463
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 01 Aug 2026
463 points (99.6% liked)
Technology
86866 readers
4423 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
I will take things that never should be connected to Internet for $200 Alex.
Remote monitoring? Sure. Remote managing? Fuck that. These facilities shouldn't be unstaffed for days at a time.
It's called paying people to watch the systems during off-hours. It's often way cheaper than setting up firewalls, setting up alerts, maintaining patches, paying a VPN company to manage connections, paying another company to handle authentication, and so on. Security constraints are getting so bad at my office I'm seriously thinking of how we can do more things with pen and paper.
The things you mentioned probably aren't the problem. It's not hard or expensive to setup secure remote access for systems.
The real problem is that a lot of this very expensive and very specific infrastructure equipment is also very old, and frequently does not support newer and more secure protocols.
Source : I've been trying to get gas generators to fire off email alerts using modern authentication with conditional access for about a week now.
Changing tech is usually a lot harder than adoption. Better methods and protocols will keep emerging to fight new digital threats but with physical threats usually don't change. Only exception is social engineering (e.g. attacking a locked door by tricking someone into opening it). Even then a physical presence is required and someone can't enter a locked room from 2000 miles away.
Security constraints are so bad at home I want to just buy paper books or go to library.
Oh for sure, air gapped sensors that relay information are going to be necessary. We should be building these systems with absolute security because they are critical to infrastructure.
Some people will say it's too hard to retrofit onto legacy equipment, but all it really means is adding a secondary system on top of the legacy system. Just a sensor array that has no interaction with existing systems.
Yup. Fancy architecture diagram:
Right. Why would you do this? Monitoring being available on the Intranet, of course. But controllers on the open internet?
Might as well really focus on ease of use and just make a live website with one big button that says "cut off all electricity and turn all the water into poison, lol"
And guarded by default passwords
And the user support AI the website automatically opens in in popup can just tell you if you tell it you're the King of Water and you forgot the account info.
It is also very easy to airgap monitoring.
Exactly! Whenever I see one of these stories of a utility being hacked that's my first thought.
A simple 300 bps connection over POTS to relay the information from the process controller is all you need. But even POTS is disappearing.