CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

  • khepri@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    22 hours ago

    So are we just kind of admitting that there exists no way to expose any networked device to the internet securely? Because if it’s not possible for PLCs I don’t see why it would be possible for any device. If water utilities have to take these offline, then how does that advice not apply for every internet-capable device in every commercial and industrial facility worldwide?

    • emergencyfood@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 hours ago

      There are ways, but they are costly and complicated and do not stop all attacks. So the golden rule is that if critical infrastructure doesn’t need to connect to the internet, it shouldn’t.

    • Archr@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      22 hours ago

      I don’t work directly with PLCs but we do have them at my work. The main thing that makes these different from any other devices is that they typically control physical machines. Which means there is a real danger that them becoming compromised could lead to damaged equipment or even death.

      Additionally, many PLCs use older OS versions like xp because their software is notoriously out of date (if it’s working why rewrite it when that could introduce safety concerns)

      This “urgent” message from CISA does not prove that any of these devices are internet accessible just that if they are then they should be removed. If CISA wanted to require this then they would have released a binding operational directive (BOD) or an emergency directive (ED). Both of which are publicly viewable on their site.

    • historicaldocuments@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      14 hours ago

      So are we just kind of admitting that there exists no way to expose any networked device to the internet securely?

      It’s done all the time. It’s not a product you can buy, though, it’s a process. There’s probably a good “go by” for how to start the process for citywide infrastructure, but it’s just one more document for people to ignore.