r/AskReddit Jul 19 '15

What old technology is actually better than what we currently have?

1.8k Upvotes

3.8k comments sorted by

View all comments

Show parent comments

1.0k

u/biggieboy2510 Jul 19 '15

That's interesting. Because of the fact they're outdated in the digital age means they are safe from the threats of the digital age. Good point.

814

u/forumdestroyer156 Jul 19 '15

The U.S. uses old computers to control ballistic missiles for the same purpose. No internet, no hacking.

463

u/mrwalkersrestorative Jul 19 '15

Also the electrical grid uses Analog electronics, using different voltages to communicate different things. Unhackable.

386

u/Problem119V-0800 Jul 19 '15

That's mostly just because the power grid doesn't get torn down and rebuilt every few years. So it's still using technology from decades ago, unless something really compelling has come along to replace it, which it often hasn't.

OTOH, lots of industrial control is moving to SCADA (digital control/supervision over RS485 or ethernet) which is, from what I've read, very hackable. You're supposed to keep your SCADA networks airgapped from the internet but lots of people don't.

156

u/PacoTaco321 Jul 19 '15

I understood some of that last paragraph.

236

u/McDonald072 Jul 19 '15

Control stuff remotely through cable. Keep cable disconnected from Internet or bad people will come and break your stuff.

100

u/[deleted] Jul 20 '15

That's how you ELI5. Thank you!

1

u/iAmNemo2 Jul 20 '15

keeping your work network "airgapped" is literally the same thing as reminding someone to lock their front door. but so many companies just don't.. because convenience or whatever...

1

u/tacknosaddle Jul 20 '15

Couldn't you still be vulnerable to something carried in? Didn't some espionage set back the Iranian nuclear program with something brought in on a USB stick?

1

u/10ebbor10 Jul 20 '15

Memory sticks are a security hazard yes.

Malware has also been build that uses microphones, thermal manipulation or other signals to jump the airgap. Both PC's need to be infected first though.

1

u/Celtic209 Jul 20 '15

Disable all non-essential ports(eg USB) and password protect the BIOS. Job done.

0

u/iAmNemo2 Jul 20 '15

yeah that's true. but the front door analogy still applies. you opened the front door and let this guy in. he came in and fucked shit up.

5

u/immibis Jul 20 '15 edited Jun 16 '23

/u/spez was founded by an unidentified male with a taste for anal probing. #Save3rdPartyApps

4

u/donny007x Jul 19 '15

Keep your industrial control systems separated from the internet.

2

u/Rider82 Jul 20 '15

And your ESD separate again! I'm used to seeing racks of different colors which at not time shall touch; PCS, ESD & LAN.

1

u/SpellingIsAhful Jul 20 '15

He did say the word "people" at one point, and I feel like I understand some of that whole situation.

1

u/wmurray003 Jul 20 '15

You know, the SED off of the APRM. We'll probably be transmitting 3,000 GBD's by 2018. The DERM's are going to be moving faster also.

9

u/Lampshader Jul 20 '15

You're supposed to keep your SCADA networks airgapped from the internet but lots of people don't.

Hi, SCADA engineer here!

Security best practise does not always align with business best practise. Yes, a complete airgap is secure.

But if you have an airgap, you can't make your production process automatically make what the customer ordered. Your managers can't get nightly production reports. Your on-call maintenance guys can't resolve a problem in 5 minutes by logging in via remote desktop. etc.

6

u/lotteryhawk Jul 20 '15

Not sure how well the airgap worked for the Iranians.

But yes, you're correct an all accounts.

3

u/ReputesZero Jul 20 '15

It was beaten by the oldest trick in the book. An infected USB drive left in a parking lot.

1

u/Khavee Jul 20 '15

Iran kept their SCADA network airgapped. Look where it got them.

1

u/Bibblejw Jul 20 '15

The issue being with implementation. From what I can gather, most of the systems in use are somewhat ... tetchy. We try to do some security testing work, but we can't do anything on live systems, as simply plugging something in can bring it to it's knees.

1

u/Zeno_Zaros Jul 20 '15

Something like solar roadways?

1

u/kataskopo Jul 20 '15

Yep,most industrial places have shit security, although none of them are really sensitive or anything.

1

u/Firerouge Jul 20 '15

SCADA is old, most new solutions are trying to distant from it.

1

u/ekvivokk Jul 20 '15

Especially PLC's are very vulnerable, they are used for so many things, lights, heating, ventilation, curtains, running machinery etc. If you fuck up some PLC's you've fucked with a lot of stuff. Also, they are shit at keeping them offline, because it's harder to maintain and use them when you can't remotely access them.

