Water system controllers don't belong on the internet, says ex-NSA chief (theregister.com)
152 points by Bender 7 hours ago
aliasxneo 6 hours ago
Part of my career encapsulates a period where I was a PLC programmer, installer, commissioner, and troubleshooter for massive build outs (sky scrapers, data centers, laboratories, factories). Interestingly, this was after years of teaching myself software engineering, eventually participating in large open source projects. The clash of entering the PLC world was _extremely_ harsh.
Let me give an example: I once worked with an integrator who was working on an AHU feeding an extremely critical portion of a datacenter (I was a lead by this point and mostly played babysitter). During certain points of the day you couldn't open the door to this room due to negative pressure because the logic was over-ramping the exhaust fans. As I watched this contractor work, I saw him open his laptop, with Windows on it (because Microsoft has had a death grip on this industry for decades now), and proceed to backup the PLC program into a massive folder with God knows how many other "customer projects" he was carrying around in this thing. He then proceeded to go do some physical checks in the field, came back, and prepared to upload the fixed program. As I watched, I noticed he _grabbed a backup from ANOTHER customer_ and I immediately had to intervene. Who knows what untold damage I saved from that single move.
I tell this story to demonstrate just how far into the dark ages this industry is. I vividly recall coming into the data center for a fortune 50 company, one everyone here would know, and being astonished that they had never heard of Network Attached Storage or RAID and why they might want to consider a disaster recovery plan for their multi-million dollar mechanical plant.
This industry is in _desperate_ need of strong technical help, but unfortunately the "higher ups" tend to be the same people who are "comfortable" with the way thing are and refuse to move. I literally tried for a decade before giving up and moving into software engineering proper.
So, anyways, just imagine the most archaic and barbaric set of IT software, controls, and procedures, dumb that down even further, and you've landed on the infrastructure/teams that operate probably half of critical infrastructure.
amluto 4 hours ago
Another odd observation about the industry. For better or for worse, I inherited a little system controlled by a Fanuc PLC. It had a bug and would occasionally get stuck in a bad state. By some minor miracle, I managed to track down the person who had originally programmed it (now retired and moved out of state), and he emailed me a file and introduced me to his apprentice (who lives in a third state). I found a trial version of the design software, opened the file and found the bug (despite never having seen this style of programming before). Since I had no way to upload a new file (and since it wasn’t clear that uploading it without a matching outdated and not easily available copy of the programming environment would be wise), I convinced the apprentice to come visit while we was nearby for another client. He did not see the bug even when I pointed it out, but I convinced him to make the change and upload the modified file. Now the system works. (He had a Windows laptop with a giant folder of customer files, of course.)
While he was on site, I asked him why there was nothing on the PLC or its enclosure to identify his old boss or give any contact information, and he seemed surprised and told me that no one ever does that. I asked how a new owner is supposed to get support, and he shrugged.
If this thing ever fails, I’ll probably replace it with an Arduino or an ESP32 or something along those lines. Or I’ll just find something off the shelf to replace the entire system.
polishdude20 3 hours ago
The best thing they could do to new PLC's would be to have the src code live alongside the firmware inside. So any new person would be able to open it and reason about it.
ssl-3 3 hours ago
coryrc 3 hours ago
steve_adams_86 5 hours ago
Everything you're describing mirrors my experience with remote scientific deployments and lab equipment (wet labs in particular). I support a team which manages dozens of these, and while it's shocking how inefficient and unsafe their practices are, it's similarly shocking how poorly the industry has kept up with or even tried to establish better practices. We get brand new equipment that costs in the realm of $10k for a tiny logger, and the thing is barely capable of remotely managed deployment of version controlled firmware. There are no tools in place to allow proper testing of the firmware unless you have the cash to buy extras and build test harnesses from them. The firmware itself is often in languages that don't have proper testing frameworks, type systems, IDEs, etc.
It's HARD to do the right thing. Dragging and dropping files into proprietary hardware management programs is the de facto standard.
Then you layer on top the unfortunate reality that sometimes electricity does weird stuff, people design weird circuits or wire the wrong components in, and firmware tends to have to deal with non-deterministic inputs a lot more often than, say, an API on the web. It's rough.
The pay is also so much worse in my experience.
analog31 4 hours ago
>>> The pay is also so much worse in my experience.
