50 pointsby speckx5 hours ago3 comments
  • ilikeitdark13a few seconds ago
    Some people allegedly say that the US should treat heads of companies like they do in China, when found guilty of certain crimes. Allegedly.
  • BlackRabbit12 hours ago
    > Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts).

    Describe the network security of the industrial automation industry and their customers in a single statement. Lol.

    • tamimio2 hours ago
      It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..
      • fc417fc802an hour ago
        I don't see the issue with either of those things? At least as long as they're properly secured. (Which they probably aren't but that's neither here nor there.)
        • fathermarz15 minutes ago
          Well I think it speaks to the age of the equipment they are speaking of in the industrial sector.

          How do you lockdown something that may have not been taken offline for decades because it will cost downtime or harm. Or something that can’t be locked down without tossing new tech around it that may not be compatible with the protocols etc.

        • tamimio15 minutes ago
          It is an issue, dial up lacks tunnel encryption and if you managed to make it, it will be useless in real scenarios, and 3g is being phased out and obsolete
  • pudgywalsh3 hours ago
    Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will.

    CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration.

    Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. You cross a threshold where you're being deliberately careless.

    When you are putting more effort into securing your Plex server on your home network then public utilities are taking on machinery that dumps chemicals into the local water, something is not right and finger-pointing isn't going to fix it.

    • Avicebron3 hours ago
      I think it's less carelessness and more the inability to attract (pay) people who have the technical knowhow to properly secure infrastructure. Even a lot of developers are poor network engineers and treat IT like magic at their own companies.
      • pudgywalsh3 hours ago
        I've met info-sec / vulnerability researcher types that were egregiously reckless, like plugging Raspberry Pi's into the production network kind of thing.

        Public sector has always paid low. But the problem is widespread, almost universal, and they've had a 15 year head start of the federal government telling them to get their shit together.

        At some point it just became standard industry practice is my guess.

        • doobiedowneran hour ago
          Upgrades to waste water are project based. Lowest bidder will not provide security for free. Security may be mentioned in spec but in hand waved language that can be hand waved away. That company doing the improvement project will have next to no documentation from the previous engineering effort. Just do bare minimum and move on to next job, because no one is getting paid enough to do put in more effort.
        • elictronic43 minutes ago
          In all things when it fails in a drastic way the system will be corrected. People will die, it will suck, changes will be made.

          Government is supposed to respond to these things and create incentives to correct. Telling a small municipality to do something without a carrot ir stick does nothing.

          In this instance someone else will be providing the stick.

      • moscoe3 hours ago
        You’re on the right track, I think. But, I wouldn’t say it’s about the pay to attract competent workers. I think it has more to do with the incentive structures once you’re in. Incentives and performance management are fundamental problem in civil service. The incentives to set high standards and hold individuals accountable simply do not exist.

        The one and only exception is the military, because lives are literally on the line in a way that is not at all abstract.

        • Avicebron2 hours ago
          Usually when people say this they are dog whistling privatization. Which is the exact opposite thing people need in infrastructure, ask anyone who has to deal with PG&E.

          Paying skilled people highly does actually incentivize people to do better work, especially if they are actually embedded into the community they are essentially working for. If being a civil servant was as "glorious" as being a techie is SF there would be a very different attitude around the work.

          • mlyle28 minutes ago
            I think the big problem is administrative capacity.

            There are better run governments than we have in the US.

            The contempt for the state is a self-fulfilling prophecy. The state is incompetent because many of us believe it is inevitable that it will be. Compensation is just a part of it; coherent administration with continuity is even more important.

          • fc417fc80230 minutes ago
            Why do you assume that PG&E has a good incentive structure, or that the public sector must necessarily have a bad one? My only objection to the preceding comment would be that struggling with perverse incentives isn't limited to civil service. Incentive structures are a core struggle of approximately all large groups of people.
          • moscoe2 hours ago
            In an environment without accountability, higher pay is just more incentive to lay low and not take any personal risk. Why do anything other than the bare minimum when there is no upside? In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing.

            The people who climb to the top aren’t the ones who took a risk and got the reward. Quite the opposite, they’re the ones who learned to play the game and didn’t upset the power structure by rocking the boat. No one is going to tell the emperor he has no clothes when the path to power is political and has no grounding in reality.

