3 ms·
There are many wireless pump-and-reservoir systems that while not internet connected, use insecure RF links. These local RF (and casting a wider net, Bluetooth)
by clbrmbr 2mo ago
There are many wireless pump-and-reservoir systems that while not internet connected, use insecure RF links. These local RF (and casting a wider net, Bluetooth) interfaces are also ripe for abuse.
- Wowfunhappy 2mo agoWouldn't the physical facilities themselves have security?
- lokar 2mo agoI assume they are talking about things like water towers that are spread around, and linked back to hq via insecure wireless.
- amluto 2mo agoYou can also find all kinds of interesting water infrastructure, often with no electronics, all around town. It rarely has any sort of security beyond a padlock.
- procarch2019 2mo agoYou’d be surprised how insecure some of these facilities are, especially to someone who has working knowledge of what a PLC (or other process controllers) does and how it works. You can easily look like a tech who belongs there either troubleshooting something or working on a project. I’ve been doing industrial controls for 15 years and surprisingly infrastructure is some of the most poorly funded. I believe a lot of these places are run by operating companies, so it’s bidded out (we all know how bids work I think). I’m not surprised when I walk into these places and see the computers are running EOL operating systems and the networking is essentially flat.
- Wowfunhappy 2mo agoOkay but then is the RF connection really your biggest concern? I'm kind of worried (probably unnecessarily) that posting ideas would get me on some list, but it seems like there would be many simpler terrorism opportunities once you have physical access.
- bobmcnamara 2mo agoHistorically people just shoot pipelines and transformers.
- tialaramex 2mo agoWWII provides some interesting data points. On the one hand, yes, as Germany occupied numerous neighbours people - even sometimes in the face of group punishment, kept sabotaging the German military and its logistics. In some cases there are literally enemy agents, the Special Operations Executive† but often they're local partisans either working with the SOE or on their own. But on the other hand, even though the Americans suspected that people who merely looked Japanese might be traitors, AFAIK there aren't any clear examples where the people who were sent to camps actually were enemy spies who'd have sabotaged America given the chance. And in Britain the counter-intelligence operation was so successful that when captured German spymasters revealed their list of agents in Britain, every name was already either working for Twenty Department (20 = XX = Double Cross, we can't resist a pun) or in prison for espionage or dead. † notably in WWII if as a woman you say you want to be on a ship of the line, or crew front line aircraft and attack the Nazis you will be told women can't serve front line roles and at most you'll be doing delivery runs in relative safety. But if you know the right people to become a spy they will cheerfully send you behind enemy lines even though if caught you will almost certainly be horribly tortured and then probably killed and the government which sent you won't even acknowledge you existed for years. So, maybe the risk from people who are already where your infrastructure is is much lower that you'd think if you haven't invaded them and occupied their land. On the other hand remote adversaries are definitely always a risk.
- amelius 2mo agoForgive my ignorance but isn't a PLC simply a computer with some GPIO ports? I.e., a Raspberry Pi could be called a PLC? Why are we talking about them as if they are something else? Is it an exotic OS that makes them different?
- stackghost 2mo agoIf a Raspberry Pi had industrial environment ratings and was certified hard real time, then yes it could be considered a PLC. All the ones I've encountered in the wild ran VxWorks
- Kim_Bruning 2mo ago> If a Raspberry Pi had industrial environment ratings and was certified hard real time, then yes it could be considered a PLC. Ostensibly yes, but so far I haven't seen anyone really use a PLC in a way that requires hard real time (so far). The cycle on eg a siemens S7-1200 is anyway much too slow for anything really exciting, and a Pi might very well be more reliable in actual practice, were it not for the very unfortunate tendency to eat SD cards. :-P (And revolution pi actually ships a hardened Pi for industrial use. So that's one way to go about it. I'm not a big fan of that brand, but it's a data-point. Meanwhile in personal experience some regular pi's left in industrial cabinets for one-off emergency monitoring purposes have managed to stay annoyingly alive over time.)
- tamimio 2mo agoNot really, sure you can use a rpi to control some hw but they are not the same, a PLC usually run rtos, is deterministic (you can predict timing) while rpi relies on linux OS and its scheduler, the PLC also uses ladder language or function block compared to rpi high level language, and obviously PLC industrial grade I/O both analog and digital that also deal with voltage noise that usually happens by field sensors, and environmentally rugged and rated to run non stop compared to rpi. Now, if you really want to use rpi as a plc, you need something like openplc or codesys as a runtime, add some HATs for I/O, and use protocols like modbus. It will be a software plc but you are missing the hardware certification and other features. Rpi is good as edge computing rather than plc, like processing vision or data logging, it’s why in drones you need the autopilot AND rpi or companion computer, each does certain functions.
- KellyCriterion 2mo ago> so it’s bidded out < Na, bro! Today we call this "public private partnership" :-D
- lll-o-lll 2mo agoRF as in radio. Radio waves have this nasty habit of leaking out past the fence: https://cyote.inl.gov/content/uploads/24/2025/12/CyOTE-Case-Study_Maroochy.pdf https://cyote.inl.gov/content/uploads/24/2025/12/CyOTE-Case-... In water/wastewater much of infrastructure is physically remote and physical security is the typical engineering trade offs. https://validmfg.com/product/lift-station/ https://validmfg.com/product/lift-station/ Inside this box you have access to the “production” network, if you will. Unfortunately, most SCADA systems implicitly trust their RTUs/PLCs, so this has always been a weak point for the system. Hopefully the situation has improved. The reality is that critical infrastructure is rarely tested against genuine hostility, except in times of war. There is “cyber” activity going on all the time, but attacks that require physical proximity will probably only happen when things have escalated to hardware. Hopefully the NSA’s of the world run “pen testing” for these companies from time to time.
- clbrmbr 2mo agoThe range on one RF system I worked on was 2mi with a wet noodle for an antenna.
- barbazoo 2mo agoIf that means you need to at least be physically present then I'd say that's a lot of protection already. Means someone in a foreign country can't simply get lucky fuzzing.
- judge2020 2mo agoAlternatively, small drones exist, and so do low power devices you could slingshot/shoot into a secure area and set to auto wipe after they've done their job. Maybe could even build it out of biodegradable material so it'll clean up in short time.
- closeparen 2mo agoIf you've got secret agents on enemy soil who can get near targets with drones, you're probably just bombing them.
- judge2020 2mo agoUnless you're running out of munitions. And nuclear isn't exactly a great option.
- throwitaway222 2mo agoModern warfare is sneaky. What's the worst you can do without starting an actual war? Plus what's the point of retaliating if the actual combatant was just "an insane person from another country". IE - There's no way to prove he's working for the CCP or IRGC, for example, maybe he's just a crazy person.
- thrill 2mo agoWhy bomb something, which carries its own risk profile and success criteria, when you can make some piece of equipment malfunction just enough to wear out in a year instead of 20 years?
- mapkkk 2mo agohell, you could even fedex them your own remote hands a la LTE modem tied to an rpi.. you could do what you need to by the time someone gets around to opening the box