RU version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
56% Positive
Analyzed from 1622 words in the discussion.
Trending Topics
#water#iran#https#war#trump#big#doesn#cisa#www#more

Discussion (52 Comments)Read Original on HackerNews
If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted.
Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope.
It wouldn't cause the mass casualties an enemy might assume.
The only thing I can see is some political crony company getting a big payment from the federal budget to take on the "burden" of doing so. But then not actually distributing enough water so they can still price-gouge individuals because we wouldn't want people to become entitled, right?
Struggling for a source.
Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?
If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books.
https://archive.org/details/operatingmanualforspaceshipearth...
The ICE budget was just increased by $70 BILLION, bringing its total to >$200 billion.
If your question was only a trite recitation of the fact that private enterprise consistently refuses to practice cybersecurity then you've added nothing.
If your question was about who watches the watchers and what we're doing about the fact that private enterprise refuses to practice cybersecurity then it was an incredibly relevant statement.
After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.
https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...
Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…
It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.
These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.
[0] https://www.cisa.gov/topics/industrial-control-systems , and https://www.gao.gov/assets/d24106576.pdf for an idea of the staffing they’re doing it with…
[1] https://www.epa.gov/dwreginfo/information-about-public-water...
Why?
The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.
The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.
https://news.ycombinator.com/item?id=39243560
https://web.archive.org/web/20240409155326/https://www.awwa....
(cybersecurity practitioner is a component of my professional persona)
[Riffing on the gag, not an actual misunderstanding, just to be clear.]
I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.
I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!
This is a bit unhinged.
What a coward and a traitor to the American people.
I'm no Trump supporter and this war was a big mistake, but justifying a nation poisoning another's civilian water supply is a bit upside down.
That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.
[0]: https://www.commondreams.org/news/iran-water-desalination-pl...
I think we should think about making blatant lies by politicians a crime.
If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.
> “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”
But I do appreciate the attempt anyway.
Homosexuals.
Communists.
Islamics.
Hispanics.
Liberals.
Intellectuals.
There’s always an other. That’s what the Republicans have been doing for decades.