7 ms·
Drinking water systems for 26M Americans face high cybersecurity risks
- xyst 2y agoWith the potential gutting/further defunding of EPA and other federal regulatory agencies. My money says there will be no action taken until an actual security incident occurs. Administrations don’t care about the long term health of the country, only what they can do in 4 year spans. Cybersecurity is unfortunately not “sexy” enough for the common American voter to get behind.
- javajosh 2y agoI think it is safe to say that few if anyone actually understands the common American voter and what they actually care about. Anecdotally, the prevalence of cyber-security plot points in action thriller movies/games/books indicates that there is at least some awareness of the threat.
- frutiger 2y agoSomehow I doubt the security posture was magnificent even before the defunding. This kind of thing is usually a simple checklist item for companies let alone government agencies.
- 015a 2y agoBecause it was being addressed before the defunding? I mean... clearly not. They haven't been defunded yet. The issue is unlikely to be money, nor is it likely to be technical. If throwing ever-increasing amounts of money at the problem isn't fixing it, maybe it isn't all that crazy to try the opposite.
- toomuchtodo 2y agoRepublican lawmakers and the water industry sued the EPA saying it would be too expensive to secure water systems. > In a statement to Recorded Future News, an EPA spokesperson confirmed that the memorandum – handed down in March – was being withdrawn due to lawsuits filed by attorneys general in the States of Missouri, Arkansas, and Iowa as well as industry groups American Water Works Association (AWWA) and National Rural Water Association (NRWA). There is no point in trying to solve what there is no will to solve. Less money, more money, they just don’t want to have to do it or be liable. https://therecord.media/epa-says-litigation-from-republicans-and-water-companies-forced-withdrawal-of-cyber-memo https://therecord.media/epa-says-litigation-from-republicans... https://www.iowaattorneygeneral.gov/newsroom/attorney-general-bird-sues-biden-administration-over-new-cybersecurity-regulations-for-public-water/ https://www.iowaattorneygeneral.gov/newsroom/attorney-genera... https://content.govdelivery.com/attachments/IACIO/2023/04/18/file_attachments/2470891/Iowa%20Petition%20for%20Review.pdf https://content.govdelivery.com/attachments/IACIO/2023/04/18...
- 015a 2y agoThat's not how I read that. This statement from the EPA is the crux of it: "Most cybersecurity practices can be implemented at minimal cost."; a statement that anyone involved with software/cybersecurity knows has never been true about any software system, ever. It feels very reasonable to me that some of these dirt-poor counties could look at a new set of cyber requirements and say, we physically cannot pay for this; and while the EPA goes on to list sources of funding they offer, I don't know much about those; its possible that given they've already vastly underestimated the cost of securing an industrial software system, they're also vastly under-provisioning the grant funding available to do it. No one wants their water systems insecure. Republicans aren't a comic book villain; and to help empathize with how they think, right or wrong, consider this: What if we took a good chunk of the EPA's budget and distributed it to the local water utilities directly (in other words: Your federal taxes go down, your county taxes go up). The EPA seems really good at drafting memorandums they have to redact and publishing reports about how insecure our water systems are; Republicans would argue, the money we spent on those things did nothing to help actually fix the problem, so maybe the solution is "less EPA". I'm not saying this is right, and I'm not saying its even representative of a cogent reality. I'm just saying, this is the line of thinking.
- toomuchtodo 2y agoAs a cybersecurity practitioner and owner of a mid 7 figures budget to defend an enterprise, I am not unfamiliar with the costs (controls, staff, implementation). But, the evidence is clear that the response was “no” to this effort, and no further action or negotiation to improve the security posture of these entities. I know what it looks like when someone says “we don’t have the funds for this, what can we do with what we have?” but also what it looks like when lack of funding is an excuse to take no further action. Republicans have made no effort to appropriate funding for this work at either the federal or state level, for example. If this matters to them, when can we expect this to happen? And how many people will have to be harmed first for it to happen? > Republicans aren't a comic book villain; Agreed, they’re much worse. “We’re going to spend nothing, and when something happens to you, too bad, so sad” under the guise of fiscal responsibility. But if that’s what you vote for as a voter, who am I to get in your way? This isn’t a problem to be fixed, this is an indicator of electorate intent. > What if we took a good chunk of the EPA's budget and distributed it to the local water utilities directly (in other words: Your federal taxes go down, your county taxes go up). This sounds like a recipe for fraud and waste due to the sophistication of those responsible at the local level, with no accountability.
