Re: US Govt Warns About Siemens S7 PLA - Iran Can Hack 'Em
c186282 <[email protected]>
| Newsgroups | comp.os.linux.misc,alt.security |
|---|---|
| Organization | wokiesux |
| Message-ID | <[email protected]> |
On 8/22/26 08:22, The Natural Philosopher wrote: > On 22/08/2026 00:49, Roger Blake wrote: >> I remember reading an article years ago where it was stated that >> when what came to be known as the internet was under development >> it never occurred to anyone that users would attack each other. > > Remember the Internet was devised initially (DARPANET) as a weapons > grade military network that could withstand a nuclear attack and still > allow someone to push the red button. > Which is why IP packets have no field representing 'cost' embedded in them "Cost" ? What exact def did you have in mind ? > Imagine if any website could charge you for access seamlessly, with your > ISP charging you the picocents for each packet downloaded via them and > reimbursing the sites owners. > > NO advertising needed Constant rip-offs ... that's pretty standard now. Client/mainframe became "PCs"/Net and has now drifted back to the old model. Cash-extraction for every byte, even if they try to hide that. > But the point remains TCP/IP was optimised cor reliability diverse > routing and connectivity. Correct. It's pretty strong if used correctly. But it was also designed with a MUCH MUCH simpler environment in mind. The packet-routing equation alone these days is just insane. Ye and me are old enough to remember when there was no 'internet', no DARPA-net. A Big Box somewhere and low-speed direct serial connections, maybe over horribly low-speed modems. The old IBM and DEC systems were made for international collaboration and commerce - over those SLOW SLOW connections. Better condense yer data intelligently, and no flashing ads for gambling and porn sites ! :-) > Any security was to be provided either at a physical level - cables > inside locked locations - or at a higher level by firewalls, encryption > and network virtualisation. > > It is not the fault of the Internet that people do not routinely employ > these to protect their networks. Employing ENOUGH, and "enough" is harder and harder to achieve every day now, is very DIFFICULT. Pretty soon you are drowned by your own 'security' measures and remember each 'measure' may have it's OWN flaws someone can exploit. Basically you have to analyze YOUR risks - who/what/why might want to get at YOUR stuff. For Joe Average, not many are particularly interested except MAYBE stealing his bank routing number or Amazon acct password if you make it super-easy. For bigger biz and banking and govt/defense however the risk is MUCH greater. Such systems attract the worst of the worst and they WILL put major time/resources into their evils. But, theoretically, the 'big' players OUGHT to be able to afford a squad of their OWN in-house geeks who can find and fix such evil efforts. But is seems fewer and fewer DO - they just turn it over to "Company-X" which promises everything and rarely delivers. In the small print somewhere C-X be held harmless or be able to SWEAR it was YOU who screwed their 'perfect' protection scheme. Employ Company-X and, if all goes to hell, YOU can't be blamed. It's all THEIR fault !!!