10 ms·
There's definitely some advantages to using age-old practices. It's easy to explain how trust and verification works in a system when 2 people have separate phy
by kevan 7y ago
There's definitely some advantages to using age-old practices. It's easy to explain how trust and verification works in a system when 2 people have separate physical keys and you need both to perform an action. It's a lot harder to explain things like modern crypto to most people. Until a critical mass of the decision-making chain understand the tech we may be better off not using it for mission-critical things.
Alternatively, this could also be a misguided effort that holds back smart-grid tech in America by a decade. It's really hard to tell.
- Finnucane 7y agoDoes smart-grid tech work any better than smart-home tech? So far most 'smart' tech hasn't had a good track record on security or reliability, certainly not at the level you would trust your major infrastructure to it.
- penagwin 7y agoKeep in mind most "smart home" technology is marketed at consumers who have no idea what SSL/TLS is (nore do many care sadly even though they should), and are meant to be as cheap as possible. While I have no clue what the security or reliability looks like in industrial applications, I would hope they evaluate their solutions with reliability in mind.
- mlaretallack 7y agoMost industrial application also done know or care what ssl/TLS is (however this is starting to change). I have had industrial control systems reboot by just doing an nmap scan.
- raverbashing 7y agoThis It's barely better than iot stuff. And some "older" systems probably still need NT4 to run (I mean, if you're lucky)
- andrewnicolalde 7y agoHah. My hope died with the 30 ICS-CERT emails I’m bombarded with each day.
- tw04 7y ago>While I have no clue what the security or reliability looks like in industrial applications, I would hope they evaluate their solutions with reliability in mind. Keep hoping... The number of industrial systems deployed that are connected to the internet with the default passwords unchanged or no passwords is nauseating. https://threatpost.com/exposing-scada-systems-shodan-110910/74644/ https://threatpost.com/exposing-scada-systems-shodan-110910/...
- penagwin 7y agoSerious question. I've been hearing about industrial applications/medical etc. having default passwords exposed on the internet for years. How have they not been exploited/fixed already? Shodan's made it clear for years, of course anybody can use zmap/masscan.
- tw04 7y agoPeople that know the passwords are generally ethical. Plus the risk reward isn't there. Say you have a hack for a pacemaker and you kill 1000 people. Then what? Literally every nation on Earth will be looking for you and you will either rot in prison for life or be put to death. And if the wrong country gets you first there will likely be a lot of torture along the way. Without having hacked a database of patient to device mappings, it's not like you can ask for ransom.
- lallysingh 7y agoFrame someone you don't like, short the vendor's stock, or separately hack a hospital to get the patient records. You don't even have to kill them for that, just a recordable, scary event. Also, you may already want someone in particular dead and are just looking for a vector. This seems almost untraceable.
- penagwin 7y agoI've seen several talks where they demoed showing access to hydroelectric dams, etc. I'm thankfully not this person, but at a basic level I could see some bored teen turning off a dam just for fun. Honestly the only reason I don't is because it would be "wrong" to do, but the internet is full of people, it's certainly not a stretch that somebody would want to.
- sephamorr 7y agoFor the utilities, absolutely. The utilities have hard requirements of delivering power to all customers while maintaining grid and frequency stability, so the ability to shape demand and supply quickly is at least one very valuable knob.
- jhayward 7y agoYes. The modern sensors and controls being built in to US electric transmission and distribution systems have resulted in a far better run grid: more stable, more reliable, more efficient, fairer, and enabling things like real-time market making which enables rapid improvement using new technologies such as grid storage batteries, etc. It does come with some vulnerabilities. I'm not sure what the best way forward on those is; I suspect this bill's effects, if any, will not result in a more resilient or less vulnerable grid system. Attackers will just find different leverage points to attack.
- ahje 7y agoSomewhat related anecdote: I live in the Finnish countryside, and since much of the power grid out here is still ancient, there are power outages rather often. However, if the power goes out, there's always something that tries to power everything back on automatically after exactly 30, 60, 120 and 240 seconds. If something's still wrong, the power will simply flick on and then off within a few seconds. If an outage lasts more than four minutes, it usually takes much longer to get it running again (I assume it's because it then triggers an alert that will be handled by a human operator). I would assume there's a lot of similar stuff going on in the US power grid, considering it's immense size what I suspect is a somewhat similar mix of new and very old equipment. And yes, surge protectors are mandatory here.
