9 ms·
Computer intrusion inflicts massive damage on German steel factory
- dang 12y agoUrl changed from http://www.popularmechanics.com/_mobile/how-to/blog/hackers-control-german-steel-mill-17562155 http://www.popularmechanics.com/_mobile/how-to/blog/hackers-..., which points to this. Edit: and also from http://arstechnica.com/security/2014/12/computer-intrusion-inflicts-massive-damage-on-german-steel-factory/ http://arstechnica.com/security/2014/12/computer-intrusion-i..., which points to this.
- machrider 12y agoOddly enough, the Ars article is just a slight rephrasing that adds zero value beyond the original article: http://www.itworld.com/article/2861675/cyberattack-on-german-steel-factory-causes-massive-damage.html http://www.itworld.com/article/2861675/cyberattack-on-german...
- dang 12y agoThanks! Changed.
- joshvm 12y agoI've done some work in steel factories, though only for offline/closed systems that have no interaction with the main control code. Factories like this one probably operate at around 60%+ capacity, so they'll be operating sometimes all day, sometimes all night. If you ever get the chance to visit, do so, even if you don't really care about how steel is made. The sheer scale of everything is amazing. Everything is very big, very hot and if you have to hit the big red button, it costs a lot of money. Unscheduled downtime is very expensive. Steel tends to be workable when it's hot/molten and therefore pliable. If you suddenly stop a machine then you're left with solid steel in places you don't want it which takes a lot of time and effort to remove. One of the common reactions to this story is "Why didn't they hit the emergency stop?" - the answer is because it costs an absolute fortune to do so.
- fennecfoxen 12y agoTo be more pedantic, the answer is "that was the emergency stop - there's a reason they only use it in emergencies".
- rab_oof 12y agoHow do workers melt solid steel once it's cooled in places?
- userbinator 12y agoBy heating it... large torches are probably required. I wouldn't be surprised if it was cheaper to replace a clogged assembly than to try to melt the steel back out of it.
- pgrote 12y agoI wondered the same and found this informative article: http://www.steelguru.com/article/details/Mzc%3D/_Blast_Furnaces.html http://www.steelguru.com/article/details/Mzc%3D/_Blast_Furna... Fascinating.
- userbinator 12y agoFascinating indeed. Here is a related article about an explosion that happened while trying to restart a chilled furnace: http://www.hse.gov.uk/pubns/web34.pdf http://www.hse.gov.uk/pubns/web34.pdf
- ArchD 12y agoI never understand why people need to connect industrial plants to the Internet. Do they actually need to control them over the Internet instead of on-site? And, if they need to use the Internet on-site, can't they make an air gap and segregate the computers that can access the Internet from computers that can access the plant machinery?
- ArchD 12y agoOK, granted they may want to monitor the plant remotely. Then they could have a plant-connected machine dump UDP monitoring packets to an Internet-connected machine, and have the plant-connected machine block all incoming packets from the Internet-connected machine.
- gear54rus 12y agoIt seems that there are many ways this could be done right (and does not seem a particularly hard challenge), it's just that people in charge probably were pretty much inept at that task. You know how it is, no one cared about it until it happened. It just wasn't a priority.
- spacecowboy_lon 12y agoI get the impression from dealing with german companies that they tend to be very good at traditional "engineering" but when it comes to it/computers they are 10 or 15 years behind. I also think that in germany its considred that the good engineers and asociate profesionalas want go and work for firms like Audi.
- fidotron 12y agoIt's not just Germans. Anyone that isn't primarily in software has this phenomenon. Mobile phone makers, for example, are a disaster, and it's only having a whip wielded by a software company with some power over them that prevents it becoming a complete train wreck. In my experience the most dangerous are engineers in other domains that learned just enough programming to get the job done but can't understand the giant holes they've created and not run into.
- DaveSapien 12y agoThis sounds like an inside job, seems too specific (and obscure) an attack. Idle speculation, maybe a disgruntled ex-employee's offspring? Who knows.
- higherpurpose 12y agoStuxnet made it "acceptable" to do this. I hope the US government recognizes that.
- warble 12y agoBecause when I hack to destroy I always wait for the US Government to do it first.