The result is that anybody who can program well enough to develop software is doing so. Those with any programming skills who remain behind are smart-but-undisciplined programmers, people who have a reason to be in a particular geographic area, too old to think about changing careers, or just plain nuts.
This is what "lack of investment in manufacturing, research, and infrastructure" looks like. Sow what you reap.
Disclosure: I might be one of those people. I came out of grad school in physics research, and programmed an entire plant. Thankfully, that was before it was economical to put every controller on the Internet.
b40d-48b2-979e 4 hours ago
Not only is the pay worse (like literally half of what you make doing webdev for a corp), but they mandate you be on site at a factory working first shift like you're on the production floor or something, clocking in and out when you're a salary worker. It's an awful culture.
technion 5 hours ago
Im supposed to be doing endpoint work with people working in this field amd basically have to convince compliance they'll need to be local administrators to do their job. They get onsite and dont know what app they'll need until they look at a plc model. They'll download something from a .tw ftp server and its an unsigned executable that absolutely must run as admin to program these things.
It is amazing how much of the sysadmin community just doesnt believe this is a thing you need to work with, everyone insisting its just security people being lazy and so on.
tedd4u 3 hours ago
Oof, that's bad. Iran got burned real bad by Stuxnet, you know they would love to score big with PLC sabotage.
hackernud3s 32 minutes ago
Kim_Bruning 5 hours ago
Oh I can tell stories too! Meanwhile these guys often have huge amounts of practical experience as electricians or control technicians/engineers to go with their PLC skills, so you can't just say we should get rid of them either.
Breaking into the industrial market is tricky if you don't have connections too. And if you're hired as the PLC programmer, it's sometimes an afterthought AFTER the plant is already built. "What do you mean it'll take another month? The plant is finished, isn't it?".
Oh, and some projects ban "PC"s to begin with. Which sort of excludes any kind of PC programmer. And it sort of even makes sense. A lot of default PC behaviors (especially commercial software), are no longer user-unfriendly but potentially very expensive or even user-lethal when attached to a physical plant.
Sounds like I could learn some things from you (and maybe vice versa). Poke me on the email in my HN profile!
aliasxneo 5 hours ago
Yes, I don't mean to poke fun solely on the integrators. I've seen the "software first" type land in the same role and flail just as hard, if not harder. I recall one individual, who was quite proud of his "beautiful" ladder logic code, after about 3 months of being at the company ended up destroying a $100k+ chiller plant by cavitating all of the pumps because they didn't understand head pressure.
I think that's one of the core difficulties with PLC programming. You have to have strong knowledge on traditional science fields like thermal dynamics, material sciences, fluid mechanics, etc., while also understanding the limitations of a 16 bit floating point integer and why overflowing that can be catastrophic.
amluto 4 hours ago
elevation 5 hours ago
A colleague of mine transitioned from a senior IC role to manager of a PLC group in the same company. Their methods were just as unsophisticated as you describe, and now he is attempting to evangelize/impose the finer parts of software engineering discipline, such as source control and integration tests (which can be trickier when it requires a hardware test bed.) Bringing some new tools to bear can be a fun job, as long as the team trusts you.
aliasxneo 5 hours ago
Yes, the fortune 50 company I spoke of was running some of the most advanced data centers in the world. There was literally a team of world class IT specialists walking the same corridors as the industrial automation team but they might as well have spoken different languages.
I remember a time where I was beating the drums on security and ended up in a meeting with a senior red team member in the company. This person was absolutely convinced we were not running Windows Server 2008 anywhere in the company (the year was 2019 at the time of that meeting). Needless to say, he was very concerned when I showed him the 50+ servers running it globally, all covering critical infrastructure.
I think eventually Ragnarok will happen and things will improve. I just hope it's not as detrimental as it seems setup to be.
AlotOfReading 5 hours ago
integration tests (which can be trickier when it requires a hardware test bed.)
I use this as a fizzbuzz-type test when I'm interviewing at hardware companies: do they have development hardware in a rack with programmable power supplies and mini-PCs (or similar)? It's a low, low bar for testing, and rules surprisingly many companies.They'll often just have The Guy running manual tests instead.
procarch2019 3 hours ago
Sounds like we have a similar development path. People fail to understand how complex some of these systems can be, especially since you have to have the project to understand what registers/variables are what. Some when Joe the contractor does a job and walks away, you better make sure they give you the project and you store it in a nice safe place.