- cesarb 7y ago> there's always something that tries to power everything back on automatically after exactly 30, 60, 120 and 240 seconds Sounds like a recloser, which tries a number of times to restore power under the assumption that most faults are transient (for instance, a branch falling in the wires and then sliding to the ground). After a set number of retries, it gives up and stays open; at that point, a human has to locate the fault, clear it (for instance, poking the fallen branch with a stick until it falls to the ground), and then tell the recloser to close the connection again.
- ahje 7y ago
- xvilka 7y agoIt is just because ICS/IoT vendors do not care/know a thing about cybersecurity. If you push security development practices, it should really improve the situation. Just prevent an access to the market until they pass the red team audit. Would surely motivate them enough.
- toomuchtodo 7y agoI have seen a contactor SCADA controller (high voltage physical relay) for a high voltage transmission line at a Florida substation on the public internet (no airgap, no vpn) during an audit. Apply brakes while we work on the steering. This is good policy. “Internet Of Shit” is no joke.
- nitrogen 7y agoIndustrial controls at least work most of the time. Can't quite say that about consumer gear.
- jacquesm 7y agoThat does not surprise me in the least. Some of the stuff I came across doing DD would make your hair stand on end, after 130 companies I'm more surprised by the ones that do it right than the ones that have no clue.
- toomuchtodo 7y agoAgree entirely.
- crankylinuxuser 7y agoIn a hacking group I'm part of, we had an address that ended up being a passwordless VNC to what looked like a centrifuge controller. It was at a place whose IP tracked to CERN. We reported it as fast as we fucking could. It took about 6 hrs for them to get it off the public internet with no password.
- toomuchtodo 7y agoThank you for reporting this!
- crankylinuxuser 7y agoWe do what we can. From our assessment, it looks like that was a complete mistake. And those do indeed happen. But what if someone were to have found it and were malicious, and started randomly mashing buttons? That's why our jobs as sysads are never done. We occasionally do boneheaded stuff. Users also do. And so do contractors. And I'll do what I can when I see something wrong. Professional courtesy.
- ethbro 7y agoMy intuition from experience is that in sufficiently complex systems (basically all modern hardware + software systems), things break from humans misunderstanding or not knowing the rules far more often than from physical failure. If there's a reason for using an electronic system, by all means. But for God's sake air-gap it, compartmentalize functionality with clearly defined interfaces, build simple fault-tolerant monitoring, and make final controls hand-on-metal. When multi-million dollar warships are crashed because of poor UX, I have zero faith we're safely managing complexity.
- qserasera 7y ago>When multi-million dollar warships are crashed because of poor UX, I have zero faith we're safely managing complexity. My understanding of the incident is that the auto-detection functions failed and when human functions were not done per SOP due to exhaustion and senior command elsewhere the vessel came into jeopardy. Then when inexperienced and untrained crew members tried too late to evade. An apparently too complex UX was sending ship controls to more than one console. This culminated into one of the multi-million dollar warships crashing.
- agoodthrowaway 7y agoI wonder what would happen in an actual battle with the fog of war when people are pushed beyond exhaustion. What happens when senior command is dead or missing?
- metaphor 7y agoThere exists a very distinct line between routine/exercise and war. You may have missed the opportunity to experience this distinction first hand, but I can assure you with the utmost confidence, the meta does indeed change.
- dvdbloc 7y agoWhat event was this?
- hinkley 7y agoNearly this exact scenario has been bugging me for a couple months. I started thinking about it due to deployment issues. Why don't we have a proverbial two key system for certain activities like deploying to production or deleting user accounts, or backups? We make do with things like pull requests, but everywhere we've ever had retros, I've run into situations where someone did something very stupid, somebody else rubber stamped it, and now we have a mess. Approvals on an action do not approximate the ritual sobriety that is embodied in two independent humans deciding to turn a key. There are some people for whom these two actions can be considered equivalent, but we tend to bag on them for their meticulousness. I think I'm wanting a tool where I type "deploy 1.0.12345 to production" and it sits there waiting until someone else types "deploy 1.0.12354 to production", and then it stops us because one of us transposed some digits.
