6 ms·
Lots and lots of heavy machinery uses Windows computers even for local control panels.
by lima 2y ago
Lots and lots of heavy machinery uses Windows computers even for local control panels.
- mulmen 2y agoBut why does it need to be remotely updated? Have there been major innovations in lift technology recently? They still just go up and down, right? Once such a system is deployed why would it ever need to be updated?
- stevarino 2y agoSecurity patches, assuming it has some network access.
- mulmen 2y agoWhy would a lift have network access?
- gtirloni 2y agoDo you see a lot of people driving around applying software updates with diskettes like in the old days? Have we learned nothing from how the uranium enrichment machines were hacked in Iran? Or how attackers routinely move laterally across the network? Everything is connected these days. For really good reasons.
- seanthemon 2y agoYour understanding of stuxnet is flawed, Iran was attacked by the Us Gov in a very very specific spearfish attack with years of preparation to get Stux into the enrichment facilities - nothing to do with lifts connected to the network. Also the facility was air-gapped, so it wasn't connected to ANY outside network. They had to use other means to get Stux on those computers and then used something like 7 zero days to move from windows into Siemens computers to inflict damage. Stux got out potentially because someone brought their laptop to work, the malware got into said laptop and moved outside the airgap from a different network.
- hilbert42 2y ago"Stux got out potentially because someone brought their laptop to work, the malware got into said laptop and moved outside the airgap from a different network." The lesson here is that even in an air-gapped system the infrastructure should be as proprietary as is possible. If, by design, domestic Windows PCs or USB thumb drives could not interface with any part of the air-gapped system because (a) both hardwares were incompatible at say OSI levels 1, 2 & 3; and (b) software was in every aspect incompatible with respect to their APIs then it wouldn't really matter if by some surreptitious means these commonly-used products entered the plant. Essentially, it would be almost impossible† to get the Trojan onto the plant's hardware. That said, that requires a lot of extra work. By excluding subsystems and components that are readily available in the external/commercial world means a considerable amount of extra design overhead which would both slow down a project's completion and substantially increase its cost. What I'm saying is obvious, and no doubt noted by those who've similar intentions to the Iranians. I'd also suggest that the use of individual controllers etc. such as the Siemens ones used by Iran either wouldn't be used or they'd need to be modified from standard both in hardware and with the firmware (hardware mods would further bootstrap protection if an infiltrator knew the firmware had been altered and found a means of restoring the default factory version). Unfortunately, what Stuxnet has done is to provide an excellent blueprint of how to make enrichment (or any other such) plants (chemical, biological, etc.) essentially impenetrable. † Of course, that doesn't stop or preclude an insider/spy bypassing such protections. Building in tamper resistance and detection to counter this threat would also add another layer of cost and increase the time needed to get the plant up and running. That of itself could act as a deterrent, but I'd add that in war that doesn't account for much, take Bletchley and Manhattan where money was no object.
- rkagerer 2y agoI once engineered a highly secure system that used (shielded) audio cables and amodem as the sole pathway to bridge the airgap. Obscure enough for ya? Transmitted data was hashed on either side, and manually compared. Except for very rare binary updates, the data in/out mostly consisted of text chunks that were small enough to sanity-check by hand inside the gapped environment.
- Mistletoe 2y agoYou picked a really odd day and thread to say that everything is connected for really good reasons.
- SkyPuncher 2y agoThey're probably deployed to a virtualized system to easy with maintenance and upkeep. Updates are partially necessary to ensure you don't end up completely unsupported in the future. It's been a long time, but I worked IT for an auto supplier. Literally nothing was worse than some old computer crapping out with an old version of Windows and a proprietary driver. Mind you, these weren't mission critical systems, but they did disrupt people's workflows while we were fixing the systems. Think, things like digital measurements or barcode scanners. Everything can be easily done by hand but it's a massive pain. Most of these systems end up migrated to a local data center than deployed via a thin client. Far easier to maintain and fix than some box that's been sitting in the corner of a shop collecting dust for 15 years.
- mulmen 2y agoOk but it’s a LIFT. How is Windows even involved? Is it part of the controls?
- notimetorelax 2y agoProbably for things like this - https://www.kone.co.uk/new-buildings/advanced-people-flow-solutions/monitoring-solutions/ https://www.kone.co.uk/new-buildings/advanced-people-flow-so... There’s a lot of value on Internet of Things everything, but comes with own risks.
- mulmen 2y agoI'm having a hard time picturing a multi-story diesel repair shop. Maybe a few floors in a dense area but not so high that a lack of elevators would be show stopping. So I interpret "lift" as the machinery used to raise equipment off the ground for maintenance.
- cyberax 2y agoSeveral elevator controllers automatically switch to the safe mode if they detect a fire or security alarm (which apparently is also happening).
- Drygord 2y agoRemember those good old fashioned windows that you could roll down manually after driving into a lake? Yeah, can’t do it now: it’s all electronic.
- mulmen 2y agoI’m sure that lifts have been electronically controlled for decades. But why is Windows (the operating system) involved?
- mihaaly 2y agoOr being online in the first place. Sounds like an unnecessary risk.
- chrisjj 2y ago> But why does it need to be remotely updated? Because it can be remotely updated by attackers.
- deleted 2y ago[deleted]
- pas 2y agobut why do they have CS on them? they should be simply not connected to any kinds of networks. and if there's some sensor network in the building that should be completely separate from the actual machine controls.
- bloopernova 2y agoCompliance. To work with various private data, you need to be accredited and that means an audit to prove you are in compliance with whatever standard you are aspiring to. CS is part of that compliance process.
- KolmogorovComp 2y agoWhich private data would a computer need to operate a lift?
- fragmede 2y agowho's allowed to use the lift? where do those keycards authenticate to?
- bloopernova 2y agoAnother department in the corporation is probably accessing PII, so corporate IT installed the security software on every Windows PC. Special cases cost money to manage, so centrally managed PCs are all treated the same.
- xcv123 2y agoIt must be security tags on the lift which restrict entry to authorised staff.
- gtirloni 2y agoAnything that touches other systems is a risk and needs to be properly monitored and secured. I had a lot of reservations about companies installing Crowdstrike but I'm baffled by the lack of security awareness in many comments here. So they do really seem necessary.
- saganus 2y agoThat sounds...suboptimal. I would imagine they used specialized controller cards or something like that.
- Ekaros 2y agoThey optimize for small batch development costs. Slapping windows PC when you sell a few hundred to thousand units is actually pretty cheap. Software itself is probably same order of magnitude, cheaper for UI itself...
- delfinom 2y agoAnd cheap both short and long term. Microsoft has 10 year lifecycles you don't need to pay extra for. Linux you need IT staff to upgrade it every 3 years. Not to mention hiring engineers to recompile software every 3 years with the distro upgrade.
- kchr 2y agoUbuntu LTS has support for 5 years, can be extended to 10 years of maintenance/security support with ESM (which is a paid service). Same with Rocky Linux, but the extra 5 years of maintenance/security support is provided for free.
- ekianjo 2y agothats just asking for trouble.