TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

U.S. Power Companies Warned ‘Nightmare’ Cyber Weapon Already Causing Blackouts

31 点作者 kobayashi将近 8 年前

3 条评论

santaragolabs将近 8 年前
So I&#x27;ve been in the position, a few years back, where I spent months doing comprehensive code reviews of these energy distribution management systems and what not more. It&#x27;s all super scary legacy stuff and the code in general is horrendous (regardless of vendor). It&#x27;s next to unmaintainable, it&#x27;s next to un-upgradeable due to the risk of outages and there has been no oversight into it whatsoever.<p>All the comments regarding &quot;who puts these things on the internet&quot; are missing the point completely. It doesn&#x27;t matter if this stuff is on the Internet or not. It only makes it somewhat easier to get access to these networks and start causing outages. However you&#x27;ve got thousands of miles of converter stations and transformers and power lines dotting the country. It&#x27;s not that hard to go to the middle of nowhere and get access to the backend networks that carry for example the DNP3 traffic. Once you&#x27;re on there you can carry out these type of attacks too.<p>The fact that an enemy can just use the Internet to penetrate the power companies&#x27; networks and pivot from there to their back end networks and actually touch equipment is the icing on the cake; it means they don&#x27;t need to bother with recruiting and sending spies who can get physical access somehow.
评论 #14546481 未加载
protomyth将近 8 年前
What is exactly is the value of having any of our utilities connected to the internet? It seems the security risk is too high. It is bad enough we have to rely on people not inserting a bad USB drive or other physical plant problems.
评论 #14542901 未加载
评论 #14542982 未加载
评论 #14545788 未加载
评论 #14542783 未加载
评论 #14542836 未加载
kobayashi将近 8 年前
Direct link to the Dragos executive summary and full report PDF: <a href="https:&#x2F;&#x2F;dragos.com&#x2F;blog&#x2F;crashoverride&#x2F;" rel="nofollow">https:&#x2F;&#x2F;dragos.com&#x2F;blog&#x2F;crashoverride&#x2F;</a>