vivster said:
Teeqoz said:
What scared me the most was that those IBM engineers so easily managed to hack that nuclear powerplant. That one doesn't seem like a cherry picked coincidence. What if some terrorist organisation tries to hack a nuclear powerplant, and tries to make it have a meltdown/blow up/whatever?
BTW, are you accusing me of believing everything due to a lack of knowledge? 
|
They didn't "easily hack a power plant". They relied on a chain of stupid people to do the work for them. This maybe workes in 1 of 100 cases.
Also hacking one terminal doesn't mean you can do anything with it. Systems do not tend to be converged, especially not in a high security scenario. Pretty sure that all the critical stuff runs on a different application and maybe even a different OS. Also probably far from any network connection.
You don't just look at something and then type in a few commands and suddenly it's hacked. You need a chain of events, lots and lots of information and a good portion of luck. And it all comes down to the stupid people to wreck everything for themselves with only minimal input from the hacker itself. I mean how do you think the attackers obtain vital information? Because stupid people don't know when to shut their mouths or write mission critical passwords on pieces of paper.
Security systems and network designs nowadays are fairly secure. That's why you can't compare incidents from 20 years ago with today. Hell not even incidents from 5 years ago. Network and security technology moves very fast. And the more critical the application the faster it moves.
This race isn't decided by how skilled an attacker is or how advanced the technology used is. It's a race of how far from vital applications can the companies keep the idiots.
|
Do you talk out of experience actually working on such critical applications, or is it a belief based on common sense ?
Myself I have been working on quite a lot of applications that were financially or commercially critical, and... OMFG ! Whatever can be considered as idiotic or highly risky is done. 5 years without an upgrade for a linux, no care of sql injection, etc., etc. And I'm not a specialist about security, that's just what was so obvious I could see it, in different companies and different countries. And that's exactly why Sony get hacked, and why millions of credit card number, personnal informations were stolen. So, I really hope they are doing a better job for a nuclear power plant. But, really, Tepco can't even have compliant cable for their emergency generator, why would they have a good security ? The only thing I can believe, is that their system are just oustide of internet, that there is no external connection possible.