https://www.theregister.com/2024/11/24/water_defcon_hacker/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Cybersecurity Month VMware Explore Blackhat and DEF CON Cloud Infrastructure Month Malware Month The Reg in Space Spotlight on RSA Vendor Voice Vendor Voice Vendor Voice All Vendor Voice HERE and AWS Vonage Amdocs GE Vernova with AWS GE Vernova with AWS Siemens and AWS Gen AI Siemens and AWS IT/OT Amazon Web Services (AWS) New Horizon in Cloud Computing DDN Google Cloud Data Transformation Google Gemini Hewlett Packard Enterprise: Edge-to-Cloud Platform Intel vPro VMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [front] Security 3 comment bubble on white Volunteer DEF CON hackers dive into America's leaky water infrastructure 3 comment bubble on white Six sites targeted for security clean-up, just 49,994 to go icon Iain Thomson Sun 24 Nov 2024 // 15:27 UTC # A plan for hackers to help secure America's critical infrastructure has kicked off with six US water companies signing up to let coders kick the tires of their computer systems and fix any vulnerabilities. Launched at this year's DEF CON, the Franklin project is a scheme to shore up key systems by using the skills of top hackers. As the conference's founder, Jeff Moss, explained to The Register at the time, it's an attempt not only to strengthen US resilience to online attacks, but also to chronicle what is being done in a yearly "Hacker's Almanack" so that others can learn essential skills. Now the scheme is kicking off in earnest with a partnership between the University of Chicago Harris School of Public Policy's Cyber Policy Initiative (CPI) and the National Rural Water Association (NRWA). The organizations are deploying top coders to investigate the security of six water companies based in Utah, Vermont, Indiana, and Oregon, fix any issues, and then pass the knowledge on. [front] "DEF CON's superpower is that we're a bunch of hackers that want to help, figure out how things work, or love pointing out how things are broken and might be fixed. It turns out there are a lot of groups that want to hear that perspective, and would like advice and help," said Moss. "This is our first initiative to turn a single weekend of people together into doing good things year round." [front] [front] Program director Paul Chang told The Register that the situation was similar to when DEF CON started a move to sort out problems in voting machines, but a lot more complicated. With voting machines, two manufacturers have 70 percent of the market, but with water companies, there are around 50,000 individual suppliers in the US, and they all have different IT systems. Volunteers will work with techies, be matched to a water company, and spend time helping suppliers harden their systems against outside attacks. It's needed - we've already seen China, Russia, and Iran having a nose around US critical infrastructure and water systems would make an excellent target in the event of a conflict. * DEF CON Franklin project enlists hackers to harden critical infrastructure * Lights, camera, AI! Real-time deepfakes coming to DEF CON * Ransomware can mean life or death at hospitals. DEF CON hackers to the rescue? * DEF CON to set thousands of hackers loose on LLMs "We're hopeful that we'll have raised enough public perception around this and awareness of the issue, and most importantly, have the policymakers - at least some of them - on our side," Chang explained. "As much as many things are now completely disagreeable for both parties, I think one thing we might be able to get on the same page on is I would love for my drinking water to not be poisoned." The volunteers have a broad range of skills, he said, ranging from students to experienced veterans with 30-plus years of experience. The one thing they share is enthusiasm, he said, but there's a lot of work ahead. [front] "The water sector faces increasing cybersecurity-related risk," said NRWA CEO Matt Holmes. "Over 91 percent of the approximately 50,000 community water systems in the United States are small, serving fewer than 10,000 people. NRWA and our members are at the forefront of this challenge. This partnership brings cybersecurity experts to rural America to provide the tools our sector needs to assess, prepare, and respond to cyberattacks." (r) Get our Tech Resources # Share More about * DEF CON * Infrastructure Security * Security More like these x More about * DEF CON * Infrastructure Security * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * CHERI * CISO * Common Vulnerability Scoring System * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * Digital certificate * Encryption * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust More about # Share 3 comment bubble on white COMMENTS More about * DEF CON * Infrastructure Security * Security More like these x More about * DEF CON * Infrastructure Security * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * CHERI * CISO * Common Vulnerability Scoring System * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * Digital certificate * Encryption * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Will passkeys ever replace passwords? Can they? Systems Approach Here's why they really should Security17 Nov 2024 | 118 Microsoft Power Pages misconfigurations exposing sensitive data NHS supplier that leaked employee info fell victim to fiddly access controls that can leave databases dangling online Security15 Nov 2024 | 6 Trump taps border hawk to head DHS. Will Noem's 'enthusiasm' extend to digital domain? Analysis Meanwhile, CISA chief Jen Easterly will step down prior to inauguration Public Sector23 Nov 2024 | 27 Why AI builds best on private clouds AI projects under pressure to show real value in the tightest of timeframes might be worth keeping on-premises Sponsored Feature [front] America's drinking water systems have a hard-to-swallow cybersecurity problem More than 100M rely on gear rife with vulnerabilities, says EPA OIG Public Sector19 Nov 2024 | 18 DARPA-backed voting system for soldiers abroad savaged VotingWorks, developer of the system, disputes critics' claims Security21 Nov 2024 | 4 Here's how a Trump presidency could change the tech industry Kettle Anything could happen in the next half ... decade Public Sector13 Nov 2024 | 123 Here's what happens if you don't layer network security - or remove unused web shells TL;DR: Attackers will break in and pwn you, as a US government red team demonstrated Security22 Nov 2024 | 3 Google's AI bug hunters sniff out two dozen-plus code gremlins that humans missed OSS-Fuzz is making a strong argument for LLMs in security research AI + ML20 Nov 2024 | 9 Healthcare org Equinox notifies 21K patients and staff of data theft Ransomware scum LockBit claims it did the dirty deed Cyber-crime20 Nov 2024 | 1 iOS 18 added secret and smart security feature that reboots iThings after three days Security researcher's reverse engineering effort reveals undocumented reboot timer that will make life harder for attackers Security19 Nov 2024 | 38 Five Eyes infosec agencies list 2023's most exploited software flaws Slack patching remains a problem - which is worrying as crooks increasingly target zero-day vulns CSO14 Nov 2024 | 28 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2024 no-js