People use 1000x more water than they need to drink.
If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted.
Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope.
It wouldn't cause the mass casualties an enemy might assume.
DOGE eliminated 1/3 of CISA staff in 2025. Trump reduced the 2026 CISA budget by $491 million (17%). Trump intends to slash their budget by an additional $707 million in 2027.
I think this landscape is littered with simulated systems as honeypot. Once you have it a normal adversary would stop searching, besides regular checks that the gun still works.
I deplore all of this nonsense. But I can’t help but observe the symmetry. The US president threatened to destroy Iranian water plants; an Iranian water plant was destroyed…
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.
After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.
Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.
When will the public figure out that many IT exploits are the result of malpractice by developers and network adminstrators, and the businesses employing them? We're building and operating bridges that we know will collapse. Our products are nearly indefensible, literally - they can't realistically be secured except at great expense. We talk about the imbalance between costs of attack and defense; we made that imbalance.
The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.
The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.
Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…
It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.
These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.
Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.
If I was in a power position, I could theoretically channel this water into my own private reservoirs and locations like private land, bunkers, etc to weather a disruption, and blame Iran and it would be really hard to validate.
I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.
I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!
But they wouldn't need to false-flag an excuse to capture and privatize resources, they could and would just do that openly. The government can just take whatever it wants through eminent domain.
We don't follow "rules" in war anymore, according to "Secretary of War" Pete Hegseth. We show no quarter and take no prisoners, we pursue "maximum lethality, not tepid legality."
That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.
They always point to a state actor to skirt liability for their own shitty IT work. Then the dim evil journalists swallow it whole, later regurgitating it for their eager little baby bird subscribers.
If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.
> “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”
Iran is beside the point. There is always a convenient bogeyman: China, Russia, North Korea… They sow discord between peoples to cover-up the ineptitude of domestic institutional assholes.
People use 1000x more water than they need to drink.
If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted.
Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope.
It wouldn't cause the mass casualties an enemy might assume.
Iran doesn't need to cause mass casualties. They just need to make US citizens hate the war in Iran.
[delayed]
Exactly how big do you think those bottles would be?
Wasn't there a Defcon or Derby talk about this years back? (The insecurity, not the Persian angle)
Struggling for a source.
Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?
Not sure about defcon, but Buckminster Fuller wrote waay back in the sixties about the New York's vulnerability to a fresh water supply attack.
If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books.
https://archive.org/details/operatingmanualforspaceshipearth...
https://archive.is/fa2Xj
Where does all the money go? Not to cyber apparently.
DOGE eliminated 1/3 of CISA staff in 2025. Trump reduced the 2026 CISA budget by $491 million (17%). Trump intends to slash their budget by an additional $707 million in 2027.
I think this landscape is littered with simulated systems as honeypot. Once you have it a normal adversary would stop searching, besides regular checks that the gun still works.
I deplore all of this nonsense. But I can’t help but observe the symmetry. The US president threatened to destroy Iranian water plants; an Iranian water plant was destroyed…
https://www.nbcnews.com/world/iran/water-energy-sites-hit-us...
https://apnews.com/article/trump-iran-threat-desalination-pl...
It sure reads like more of a tit-for-tat in that context.
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.
After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.
https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...
Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!
Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.
When will the public figure out that many IT exploits are the result of malpractice by developers and network adminstrators, and the businesses employing them? We're building and operating bridges that we know will collapse. Our products are nearly indefensible, literally - they can't realistically be secured except at great expense. We talk about the imbalance between costs of attack and defense; we made that imbalance.
The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.
The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.
I mean
Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…
It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.
These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.
[0] https://www.cisa.gov/topics/industrial-control-systems , and https://www.gao.gov/assets/d24106576.pdf for an idea of the staffing they’re doing it with…
[1] https://www.epa.gov/dwreginfo/information-about-public-water...
Who connected the systems to the Internet in the first place?
Why?
Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.
https://news.ycombinator.com/item?id=39243560
https://web.archive.org/web/20240409155326/https://www.awwa....
(cybersecurity practitioner is a component of my professional persona)
Is this the true reason for the cyclosporasis outbreaks?
Nah. Cyclospora is a parasite, not a virus.
[Riffing on the gag, not an actual misunderstanding, just to be clear.]
Can we still blame Mexico, Taylor Farms and Taco Bell as well?
Taco Bell is secretly funded by Iran and North Korea and invented covid…
If I was in a power position, I could theoretically channel this water into my own private reservoirs and locations like private land, bunkers, etc to weather a disruption, and blame Iran and it would be really hard to validate.
I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.
I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!
I understand being mad, I also get mad.
This is a bit unhinged.
We used to say that about some things before Snowden. And then there was Snowden.
But they wouldn't need to false-flag an excuse to capture and privatize resources, they could and would just do that openly. The government can just take whatever it wants through eminent domain.
You know water is kind of big right?
> “I think Minnesota is behind it,” Mr. Trump said on Friday in response to a reporter’s question about Iran’s possible involvement,
What a coward and a traitor to the American people.
He knows he brought these attacks with his war, but he doesn’t take the blame for anything.
Either he knows and doesn't want to take the blame, or he doesn't know. I'm not sure which one is worse.
He stopped going to security briefings before, maybe he simply doesn't care to know.
> he brought these attacks with his war
I'm no Trump supporter and this war was a big mistake, but justifying a nation poisoning another's civilian water supply is a bit upside down.
Yeah, what could we possibly have done[0] to justify an attack on our water supply????
[0]: https://www.commondreams.org/news/iran-water-desalination-pl...
Ask the people of Flint, Michigan?
We don't follow "rules" in war anymore, according to "Secretary of War" Pete Hegseth. We show no quarter and take no prisoners, we pursue "maximum lethality, not tepid legality."
That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.
I hope it gets bad enough people wake tf up and do something with me about it.
It was probably the same (imaginary) people who damaged the lining of the Reflecting Pool.
I think we should think about making blatant lies by politicians a crime.
What's one more crime compared to all of the ones they've already committed?
[dead]
[dead]
They always point to a state actor to skirt liability for their own shitty IT work. Then the dim evil journalists swallow it whole, later regurgitating it for their eager little baby bird subscribers.
If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.
<adjustsTinFoilHat> The Trump plan in Iran is not working. Gotta make them look like the evil bogeyman to get people to support further action.
This conspiracy theory would make more sense if he wasn’t working so hard to divert blame away from Iran: https://www.politico.com/news/2026/07/31/trump-minnesota-wat...
> “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”
The rest of the thread demonstrates well enough that flagging would have been a better response than trying to engage with it factually.
But I do appreciate the attempt anyway.
As if it were only Minnesota. But his base doesn’t pay attention to details.
Iran is beside the point. There is always a convenient bogeyman: China, Russia, North Korea… They sow discord between peoples to cover-up the ineptitude of domestic institutional assholes.
Blacks.
Homosexuals.
Communists.
Islamics.
Hispanics.
Liberals.
Intellectuals.
There’s always an other. That’s what the Republicans have been doing for decades.
> There’s always an other. That’s what the [group I definitely don't belong to] have been doing for decades.
Please reconsider your logic. And:
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
In this war initiated by USA and Israel, it isn't Iran who's attacking civil targets.