Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

31% Positive

Analyzed from 769 words in the discussion.

Trending Topics

#security#government#internet#infrastructure#water#federal#default#passwords#more#minnesota

Discussion (20 Comments)Read Original on HackerNews

BlackRabbit1•39 minutes ago
> Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts).

Describe the network security of the industrial automation industry and their customers in a single statement. Lol.

tamimio•30 minutes ago
It’s far worse, just last week I was assessing some architecture and there’s still dial up and 3G connected devices in some of the most critical infrastructure around..
pudgywalsh•about 2 hours ago
Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will.

CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration.

Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. You cross a threshold where you're being deliberately careless.

When you are putting more effort into securing your Plex server on your home network then public utilities are taking on machinery that dumps chemicals into the local water, something is not right and finger-pointing isn't going to fix it.

Avicebron•about 2 hours ago
I think it's less carelessness and more the inability to attract (pay) people who have the technical knowhow to properly secure infrastructure. Even a lot of developers are poor network engineers and treat IT like magic at their own companies.
pudgywalsh•about 2 hours ago
I've met info-sec / vulnerability researcher types that were egregiously reckless, like plugging Raspberry Pi's into the production network kind of thing.

Public sector has always paid low. But the problem is widespread, almost universal, and they've had a 15 year head start of the federal government telling them to get their shit together.

At some point it just became standard industry practice is my guess.

doobiedowner•23 minutes ago
Upgrades to waste water are project based. Lowest bidder will not provide security for free. Security may be mentioned in spec but in hand waved language that can be hand waved away. That company doing the improvement project will have next to no documentation from the previous engineering effort. Just do bare minimum and move on to next job, because no one is getting paid enough to do put in more effort.
moscoe•about 2 hours ago
You’re on the right track, I think. But, I wouldn’t say it’s about the pay to attract competent workers. I think it has more to do with the incentive structures once you’re in. Incentives and performance management are fundamental problem in civil service. The incentives to set high standards and hold individuals accountable simply do not exist.

The one and only exception is the military, because lives are literally on the line in a way that is not at all abstract.

Avicebron•about 1 hour ago
Usually when people say this they are dog whistling privatization. Which is the exact opposite thing people need in infrastructure, ask anyone who has to deal with PG&E.

Paying skilled people highly does actually incentivize people to do better work, especially if they are actually embedded into the community they are essentially working for. If being a civil servant was as "glorious" as being a techie is SF there would be a very different attitude around the work.

cyanydeez•about 1 hour ago
We just started replacing our PLCs. They absolutely were setup with default passwords, but weren't put on the public internet.
andyjohnson0•about 2 hours ago
> Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords.

I work with PLCs. Default passwords of not, the idea that such weakly secure devices are being made accessible from the public internet boggles my mind.

pudgywalsh•about 2 hours ago
Yeah I meant the default passwords are simply the cherry on top of already egregiously poor security.
lorreyfum•about 1 hour ago
Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.
throwaway894345•40 minutes ago
Kind of feels like national security is the job of the federal government. Seems fair to say the federal government should do their job. They started a war for no reason and failed to anticipate not only these infrastructure breach but also the closure of the Hormuz strait.
pudgywalsh•8 minutes ago
So the federal government should be responsible for every rinky-dink water well in Bumblefuck, Minnesota?

> failed to anticipate not only these infrastructure breach

They've been warning them for close to two decades.

Minnesota chose the path of no locks on their front doors and are now crying that someone walked in without knocking first.

throwaway894345•43 minutes ago
Yes, utilities shouldn’t be negligent, but national security is 100% the federal government’s responsibility. If the vulnerabilities were so trivial, then it’s even more damning that the federal government was caught with its pants down, particularly since they were the only ones who knew they would be starting a war.

> finger-pointing isn't going to fix it.

Your entire comment was finger pointing…

idontwantthis•about 2 hours ago
Until the people in charge face jailtime for hurting innocent people, why would they care? The government shouldn’t be warning, it should be ordering and imprisoning. And funding and educating where there are genuine gaps.
cyanydeez•about 1 hour ago
a broken clock, yada yada.
AnimalMuppet•24 minutes ago
"I blame it on Minnesota because they are grossly incompetent."

"I think Minnesota is behind it."

The first quote makes it the state's responsibility to secure local water systems, which I'm not sure that it is. The second makes it at least sound like the state of Minnesota is the entity running the attack on local water systems within their state, which is off in paranoid conspiracy territory.

Trump was absolutely wrong.