2 ms·
Don't put your PLCs directly on the internet. In fact most industrial stuff is very not made to be directly connected to the internet. But interpose a firewall
by Kim_Bruning 2mo ago
Don't put your PLCs directly on the internet. In fact most industrial stuff is very not made to be directly connected to the internet. But interpose a firewall+VPN solution and you might be ok, if done competently.
And remote access to hardware definitely makes management and maintenance a lot easier and quicker. (else you need to drive out for every minor issue)
- tomsanbear 2mo ago"If done competently" is a bold assumption unfortunately, not just these days but always
- closeparen 2mo agoIf we can beat a security-state airgap by sprinkling USB drives in the parking lot, I think the Iranians can beat an "internal" network by getting someone to click on an email attachment or visit the wrong website on their municipal issued Windows machine. It's very common for the proprietary software for interfacing with ancient, expensive machines to break after OS upgrades, so they're probably unpatched... you might not even need to burn a 0-day.
- Kim_Bruning 2mo agoWhich would then tunnel through the VPN and still hit the PLC. Right. "But we need it on our windows computer" is not an entirely unreasonable ask. But security is only partially served.