←back to thread

58 points JumpCrisscross | 7 comments | | HN request time: 0.454s | source | bottom
1. Animats ◴[] No.43667500[source]
Then they'll make them "cloud-enabled" and they will be hacked.

It's scary to see protective relays for power systems with embedded web servers. "IEEE C37.118 synchrophasor measurement, DNP3 Outstation, Modbus TCP/RTU, Telnet, FTP, Simple Network Time Protocol (SNTP), built-in web server, and IEC 61850" [1]

[1] https://selinc.com/products/351/#

replies(2): >>43668181 #>>43668553 #
2. fc417fc802 ◴[] No.43668181[source]
It's fine provided that the link from the equipment that feeds it data is optically isolated to only go in one direction.

A public internet connected web server that enables remote equipment control is indeed scary.

replies(1): >>43668317 #
3. Animats ◴[] No.43668317[source]
> It's fine provided that the link from the equipment that feeds it data is optically isolated to only go in one direction.

Then people get two of them, one for each direction.[1] Can someone explain why this is supposed to be secure? It's apparently a real product.

[1] https://owlcyberdefense.com/product/recon-2u/

replies(2): >>43668734 #>>43670707 #
4. sightbroke ◴[] No.43668553[source]
> Then they'll make them "cloud-enabled" and they will be hacked.

It's worse:

https://arstechnica.com/security/2025/01/could-hackers-use-n...

replies(1): >>43671764 #
5. fc417fc802 ◴[] No.43668734{3}[source]
Wut? That reads like satire. The equipment is inside the security boundary, the LAN is outside. What is the purpose of enforcing one-way control signals when the thing sending the control signals is by necessity within the same security boundary as the destination for those signals?

I want to extend the benefit of the doubt and assume my own ignorance but I'm really struggling with this one.

6. mppm ◴[] No.43670707{3}[source]
Amazing. Maybe I should pitch them my idea of MIL-spec acoustic relays for communicating with air-gapped facilities?
7. metalman ◴[] No.43671764[source]
the integration of the SST's is years out, anything right now is test phase, and work at bringing awareness to the grid operators, who by the way are all conversant with the peculiaritys of working with steam, ie: a conservative bunch who you can bet, will be running code on terminals so esoteric and unpublished as to invite madness for the unwary.........that, and power companys have been embedding there own private fibre inside the core's of the HVTL, so they have unusual options. It's the grid fer fucks sake, give them some credit. Powermag looks to be extra solid,bookmarked.