentive for OT solution architects to get it right.
Infrastructure usually has a long lifetime.
Things become much more vulnerable as time rolls on e.g. we should be worried about AI hacking of smart meter firmware (hard to secure and expensive to upgrade).
Today's secure system is tomorrow's insecure system. E.g. https://news.ycombinator.com/item?id=49413320 :
Finally, I poked at something that wasn’t connected over USB but WiFi instead, the Elgato Key Light Mini. This one turned out to be way more interesting than I expected: it’s the only one with meaningful firmware integrity protection.
Unfortunately, while that’s an improvement over all of the other devices we’ve looked at, it protects the firmware at exactly one point in time: when an update is happening. It’s not a boot time check enforced by the bootloader or any other kind of secure boot scheme, and the updater happens to be running while everything else in the device is still operating, meaning there’s huge attack surface to try to disable that signature validation. I asked Claude to look for an exploit that might enable this, and it found a doozyFor power I can understand. For water supply it is harder to understand. Does water supply have similar characteristics to power, for example can you turn on a reservoir when there is an “outage” in another?
From a efficiency perspective centralized anything seems better at first glance, however decentralized anything just seems more resilient in the long run like nature and/or our universe.
It's the same lesson that we can learn from Star Trek, Star Wars, and all the other self-aggrandising lore that humanity concocts when gazing lovingly in the mirror.
There is no greater enemy than greedy, barbaric humanity itself.
And, when someone mentions Star Trek as a good example of engineering, I can’t do anything other than laugh. Do they really need to pass high power systems behind crewed consoles on the bridge so they can explode dramatically?
"Modern" software unnecessarily includes and routinely unnecessarily forces network connectivity
Perhaps they were saved by an old mindset
Doing some reading over at textfiles.com can reveal how cautious people were in the 1990's about connecting to the internet
The thing is: police actually have data on swords and bows, and the fact it is so unusual to commit crimes with these limit the search space and tend to make the investigation easier.
I haven't really gotten really into this, but from what I can tell, anything that has to do with mobile phones is strictly worse in terms of anonimity than Wifi.
At least anything that ties a Wifi connection to you you can change in an OS setting, but if you get into faking IMEI/SIM stuff, that can very quickly get you charged with an actual crime.
If you dig into the fake cell tower rabbit hole you'll find what you're talking about to be an even worse problem.
How do you suppose mobile phones are meant to work without subscriber info?
> I haven't really gotten really into this
Clearly.
It used to be that when the telco detects an IMEI change for your SIM, they send a configuration over the air so that you have access to the data network.
I was hoping it was gonna be about how our modern practices are making things less secure.
For instance, we claim we need to be able to rapidly update clients so that we can patch security vulnerabilities as they are discovered (often without involving the user at all). And there are a lot of companies that have an incentive to push this narrative because they have products which facilitate this whack-a-mole approach to security. But there's no reason to believe that new software is more secure than old software. Old software is just more likely to be known to be insecure. So anything written before it became trendy to update without your user's consent is more secure in at least one way because it is not configured to automatically update to whatever comes down the pipe from "the vendor".
About your second comment- newer systems CAN be less secure, but not always. But even if they are, falling back on things like eLoran are important.
Consider the CrowdStrike debacle. It wouldn't have been a big deal if they could just boot to yesterday's config because today's config is broken, but neither vendor involved trusts their users enough for that kind of thing, which turned it into a disaster.
It's remarkable how much more time one has to wait just to access the same level of information (Cookie Policy, EULAs, etc).
Even with "lighter" weight HTTP Firewall utilities such as Anubis (https://github.com/techaroHQ/anubis), the average user has to pay for other's (DDoSers) misdeeds. Now no one can visit a site without a firewall unless it's static and rate-limited by IP address to avoid crashing a small home server. Some impressive LMDBs might be able to serve up to 100,000 requests per second on a lightweight PC, but then again they could still be knocked offline from a super resourceful organization. I like not putting all my eggs in one basket.
A similar bug could happen with something like Cloudflare- the computer serving up the firewall could have a bug, and it's not programmed to fall back on serving the site without the gatekeeping. If the site is prominent enough, it might routinely face DoS attacks which prevents it from being used. But if it's an uneventful day, it could still manage a lower-tech firewall and still be functional.
hmm
This is BBC Future - the BBC's tech clickbait publisher - not BBC News.
BBC consists of the non-profit news bureau as well as at least a dozen for-profit clickbait and listicle publishers. BBC's ad-free mandate is only for the UK.
> in the age of Claude - I am pretty sure I can destroy your legacy software in minutes
Yep. One of our PortCos has unrestricted access to Anthropic and GPT models. With whitebox testing, it's trivial to identify vulns in legacy environments. With blackbox testing, it takes some effort but it doable with the right steering.
The article links to a vulnerability from 1998, which I expect is already fixed in the versions of Eudora people still use.
I agree it would probably be easy for AI to find exploitable bugs though.
I hope they are authenticating the server to prevent MITM attacks.
Yes but you'd need to a) know that they use that particular software and b) have a reason to bother destroying it in the first place.
That is really the crux of the idea.
The client the guy in the article uses isn't secure because it has no security vulnerabilities - it is secure because nobody bothers to target Eudora users in general.
Of course as others mentioned, if the target switches from "Eudora users in general" to "that guy in particular" then the situation changes (though the attackers would still need to realize he uses Eudora - assuming this article didn't exist to reveal it anyway :-P).
But aside from that, even "in the age of Claude", i doubt anyone is wasting time and/or tokens scanning the open Internet for all sorts of old vulnerabilities in antique software that (relatively) nobody uses in hopes they catch some random passer-by as there is barely any ROI by doing that compared to taking advantage of vulnerabilities on software that people actually use.
[1] https://en.wikipedia.org/wiki/The_Cuckoo%27s_Egg_(book)
[2] https://news.ycombinator.com/user?id=CliffStoll
[3] https://news.ycombinator.com/item?id=21830277
This is the thing with AI - it has an infinite capacity to do things - the same way we find new RCEs by the dozen so we can fix them, our attackers find them so they can get infiltrate our systems.
Back when my friend Jim (retired Pilot) and I visited Chicago's Approach Control facility, I asked one question "What would happen if GPS went away?", they didn't like the question one bit.
It's really not good the way we're getting rid of ground based navigation aids in the US.
I have also seen virus source code published in books and magazines. We don't have such threats anymore.
virus source code published in books and magazines. We don't have such threats anymore.
--
No, we do not need this anymore - today you have CAPTCHAs, convincing people to copy & paste PowerShell code on their machine and execute it with Admin privileges! :-D
https://www.theregister.com/on-prem/2018/02/06/ghost-in-the-...
There are hospitals out there still running on windows XP. Someone's going to skim this article and say "look, we're actually being prudent"!
The problem is that most of these older devices are about to be replaced and many manufacturers have switched to Linux for their operating system. It's cheaper and requires no licensing, but far more insecure. It needs almost constant patching to stay secure because the attack surface is so large.
Nuclear centrifuge software? Rare, expensive, hacked.