BBC Stuxnet programme (OT)

Jan 17, 2017 67 Replies

It used to be expensive to make stuff updatable, now it is easy. Cameras can be updated either to change/improve functionality, or to cope with new lenses.

I'm not familiar with Siemens PLCs, but these certainly were updatable. And whether these ones were or not, I believe many PLCs are networkable.

Good luck with that.

You already admitted you don't know anything about PLCs.

PLCs are not "embedded inside the product". Especially given that with the ones I worked with the "product" was a biscuit or crisp factory.

I've been writing software so long it's getting embarrassing (some of my colleagues weren't even born) and this has always been true: You try to find the bugs before you ship the product.

Equally true: You never find them all.

Which merely means that the only chance for it to get infected with malware was before you shipped it.

OTOH there was a lot less malware around last time I shipped anything with ROMS we didn't intend to update.

Andy

well of course things were shipped with bugs in

the market lived with them

(or the company went bust!)

You stated Firmware (needs to be updated), with no qualification

it is not only PLCs that have firmware

in fact I would go so far as to say that PLCs are a tiny minority of item with firmware

I am therefore perfectly entitled to assume we are talking about generic firmware

but the firmware is embedded inside the PLC, that's the point

which is significant how?

tim

I'm not sure what you mean by "merely" .

Surely the point of this infection (under discussion) is that it can work without you having to break through the physical security systems of the victim.

tim

surely this is a chicken and egg argument

There was no malware because it could not have been effective

tim

En el artículo , mechanic escribió:

And random USB keys "accidentally" dropped near the location, à la Mr. Robot.

En el artículo , trigger escribió:

Security through obscurity, innit.

En el artículo , newshound escribió:

Yet?

Interestingly, one of EDF's UK nukes has just had repairs to the turbine overspeed protection. it's back in service now, so I'm not sure which one. May have been Hunterston B.

Also found this while searching:

"Events reported to ONR by EDF Energy (01 Apr 2012 to 19 Jan 2016)"

formatting link

All unrated, or level 0/1 (not significant). Good to know.

En el artículo , newshound escribió:

You'll like this.

"Audio-based networking may seem an unusual choice for the Internet of Things, especially when used for machines to bellow information at each other inside a nuclear power station"

Overspeed trips are quite complicated mechanical systems, they are regularly tested and occasionally found to be out of spec or to need adjusting.

Interesting list, one of the merits of a very open, "no blame" reporting system. The same list can be found on the ONR site, together with lists of incidents at other UK nuclear sites.

You'll see that one of the EDF INES 1 events was a double reactor trip when an offsite fault took down the 400 KV lines. This is the correct response from the control system, it has that rating because an event which in itself has no great significance (like loss of a single engine in a commercial airliner) may be more serious if they occur in combination with other events.

Yes, I did! They explain one of the reasons:

"As for the nuclear power stations, Chirp's tech has found a useful niche in IoT sensor applications where traditional RF networking cannot be used. Nuclear power stations have an absolute ban on RF over fears of interference ? thereby ruling out Wi-Fi, Bluetooth and all the usual go-to wireless networking technologies"

En el artículo , newshound escribió:

It also ties in with the air-gap approach to security we were discussing earlier in the thread. If equipment is networked using Chirp, that's another vector for attack/infection, showing that air-gapping per se is meaningless in the context of security.

I worked for some years at an astronomical observatory. RF equipment, such as wi-fi was banned inside the observing dome while the telescope was operating to prevent the possibility of it interfering with the very sensitive CCD detectors used in the instruments.

The staggering non sequitur from the brainless monkey, is noted.

Meanwhile elsewhere, the NHS is dispensing with alcohol hand wipe dispensers as seniors consultant Mike fuckedBrainson has shown that they are 'just another vector for infection'

If you have got into the turbine hall, you have already breached the site security. If you can damage an oil, feedwater, or steam pipe this can cause a big incident. In any case, this is technology transmitting instrumentation data out to a logger or display, it won't be part of a control loop. At most, it might provide a trip signal.

En el artículo , newshound escribió:

In that particular usage scenario, yes. But the point of the Register article is that Chirp is a layer 1/2 protocol.

You could lay TCP/IP on top of it if you wanted, with all the advantages and drawbacks that entailed. Some bright spark might decide that it's a grand idea to install PLC firmware over Chirp - after all, to the software, it looks just like another TCP/IP node.

We had an "amusing" case of this a few years ago. At that time, I lived sufficiently out of the way that broadband was not available, so in order that I could dial in to provide support, my employer supplied an ISDN BRI service and a Cisco dial-on-demand ISDN router. They also paid for the "calls". This worked fine for several years, until some plonker installed some network discovery software at the other end, which dialled the *outbound* ISDN, connected to my router, said hello (or whatever it did) and then disconnected. Every few minutes. No-one noticed this until the bill arrived - for several thousand pounds. Then there was a lot of arguing about who was going to pay for it - fortunately not me.

The moral of the story being that TCP/IP is very clever about not caring what the lower layers are, but beware, in case they're high-latency, low bandwidth or expensive!

They are if they are used rather than soap and water as everyone with sense already knows.

They do FA with viruses while soap and water removes them.

Many local authority non-NHS buildings where alcohol dispensers were fitted at every door during past swine/bird flu scares, have realised nobody cleans their hands with them and the cartridges have passed their use by date, so are now removing them.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required