The Register Home Page

back to article Despite cyberattacks, water security standards remain a pipe dream

It sounds like the start of a bad joke: Digital trespassers from China, Russia, and Iran break into US water systems. But as White House cybersecurity chief Anne Neuberger reminded Billington Cybersecurity Summit attendees on Tuesday, it's not a joke. "Water is the only sector where we've seen three different countries attack …

  1. Anonymous Coward
    Anonymous Coward

    Digital water is now a thing :o

    > It sounds like the start of a bad joke: Digital trespassers from China, Russia, and Iran break into US water systems.

    Sure does, send for Walter O'Brien /s

    Scorpion: hacking the airplane scene

    1. Jou (Mxyzptlk) Silver badge

      Re: Digital water is now a thing :o

      They seem to filter US-hacks-US out of mentioning...

    2. Alan Brown Silver badge

      Re: Digital water is now a thing :o

      The first such incident was a disgruntled ex-employee who caused a massive sewage overflow in the 1990s (things weren't even passworded!)

      30 years later the problem remains just as bad - demonstrating that without personal C-level liabilities, nothing will change

      Add criminal penalties for leaving critical systems exposed to the Internet and I'll guarantee that problems are addressed in weeks

  2. Jou (Mxyzptlk) Silver badge

    Making money is more important than infrastructure

    That stuff is quite easy to make more secure. Missing: Actual will to do so.

    1. Evil Auditor Silver badge

      Re: Making money is more important than infrastructure

      Indeed. Short answer: Do. Not. Connect. Critical. Infrastructure. To. The. Interwebs.

      Long answer: hide critical infrastructure behind walls of security that do not need to operate 24/7/365 and hence can be properly patched and maintained. Darn, I'd better tell this to operators for a proper consultant fee and get stinkin' rich.

      1. Like a badger Silver badge

        Re: Making money is more important than infrastructure

        You think anyone will listen?

        1. I am David Jones Silver badge

          Re: Making money is more important than infrastructure

          The Russians?

        2. Evil Auditor Silver badge

          Re: Making money is more important than infrastructure

          If they paid, why would I care? Seriously though, many will only listen after the manure hit the fan and covered them.

          1. Will Godfrey Silver badge
            Unhappy

            Re: Making money is more important than infrastructure

            What makes you think they will listen then?

      2. PRR Silver badge

        Re: Making money is more important than infrastructure

        > Do. Not. Connect. Critical. Infrastructure. To. The. Interwebs.

        I don't. The only control on my well water pump is a pressure switch. Yes, it also relies on the Electric Grid, but that's fragile out here in the woods so we have workarounds.

      3. ecofeco Silver badge

        Re: Making money is more important than infrastructure

        Indeed. Short answer: Do. Not. Connect. Critical. Infrastructure. To. The. Interwebs.

        But that's just crazy commie talk!

      4. Anonymous Coward
        Anonymous Coward

        Re: Making money is more important than infrastructure

        The screwup started when someone decided it was OK to control SCADA with Windows NT, it's been downhill ever since.

        That said, it wasn't the only problem. I assume it's fixed since I looked at this years ago for a very large outfit, but there were SCADA products you could lock into an indetermined state (read: you had no way to predict in which state it would lock) by a SINGLE malformed network packet, and you could not fix that by taking the device from power or resetting it, you had to reload its firmware. So, nada remote fixing, someone had to go physically onsite.

        So, combine a truly pathetically unsecure OS platform and products not designed to protect themselves (old assumption of indeed a closed network*) and the recipe for disaster was pretty much complete. And evidently it still is. I have no idea if this stupidity has since progressed to ESD platforms, but if so, God help us.

        * "Closed" until an engineer jacked in their laptop to configure things - hello outside source of malware.

  3. Henry Wertz 1 Gold badge

    scada in general

    scada systems in general are not secure from what i've read,. i mean some are obsolete but it's like the CAN bus on autos. security was no priority since these systems are not inended to be reachable from the internet.

    That's the solution here, at least short to medium term. (Long term new powrr pleants, water treatment plants, etc. shoiuld have secure systems and standards to use). short and mid term, strong use of vpns and access controls. if there's any access outside a vlan. do not allow direct access, run it through something to sanitize requests (if i's to monitor stuff don't even allow other commands through) and make very sure that part is secure.

    At least the reports i saw of earlier breakins. it's not like they truly hacked into a remote system. they'd find open ports and even publically accessible remote desktips (vnc or the like) . I think some facilities are properly locked down tight. So juist some best practices for the rest to implement in order to keep the "keep these systems off the public internet" systems off the public internet would go a long ways toward securing things.

  4. sitta_europea

    We always used to have water at our house when there wasn't an Internet. It was never an issue.

    And there was never any problem with reading the meter. There wasn't one. We paid a quarterly bill, which as it happens was always very reasonable.

    It's only since there's been an Internet, and water meters, that the water supply has been unreliable.

    You know why there are domestic water meters?

    They'll tell you that it's about responsible use, and shit like that.

    Well that's all bollocks. It's about profit. There's more water leaks out of the water companies' unmaintained pipes than goes through all the domestic water meters combined.

    We're where we are because of greed.

    I don't know why we let them get away with it.

    Who owns the water anyway?

    1. Evil Auditor Silver badge

      Where I dwell, we do not pay for water. We pay for the infrastructure to provide potable water and for the infrastructure to treat wastewater - measured by domestic water meters.

  5. gormful

    > A month later, state attorneys general of Arkansas, Iowa, and Missouri sued the EPA to stop the rule, arguing that it "intrudes on states' sovereignty."

    To misquote Donald Trump, China can do "whatever the hell it wants" to those states and their water supplies.

  6. Alan Brown Silver badge

    A new list-of-shame of default passwords exposed to the Internet needs to be fired up

    But, of course the standard response will be to deny everything and shoot the messenger

  7. TheSmokingMan666

    Oldsmar Was A Red Herring

    You guys cited the Oldsmar incident. That was a bored employee who tried to lie to cover up their shenanigans by claiming a cyber intrusion took place.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like