Author Topic: Cyber firms warn of malware that could cause power outages  (Read 1243 times)

0 Members and 1 Guest are viewing this topic.


Offline Jeroen3

  • Super Contributor
  • ***
  • Posts: 4184
  • Country: nl
  • Embedded Engineer
    • jeroen3.nl
Re: Cyber firms warn of malware that could cause power outages
« Reply #1 on: June 13, 2017, 09:25:01 am »
I'm not surprised. I've read elsewhere this malware erases the infected unit. So at least it's not that bad.

When you search shodan.io for abb or siemens you get many hits. Right now it lists one with firmware from 2015. That's prehistorical in real years.
 

Offline lapm

  • Frequent Contributor
  • **
  • Posts: 564
  • Country: fi
Re: Cyber firms warn of malware that could cause power outages
« Reply #2 on: June 14, 2017, 09:42:45 am »
Thats because some idiot manager desided to save some money and use internet as communication channel to help control all that power infrastructure. What happens when idiots put stuff on internet? Unsecured access, bad configurations on devices, etc... Because since none knows they are there, they must be safe, right  :palm:
Electronics, Linux, Programming, Science... im interested all of it...
 

Offline Jeroen3

  • Super Contributor
  • ***
  • Posts: 4184
  • Country: nl
  • Embedded Engineer
    • jeroen3.nl
Re: Cyber firms warn of malware that could cause power outages
« Reply #3 on: June 14, 2017, 10:54:48 am »
No it's more complicated. Projects like energy infrastructure take long. Little less long than a an aerospace project, but still long due to them being overseen by the government.

Say, a new high voltage switching substation is commissioned today, it will use plans drafted at least 5 years ago. This also means it used PLC's and software from 5 years ago. Because getting changes certified will take a lot of eyes and "consultants", again.

This is the root cause why democratic governments are fundamentally incapable of setting up an IT infrastructure. Everything needs to first-time-right, if not, there must have been mistakes made by someone. These mistakes must be investigated, by a commision. They also see IT as a cost, and not as an investment. This means each decision needs to pass by a council or commission, who hire many consultants because they themselves lack knowledge required to fill the position. This obviously does not work.

Managers care for the company, they have hired you because they don't know. It's up to you, the engineer, to make the systems safe and secure. You should refuse to build an unsafe system. The manager either agrees, or lost an engineer.
« Last Edit: June 14, 2017, 10:56:45 am by Jeroen3 »
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf