Remix.run Logo
throwaway894345 7 hours ago

Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.

pudgywalsh 6 hours ago | parent | next [-]

So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota?

> failed to anticipate not only these infrastructure breach

They've been warning them for close to two decades.

Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.

jimberlage 4 hours ago | parent | next [-]

The federal government could potentially oversee the most populous areas of the state and those near a military installation pretty easily. They don’t have to look at every one.

throwaway894345 5 hours ago | parent | prev [-]

The federal government makes sure everyone who sends a venmo for $60 pays taxes on it so yeah I think securing our national infrastructure is not an unreasonable expectation.

zdragnar an hour ago | parent [-]

There's no "national infrastructure" for water. Aside from what the EPA does, it isn't within the remit of the federal government to manage municipality water systems.

throwaway894345 an hour ago | parent [-]

My wording was ambiguous. “national infrastructure” can refer to either the infrastructure in our nation or infrastructure managed by the federal government. I meant the former.

fathermarz 5 hours ago | parent | prev [-]

I will repeat a comment from below. There are over 150k water utilities alone in the US.

Passing the buck to the Federal Government is not understanding the problem.

throwaway894345 5 hours ago | parent [-]

There are 150 million taxpayers and the federal government regulates all of them. I don’t see why they can’t audit 0.1% of that. If there are 150,000 utilities then absent some regulation, some of them will fuck up. If we want fewer fuckups, you need regulation.

fathermarz 4 hours ago | parent [-]

What’s the penalty you would impose on a rural water system that has under 10 employees that services thousands of people for water and/or wastewater?

What does that audit look like and how frequent does that happen? It’s a security assessment? A quality assessment? A risk assessment?

I’m open to the idea, but I will repeat, I don’t think the problem is well enough understood for a “make the feds do it” type of comment.

throwaway894345 4 hours ago | parent [-]

It’s the same regulatory/incentive toolbox as any industry, including possibly accepting lower security standards for tiny treatment plants just like we accept less security for podunk airports.

> make the feds do it

National Security has always been a federal government responsibility. You make it sound like I’m expecting the federal government to take on some new responsibility. If the federal government starts a war with another country they’re absolutely responsible for minimizing by collateral damage at a fucking minimum.

fathermarz 3 hours ago | parent [-]

National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground?

NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so.

I agree that in theory this would not be a stretch if the stars aligned, but these are for the most part, not federal government funded entities nor government controlled even at a state level. They are usually clooged together by 100 years of paper maché. And that’s just water. What about Energy? Data Centers? Pharma? Regulation is way too far behind to just instantly drop a silver bullet.

And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI.

throwaway894345 an hour ago | parent | next [-]

> The issue comes down to actual skilled people hours to do the work and resource constraints to do so.

It comes down to incentives. If you want broad security you have to do more than hope that every water utility will both hire good people and also allow them to do their jobs properly.

> But what does that fundamentally mean for boots on the ground?

How does any regulation look on the ground? How does the federal government regulate banks and airports?

> these are for the most part, not federal government funded entities nor government controlled even at a state level

Neither are banks or airports

> What about Energy? Data Centers? Pharma?

Energy and pharma are already regulated. Maybe data centers will be eventually if they are deemed sufficiently critical.

> Regulation is way too far behind to just instantly drop a silver bullet.

I don’t know what this even means in the context of securing our water system. Do you mean to say that regulation can’t ensure that these software systems don’t use default passwords and so on?

> And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI

What is new is that we started a war with a country with a respectable technology competency without doing anything to shore up our defenses.

ImPostingOnHN an hour ago | parent | prev [-]

> IT does not equal OT

I'll say, you should see the hours I have to work sometimes. Honestly I've rarely seen IT jobs pay OT.