A good system integrator is worth their weight in gold. Sure they cost more, but getting a whole package turned over to you is worth a million more than 5 years into the lifecycle of a factory when someone wants to make mods/fix a bug/etc and has to reinvent the whole car, not just the wheel.
This industry is always 10-20 years in the past. My company’s preferred vendor only just started supporting virtualization (this is for a DCS) in the past 10 years. I still have to tell my sales people to provide A/V and minimalistic backup and recovery on every project (they essentially cost nothing compared to the rest of any project).
closeparen 2 hours ago
I enjoy watching Cursed Controls on YouTube. For him, the gold standard is a flash drive with the program on it physically hanging out in the control cabinet.
xtajv 2 hours ago
Storytime: Once upon a time, I was a young grasshopper at a small consulting firm at which every employee was issued a Windows machine, our source control system was "\Customers" on C: drive, and our deployment strategy was "putty + copy-paste + hot-reload".
One morning, I heard something terrible while my boss's boss's machine was booting. Something akin to grinding. The thing was angry.
I gave boss^2 a heads-up that his hard drive might be failing, and that he might want to run a S.M.A.R.T. check on the poor thing. I also asked where the backup hard drives were, because I was brand-new and assumed that I just hadn't been issued one yet.
I checked the supply closet, found no hard drives, popped over to the office admin person, and recommended a deal I'd seen on some WD black drives before I realized that the place had gone quiet.
Everyone looked at me like I was from Mars.
Exactly 7 days later, boss^2's hard drive failed. We lost a week of work and had to zero out a 5 days x 3 employees worth of billable hours. We also ended up delivering late.
The client was pissed.
Based on the nasty looks that I got afterwards, it appeared that the standard assumption was that I had tampered with the drive to prove a point. (Um, nope).
I have since learned to ask prospective employers about their backup strategy.
TacticalCoder 5 hours ago
> So, anyways, just imagine the most archaic and barbaric set of IT software, controls, and procedures, dumb that down even further, and you've landed on the infrastructure/teams that operate probably half of critical infrastructure.
Same with SCADA: just as bad as what you describe.
aliasxneo 5 hours ago
We once reversed engineered Schneider Electric's ION protocol because they wanted to charge us $10k per "seat" to get software that could interact with it directly. We took home a controller and developed a Python program that could intercept and understand the RS-232 comms. We then developed our own system to interact with it. It was all unencrypted. I just did a quick search and it looks like "Secure ION" is now a thing, introduced in the year 2023. Which just proves my point.
tamimio 4 hours ago
The worst part -as I mentioned in another comment few days earlier- is most of the network is ancient, dialup, poor architecture designed by people who barely touched a computer, very old OSes, one utility had windows 3.1 a couple years ago! For them as long as it’s working, don’t touch it, because a downtime is far more costly and it will bring many eyes and attention to them than just sit and hope nothing will happen. Physical security is a major gap too, I have been to many locations where the field server panels are just behind the door, the RTUs are just closed with panel keys, even the whole facility are using some old HID cards that you can unlock in few seconds, this is even in R&D that beyond automation but also in robotic ones.
chmod775 19 minutes ago
At modern population densities, basic infrastructure breaking on down on a large scale can kill millions in a matter of weeks.
The largest threat isn't bombs falling on our heads, it's incompetent fools leaving the door open to their enemies.
These aren't mistakes that can be excused. Failing in one's duty to steward important infrastructure must mean immediate replacement of leadership.
clbrmbr 6 hours ago
There are many wireless pump-and-reservoir systems that while not internet connected, use insecure RF links. These local RF (and casting a wider net, Bluetooth) interfaces are also ripe for abuse.
barbazoo 5 hours ago
If that means you need to at least be physically present then I'd say that's a lot of protection already. Means someone in a foreign country can't simply get lucky fuzzing.
judge2020 3 hours ago
Alternatively, small drones exist, and so do low power devices you could slingshot/shoot into a secure area and set to auto wipe after they've done their job. Maybe could even build it out of biodegradable material so it'll clean up in short time.
closeparen an hour ago
Wowfunhappy 6 hours ago
Wouldn't the physical facilities themselves have security?
procarch2019 6 hours ago
You’d be surprised how insecure some of these facilities are, especially to someone who has working knowledge of what a PLC (or other process controllers) does and how it works. You can easily look like a tech who belongs there either troubleshooting something or working on a project.
