[HN Gopher] Volunteer DEF CON hackers dive into America's leaky ...
       ___________________________________________________________________
        
       Volunteer DEF CON hackers dive into America's leaky water
       infrastructure
        
       Author : rntn
       Score  : 35 points
       Date   : 2024-11-24 16:09 UTC (6 hours ago)
        
 (HTM) web link (www.theregister.com)
 (TXT) w3m dump (www.theregister.com)
        
       | mxuribe wrote:
       | I am both heartened by the fact that there are volunteers willing
       | to help society, but also very sad that this is even needed.
       | Where and how has the American government - both sides i feel -
       | so disastrously failed its people, that it is needed to rely on
       | volunteers to help with something that i feel should have been
       | managed by government.
       | 
       | Before anyone starts rambling on about politics too much on any
       | side, i blame all sides. What i recall from my basic education so
       | many decades ago is that government should help to provide at
       | least some fundamental areas of infrastructure (e.g. roads and
       | such, etc.), and then commerce (private enterprise, etc.) can
       | take place above it, and than things proceed from there, yada
       | yada.
       | 
       | I don't know what is more basic infrastructure than water and its
       | associated management? Where is the NSA in all of this? What
       | about Department of Homeland Security's Cybersecurity and
       | Infrastructure Security Agency (CISA), where are they in all of
       | this?
       | 
       | Clearly, this story ticked me off, and apologies for that...but,
       | if we're at the stage in society where volunteers is a viable
       | solution for a very fundamental element in life...then clearly
       | lots of other things have severely failed.
        
         | righthand wrote:
         | Most of our infrastructure was built a long time ago (except
         | roads) and don't actively see maintenance. No one from the
         | current generations has had to pay for real impactful
         | infrastructure for decades. Now that all the infrastructure is
         | failing or has security holes nobody wants to pay for it to be
         | fixed. If you look up major infrastructure repairs in the last
         | few decades you will see much of what could have been long term
         | fixes were reduced to short term fixes.
         | 
         | Properly fixing infrastructure has become expensive as
         | construction costs have skyrocketed in the last few decades.
         | 
         | Look at the CHIPS bill, huge infrastructure gain but also was a
         | part of the 9% inflation because building this infrastructure
         | is expensive. The American people were warned about it causing
         | inflation but wanted it anyways. When inflation hit they all
         | conveniently forgot the cost of new infrastructure in the US
         | and chose to cling to lies about how disastrous the last 4
         | years have been.
         | 
         | That is why today no one does anything about problems until a
         | bridge collapses. You can make more money today by passing the
         | buck to the next generation and passing blame to whoever came
         | before you.
        
           | chc4 wrote:
           | CHIPS was signed into law in August 2022. The yearly
           | inflation rate for 2023 was 4.12%. Inflation, especially in
           | the wake of the COVID-19 pandemic, was caused by an extremely
           | large amount of different issues and chalking 9% inflation up
           | to infrastructure spending is a wild jump.
        
             | righthand wrote:
             | Good thing I didn't chalk up infrastructure spending as the
             | only cause by stating "part".
             | 
             | > but also was a part of the 9% inflation
             | 
             | Yes there are other reasons, COVID payments being another
             | reason, which citizens were warned about. The first payment
             | was signed by Donald Trump himself. Any time there is an
             | increase in spending it will cause inflation. Increasing
             | defense spending is another cause which happens yearly.
        
               | jeffbee wrote:
               | Did CHIPS and stimulus checks also cause inflation in
               | Germany, Italy, France, Japan, Canada in Britain? Asking
               | because they all had higher inflation than US.
        
               | righthand wrote:
               | The pandemic caused global inflation. I don't know why
               | you'd insinuate increased spending in America directly
               | correlates with increased spending in Europe. I'm not
               | sure what point you're trying to make either.
        
           | mxuribe wrote:
           | Yeah, by no means do i believe that infra.-related topics are
           | easy nor cheap nor fast to resolve...in fact, i believe them
           | to be some of the most diffult and/or complex for myriad
           | reasons...I'm just venting i guess because its more a matter
           | of poor decisions made over time, rather than what is
           | actually and technically possible in our society. But, yeah,
           | passing the buck seems to be what happens, and to our greater
           | detriment.
        
