• kyTdKZx9PtDQ9e56u06@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    44 minutes ago

    “The amount of non technical people performing shadow IT work at local municipalities is flabbergasting. You have no idea of the amount of exposed endpoints with admin:admin as their credentials.” - dude I know.

  • AuroraZzz@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 hour ago

    Okay. What are they gonna do about it? Are they just going to be “on edge” and take no action whatsoever?

    • dan1101@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 hour ago

      They are thinking about possibly starting to do something about it.

      I wonder if the people/businesses that set up the internet connectivity are even around any more.

  • Wildmimic@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    0
    ·
    4 hours ago

    LOL why are those systems even exposed to the internet? This is fucking inane, making sure those systems can’t connect to the internet is basic security, and whoever decided to cut corners here should get fired, sued, sentenced and fined, all of this into eternity because their decision was fucking braindead. VPNs are NOT a new technology.

    • IphtashuFitz@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      28 minutes ago

      VPNs are too complex for non-technical people. I used to work in IT for a big university. When I managed the installation of a large research cluster they insisted it be publicly accessible so that traveling professors, etc. would have easy access to it. Long story short, I found it had been compromised by an IP address in China within hours of it being on-line.

    • RememberTheApollo_@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 hours ago

      A lot of our critical infrastructure is connected. From power generation to water to sewer. All have been subject to hacking attempts, some successful.

      I have also been saying for quite a long time that these things should not be connected in a way that they can be damaged or disabled by internet.

      But y’know, put it all on the web and write controller software for centralized remote operation and monitoring so you can fire people and run the system with less people for more profit.

      • wetsoggybread@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 hours ago

        When it comes to SCADA systems they should never be connected to the internet and should be air gapped to prevent intrusions. If connecting from a remote location it should be secured with a VPN, 2fa and be read-only. SCADA systems are almost constantly monitored 24/7 and someone onsite should be able to handle any emergencies

  • Nobody@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 hours ago

    Vulnerabilities exposed, but nothing to see here. I’m sure there aren’t vulnerabilities like this in infrastructure everywhere.

    Probably just a fluke.

    • Frozengyro@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 hours ago

      Honestly can’t understand why all infrastructure isn’t air gapped. As someone who knows nothing about cyber security it seems like it would be the easiest way to prevent this.

      • TehWorld@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 hours ago

        Because money. It cost tax dollars to roll a truck to these sites every time a switch needs to be thrown. I heard that an air raid siren went off not too long ago because some kids figured out that they were controlled by DMTF tones on an unencrypted radio frequency.