this post was submitted on 01 Aug 2026
171 points (98.3% liked)

Technology

86780 readers
3871 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 24 comments
sorted by: hot top controversial new old
[–] ContactClosure@lemmus.org 18 points 15 hours ago

I'm just glad they put my water and power meter on the internet so they wouldn't have to pay someone to come check it. Capitalism is the best.

[–] kyTdKZx9PtDQ9e56u06@lemmy.dbzer0.com 28 points 18 hours ago (1 children)

"The amount of non technical people performing shadow IT work at local municipalities is flabbergasting. You have no idea of the amount of exposed endpoints with admin:admin as their credentials." - dude I know.

[–] Doom@lemmy.world 7 points 14 hours ago

I don't miss network administration. The long drag out conversations with clients to convince them that basic security was necessary while dodging the "it's fine we've always done it this way" and "we don't want to memorize new passwords" hot spots.

[–] AuroraZzz@lemmy.world 21 points 18 hours ago* (last edited 18 hours ago) (2 children)

Okay. What are they gonna do about it? Are they just going to be "on edge" and take no action whatsoever?

[–] Switorik@sh.itjust.works 14 points 16 hours ago (1 children)

You just described the last 10 years of politics

[–] heartSagan5@lemmy.zip 2 points 14 hours ago

My favorite quote from Red Tails was that “politicians resist spending until the very last minute” (or similar). Man, that film was good.

[–] dan1101@lemmy.world 10 points 18 hours ago

They are thinking about possibly starting to do something about it.

I wonder if the people/businesses that set up the internet connectivity are even around any more.

[–] Wildmimic@anarchist.nexus 38 points 21 hours ago* (last edited 21 hours ago) (3 children)

LOL why are those systems even exposed to the internet? This is fucking inane, making sure those systems can't connect to the internet is basic security, and whoever decided to cut corners here should get fired, sued, sentenced and fined, all of this into eternity because their decision was fucking braindead. VPNs are NOT a new technology.

[–] IphtashuFitz@lemmy.world 17 points 17 hours ago (1 children)

VPNs are too complex for non-technical people. I used to work in IT for a big university. When I managed the installation of a large research cluster they insisted it be publicly accessible so that traveling professors, etc. would have easy access to it. Long story short, I found it had been compromised by an IP address in China within hours of it being on-line.

[–] Wildmimic@anarchist.nexus 14 points 17 hours ago* (last edited 17 hours ago)

Non-technical people should not have a say in security at all. Just as the opinions of Joe Shmoe should be disregarded in sectors like public health, science, law and politics. We have to start to purge the people knowing shit in all important areas. Crap like a shitstorm on X (aka nazi central) or something should be used to target the participants in those campaigns to mark them as unreliable bums.

Edit: more extreme people than me might propose a system that is close to the Black Mirror episode "Hated in the Nation", but not with killing the fuckers participating, but by taking away their talking rights on online platforms. Humanity would be better off this way.

[–] stealth_cookies@lemmy.ca 6 points 15 hours ago

Seriously, you can setup VPNs to only allow specific trusted devices. With critical infrastructure it should be a whitelist only security model.

[–] RememberTheApollo_@lemmy.world 8 points 19 hours ago (2 children)

A lot of our critical infrastructure is connected. From power generation to water to sewer. All have been subject to hacking attempts, some successful.

I have also been saying for quite a long time that these things should not be connected in a way that they can be damaged or disabled by internet.

But y’know, put it all on the web and write controller software for centralized remote operation and monitoring so you can fire people and run the system with less people for more profit.

[–] blargh513@sh.itjust.works 8 points 17 hours ago

Ooh I do security stuff.

I'm willing to bet that there are a core of talented systems engineers that built out the control systems for water plants. They are smart people that care deeply about what they do.

Their "leadership" however is usually made up of a loose group of interchangeable clowns that cycle in and out based on connections, nepotism and financial incentives. Their job is to do stuff to impress other important people and that usually means cutting costs. Sometimes it means getting into bed with a vendor or other company so they can profit from the relationship.

They will direct the engineers to use stupid shit, turn off controls, use platforms that are wholly inappropriate.

They will make a mess out of a system that was designed well to the point where fixing all the problems is impossibly expensive. They will declare that its good enough and then take their next job.

I have watched this cycle happen over and over. Current company has about 10+ years of problems stacked up and it would cost more to fix them than the company makes in revenue for a few years. They won't be fixed.

[–] wetsoggybread@lemmy.world 12 points 19 hours ago

When it comes to SCADA systems they should never be connected to the internet and should be air gapped to prevent intrusions. If connecting from a remote location it should be secured with a VPN, 2fa and be read-only. SCADA systems are almost constantly monitored 24/7 and someone onsite should be able to handle any emergencies

[–] WanderingThoughts@europe.pub 42 points 23 hours ago (1 children)

Maybe they can use AI to fix it

[–] athatet@lemmy.zip 3 points 16 hours ago (1 children)

So use an ai cat in the image? Interesting choice.

[–] WanderingThoughts@europe.pub 3 points 15 hours ago

To illustrate it's only good in stupid stuff like that and not so good for real work.

[–] modem_down@thebrainbin.org 28 points 22 hours ago

This coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.

Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.

Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.

[–] Lushed_Lungfish@lemmy.ca 6 points 18 hours ago

Wasn't this part of the plot to one of the Splinter Cell games?

[–] Nobody@anarchist.nexus 16 points 23 hours ago (1 children)

Vulnerabilities exposed, but nothing to see here. I’m sure there aren’t vulnerabilities like this in infrastructure everywhere.

Probably just a fluke.

[–] Frozengyro@lemmy.world 12 points 20 hours ago (1 children)

Honestly can't understand why all infrastructure isn't air gapped. As someone who knows nothing about cyber security it seems like it would be the easiest way to prevent this.

[–] TehWorld@lemmy.world 4 points 19 hours ago (1 children)

Because money. It cost tax dollars to roll a truck to these sites every time a switch needs to be thrown. I heard that an air raid siren went off not too long ago because some kids figured out that they were controlled by DMTF tones on an unencrypted radio frequency.

[–] unitedwithme@lemmy.today 2 points 18 hours ago

We call those tornado sirens now. Wonder if ours function that way 🤔😅

[–] jjlinux@lemmy.zip 1 points 14 hours ago

Have the new data centers handle that. There fixed. 🤣