Water system controllers don't belong on the internet, says ex-NSA chief
A former NSA chief emphatically states that critical water system controllers have no business being on the internet, citing recent suspected Iran-linked cyberattacks. This sparks a classic Hacker News debate on the perils of connecting vital infrastructure, the challenges of air-gapping, and the perennial tension between convenience, cost, and national security. The story resonates deeply with the community's focus on cybersecurity, nation-state threats, and the often-underfunded state of public utility IT.
The Lowdown
The article highlights retired General and ex-NSA chief Paul Nakasone's stark warning regarding the direct internet connectivity of water system Programmable Logic Controllers (PLCs). His admonition comes in the wake of suspected Iran-linked cyberattacks targeting water facilities across at least 12 US states.
- Nakasone asserts that these PLCs, which control essential functions like tank levels and pumps, should not be exposed to the internet, pushing for 'higher standards' in critical infrastructure defense.
- Security researchers strongly suspect Iranian actors, who have a history of targeting such devices, are behind the recent disruptions, though official US government attribution remains unconfirmed.
- The US water sector presents a vast and vulnerable attack surface, comprising 50,000 disparate municipalities, many of which are underfunded and lack dedicated cybersecurity personnel.
- Nakasone advocates for a collaborative, multi-partner approach to defense, referencing initiatives like DEF CON Franklin (volunteer hackers securing water systems) and Project Chimera (an open-source cybersecurity platform for critical infrastructure).
Ultimately, the piece underscores the urgent need to reassess and reinforce the cybersecurity posture of America's vital utilities against increasingly sophisticated nation-state cyber threats.
The Gossip
Connectivity Quandaries
Commenters extensively debated the fundamental dilemma of connecting critical infrastructure to the internet. While some advocated for strict air-gapping, citing the inherent insecurity of any connected system, others acknowledged the practical benefits of remote access for management and maintenance. Solutions like competent firewall/VPN setups were proposed, but often met with skepticism regarding their real-world implementation, particularly given cost constraints and legacy systems.
Agency Agendas and Hypocrisy
A significant thread explored the perception that intelligence agencies, like the NSA, might prioritize maintaining global exploitation capabilities over actively securing domestic critical infrastructure. Some commenters cynically suggested that the NSA's current stance on securing systems might contradict their historical actions of developing and leveraging vulnerabilities for offensive purposes.
Security Skepticism
A prevailing sentiment was a deep distrust in the ability to adequately secure any system once it's connected to a network, summarized by the mantra 'If it's connected, it's compromised.' Many expressed concerns about the pervasive incompetence in IT security, particularly within underfunded critical infrastructure, and questioned whether 'normal network security' is ever truly sufficient against determined adversaries.