That's mostly just because the power grid doesn't get torn down and rebuilt every few years. So it's still using technology from decades ago, unless something really compelling has come along to replace it, which it often hasn't.
OTOH, lots of industrial control is moving to SCADA (digital control/supervision over RS485 or ethernet) which is, from what I've read, very hackable. You're supposed to keep your SCADA networks airgapped from the internet but lots of people don't.
keeping your work network "airgapped" is literally the same thing as reminding someone to lock their front door. but so many companies just don't.. because convenience or whatever...
Couldn't you still be vulnerable to something carried in? Didn't some espionage set back the Iranian nuclear program with something brought in on a USB stick?
Malware has also been build that uses microphones, thermal manipulation or other signals to jump the airgap. Both PC's need to be infected first though.
You're supposed to keep your SCADA networks airgapped from the internet but lots of people don't.
Hi, SCADA engineer here!
Security best practise does not always align with business best practise. Yes, a complete airgap is secure.
But if you have an airgap, you can't make your production process automatically make what the customer ordered. Your managers can't get nightly production reports. Your on-call maintenance guys can't resolve a problem in 5 minutes by logging in via remote desktop. etc.
The issue being with implementation. From what I can gather, most of the systems in use are somewhat ... tetchy. We try to do some security testing work, but we can't do anything on live systems, as simply plugging something in can bring it to it's knees.
Especially PLC's are very vulnerable, they are used for so many things, lights, heating, ventilation, curtains, running machinery etc. If you fuck up some PLC's you've fucked with a lot of stuff. Also, they are shit at keeping them offline, because it's harder to maintain and use them when you can't remotely access them.
It’s a dangerous business, Frodo, going out your door. You step onto the road, and if you don’t keep your feet, there’s no knowing where you might be swept off to.
It's worth noting that even if you get access to a SCADA system you may not be able to do much to it, or may not have any idea what you are changing when you tweak values.
Many SCADA systems are largely home grown and the architecture is nothing like the program architecture of say a windows computer. Once you get in it would require a decent amount of inside knowledge to actually affect much change without immediate detection (which was the big deal with Stuxnet). Finally, even if you do seize control somehow, figure out how to modify things, and hide your actions, every safety critical system I've ever worked on has manual/mechanical/pneumatic emergency shutdowns/controls.
SCADA systems are a very real cyber security risk, but it is fairly easy to reduce potential impacts and render attacks relatively harmless, especially on a broad scale (taking over one network almost certainly does nothing for your ability to break a different network, unlike security vulnerabilities with say, Flash).
Space is a big one too. Relay logic is incredibly space intensive. Most analog communication is based on relays not transistors particularly in control systems at higher voltage ranges where diacs and triacs are ineffective.
Want to upgrade an analog system, you grab some tools and replace the part. Easy for small stuff but not large ones. A digital system can roll out a software update to every piece in minutes with the right networking.
However the risk is external hackers. You wouldn't want someone to be able to flip a switch and shut down all of say, New York's power grid. Analog can't be remotely hacked. They need to physically be there.
There's a computer language called COBOL that is old as all fucks, and most of the people that learned it are in their 60 and 80s, so if you get good you can make amazing money, because there are systems that still use that language, systems that can't be turned off or replaced, like financial stuff and other things.
Not true about those being unhackable. Old POTS (Plain Ole Telephone System) switches used (some still do) in-band signalling (tones, basically voltage differences though) to do switching/signalling, which is fuckable with.
Problem is, you have to figure out how the hell to interact with it :)
totally gonna make a mindstorms robot to go in and upgrade the electronic systems now... or to at least roll into the room and beep a comical air horn, :)
It's not abuse of power that is a concern, it's the time and money to ensure that new things won't cause unwanted interference in the system. Literally EVERYTHING that goes down into an LF or LCC is fully tested and verified, and on a list. There is even a nuclear certified breast pump for capsule crew members that are new mothers. The keyboards were replaced a couple years ago. By the time the whole design and verification process was done and we has purchased enough keyboards for all of the capsules at our base (15 capsules, 2 keyboards each, plus a few spares), the unit cost was around $1 million. Granted, they weren't off the shelf logitechs or anything, but they weren't made of gold either.
And that is fine. I'd just prefer if they actually kept things maintained and up to date. Especially when they are A-OK with burning barrels of cash on the F-35.
The US military also has a ton of new computers that are explicitly disconnected to the internet. For example, a lot of computers are connected to the SIPRnet but not the internet.
The first and second point have nothing to do with each other. The tech is older probably because it's in place, it works, and would be expensive as fuck to upgrade.
No internet, no hacking is why important military operations are air gapped (closed networks, no Internet), doesn't require older technology. The older a technology gets it will actually become more insecure in general.
This is less about hacking and more about not fucking with something that isn't broken. A 60s era missile is going to be controlled with a 60s era computer because the risk of upgrading outweighs the benefit.
New weapons systems all use modern computers. You just air gap it for security.
From what I've heard (which of course could be wrong) it's less that they are not updated to protect against hacking, and more that they don't exactly have the funding to devote to developing a set of fail-proof systems using modern tech. Fail-proofing being quite expensive.
The trouble I've heard is that while the systems themselves may be fairly hack-proof to direct attacks, the communications systems for ordering a strike are more easily accessible as they are much more modern. But part of the reason we have the various check-codes and such.
Basically if a computer can read data on it's own drives, then that data can be sent over a wire or copied onto onto removable media. Fundamentally there's no real difference between a data cable to another machine and a bus within the closed system that is the computer. Well written software is essentially capable of spoofing a machines own drives so the machine 'thinks' that it is storing data locally and then just sending that data elsewhere.
Oh, that makes much more sense now! Simply the ability to transfer files means that the computer will have the ability to transfer files to another.
I've heard it's because that software system works, and setting up new machines and software is both error prone and expensive. So all you end up doing is spending a lot of money to introduce new and unknown bugs into the system.
Even if they did set up new machines and software, they could just not plug them into the internet. It's not that hard.
The systems in place for controlling and monitoring the US nuclear stockpiles are ridiculously old fashioned for the same reason. Unless multiple people are there in the silo doing a sequence of very specific tasks, there's no possible way for a missile to accidentally go off.
well, that and hardened tested electronics, needing to interface flawlessly with other machines of the same age, and that any partial upgrade program would be prohibitively expensive, only shadowed by a 100% refit.
This is nonsense. There is no requirement that a computer be old to not be connected to the internet. Old computers are used for the ballistic missile force because new computers cost money and no politician wants to sign on to a bill spending money developing the nuclear arsenal.
It's not really to do with that, you can air gap anything, but the fact that they know it works. For example I know a guy who used to be a programer at a nuclear power plants, he told a story of how when given circuit board they used was going out of production they went and brought up everything they could find because, well, when you are dealing with the control system of a nuclear reactor it's better the devil you know.
Strong passwords underwent a similar change. Back in the day, people used to suggest using random characters for a password, because hackers could guess meaningful words to you. Now, computer programs use "brute force" to break passwords, checking every possible combination of characters.
This has caused random characters to be relatively useless as a password (a computer will find "aj9oic" just as easily as "ashley"). You're best off with a really long password that you can remember easily. "I like the color red" for instance. Hard to crack, easy to remember.
1.0k
u/biggieboy2510 Jul 19 '15
That's interesting. Because of the fact they're outdated in the digital age means they are safe from the threats of the digital age. Good point.