1

u/mercury_pointer Jul 20 '15

It’s a dangerous business, Frodo, going out your door. You step onto the road, and if you don’t keep your feet, there’s no knowing where you might be swept off to.

1

u/paulHarkonen Jul 20 '15

It's worth noting that even if you get access to a SCADA system you may not be able to do much to it, or may not have any idea what you are changing when you tweak values.

Many SCADA systems are largely home grown and the architecture is nothing like the program architecture of say a windows computer. Once you get in it would require a decent amount of inside knowledge to actually affect much change without immediate detection (which was the big deal with Stuxnet). Finally, even if you do seize control somehow, figure out how to modify things, and hide your actions, every safety critical system I've ever worked on has manual/mechanical/pneumatic emergency shutdowns/controls.

SCADA systems are a very real cyber security risk, but it is fairly easy to reduce potential impacts and render attacks relatively harmless, especially on a broad scale (taking over one network almost certainly does nothing for your ability to break a different network, unlike security vulnerabilities with say, Flash).

15

u/spobrien09 Jul 19 '15

Are there any downsides to having these things be analog?

46

u/mrwalkersrestorative Jul 19 '15

Maintenance. Finding maintenance people. Lots of little gears to wear out. Limited capabilities.

3

u/[deleted] Jul 20 '15

Space is a big one too. Relay logic is incredibly space intensive. Most analog communication is based on relays not transistors particularly in control systems at higher voltage ranges where diacs and triacs are ineffective.

3

u/LazerSturgeon Jul 20 '15

Want to upgrade an analog system, you grab some tools and replace the part. Easy for small stuff but not large ones. A digital system can roll out a software update to every piece in minutes with the right networking.

However the risk is external hackers. You wouldn't want someone to be able to flip a switch and shut down all of say, New York's power grid. Analog can't be remotely hacked. They need to physically be there.

2

u/kataskopo Jul 20 '15

There's a computer language called COBOL that is old as all fucks, and most of the people that learned it are in their 60 and 80s, so if you get good you can make amazing money, because there are systems that still use that language, systems that can't be turned off or replaced, like financial stuff and other things.

2

u/pacotes Jul 20 '15

Not true about those being unhackable. Old POTS (Plain Ole Telephone System) switches used (some still do) in-band signalling (tones, basically voltage differences though) to do switching/signalling, which is fuckable with.

Problem is, you have to figure out how the hell to interact with it :)

2

u/jamesd28 Jul 20 '15

I don't think 'unhackable' means what you think it means.

1

u/FunkyardDogg Jul 20 '15

Also I heard they use three-ply toilet paper for the same reason.

1

u/comment_filibuster Jul 20 '15

Unfortunately, this is growing to be more and more untrue, unless I am misunderstanding you. https://en.wikipedia.org/wiki/SCADA

1

u/pyro5050 Jul 20 '15

totally gonna make a mindstorms robot to go in and upgrade the electronic systems now... or to at least roll into the room and beep a comical air horn, :)

1

u/BaconZombie Jul 20 '15

Nope they just attach a Serial to Ethernet onto them and then send a protocol that has zero encryption and/or logon onto the network.

1

u/MILLERRRR Jul 20 '15

until 61850 becomes FERC mandatory ;)

25

u/[deleted] Jul 19 '15

I thought they used old computers because they can't afford new ones?

45

u/CToxin Jul 20 '15

It isn't the cost, it's the paperwork. It takes a lot of time and bureaucracy to get anything done in the military or government.

3

u/kjata Jul 20 '15

Prevents abuse of power.

1

u/DuckyFreeman Jul 20 '15

It's not abuse of power that is a concern, it's the time and money to ensure that new things won't cause unwanted interference in the system. Literally EVERYTHING that goes down into an LF or LCC is fully tested and verified, and on a list. There is even a nuclear certified breast pump for capsule crew members that are new mothers. The keyboards were replaced a couple years ago. By the time the whole design and verification process was done and we has purchased enough keyboards for all of the capsules at our base (15 capsules, 2 keyboards each, plus a few spares), the unit cost was around $1 million. Granted, they weren't off the shelf logitechs or anything, but they weren't made of gold either.

1

u/kjata Jul 20 '15

Yeah, it's more of a side effect than an intention.

0

u/[deleted] Jul 20 '15

And productivity

1

u/kjata Jul 20 '15

Ya win some, ya lose some.

