← Back to context

Comment by mrngld

7 hours ago

I'm not seeing why it has to be connected to the internet. Make it a private, air-gapped intranet for all (or most) of the benefits of being "connected", but with no entry point for someone sitting on another continent to turn off the water.

mostly, because setting up a separate network is harder.

a virtual network built upon the regular internet is much easier.

And yes, mostly done wrong

  • I’m glad you raised this point. What are some of the better VPNs you’ve seen for secure industrial .

    I asked because of books I had read about the bad ones, where unsecured industrial control protocols were exposed wirelessly , or via vpns. And I’ve been curious if any good ones are out there .

Are you talking about the media layer or the application layer? What would be the alternative to using the internet media layer? Every utility running their own private media ? So a duplicate network of media, as broad physically as the internet, that’s not connected to the internet? That hackers could tap into, and with poorer security, because it wouldn’t be constantly probed.