By using this site, you agree to our Privacy Policy and our Terms of Use. Close
Norris2k said:

Do you talk out of experience actually working on such critical applications, or is it a belief based on common sense ?
Myself I have been working on quite a lot of applications that were financially or commercially critical, and... OMFG ! Whatever can be considered as idiotic or highly risky is done. 5 years without an upgrade for a linux, no care of sql injection, etc., etc. And I'm not a specialist about security, that's just what was so obvious I could see it, in different companies and  different countries.  And that's exactly why Sony get hacked, and why millions of credit card number, personnal informations were stolen. So, I really hope they are doing a better job for a nuclear power plant. But, really, Tepco can't even have compliant cable for their emergency generator, why would they have a good security ? The only thing I can believe, is that their system are just oustide of internet, that there is no external connection possible.

I do talk out of experience. I am a network admin specialized in security in a medium sized IT company that operates world wide.

And with idiots I include of course not only the people who maintain the technology but also the ones who provide money for upgrades or in this case more often don't. A lot of CEOs in this world pretty much invite hackers into their networks by not providing sufficient funds and manpower to protect critical applications. It's generally a bit better in state run facilities than in completely private companies who are practically optimizing their risk management by deliberately calculating possible security breaches into their budget.



If you demand respect or gratitude for your volunteer work, you're doing volunteering wrong.