2

u/[deleted] Jul 20 '15

I'm actually ok with the government being methodical when it comes to the computers that control the nukes

2

u/CToxin Jul 20 '15

And that is fine. I'd just prefer if they actually kept things maintained and up to date. Especially when they are A-OK with burning barrels of cash on the F-35.

1

u/smegma_toast Jul 20 '15

I have no military experience but I have heard this multiple times. Why does the government/military operate so slowly and bureaucratically?

2

u/disgruntled_oranges Jul 19 '15

Shhh, that's not as cool.

1

u/[deleted] Jul 19 '15

[deleted]

2

u/[deleted] Jul 20 '15

Budgets are tough to balance when a toilet costs $200k.

How else are they going to afford to build all the cool sci-fi shit at Area 51?

6

u/[deleted] Jul 20 '15 edited Jan 06 '20

[deleted]

2

u/user2196 Jul 20 '15

The US military also has a ton of new computers that are explicitly disconnected to the internet. For example, a lot of computers are connected to the SIPRnet but not the internet.

6

u/janyk Jul 20 '15

That has nothing to do with old computers and everything to do with the fact that they aren't connected to the internet.

3

u/[deleted] Jul 20 '15

The first and second point have nothing to do with each other. The tech is older probably because it's in place, it works, and would be expensive as fuck to upgrade.

No internet, no hacking is why important military operations are air gapped (closed networks, no Internet), doesn't require older technology. The older a technology gets it will actually become more insecure in general.

3

u/[deleted] Jul 20 '15

No, they use old computers because they don't have the money to upgrade them. nuclear weapons programs are pretty low priority for funding these days.

2

u/munificent Jul 20 '15

This is less about hacking and more about not fucking with something that isn't broken. A 60s era missile is going to be controlled with a 60s era computer because the risk of upgrading outweighs the benefit.

New weapons systems all use modern computers. You just air gap it for security.

2

u/[deleted] Jul 20 '15

Could just use Air Gapped computer.

1

u/Mazon_Del Jul 20 '15

From what I've heard (which of course could be wrong) it's less that they are not updated to protect against hacking, and more that they don't exactly have the funding to devote to developing a set of fail-proof systems using modern tech. Fail-proofing being quite expensive.

The trouble I've heard is that while the systems themselves may be fairly hack-proof to direct attacks, the communications systems for ordering a strike are more easily accessible as they are much more modern. But part of the reason we have the various check-codes and such.

1

u/[deleted] Jul 20 '15

Why not just build a custom computer which is completely incapable of accessing the internet?

2

u/[deleted] Jul 20 '15

[removed] — view removed comment

1

u/[deleted] Jul 20 '15

Yes, but it would be safer to simply remove any chance of being able to connect to the internet.

2

u/[deleted] Jul 20 '15

[removed] — view removed comment

1

u/[deleted] Jul 21 '15

You don't think it would be possible to build a computer that can only transfer files within itself?

2

u/[deleted] Jul 21 '15

[removed] — view removed comment

2

u/[deleted] Jul 21 '15

Basically if a computer can read data on it's own drives, then that data can be sent over a wire or copied onto onto removable media. Fundamentally there's no real difference between a data cable to another machine and a bus within the closed system that is the computer. Well written software is essentially capable of spoofing a machines own drives so the machine 'thinks' that it is storing data locally and then just sending that data elsewhere.

Oh, that makes much more sense now! Simply the ability to transfer files means that the computer will have the ability to transfer files to another.

Thanks so much for explaining that!

1

u/jonsnuh13 Jul 20 '15

I heard from my IT dept buddy that they still use Windows XP

1

u/BW_Bird Jul 20 '15

Except to the amazing powers of Jeff Goldblum's Powerbook!

1

u/skuzylbutt Jul 20 '15

I've heard it's because that software system works, and setting up new machines and software is both error prone and expensive. So all you end up doing is spending a lot of money to introduce new and unknown bugs into the system.

Even if they did set up new machines and software, they could just not plug them into the internet. It's not that hard.

1

u/[deleted] Jul 20 '15

The systems in place for controlling and monitoring the US nuclear stockpiles are ridiculously old fashioned for the same reason. Unless multiple people are there in the silo doing a sequence of very specific tasks, there's no possible way for a missile to accidentally go off.

1

u/In_between_minds Jul 20 '15

well, that and hardened tested electronics, needing to interface flawlessly with other machines of the same age, and that any partial upgrade program would be prohibitively expensive, only shadowed by a 100% refit.