- Spooky23 2y agoThere has actually been a lot of investment in this area, especially in the last few years. Cyber is seen as a risk and most municipal utilities and auditors are treating it as such. The private companies… not so much unless there’s a clear financial benefit or mandate.
- Eumenes 2y ago> Cybersecurity is unfortunately not “sexy” enough for the common American voter to get behind. Government info-sec jobs suck too. Crap pay, red tape, onsite only. Also, alot of security people have ethics surrounding privacy, data security, etc. Why work for a culture that spies on its own citizens, its allies, and engages in global terrorism? The NSA can attract some decent mathematical minds but lacking on the security front.
- tetnis 2y agothe math people work towards the same goal. why single them out
- Eumenes 2y agoThe NSA famously recruits math geniuses and quants to solve abstract problems, esp. around cryptography. If you're a security person hired to harden infrastructure or web services, its not so abstract. People like Snowden for example.
- alephnerd 2y agoNSA's early career recruiting pipeline is pretty strong at the collegiate level. They recruit from a LOT of good universities that top tech employers don't recruit from (eg. UTSA, Texas Tech). The issue is the US Government is hundreds of agencies, and each state in turn has hundreds of agencies as well. Each of these agencies has their own IT that manages that agencies's infra and security AND they are very limited funds wise and salary wise. For example, back when I was a PM, a customer of mine was the de facto CISO of a several hundred person agency yet only earned around $120k a year and had a less than $1M budget for all IT spend. The agency could not build it's own hiring pipeline (having to resort to USAJOBS and the department it was a part of) nor was there any truly unified security platform. While the naive answer would be "have everyone use a single platform", just about every presidential administration in the past 20 years has tried that and failed.
- fsflover 2y ago
- davemp 2y agoIt’s probably necessary for something along the lines of requiring a licensed engineer to sign off on these systems if private companies are going to manage critical infrastructure.
- VoodooJuJu 2y agoI think it'd be a shame if engineers were the ones to make the decision in this case. The decision needs to be made by people with a more serious understanding of risk and fragility, like the military generals, and especially by the people who will bear both the upsides and downsides of the decision, a.k.a. the local community who will be consuming the water.
- Loughla 2y agoThis is one of the few areas where rural living is better, in my experience. Our water, power, and Internet are all delivered by local co-ops. We actually do get a direct say in how the money is spent on our infrastructure. It's one of the reasons why I have fiber Internet whereas the closest town (managed by for profit entity) is still fighting to roll it out years after we had ours run to us. I also got reimbursed by the co-op for the water line to my house when we built the place. I also lobbied the power board to prioritize tree removal near lines for a more reliable service.
- maxerickson 2y agoMy rural "neighbors" pay more than 2x for electricity and don't have any water/sewer service. I live in a small town in a geographically large county that only has about 35,000 residents, so there may be differing ideas of rural at play.
- Loughla 2y agoWe pay more, yes, but not 2x what the city people pay in the next county over. Maybe 1.2x or so. Obviously there is no sewer service, just septic tanks. That cost is minimal once they're installed. Install price was around 5k, and it costs $200 to have it pumped ever four or five years. The definition of rural to me is around 12k residents in a county that is around 1000 square miles. That's the size of where we are. The largest town is around 3k people. Two counties over is a city of about 40k. The 3k town is part of our co-op, so they have fiber. The 40k had less than 15% on fiber the last I knew, but that was two years ago. Since then they haven't run anymore lines, but have added customers on their existing lines.
- elmerfud 2y agoMy core question is, why? I understand that security can be difficult, but why is infrastructure that is able to operate effectively for many decades before micro controllers were even a thing vulnerable to remote attacks. I get having monitoring systems for it that are accessible in a way they could be hacked and disrupted, but why is the core operational infrastructure that way? Command and control should be isolated and be using 50-70 pneumatic tech to control it. Building in such a way to allow it to be disrupted remotely is the core problem here. Just because you can, doesn't mean you should.
- RandomThoughts3 2y ago> I get having monitoring systems for it that are accessible in a way they could be hacked and disrupted Actually it’s very easy to isolate that part. One way network equipments with physical isolation have existed for decades. An optic fibre with only an emitter on one side and only a receiver on the other will do the trick.
- elmerfud 2y agoFiber still relies on electronic circuits. While they can be isolated network wise they are not immune to attacks in the way a pneumatic system is.
- RandomThoughts3 2y agoThat’s irrelevant. Pneumatic systems don’t expose telemetry towards the network. If you want to do that - and you do because having someone next to your equipment all the time to monitor things is both a waste of time and money and very error prone - you will need a data diode.