         | mastax wrote:
         | > What about Department of Homeland Security's Cybersecurity
         | and Infrastructure Security Agency (CISA), where are they in
         | all of this?
         | 
         | The CISA does this type of thing all the time. Here is an
         | example just from their recent news releases in the past week:
         | https://www.cisa.gov/news-events/alerts/2024/11/21/cisa-rele...
         | 
         | The CISA offers to assist infrastructure providers in a number
         | of ways: https://www.cisa.gov/resources-tools/services/assist-
         | visits Presumably the NRWA could have asked the CISA for help
         | with this initiative.
         | 
         | The CISA has 3,000 employees and a budget of $3B, which is a
         | lot, but not enough where they can be involved in everything.
         | For reference there are 12,500 utility scale power plants and
         | 148,000 public water systems in the United States. The scale of
         | the problem means they must be mostly an advisory organization,
         | where most of the work gets done by people at the
         | infrastructure organizations or, sure, volunteers.
         | 
         | Now, I'm not saying that the CISA is doing a good job, I
         | genuinely have no idea. Determining that would take a lot of
         | knowledge, probably insider knowledge, and weighing what
         | they're doing against what resources they have available. But
         | them not being involved in some random project that showed up
         | in your newsfeed doesn't mean they have severely failed.
        
           | mxuribe wrote:
           | Agreed, that i also have no idea how CISA is performing; i
           | honestly cannot say anything good or bad - since i have zero
           | data to substantiate my opinuion.
           | 
           | > ...But them not being involved in some random project that
           | showed up in your newsfeed doesn't mean they have severely
           | failed.
           | 
           | I surely and honestly hope that you are correct!
        
         | rubyfan wrote:
         | I wish we could stop looking for someone to blame or complain
         | about and start looking for solutions. I think that's the
         | spirit of volunteering here.
        
           | haliskerbas wrote:
           | Part of looking for solutions requires root cause analysis.
           | Which can be "blameless" but there is at some point a need to
           | figure out where the holes are in a system to be able to
           | patch them. Otherwise people will never know if they're
           | paying for a problem to occur (taxes) and then paying to help
           | fix them too (donations + volunteering)!
        
             | mxuribe wrote:
             | Now, this is a good point! I'm actually willing to pay
             | taxes to ensure they are used for the common good. My
             | offspring no longer is school age, but i am STILL willing
             | to pay taxes that pay for elementary school, and
             | such...Because it helps society and the common good in so
             | many ways. But, i think we have to have discussions when
             | those infra.-level things are not providing the benefits
             | because those in power keep making awful decisions...and
             | the next steps don't involve removing said efforts, but
             | rather improving them, bettering their implementations,
             | etc...and that can start with a post-mortem, or RCA, even a
             | simple 5 Whys, whatever it takes to help society stay safe,
             | improve well-being for all, give societal particiapnts a
             | chance at propserity, etc. :-)
        
           | mxuribe wrote:
           | I was lamenting the state of society, that's all. I think any
           | volunteers - regardless of area - are true champions. But, i
           | was simplky casting shade to those in power for their
           | failings, and allowing things to trickle to what i believe is
           | a sad state of affairs. I'm just some rando on the web
           | yelling at (the men who "created") the clouds. ;-)
        
         | wslh wrote:
         | While I see your point, over time, I've come to think that
         | cybersecurity is a fundamentally different and indomitable
         | beast. Consider the sheer number of software projects, devices,
         | and products being developed, each inevitably introducing all
         | kinds of bugs, versus the relatively small number of people who
         | truly understand the craft of real offensive security.
        
           | Veserv wrote:
           | The very concept of "offensive security" is indicative of the
           | problem.
           | 
           | If you want to make a secure military base, you do not hire a
           | spec ops team to develop one. If you want to make a
           | bulletproof vest, you do not hire a gunsmith to design new
           | synthetic fibers.
           | 
           | Having offensive teams on hand to verify and validate is
           | necessary, but largely orthogonal to the task of design and
           | development. The skillsets are highly dissimilar.
           | 
           | The fact that people think this is the golden way shows how
           | absolutely intellectually bankrupt the entire commercial
           | cybersecurity industry is on a theoretical level. And the
           | complete inability to protect against the regular and
           | standard threat actors today shows and supports that
           | empirically.
        
           | mxuribe wrote:
           | While i agree that cybersecurity is no way at all an easy
           | thing, i politely disagree that it is indomitable. I'm gonna
           | stretch your intent there to use a cheesy analogy: its like
           | saying humans thought buidling anything over rivers was
           | simply beyond their tech means, so bridges were never
           | invented...But, you know, we have the technology to cross
           | over rivers. (I know, i know, inventing bridges and
           | establishing new standards for safer worlds vis a vis
           | cybersecurity is not the same thing, sure, sure, ok.) :-)
        
