3 ms·
>Separately I'd have to ask why if your production facility is dependent on these machines that they would be Internet-connected in the first place. Anecdotall
by Sir_Substance 8y ago
>Separately I'd have to ask why if your production facility is dependent on these machines that they would be Internet-connected in the first place.
Anecdotally, I did some for-cash IT work at a trophy engraving store about a decade ago. Small shop, maybe 7 employees, they had about 6 different cnc machines of varying sizes but only one of each type.
One of the machines was a vinyl cutter that was about 4mx4m, being run by a windows 98 computer. Not windows 98 SE, the original. The manufacturer of the table had gone broke some time between the two and never released an updated driver, and it seemed it was not possible to bring the driver forwards to 98 SE, let alone xp or 7.
A new machine would have cost them something like $50,000, basically 1-1.5 employees, so they just stuck with windows 98. That machine had internet connectivity too because it was just plugged into the company network (of like 7 computers) so that it could get the job files from a shared drive, and since the company network provided internet, it had internet.
I guess the point is these companies don't get paid to keep stuff up to date or to be secure, they get paid to make trophies or whatever. They look on cyber attacks in largely the same way they look on someone driving a truck through their front wall. It might happen, their margin isn't good enough for them to spend money on preventative measures for such a specific problem, and they don't know anyone it's happened to anyway.