- Veserv 2y agoIt is cheaper, your product takes fewer people to operate, you can outsource the operations, if you deliver IoT solutions you get to call yourself a tech company which gets you valued at 30x earnings instead of 10x earnings, getting hacked does not affect your stock price, and the actual effect of getting hacked is actually minor because you get hacked by the functional equivalent of Dr. Evil who takes down water for millions of people or cripples a billion dollar business, then asks for the staggering sum of 1… million dollars.
- Eumenes 2y agoNow is a good time to prep. Get a few food grade 55 gallon drum - you can usually find them at food/restaurant supply stores or people trying to get rid of them on craigslist/fb market. Get a dolly so you can move them around your garage or basement. Just need a few teaspoons of bleach to keep it good for ~ 6 months. If your washer is in your basement, you can disconnect the cold line to fill up the drums, or you can run a garden hose. They also make kitchen faucet to garden hose attachments. When you need to drain it, a cheap transfer or sump pump will do the job.
- mindslight 2y agoSpeaking as someone who has the entirety of my heat for this winter stacked up in totes, prepping by storing bulk materials is not really something to be done lightly. Unless you turn this DIY water buffer into something you use in your every day life (ie thirsty? time to go to the basement to get a glass of water), you will get bored of maintaining it long before the municipal water supply fails. Also 55 gallons of water is ~450lbs, so it's not going to be terribly easy to move with an [appliance] dolly. You probably want pallets and a pallet jack (and a smooth concrete floor). Personally I'd suggest getting an RO filter for your every day drinking water needs, and setting up a rain barrel collection that you can routinely use for outdoor garden/plants. Then if you suddenly need drinking water, you should be good just boiling the rain water. And if there is some large scale catastrophe with some kind of chemical/radiological contaminant in the rain, you can run it through the RO.
- Eumenes 2y agoI'm not a strong person and can move around a 55 gallon barrel super easily with these dollys: https://www.amazon.com/Gallon-Heavy-Duty-Plastic-Dolly/dp/B08FSWWBGZ https://www.amazon.com/Gallon-Heavy-Duty-Plastic-Dolly/dp/B0... I can also drain it in < 5 mins with a cheap siphon (I let it drain into a sump basin). So swapping it out every few months is easy. But I agree, a RO filter is great, esp for everyday use. One concern I have with rain water barrel is how its collected. If you have an asphalt roof, there is some nasty stuff in it, and not sure if boiling helps in that situation. Need to do more research there. But its a great idea for watering a garden/yard.
- BobbyTables2 2y agoIf one concludes that >92% of Americans are served by properly secured facilities, that sounds like quite a win! (It’s all about spin) Of course, an example statistic like 99.9% of airline passengers surviving a flight is not all that great…
- arminiusreturns 2y agoYep, got to help with some water systems in small town govs. No care for security and no budget = this situation.
- aaronbrethorst 2y agoWho needs cybersecurity risks when you have an incoming republican administration hellbent on gutting regulations to the benefit of industry, a SCOTUS bending over backwards to help them do it (stare decisis? What’s that?), and a HHS secretary nominee who wants to singlehandedly trigger the next pandemic or two.
- shiroiushi 2y agoRFK isn't going to trigger a pandemic; don't be ridiculous. Pandemics aren't caused by individuals. But, similar to not having any smoke detectors in your home when something catches fire at night, being in a pandemic with him running the health agency is not going to turn out well for you.
- aaronbrethorst 2y agoWhere did I say he's going to trigger a pandemic?
- shiroiushi 2y ago>a HHS secretary nominee who wants to singlehandedly *trigger the next pandemic* or two.
- aaronbrethorst 2y ago>a HHS secretary nominee who wants to singlehandedly trigger the next pandemic or two.
- shiroiushi 2y agoThat still doesn't invalidate my statement. He can't trigger a pandemic; he doesn't have the ability to engineer a virus, and I don't think he's going to find anyone to help him do so. Besides, why do think he wants a pandemic? The guy's a fruitcake, but I haven't seen any evidence that he's actively malicious this way.
- neverartful 2y agoWhy do the water systems need to be connected to the internet at all? If the systems are completely disconnected from the internet there shouldn't be much cybersecurity risk. Of course there still needs to be proper precautions to prevent a Stuxnet type worm getting through.
- lancesells 2y agoYeah I never understand all these systems being connected at all. I understand remote working and monitoring, but is that worth it for something that is the most crucial part of society?