         | rented_mule wrote:
         | I'm a recently retired software engineer who has been on the
         | board of directors of a small rural mutual water company (i.e.,
         | owned by the customers) for ~15 years. We have less than 1,000
         | customers / shareholders. I'm in my mid-50s and the only one on
         | the board under 75-years old. Our community didn't have wired
         | internet access until eight years ago, and half the community
         | still doesn't have cell reception. You can imagine the level of
         | technical literacy.
         | 
         | It's hard to imagine significant help the government could give
         | us, short of $100K+ / year to hire a security engineer. Even
         | then, how would small utility companies find / evaluate them?
         | We already feel saddled with how many hours of mandatory
         | training we have to go through each year (e.g., board members
         | have to sit through training to remind us not to direct company
         | funds into our own bank accounts - I doubt that's a training
         | issue!). Looking at our two neighboring water companies, their
         | setups have very little in common with ours or each others. So
         | any training would be too generic to be of much use.
         | 
         | I have to give credit to our company's chairman / general
         | manager (himself 84-years old). He works to have diverse
         | expertise on the board. He's a retired wild-land firefighter,
         | plus there's a retired bookkeeper, a retired state employee, a
         | retired farmer, and me. As a group, we have a lot of experience
         | in a lot of areas. I suspect most small, rural water companies
         | haven't found a way to have that breadth of knowledge
         | available. But, even then, there's only so much that two full-
         | time plus two half-time employees can do. And it's hard to have
         | more while keeping rates sane.
         | 
         | On the security side, I'm no expert, but I pay attention. I do
         | my best to help the employees understand the dangers of
         | phishing and of downloading things onto company computers. We
         | have a consumer grade router and none of them know how to get
         | into it to open ports, etc. Even if things were locked down
         | hard, we couldn't afford to hire someone to maintain that state
         | as threats evolve. Our total compensation budget is $150K /
         | year for all employees, and 80% of that is needed for state-
         | licensed water treatment operators.
         | 
         | For us, all of that means being resigned to the fact that hacks
         | will happen. It's more about minimizing the damage and being
         | able to recover. I've pushed for using cloud services for
         | things like customer billing - these services are not the
         | ultimate in security, but they're far better than what we could
         | do with software running on our computers. I've also put append
         | only / offsite / offline backups in place so we can recover
         | from encrypting ransomware (which has hit us before, luckily we
         | could just wipe and re-install / restore).
         | 
         | The biggest thing we've done is around SCADA (software /
         | hardware involved in our water treatment and distribution).
         | When we put SCADA in place ten years ago, I pushed for it to be
         | read-only. That is, it can be used for monitoring and alerting,
         | but not for controlling anything (there's literally no hardware
         | in place to do so). So, hackers can see how much water,
         | chemicals, etc. we're using, but they can't directly change or
         | shutoff the water. They can make us think we need twice the
         | chemicals, but that will be a red flag for the operators who
         | have to manually implement it. Even then, we do manual daily
         | testing of our water in our lab and have monthly testing done
         | by state-licensed independent labs.
         | 
         | But, when we put SCADA in place, I had to stop and think a lot
         | about this given that I wasn't a security expert. And, of
         | course, the vendor was certain it was 100% secure (a red flag
         | in itself). But at least I had experience thinking about
         | software issues / impact. The operators certainly wanted
         | automated control, as that would save them from having to drive
         | to the plant in the middle of the night. And without automated
         | control, we have to use more chemicals, as we can't optimize
         | usage by reacting in real time to changes in pollutants in our
         | source water. But we'd all rather deal with those downsides
         | than find out someone has compromised our water. So it was easy
         | to sway them.
         | 
         | It's far from perfect, but we've mostly limited potential
         | damage to things that aren't deadly, literally or figuratively.
         | Without someone like our chairman / general manager being
         | dedicated to bringing in diverse expertise via the board, I
         | don't see what chance we'd have. And in certain parts of the
         | country, it would be hard to find security (or at least
         | software) expertise to sit on the board.
         | 
         | Something our state is doing to attack the lack of economies of
         | scale (in this and other areas) is trying to force rural water
         | systems to merge. About half in our area have been folded into
         | the water company for the "big" city (5K people), 20-miles away
         | from us. That's too far to move treated water given our local
         | terrain, so they have to keep running the systems from afar.
         | But at least they can spread (e.g., IT) expertise across these
         | systems. Where this has happened near us, water rates have
         | roughly doubled. Maybe that trade-off is okay, at least for
         | those who can afford it?
        
       | mapmeld wrote:
       | I don't have any inside knowledge to expand on this, but it's
       | interesting that Voting Village has had a public participatory
       | component (website, social media, annual appearance at DEFCON,
       | CFPs guiding messaging on topics on hardware and misinformation);
       | the DARPA AIxCC appears to follow that model, and yet this
       | Franklin Project is much harder to link to a website, social
       | media, mailing list, etc. Is it too early, is it invite-only...?
        
         | cosmotron wrote:
         | This seems to be the project's website:
         | http://defconfranklin.com/
        
       ___________________________________________________________________
       (page generated 2024-11-24 23:01 UTC)