Story about spies penetrating grid may be part of a PR campaign(erratasec.blogspot.com)
erratasec.blogspot.com
Story about spies penetrating grid may be part of a PR campaign
http://erratasec.blogspot.com/2009/04/has-power-grid-been-penetrated-by.html
17 comments
There's a whole lot of propaganda all around us, and the willingness of newspapers and columnists to constantly grant anonymity to sources has turned it from a valuable tool for sunlight on public affairs into a valuable tool for any stakeholder with a telephone.
But there is a flip side. Let's assume for a moment that this is a true story and that the military did not authorize its release. In that situation, an anonymous source is pretty much the only way to get the story -- unless someone is willing to ruin their career (or worse) over it.
No wonder they are suffering financially then. Perhaps it has nothing to do with the advertising industry generally but more with the people who do not trust the newspapers any longer and therefore do not read them.
As I mentioned in a comment earlier today, I have some experience in this field.
Yes, the ISOs (Independent System Operators) have Internet presences. Yes, they can send out dispatch signals to the generators over the Internet. Yes, the generators can access an extranet to find out what their current dispatch should be.
Security (in the environment I'm most familiar with) is provided using well-known standards (SSL certificates on both the server and the client). I'm sure there are ways to spoof, but I'm not an expert at those things.
I have ideas on how to create a bad day for the grid, but I don't think it would be wise for me to share them ;)
Yes, the ISOs (Independent System Operators) have Internet presences. Yes, they can send out dispatch signals to the generators over the Internet. Yes, the generators can access an extranet to find out what their current dispatch should be.
Security (in the environment I'm most familiar with) is provided using well-known standards (SSL certificates on both the server and the client). I'm sure there are ways to spoof, but I'm not an expert at those things.
I have ideas on how to create a bad day for the grid, but I don't think it would be wise for me to share them ;)
As mentioned below, why on earth are these systems (still) connected to the Internet at all?
Sure someone might have though it was a good idea, but surely someone has got to have pointed out just what a dumbfuck idea that is?
Sure someone might have though it was a good idea, but surely someone has got to have pointed out just what a dumbfuck idea that is?
More or less...
http://xkcd.com/463/
http://xkcd.com/463/
The big question: why on earth are the shutdown systems (or any others) connected to the Interwebs? How on earth could the risks of that justify whatever benefits there might be? Governments are stupid about all things except increasing their power and control, so it could be true. But I'm still skeptical.
Does anyone know why these systems would be online and what benefits would be large enough to justify this?
Does anyone know why these systems would be online and what benefits would be large enough to justify this?
Reminds me of pg's article on PR campaigns: http://www.paulgraham.com/submarine.html
If it's all lies, what's the motive? Politicians/government officials don't usually lie without some sort of expectation of benefit.
There is a significant momentum building for stronger executive control over Internet connectivity to private-sector networks that are designated as "critical infrastructure."
The proposed CyberSecurity Act of 2009 would allow the president to designate a private network (such as a SCADA system) as critical, and in the case of a declared emergency, shut it off from the Internet.
As you can imagine, there is resistance to this from multiple parties, including those industries who fear additional government regulation and also privacy and anti-censorship advocates who fear "scope creep" in the legislation.
The proposed CyberSecurity Act of 2009 would allow the president to designate a private network (such as a SCADA system) as critical, and in the case of a declared emergency, shut it off from the Internet.
As you can imagine, there is resistance to this from multiple parties, including those industries who fear additional government regulation and also privacy and anti-censorship advocates who fear "scope creep" in the legislation.
How would they send the shut-off signal? Over the internet?
Executive orders to impacted entities would involve a much more formal chain of command and control than a direct kill switch from White House.
There's no reason to think this is lies, or any kind of intentional deception.
As they say, nature abhors a vacuum, and Congresscritters see a piece of important infrastructure that's not under their control. Believing their jobs are important, they believe that this lack of regulation is a danger.
Journalists see the concern of the Congresscritters, and hey, these are community leaders: there must be something to this, so lets do some research and see what we can find -- but we're writing for the public, we've got to present it in a compelling fashion.
So all this takes is a a bunch of people who are acting according to their own world view, following whatever natural incentives they have.
As they say, nature abhors a vacuum, and Congresscritters see a piece of important infrastructure that's not under their control. Believing their jobs are important, they believe that this lack of regulation is a danger.
Journalists see the concern of the Congresscritters, and hey, these are community leaders: there must be something to this, so lets do some research and see what we can find -- but we're writing for the public, we've got to present it in a compelling fashion.
So all this takes is a a bunch of people who are acting according to their own world view, following whatever natural incentives they have.
Agreed. I don't think there was any intentional deception either.
However, don't forget the influence of the lobbyists hired by the security industry. Additionally, "non-profit" organizations involved with information security that see a potential cybersecurity boom as beneficial to their membership and influence in the field.
However, don't forget the influence of the lobbyists hired by the security industry. Additionally, "non-profit" organizations involved with information security that see a potential cybersecurity boom as beneficial to their membership and influence in the field.
Control.
When I was reading the article yesterday I wondered why are they telling us that the grid has been hacked. I thought this is not news at all, I mean what can we do about it. And how do they know that it was Chinese and Russians? I am sure any nation would like to know how the advanced grid works.
Do they already have a switch to shut-off the power grid?, telephones? regular mail? newspapers?
So why the internet? What's the threat?
Or is it about money? how so?
So why the internet? What's the threat?
Or is it about money? how so?