Comment by redeeman
3 hours ago
okay, so you think just attaching PLCs to an rs485-to-ethernet adapter and connecting it straight unauthenticated to the internet, and then calling it a day is simply perfectly reasonable, since "well.. cant expect to harden against cyber warfare!! no defect!!!" ?
because this is the kind of stuff infrastructure things do, along with MANY other things. Im sure not all infrastructure does it, but plenty do.
This is not hardening, its BASIC security. any scriptkiddie from same country could find it and cause problems.
How far would you say they should go to stop domestic script kiddies from messing with it? and if script kiddies from other countries mess with it, is it now cyber warfare?
Well, your unsourced assertions sound dramatically incompetent, but the linked article says the Russian cyberattack on Ukraine in 2015 was the first malware caused blackout, and the titular event of the article failed to cause harm, which kind of paints a different picture.
I’ll therefore decline to comment on your assertions. I will acknowledge it’s time to consider Russian interference as expected if you are designing an internet connected system, fine, but it looks like it’s non trivial to fatally compromise these systems already.