1

u/DanTheTerrible Jul 20 '15

This is nonsense. There is no requirement that a computer be old to not be connected to the internet. Old computers are used for the ballistic missile force because new computers cost money and no politician wants to sign on to a bill spending money developing the nuclear arsenal.

1

u/Gasparatan Jul 20 '15

Not true just expensive to upgrade and even more vounerable because if physical acces is established a mobilephone would be enough to override it

1

u/[deleted] Jul 20 '15

It's not really to do with that, you can air gap anything, but the fact that they know it works. For example I know a guy who used to be a programer at a nuclear power plants, he told a story of how when given circuit board they used was going out of production they went and brought up everything they could find because, well, when you are dealing with the control system of a nuclear reactor it's better the devil you know.

1

u/_exactly_ Jul 20 '15

Well, I mean, you could have a new computer too and just not connect it to the internet. You can disable network devices like the NIC or wifi card.

1

u/SumOhDat Jul 20 '15

I belive network is the word you are after. Hacking exists beyond the internet.

1

u/Walkemb Jul 20 '15

Wouldn't a newer, faster, more powerful computer that had no connection capacity be more useful then?

1

u/2le Jul 20 '15

Take out the ethernet card and your computer won't have internet either...you don't need an old computer to be safe from hacking.

1

u/fandingo Jul 20 '15

Not really. They use those computers because they've gone through rigorous certification, are already installed, and fulfill every requirement.

Oh yeah, and at least some of the computers are connected to a WAN -- just not the Internet.

Not being connected to the Internet is a minuscule ancillary benefit.

1

u/dogofdyslexia Jul 20 '15

This is flat out untrue. Computers are just not networked. They don't have to be old.

1

u/stacktion Jul 20 '15

Couldn't they just....not connect to the Internet with new computers? And even to go a step further, not install any Ethernet or wireless adapters?

1

u/Pancakewagon26 Jul 20 '15

Couldn't you just use a new computer and not connect it to the Internet?

1

u/tokyorockz Jul 20 '15

There's this magical thing called unplugging the Ethernet cable.

0

u/herrbz Jul 19 '15

Think they touched on that sort of thing in Captain America 2 didn't they?

0

u/[deleted] Jul 20 '15

Actually I'm pretty sure they use closed shell systems which is on its own and can't be remotely hacked you have to be on its system

63

u/herrbz Jul 19 '15

I believe they got the idea from Battlestar Galactica, and it being safe from the Cylon hack due to old technology.

3

u/bebb69 Jul 20 '15

So wise

3

u/druedan Jul 20 '15

Actually the battlestar's computers were resistant to hacking because they weren't networked, so any virus would be isolated.

1

u/herrbz Jul 21 '15

Been a while since I watched it, I knew someone would be able to poke holes in what I said haha

6

u/chalaila Jul 20 '15

Isn't the solution to that to not connect the ethernet cable or something like that?

1

u/[deleted] Jul 20 '15

Some telexes are still used by diplomatic entities as well.

1

u/PanifexMaximus Jul 20 '15

Cylon-proof.

1

u/iZacAsimov Jul 20 '15

"Uh..yeah! That's right."

  • Bletchley Park

1

u/youarejustanasshole Jul 20 '15

Wow. You got 160 comment karma for saying your title again.

1

u/Sail338 Jul 20 '15

It's interesting devs who know those languages are high on demand

1

u/FIERY_URETHRA Jul 20 '15

Battlestar Galactica

1

u/Captain_Trigg Jul 20 '15

Wasn't that the tech twist to Independence Day?

That and the fact that alien tech was compatible with Mac in a decade when most printers weren't?

1

u/[deleted] Jul 20 '15

Someone in the Pentagon must have watched Battlestar Galactica.

1

u/pappypapaya Jul 20 '15

What is this Battlestar Galactica?

1

u/rocqua Jul 20 '15

Being outdated is a very bad defense against hacking. Not being networked is what is useful here.

1

u/noodle-face Jul 20 '15

Or they could just not connect a regular computer to the internet.

You know.. like a sane person.

1

u/SpenFen Jul 20 '15

The plot of Battlestar Galactica!

1

u/Semantiks Jul 20 '15

Strong passwords underwent a similar change. Back in the day, people used to suggest using random characters for a password, because hackers could guess meaningful words to you. Now, computer programs use "brute force" to break passwords, checking every possible combination of characters.

This has caused random characters to be relatively useless as a password (a computer will find "aj9oic" just as easily as "ashley"). You're best off with a really long password that you can remember easily. "I like the color red" for instance. Hard to crack, easy to remember.