TSA invites itself into a new area: Open access to control systems

  Mike

    Mike

    Apparently, TSA is going to recruit an army of computer security experts from pizza boxes and gas pumps, or maybe give them a week of on-the-job training ....

    The Examiner (23 Jan 2012): TSA memo reveals railway computer hacked

    Wired/Thread Level (24 Jan 2012): Hackers Breached Railway Network, Disrupted Service

    This is not a transportation problem. This is symptomatic of a much larger issue that industry must address, e.g.

    Wired/Threat Level (24 Jan 2012): 10K Reasons to Worry About Critical Infrastructure

    Interesting that Wired/Threat Level posted the two articles about the same time. At least somebody is looking at the larger picture. If they want to solve it, keep TSA out of the way. It won't do much good if the train stays on the track while the chemical plant explodes.

    The 10K figure is incredible. I've worked with industrial control systems for years. A common refrain is "nobody would ever allow their control systems to be connected to the internet". Ha!

  Lisa Simeone

    Lisa Simeone

  CelticWhisper

    CelticWhisper

    Yeah, if they want a thicknet enema.
  Caradoc

    Caradoc

    Yeah. I've lost count of how many bean-counting assclowns have said, "Oh, it'll be OK - we're planning on using a VPN tunnel!" when they're told it's a horribly bad idea.
  Caradoc

    Caradoc

    Or a punchdown tool to the cranium.
  N965VJ

    N965VJ

    Computer Hackers Hijack US Trains

    Quite the headline for a story about a stretch of railway was slowed down and some trains were delayed by 15 minutes.:confused:
  Mike

    Mike

    Do you know for a fact that's all they could possibly do?

    Let's suppose I hacked into the control system for an oil refinery. On my first trial run, would I move an actuator by 1 or 2%, or would I send an entire control loop into fault state? Either requires the writing of only a single parameter. Make it a little more complicated by doing two things at time -- e.g. changing ramp rates & then moving the actuators to full open or full close (i.e. slam the valves shut) and you can start doing some real physical damage.

    What matters is that they were through the door, not how much or how little the hackers did.
  JoeBas

    JoeBas

  N965VJ

    N965VJ

    No, my comment was more about the alarmist headline. More sizzle than steak it seemed, but I admit this is not in my field of expertise.

    I also saw this about some goofballs in the same area around the same time messing with signals by closing the track circuit with a piece of wire, so that put me in a dismissive mood.
  JoeBas

    JoeBas

  N965VJ

    N965VJ

  JoeBas

    JoeBas

  Rugape

    Rugape

  Caradoc

    Caradoc

  N965VJ

    N965VJ

  Mike

    Mike

    If they got in, they were hacked. What matters is the access, not what was done on this particular incursion.
