Remix.run Logo
katzenversteher a day ago

Most factories I know do not allow their PLC be accessed from the internet. They are usually on a separate Network. However, the "engineering" station (the computer running e.g. TIA Portal) sometimes is.

The PLC engineers I had contact with usually had an electrical engineering background. That's why they like PLCs in the first place with the ladder logic programming languages, grafcet and if they feel fancy a bit of structured text (assembly like) or structured control language (pascal like). They indeed did not know much about software security but a great deal about machine safety.

A real security nightmare are older OPC servers (OPC-DA) which is super reliant on DCOM. OPC is quite important to connect the PLCs to SCADA systems or 3rd party devices.

lowbloodsugar a day ago | parent [-]

>They are usually on a separate Network.

Then someone plugs in a cable because boss wants something "over there" and there's already a network that runs "over there". Or optimizes to a smart switch with vlans, and then someone else optimizes to a single vlan. It's not hard to not give a shit, or not understand, network security.

lenerdenator a day ago | parent [-]

That someone can be brought into an office and shown a small diagram of the approved network topology. Then they can be shown a small diagram of the current network topology. Next, they can be asked if they're the same. If they're not, they can finally be asked if they're aware that deviating from the approved network topology without consulting infosec is grounds for termination of their employment.

edoceo a day ago | parent | next [-]

Bunch of assumptions about operational excellence in there. Doesn't match my experience but, it does match my desire.

lenerdenator 11 hours ago | parent [-]

You have to be the change you want to see in the world.

We often forget this, but computer software and hardware are engineering disciplines. Part of engineering is knowing when something's bad and telling the person who asked you to do that something that you won't do it. In the civil engineering world, this means you might have to just walk away from the project and blow a whistle before people get hurt or killed. It's time to normalize that in IT.

edoceo 10 hours ago | parent [-]

Great advice for a much younger person.

lenerdenator 10 hours ago | parent [-]

Or anyone.

It doesn't have to wait 20 years for someone to come through engineering school to happen.

crote a day ago | parent | prev | next [-]

You're assuming that it'll be noticed at all, and that the person noticing cares enough about it to make a big deal out of it - likely involving several layers of management.

In reality it'll likely first be noticed ten years down the line, by someone who lets out a big sigh, mutters something about "incompetent dipshits not updating documentation", and moves on with their day.

lenerdenator 21 hours ago | parent [-]

I'm not assuming anything.

I'm saying that's what you do in order to solve the issue. You have to actually try, and you have to do actual engineering.

If the local planning commission submits a call for proposals for a bridge to cross a 400 foot chasm over sharp rocks, and they insist that it absolutely, positively must be made out of popsicle sticks, local civil engineering firms aren't going to take up the project, because that's insane.

Why do we give the management of these places a pass for PLC and SCADA systems that could give massive problems - up to and including the loss of human life - if they're hacked?

lowbloodsugar a day ago | parent | prev [-]

We're talking about the military. Many years ago I heard a presentation by an IT guy in the marines. He stated that senior officers would regularly give him instructions that would violate some policy or other - such as giving their secure laptop direct access to the internet so they could check their personal email - as an order. That is, they could not refuse. I hope things have changed, but this fellow was dead serious at the time.

fireflash38 a day ago | parent [-]

Report that shit to your security officer