- eximius 7y agoSomeone did release a Pam module? That required confirmation before someone sudo-ed. I thought it was Stripe but I can't find it right now.
- stouset 7y agoHey, that was me! See the sister comment. It's actually a plugin for sudo (surprisingly yes, sudo has plugin capabilities[1]) and not PAM. I had originally developed it as a PAM module, but the sudo plugin API allows for the neat trick where the TTY is mirrored. [1] https://linux.die.net/man/8/sudo_plugin https://linux.die.net/man/8/sudo_plugin
- deleted 7y ago[deleted]
- fiddlerwoaroof 7y agoWe didn’t “release” it, but I worked on a dual-control PAM module: https://github.com/cjdev/dual-control https://github.com/cjdev/dual-control
- stouset 7y agoIt's not necessarily for deploys (though you certainly could make a workflow that uses it to do so!) but I developed a dual-control plugin for sudo while at Square. We use it extensively. https://github.com/square/sudo_pair https://github.com/square/sudo_pair In action: https://raw.githubusercontent.com/square/sudo_pair/master/demo.gif https://raw.githubusercontent.com/square/sudo_pair/master/de...
- rudolph9 7y agoIt probably will yield good results for the next decade but will set a bad precedent for the world in general and back us into a corner as confidence in the security for this stuff improves and the next decades passes.
- swagasaurus-rex 7y agoSoftware does not appear to be on a trajectory of increased security or reliabilty. It has always been hard to verify correctness, let alone measure how vulnerable and easy to exploit software is. Testing software has not been a suitable replacement to a large technical user base constantly tweaking and improving said software. If software were to become reliable, I'm sure those pioneers in reliable software can pave the way to reasonable use in mission critical, high value espionage targets. Until then, legislation like this will pave the way back to what has worked for centuries.
- gremlinsinc 7y agoWhy not create a closed government only internet or intranet where all grids connect to each other but none have access to the main internet. No computer in the network can connect to the internet and the govnet, maybe even have a different protocol and other unique features. They could also use ai to determine if a command to say shut something important off makes sense if not notify someone in charge before following through on suspect actions.
- IAmEveryone 7y agoThe “smart grid” we are working towards does things like scheduling your AC and dishwasher to turn on/off depending on supply and demand fluctuations. To that end, every node, both consumers and energy producers, needs to be connected. To do this completely independent from the existing internet would amount to doubling the cost of our communication infrastructure. It would also defeat your purpose, because suddenly everyone on the grid has access to the network again, and could try to attack it. You also need some connection, somewhere, to the “regular” internet. As just one example, consumption data is the basis for billing, which needs to connect to financial infrastructure. And, finally, even air-gapped systems are vulnerable. See Stuxnet.
- Nasrudith 7y agoLogistics and attendant expenses most likely - especially with practice to gain any actual benefits. Say everyone has a registered nonrepudiatable cryotographic certificate - a decent idea in theory. However apply it to every accessible grid communication part including ones which may cycle in and out and could have secrets extracted. Suddenly it doesn't provide as much benefit if a hacked SmartMeter can get in anyway and there is deniability. Better than nothing but you could have likely gotten better bang for your buck with strict firewall rules or hiring a swarm of consultants. Similarly vetting commands has two problems - one is that reaction time may be critical. Second the judgements themselves are complexity and may be a source for errors - especially when they are "triage" ones that cause a shutdown or damage to avoid greater damage
- throw0101a 7y ago> Why not create a closed government only internet or intranet where all grids connect to each other but none have access to the main internet. An air gap didn't help Iran against Stuxnet, or the US DoD against agent.btz: * https://en.wikipedia.org/wiki/2008_cyberattack_on_United_States https://en.wikipedia.org/wiki/2008_cyberattack_on_United_Sta... It wouldn't hurt, and it's probably worth doing anyway as a risk mitigation, but keeping it completely sanitary would be impossible.