I’ve been doing industrial controls for 15 years and surprisingly infrastructure is some of the most poorly funded. I believe a lot of these places are run by operating companies, so it’s bidded out (we all know how bids work I think). I’m not surprised when I walk into these places and see the computers are running EOL operating systems and the networking is essentially flat.
amelius 5 hours ago
Wowfunhappy 6 hours ago
lll-o-lll 4 hours ago
RF as in radio. Radio waves have this nasty habit of leaking out past the fence: https://cyote.inl.gov/content/uploads/24/2025/12/CyOTE-Case-...
In water/wastewater much of infrastructure is physically remote and physical security is the typical engineering trade offs. https://validmfg.com/product/lift-station/
Inside this box you have access to the “production” network, if you will. Unfortunately, most SCADA systems implicitly trust their RTUs/PLCs, so this has always been a weak point for the system. Hopefully the situation has improved.
The reality is that critical infrastructure is rarely tested against genuine hostility, except in times of war. There is “cyber” activity going on all the time, but attacks that require physical proximity will probably only happen when things have escalated to hardware. Hopefully the NSA’s of the world run “pen testing” for these companies from time to time.
lokar 6 hours ago
I assume they are talking about things like water towers that are spread around, and linked back to hq via insecure wireless.
amluto 6 hours ago
jacobgold 5 hours ago
With coding agents now being used for hacking, there's a decent chance we'll see a 9/11-scale hacking incident as a result of NSA/DHS negligence in securing American internet-connected services. Similar to how the CIA's negligence allowed 9/11 itself.
The USG should be deploying thousands of security engineers armed with the latest coding models and agents, in attempt to secure systems before they're hacked. A few billion dollars spent here could save us trillions.
pigbearpig 4 hours ago
How is it NSA/DHS negligence? Neither is responsible for securing the infrastructure of state and local governments nor private companies.
They should provide guidance, but I’m not sure we really want the NSA inside of networks more than they already are.
If voters and CEOs don’t want to spend the money required to secure their infrastructure, that’s on them.
vharuck 29 minutes ago
DHS has the Cybersecurity & Infrastructure Security Agency. Their job is to help organizations in the US with protecting public services and physical infrastructure. They are partially responsible for the outcomes.
ooterness 4 minutes ago
judge2020 3 hours ago
> How is it NSA/DHS negligence? Neither is responsible for securing the infrastructure of state and local governments nor private companies.
It is not a duty nor their responsibility. It is however bad for nation overall if companies don't dedicate some resources to security, so a sane administration will do something to advocate for it.
bjt 5 hours ago
Unlike the CIA and/or FBI being in charge of preventing attacks like 9/11, NSA and DHS aren't in charge of each state's or city's infrastructure. They could run some opt-in program that local governments could then engage with, but "negligence" is a bit strong for systems they're not in charge of and have no access to.
tony69 4 hours ago
“Not in charge of” can agree
“Have no access to” I have doubts
ungreased0675 4 hours ago
https://www.nsa.gov/Cybersecurity/Cybersecurity-Advisories-G...
While that’s not the job of the NSA, they do produce a lot of good cybersecurity guides.
jacobgold 4 hours ago
NSA's job is SIGINT, so it's at least partly their responsibility when the threat is foreign.
For example, the NSA should be successfully infiltrating every major foreign hacking team in the world and monitoring and/or disrupting their activities.
judge2020 3 hours ago
1970-01-01 7 hours ago
He is wrong and right. They should be connected to the Internet when they aren't 30 year old PLCs ripe for abuse. Until then, cut the data lines and do water monitoring the old way.
eek2121 6 hours ago
Disagree. Why connect them to the internet? They should be super hardened against attacks, and should NOT have a physical connection to the internet. Same with electrical infrastructure. Network access? Possibly, however that network should NOT be accessible from the internet.
The only exception I can think of would be for meter reading, which should be a separate, read only device with no ability to do harm altogether.
snypher 6 hours ago
At a few of our sites, we have webcam-pointing-at-gauge. Deemed secure via air gap and simple to deploy.
27183 6 hours ago
pixl97 6 hours ago
People start freaking out at the costs of dedicated fibers to every monitored facility. Hence even 'private' networks still run over the same actual lines as the internet.
baby_souffle 6 hours ago
grebc 6 hours ago
If it’s connected, it’s compromised. Or will be.
