Story about spies penetrating grid may be part of a PR campaign
erratasec.blogspot.com
erratasec.blogspot.com
Yes, the ISOs (Independent System Operators) have Internet presences. Yes, they can send out dispatch signals to the generators over the Internet. Yes, the generators can access an extranet to find out what their current dispatch should be.
Security (in the environment I'm most familiar with) is provided using well-known standards (SSL certificates on both the server and the client). I'm sure there are ways to spoof, but I'm not an expert at those things.
I have ideas on how to create a bad day for the grid, but I don't think it would be wise for me to share them ;)
Sure someone might have though it was a good idea, but surely someone has got to have pointed out just what a dumbfuck idea that is?
Does anyone know why these systems would be online and what benefits would be large enough to justify this?
The proposed CyberSecurity Act of 2009 would allow the president to designate a private network (such as a SCADA system) as critical, and in the case of a declared emergency, shut it off from the Internet.
As you can imagine, there is resistance to this from multiple parties, including those industries who fear additional government regulation and also privacy and anti-censorship advocates who fear "scope creep" in the legislation.
As they say, nature abhors a vacuum, and Congresscritters see a piece of important infrastructure that's not under their control. Believing their jobs are important, they believe that this lack of regulation is a danger.
Journalists see the concern of the Congresscritters, and hey, these are community leaders: there must be something to this, so lets do some research and see what we can find -- but we're writing for the public, we've got to present it in a compelling fashion.
So all this takes is a a bunch of people who are acting according to their own world view, following whatever natural incentives they have.
However, don't forget the influence of the lobbyists hired by the security industry. Additionally, "non-profit" organizations involved with information security that see a potential cybersecurity boom as beneficial to their membership and influence in the field.
So why the internet? What's the threat?
Or is it about money? how so?