6 ms·
It's a great question, and as someone heavily involved in industrial control systems, I ask myself and others that a lot. The only real reason I've heard comes
by dsuth 13y ago
It's a great question, and as someone heavily involved in industrial control systems, I ask myself and others that a lot.
The only real reason I've heard comes down to cost and support. It's easy to develop software for Windows, easy to find developers, easy to support the operating system, easy (debatable) to use in an industrial environment. It's a known factor.
Always remember that people on the shop floor (or hydrocarbons refinery equally) aren't interested in maintaining a PC they don't understand, and their management aren't interested in maintaining a well-educated IT department. It's a simple cost/benefit equation, and so far the benefits have been completely ignored.
Likewise, vendors of control systems don't want to put the time and effort in to develop their IDE's, display tools etc for a Unix variant. System integrators (ICS programmers and configurators)... well, we'd be cool with a Linux-based control system, if it worked well.
That's why you see Windows in industrial control environments. Couple this with the extremely conservative nature of industry, and you have a huge, glaring problem. We (ICS engineers) know it's a problem, clients are starting to realise it's a problem, but the wheels move slowly.
At least Stuxnet has made the wider industrial community aware of just how deep the shit is. Now begins the slow process of crawling back out of it.
- gcb1 13y agowhat proves that running windows is the least concern. they would have added some suid crap listening out for reason had this been linux or anything else. this is just negligence. it is the same as bridge falling it two trucks drive there at the same time. everyone would be fine blaming the architect, engineer, construction company, politician that paid for etc... that happens in software, it is nobody business.
- atmosx 13y agoSorry but in this scenario maintaining a 5-person skilled IT department was/is imperative. The TCO should of the IT department, even if you hire D. Hartmeier[1] to configure the firewalls, should be negligible compared to the operation's TCO. That said, in this case I believe that the software to manage the centrifuges is made by Siemens (Germany) and it's written on Windows. So partially it wasn't the consumer's choice to use windows. Even if they used linux, is not hard to think that the NSA could have written a Linux clone worm. The only thing that can keep away such threats is "security" as Schneir mentions here[2] "security is a process" and that process can secure any operating system out there imho. [1] http://www.benzedrine.cx/index.html http://www.benzedrine.cx/index.html [2] https://www.schneier.com/crypto-gram-0005.html https://www.schneier.com/crypto-gram-0005.html