4 ms·
So the significance here is that if you had remote access to a single wind turbine, you can control the others? Implying, if there were a vulnerability in the c
by arm85 9y ago
So the significance here is that if you had remote access to a single wind turbine, you can control the others? Implying, if there were a vulnerability in the control system of one turbine, the rest of them are exposed? Rather than showing that you can stop wind turbines from spinning, if you had physical access to the turbines.
Their "hack", which requires physical access, is about as practical as throwing a physical spanner in the mechanics.
EDIT:
I'd like to point out, there are reasons why you might want to be able to access the SCADA system of other wind turbines, from the network access of one wind turbine, which would be to allow wind-yaw optimising wind lidar systems to optimise the yaw of other, local, turbines.
- horsawlarway 9y agoI agree, the issue here is physical security. That's it. Now, there are some great arguments to be made that software security in those buildings should also be improved, but that literally doesn't matter if someone has physical access. At best you're delaying. Physical access trumps everything. There is no software on the planet that can prevent a determined attacker with physical access.
- brianwawok 9y agoAnd as mentioned above, this is silly to ignore software security. Software attacks are often far far amplified and harder to trace than their in person counterpart.
- horsawlarway 9y agoNo one is ignoring it... The whole freaking article is about companies paying specialists to see how secure their farms are. My issue is that the article glides past the "physical access" part to focus on the "scary cyber weapons" part. That's bullshit. If it was a remote exploit from an internet connected machine, sure: that's scary. This wasn't that.
- haltingthoughts 9y agoThe point is that things are connected. By physically accessing one machine you bring down not just one machine but the entire network. The importance of physical security just went up by a factor of the number of machines on the network. At some point you are going to have to focus on the network part of security. Getting physical access to one Google server shouldn't allow you to bring down all of Google.