Sadly yes, this is exactly what happens. And it ends up being IT holding the bag at the end, with the managers having long since cashed out their stock options and left.
sylver_dragon
- 0 Posts
- 3 Comments
Joined 3 years ago
Cake day: June 7th, 2023
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.
- sylver_dragon@lemmy.worldtoTechnology@lemmy.world•CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the InternetEnglish1·25 days ago
- sylver_dragon@lemmy.worldtoTechnology@lemmy.world•CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the InternetEnglish1·25 days ago
The hacks target internet-facing programmable logic controllers (PLCs)
Why the fuck
is your PLC
facing the fucking internet!Jesus Zombie Christ an a pogo stick. Has no one been paying attention for the last two decades? Seriously, we learned this sort of lesson in Two Thousand and fucking Three. Your critical assets do not get public IP addresses.
Even when a company is doing things pretty well with a VPN, all it takes is one mistake and the cat is out of the bag. At one of my previous employers, we had a fairly good setup with VPNs using single sign on via our IdM provider. IdM enforced SSO and the VPN had a number of policies setup which kept good control over what users could login. And then someone had the brilliant idea to take an old VPN appliance, reset it to factory defaults and configure it just enough to work on our network and then hung it out on the internet for some sort of test (our configuration management left a lot to be desired). Of course, that led to it being left there for a couple months and an attacker finally found it. They also had a valid username/password combination which got them in the door.
Security is hard and often expensive. But still, compared to “we put out OT devices on the internet” a basic VPN is a huge step up.