- xnull2guest 12y agoWell, I think what the parent is saying here is that the United States set a precedent for other nation states to engage in destruction of industry when they see national security or state advantages - while the myth of America being a fair and even handed juror of world affairs is not true, it is pervasive, and it (and the "West") is used as a basis for comparison. It also provides an out for a state actor who is caught and there is an attempt at an international judicial (rather than military) response: they can point at Stuxnet and suggest (convincingly IMO) that the United States should face the same standards of judgement and if they stand up a proportional reprimand. This gives an additional sort of 'insurance'. I would disagree with the parent that Stuxnet is the same type of activity (it's private industrial sabotage rather than state military sabotage). The papers with the most lip service regarding cybermilitarization (inside the US) try to suggest international norms by breaking types of operations down into an ontology that separates national security operations and military operations from activities that interfere with private enterprise, citizens and from infrastructure.
- deleted 12y ago[deleted]
- s_q_b 12y agoActually the Trans-Siberian pipeline made this acceptable, which was a cyber attack in peacetime responsible for the largest man-made non-nuclear explosion in history. Or the Turkish pipeline attack. Or the Enigma Machine hack. The crucial parts of warfare systems are C4ISR: Command, Control, Communications, Computation, Intelligence, Surveillance, and Recognizance. Computer systems have been a target of covert ops for as long as they have existed. What's happening now is that middle-weight nations (North Korea, Iran) and non-state actors (Anonymous, al-Qassam) are now able to get in on the game, which is disrupting the status quo established by the USA and USSR.
- ars 12y agoAnyone know what's the motivation? People do not work that hard to destroy something without a reason. Someone was really mad at them - ex employee maybe?
- nisa 12y agoI doubt it's another steel manufacturer but who knows? Maybe someone in the business with connections to black hats had some money to spare and said: Look what you can get going about this cyberwar stuff everyone is talking about... There is also this: http://www.heise.de/security/meldung/Verwundbare-Industrieanlagen-Fernsteuerbares-Gotteshaus-1902245.html http://www.heise.de/security/meldung/Verwundbare-Industriean... (In german)
- bostik 12y agoI have to admire your cynicism. To consider that this attack might have been nothing more than a sales demonstration... That's a scary thought, even as it sounds like something out of a James Bond film script.
- saalweachter 12y agoWhy does it have to be someone with a solid motive? The companies attacked always go on about how skilled and unstoppable their attackers are, but for all we know their software was terrible and a bored 13-year-old shut down their factory because 13-year-olds do terrible things for no reason because the parts of their brains that let them tell good ideas from bad ideas haven't grown in yet. The guy responsible for the shit software isn't going to tell the CTO his software is shit, the CTO isn't going to tell the CEO his department is incompetent and needs a good house cleaning, starting from the top, and the CEO isn't going to admit culpability to the insurance companies and shareholders who are ultimately on the hook for the damages.
- ars 12y agoBored 13 year olds usually try to be flashy or show off, but they rarely spend significant effort really causing damage. There's just nothing in it for them to actually cause damage, when demonstrating the potential to do so (without actually doing so) provides all the benefits (bragging, etc.) with much less risk. Yes, you can have one deranged person doing it, but it's just not likely.
- Animats 12y agoThe German document isn't that useful. It's just a general overview of computer security with anecdotes, not a technical analysis of this attack. Interestingly, there was a cooling water leak and an emergency shutdown at a steel plant in Pakistan in October. That plant is still off line. That's probably unrelated, though. http://www.newspakistan.pk/2014/10/27/pakistan-steel-mills-remain-shut-3-weeks-sign-resumption/ http://www.newspakistan.pk/2014/10/27/pakistan-steel-mills-r...
- frik 12y agoMore background info about the incident: https://translate.google.com/translate?hl=de?sl=auto&sl=de&tl=en&u=http%3A%2F%2Fwww.heise.de%2Fsecurity%2Fmeldung%2FBSI-Sicherheitsbericht-Erfolgreiche-Cyber-Attacke-auf-deutsches-Stahlwerk-2498990.html https://translate.google.com/translate?hl=de?sl=auto&sl=de&t... Steel plants run for years without a shut down, so this was a large scale incident as the had to shut it down because of major damage. Not related to the plant in Germany in any way, just to get you an idea how some other steel plants operate: C# WinForm based GUI control room app and Java based server app on Windows server. The server controls the various SPS. Several steel plants around the world were build with that software setup and it was not designed to be connected to the internet.
