4 ms·
Do these infrastructures really need the level of hardware they seem to use? Rather than use a unsecured raspberry pi3 with it's wifi left on, why not have a c
by jumpkickhit 9y ago
Do these infrastructures really need the level of hardware they seem to use?
Rather than use a unsecured raspberry pi3 with it's wifi left on, why not have a closed system specifically built instead. Something not casually running embedded Windows XP, rather maybe a barebones OS written in assembly with minimal networking functionality on minimal hardware.
- lucaspiller 9y agoI suspect the actual cause is similar to the fuel station hacks from a couple of years ago [0], where industrial control systems have been 'upgraded' to run over the internet. [0] https://www.theregister.co.uk/2015/02/11/anonymous_hacks_fuel_station_monitoring_system/ https://www.theregister.co.uk/2015/02/11/anonymous_hacks_fue...
- problems 9y agoBuilding on commodity hardware is cheap, easy, quick to develop and often more stable and secure. Going fully custom results in more custom components which are often less tested and less audited than their commodity counterparts. Yes, it sounds like they'll be "simple" but it rarely is so - especially when your boss or sales team asks why you don't have IP-based monitoring. The best bet in my opinion is to use commodity stuff but reduce the attack surface as much as possible by simply disabling, firewalling and physically restricting everything possible. In many cases like this, you could probably get away with absolutely minimalist control systems run on microcontrollers and similar with monitoring only over an isolated unidirectional interface (think fiber optic connection with no physical receiver on the other side).
- evdev 9y agoThe whole area is heavily, heavily reactionary and slow moving. They're on embedded XP because that's the closest they can get given the software platforms they're dependent on. You're right that locked down embedded industrial (Linux) PCs are the best option, but your control platform has to run on them...
- InclinedPlane 9y agoThis is coming from the perspective of someone who is an expert in software already, all this stuff looks like a trivial side project, right? Imagine this in different contexts though. Why go to IKEA for furniture when you can just build your own of higher quality in your garage shop? Or why bother going to a mechanic when you can just rebuild your car's engine yourself at home? The fact is, of these three examples the software one is actually the most unrealistic. Having someone on staff with software expertise is a hard problem, and an expensive one too. If you don't already have a group of folks with software expertise on staff then hiring for it becomes a massively difficult problem. This is why there's still so much business in the build-for-hire software biz. Most companies in the world who need software based solutions are not themselves software companies. They need to use objective measures to determine the quality of the companies they farm out these projects to as well as the software that results. Additionally, software built on commodity systems (like Windows XP) is often a better choice for these companies because it means there's a much larger group of folks they can hire if they need to make changes or perform service on the system in the future (which is inevitable). As much as a custom solution built on a microcontroller or small linux based embedded system might be technically superior, cheaper, and more robust, it might not be a sustainable solution for a given company.
- bsder 9y ago> Rather than use a unsecured raspberry pi3 with it's wifi left on, why not have a closed system specifically built instead. Security through obscurity. Just because a system is closed doesn't make it safer. In fact, generally the opposite. Look at the security fiasco over in medical device land.
- eksemplar 9y agoIT still hasn't made it into higher management, especially in the public sector which even privatized utilities resemble. Unfortunately this means things like security comes last, when they really ought to be part of your architectural design. We recently bought a manegement software for our translators, which somehow made it through all the business and management layers revolving public contracts without anyone questioning the fact that none of it was encrypted. Meaning anyone snooping on our network could get anything from private data to system logins with absolutely no effort. Things are getting better, but IT is still a subsection of the economy department in a lot of places, and a lot of execs still think it's magic. Couple this with most developers and entrepreneurs being hackers who want to toy around with cool world changing features, and, no one is left to worry about security.