Folly to think otherwise.
lokar 6 hours ago
A lot of water infrastructure is physically spread out. It be very expensive and cumbersome (and probably inefficient) to require staff to by physically present at each site for monitoring and making any changes.
grebc 5 hours ago
gopher_space 4 hours ago
sublinear 6 hours ago
Keeping things up to date and holding critical infrastructure to higher standards than consumer tech is not a bad idea.
Taking things offline and properly airgapped can also work, but wouldn't the cost of that exceed making specialized things and maintaining them?
We got into this situation due to cost, not ignorance. Both choices are higher cost than putting ancient devices on the internet.
oconnore 6 hours ago
Jtsummers 6 hours ago
27183 6 hours ago
Terr_ 6 hours ago
Rather than "on/off" I think we need to distinguish between at least four things:
1. Connected naively to the internet.
2. Behind a hardened VPN endpoint which is on the internet.
3. Has a separate physical private network.
4. Requires physical access.
I think it's obvious that #1 should be prohibited in favor of #2. After that point we need to ask what the impact is of a Denial of Service attack that prevents anyone from remotely accessing the system.
The difference between #2 and #3 may depend on whether things could be Very Bad if the system is disconnected at a time of the attacker's choosing. For example, disabling access to flood-control valves during a hurricane.
lokar 6 hours ago
The big question for 2 is what devices have access. If it’s a bunch of employees from loosely managed general use laptops, bad. If it’s a few computers at HQ that are totally locked down and without internet access, probably ok.
mikewarot 4 hours ago
A data diode can allow monitoring via the internet without risking ingress of control. Commercial units aren't cheap though.
Obviously we need open source designs.
Perhaps the easiest way would be a Raspberry pi set up with an opto isolated CGA/EGA/VGA/SVGA capture that could be viewed via the internet? (I mean, we're probably talking systems still running MS-DOS or Windows 98 running these systems)
Kim_Bruning 6 hours ago
Don't put your PLCs directly on the internet. In fact most industrial stuff is very not made to be directly connected to the internet. But interpose a firewall+VPN solution and you might be ok, if done competently.
And remote access to hardware definitely makes management and maintenance a lot easier and quicker. (else you need to drive out for every minor issue)
closeparen 2 hours ago
If we can beat a security-state airgap by sprinkling USB drives in the parking lot, I think the Iranians can beat an "internal" network by getting someone to click on an email attachment or visit the wrong website on their municipal issued Windows machine.
It's very common for the proprietary software for interfacing with ancient, expensive machines to break after OS upgrades, so they're probably unpatched... you might not even need to burn a 0-day.
tomsanbear 6 hours ago
"If done competently" is a bold assumption unfortunately, not just these days but always
vannevar 6 hours ago
We could say that about a lot of infrastructure that has been recklessly placed on the open Internet because it was cheaper than more secure solutions. I would say the same about home security systems, for instance.
nik282000 5 hours ago
No infrastructure should be on the open internet the potential for abuse is incredible. At a minimum a VPN should be used to tunnel all connections back to what ever command and control server exist, leaving equipment visible on the public IP should be a crime if not a felony.
gz5 3 hours ago
what does belong on the internet in a post-mythos world?
one argument: only services which need to be available to unauthenticated endpoints should be default reachable.
all other services should be default unreachable (no data plane until authorized ...then use internet and other networks to establish the connections).
yes, that is not always easy. it is much more possible than it used to be.
and arguably we now need to commit to the tradeoffs of default unreachable services.
Cider9986 6 hours ago
>Other countries start securing their water
>nsa: what no, stop that
Terr_ 6 hours ago
I sometimes wonder how much damage (and potential damage) to US infrastructure exists simply because intelligence-agencies prioritize being able to exploit it globally over fixing it on defense.
yellow_postit 5 hours ago
I sometimes think about how much the CIA risked setting back global health when using a fake vaccination program to find Bin Laden.
psunavy03 5 hours ago
The NSA's job is to collect information, not screw with people's water.
mcfdoesdev 2 hours ago
I mean, this statement shouldn't be shocking to anyone. Critical infrastructure should be air-gapped if at all practical.
thisisnotauser 4 hours ago
Duh.
logicallee 2 hours ago
>Water system controllers don't belong on the internet, says ex-NSA chief
sounds like cope for a bunch of felons that management, its director and congress can't get a handle on.
Computer0 7 hours ago
you reap what you sow