- spacecowboy_lon 12y agoThe register has speculation that it was a Thyssen Krupp plant in Brazil I susepct that if it had been actualy ingermany there might have been better security.
- brazzy 12y agoNope. Just last year, Germany's biggest IT magazine ran an article about hundreds of industrial systems having remote control UIs with insufficient security (unencrypted login, default passwords) exposed to the internet.
- spacecowboy_lon 12y agoBut where they hacked?
- mokash 12y agoParticularly relevant for me since I'm currently reading Countdown to Zero Day.
- sqeezy 12y agoi am working in a steel plant for over 20 years now, and it is easy to bash the security of those people. but just some facts from my world :-) first those plants are build for lifespans of over 30 years. general problem is 15(normal review time) years ago no one was thinking about network security as we thinking about it know . most businesses didn't even have a large internal network wich did include the production and were connected to the internet. second you can't just shutdown this things. if you have to shutdown a blast furnace we are talking about minimum stand time of 5-7 days. calculate about 400k to 1m € per day on standstill cost. and that is only for the blast furnace. if the blast furnace is not running in some steel plant NOTHING will run. (e.G. hot rolling plants) third there is no good solution on the market. if some of your guys would look into the software wich is sometimes running those large machines you would get sick to your stomach. As a more security focused person in my plant just to convince management to change the std admin passwords was a handful (well that changed like a year or two years ago). The thing is market decides what security is gonna be implemented. since there has now been a breach and a very expensive one most companies i am talking to are more focused on security now. The thing is they won't just throw away their software stack they worked on for 30 years. and reviewing software is hard and time consuming. so it will be interesting how this is developing. and no i am not working in that plant ... :-) and sorry for the bad english
- nightcracker 12y agoYou can make your English look a lot better by starting every sentence with a capital letter, and capitalizing the word "i".
- rab_oof 12y agoSpelling feedback is bike-shedding. The content is fine.
- niels_olson 12y agoIt's an interesting case of misplaced good intentions though. Here's someone with good intentions providing direct, actionable feedback. And getting negative feedback. It's how the system is supposed to work, but I hope a lot folks realize their well-intentioned comment that gets downvoted might well be getting downvoted for similar reasons: your good intentions are misplaced.
- afarrell 12y agoTo do external monitoring, couldn't you have the computer for the plant display the information on a screen in a particular font and then an internet-connected computer read the video and OCR it?
- rebootthesystem 12y agoI can't help but feel there's a rush to judgement here. If you read the article it clearly states that the Federal Office for Information Security (BSI) said, quoting the article: "describing the technical skills of the attacker as “very advanced.”" And "not only was there evidence of a strong knowledge of IT security but also extended know-how of the industrial control and production process." And HN rushes to judgement to quickly blame workers who can't use a mouse and Microsoft. Yes, the average worker in a manufacturing plant is not a CS grad. It is the job of engineers to develop systems that are usable by, well, the target user. Most Heart Surgeons don't have a CS degree. And based on meeting a number of them during the course of my business I am comfortable saying that quite a few of them are "computer challenged". Yet, most of us would not have a problem being on that operating table, yes, with a room full of computers, a good number of them running MS software and with an OR team that is likely to use the same "123456" password on everything. In a hospital you have IT and engineers who setup an infrastructure medical professionals can use. The same is true of steel plants. Yes, there's probably a lot more older code in your average steel plant. I just don't think characterizing them as IT or security morons migt be fair. The BSI characterized the attackers as sophisticated across disciplines. Let's not engage in senseless conjecture. I've owned and operated a small manufacturing plant consisting mostly of what I call "big iron" CNC equipment. Things are seldom as simple as discussions on various fora on the 'net would like them to be. Yes, in my case I air-gapped the plant and even individual machines and remote monitoring was done through a separate network that had no command-and-control capabilities at all, just sensing and reporting. There was no way to jump from the sensing network to command-and-control of any one machine, much less the plant. Even if you were physically at the factory this was pretty much impossible. Nobody wants a CNC milling machine with a 30HP spindle controllable from the internet. People are not that stupid...even if they can't use a mouse.