Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em

c186282 <[email protected]>
Newsgroups comp.os.linux.misc,alt.security
Organization wokiesux
Message-ID <[email protected]>
On 8/22/26 08:22, The Natural Philosopher wrote:
> On 22/08/2026 00:49, Roger Blake wrote:
>> I remember reading an article years ago where it was stated that
>> when what came to be known as the internet was under development
>> it never occurred to anyone that users would attack each other.
> 
> Remember the Internet was devised initially (DARPANET) as a weapons 
> grade military network that could withstand a nuclear attack and still 
> allow someone to push the red button.
> Which is why IP packets have no field representing 'cost' embedded in them

   "Cost" ? What exact def did you have in mind ?

> Imagine if any website could charge you for access seamlessly, with your 
> ISP charging you the picocents for each packet downloaded via them and 
> reimbursing the sites owners.
> 
> NO advertising needed

   Constant rip-offs ... that's pretty standard now.
   Client/mainframe became "PCs"/Net and has now
   drifted back to the old model. Cash-extraction
   for every byte, even if they try to hide that.

> But the point remains TCP/IP was optimised cor reliability diverse 
> routing and connectivity.

   Correct. It's pretty strong if used correctly.

   But it was also designed with a MUCH MUCH simpler
   environment in mind. The packet-routing equation
   alone these days is just insane.

   Ye and me are old enough to remember when there
   was no 'internet', no DARPA-net. A Big Box somewhere
   and low-speed direct serial connections, maybe over
   horribly low-speed modems. The old IBM and DEC
   systems were made for international collaboration
   and commerce - over those SLOW SLOW connections.
   Better condense yer data intelligently, and no
   flashing ads for gambling and porn sites ! :-)

> Any security was to be provided either at a physical level - cables 
> inside locked locations - or at a higher level by firewalls, encryption 
> and network virtualisation.
> 
> It is not the fault of the Internet that people do not routinely employ 
> these to protect their networks.

   Employing ENOUGH, and "enough" is harder and harder
   to achieve every day now, is very DIFFICULT. Pretty
   soon you are drowned by your own 'security' measures
   and remember each 'measure' may have it's OWN flaws
   someone can exploit.

   Basically you have to analyze YOUR risks - who/what/why
   might want to get at YOUR stuff. For Joe Average, not
   many are particularly interested except MAYBE stealing
   his bank routing number or Amazon acct password if you
   make it super-easy.

   For bigger biz and banking and govt/defense however the
   risk is MUCH greater. Such systems attract the worst
   of the worst and they WILL put major time/resources
   into their evils.

   But, theoretically, the 'big' players OUGHT to be able
   to afford a squad of their OWN in-house geeks who can
   find and fix such evil efforts. But is seems fewer
   and fewer DO - they just turn it over to "Company-X"
   which promises everything and rarely delivers. In the
   small print somewhere C-X be held harmless or be able
   to SWEAR it was YOU who screwed their 'perfect'
   protection scheme.

   Employ Company-X and, if all goes to hell, YOU can't
   be blamed. It's all THEIR fault !!!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.