            Highly conscientious, intrinsically motivated people will do the right thing in any environment. And those people don’t last long in political/bureaucratic environments where the incentives are misaligned.

            • doodlebuggingan hour ago
              Your comments show, beyond a shadow of a doubt, that you have never worked for the federal government and likely have never worked in state or local government.

              >In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing.

              Federal employment is merit based. Advances are earned, not doled out to the teacher's pet or the ass-kisser with the most perfect pucker. You have no idea what you're talking about.

              I have no idea where you or anyone else got the idea that a government employee has no responsibility or incentives and works strictly for political ends and even worse, where none are willing to speak up. You clearly have no experience in that space and should focus your comments on things that you better understand through direct experience.

              >And those people don’t last long in political/bureaucratic environments where the incentives are misaligned.

              This is bullshit and you are grossly misinformed. Plenty of people fight the polarization of the system on political lines from within the system. They use the laws that are in place in order to prevent systemic abuses. They may not win every internal fight but they do go to battle for the right reasons.

              You just have no idea.

              • fc417fc80235 minutes ago
                I don't think your attitude here is in keeping with the guidelines (or constructive discourse for that matter). You've made a number of uncharitable assumptions about the other party on the back of which you then launched into baseless personal attacks.

                Notably everything in the comment you replied to applies equally to the public and private sector. They are neutral observations about systemic motives and the associated perverse incentives.

                Also it's not clear to me that any of the utilities in question have anything to do with the federal government so I'm not sure why you dragged them into this.

        • cyanydeez2 hours ago
          We just started replacing our PLCs. They absolutely were setup with default passwords, but weren't put on the public internet.
          • fathermarz32 minutes ago
            What policies do y’all have in place for this? Is there a program in place or the beginnings of one at least?
      • arionhardisonan hour ago
        [flagged]
    • fathermarz36 minutes ago
      Not IT malpractice and this where the industry diverges. IT folks usually don’t work on or understand these systems.

      Which is one of MANY problems OT faces. IT best practices don’t suffice in OT and even when they do, most of these orgs are too resource hamstrung to do anything about all of the fires they have to put out.

      Not to mention all of the OT vendors who flooded the market with tools instead of people being taught the boring process driven work.

    • andyjohnson03 hours ago
      > Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords.

      I work with PLCs. Default passwords of not, the idea that such weakly secure devices are being made accessible from the public internet boggles my mind.

      • fathermarz22 minutes ago
        What industry? Very relevant.
      • pudgywalsh3 hours ago
        Yeah I meant the default passwords are simply the cherry on top of already egregiously poor security.
    • lorreyfum2 hours ago
      Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.
      • fathermarz28 minutes ago
        “Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.
      • throwaway8943452 hours ago
        Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.
        • pudgywalshan hour ago
          So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota?

          > failed to anticipate not only these infrastructure breach

          They've been warning them for close to two decades.

          Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.

          • throwaway894345a few seconds ago
            The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.
        • fathermarz21 minutes ago
          I will repeat a comment from below. There are over 150k water utilities alone in the US.

          Passing the buck to the Federal Government is not understanding the problem.

    • throwaway8943452 hours ago
      Yes, utilities shouldn’t be negligent, but national security is 100% the federal government’s responsibility. If the vulnerabilities were so trivial, then it’s even more damning that the federal government was caught with its pants down, particularly since they were the only ones who knew they would be starting a war.

      > finger-pointing isn't going to fix it.

      Your entire comment was finger pointing…

      • fathermarz26 minutes ago
        There are over 150k water utilities alone in the US.

        Passing the buck to the Federal Government is not understanding the problem.

    • idontwantthis3 hours ago
      Until the people in charge face jailtime for hurting innocent people, why would they care? The government shouldn’t be warning, it should be ordering and imprisoning. And funding and educating where there are genuine gaps.
    • cyanydeez2 hours ago
      a broken clock, yada yada.
    • AnimalMuppetan hour ago
      "I blame it on Minnesota because they are grossly incompetent."

      "I think Minnesota is behind it."

      The first quote makes it the state's responsibility to secure local water systems, which I'm not sure that it is. The second makes it at least sound like the state of Minnesota is the entity running the attack on local water systems within their state, which is off in paranoid conspiracy territory.

      Trump was absolutely wrong.