Slashdot Mirror


Power Grid Insecurities Examined

Joe Barr writes "Chris Gulker has taken a long and careful look at the infrastructure of our power grids and has come to some rather unsettling conclusions." A good read that outlines where the current power grid is at, and suggests some paths for the future that may help avoid future blackouts.

65 of 248 comments (clear)

  1. Shocking by Neppy · · Score: 2, Funny

    The insecurities in our power grid are quite shocking.

    1. Re:Shocking by SpaceLifeForm · · Score: 2, Interesting

      Or insecurities in computers.
      Recent grid failure in the U.S. and Ontario may (likely?) be related to computer problems.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
  2. Scared yet? by krray · · Score: 4, Insightful

    Wonderful -- as I read the article, plastered in the center of the page is the ad:

    "Microsoft - Big business ambition. Small business resources. Get your FREE 6-month trial now. Windows Small Business Server 2003".

    The very fact that the power grid, atm's, so on and so forth -- hell, I worked on the power supply to a embedded PC today for a newspaper printing press that had NT on it ... it frankly scares the hell out of me.

    There I'll be sitting there in front of my OS X or Linux box. Can't be too smug I suppose with no power. No telephone. No gas. No cash to buy bread. Hell, the auto-checkout lanes (which I refuse to use on principle) at Jewel are Mickey-MouseSoft based. Certainly no Internet.

    For my business' I absolutely refused to allow a Windows server of any type in the datacenter. I still say, "are you nuts?". Yet people still did it. Once again, Bill Gates will get a chance to screw us I guess.

    So, when is the next worm due to hit? At least my TiVo will still work... :)

    1. Re:Scared yet? by randyest · · Score: 2, Interesting

      Best part of the article, and hilarious:

      While legacy control systems are often UNIX-based ("Control-Alt-Delete scares power plant operators," Ahern said) and thus immune to MS worms and virii, their 10-megabit networking technologies can easily be overwhelmed. "Even the load from leading intrusion detection and monitoring systems can create a denial of service and shut these plants down," Ahern said.

      --
      everything in moderation
    2. Re:Scared yet? by BWJones · · Score: 4, Insightful

      ... it frankly scares the hell out of me.

      Hey, it's not just the power grid and atm's. There are command and control systems used by the department of defense that folks have migrated to Windows. Our Dept of Homeland security has standardized on Windows. Certain FAA traffic control systems are running on Windows. The Army's Landwarrior program is using Windows. Traffic control for trains and shipping are running on Windows. etc...etc...etc...

      This should scare the hell out of a lot of people.

      --
      Visit Jonesblog and say hello.
    3. Re:Scared yet? by itwerx · · Score: 3, Informative

      The auto-checkout lanes at QFC and Safeway here in WA state are Linux. :)
      Now for those who read that article, here's a reality check.
      I worked on one of the Y2K project teams that did high-level analysis for a number of midwestern power plants.
      I can tell you that NONE of their control and monitoring systems were in any way connected to the Internet or even, usually, to any other networks internally.
      The reason cited in every case was security.
      The folks I worked with are called EPRI (Electric Power Research Institute) and they are widely regarded as the world's leading authority on national and international power generation and distribution systems.
      Check out their website, they often have some interesting white-papers available for public perusal.

    4. Re:Scared yet? by Anonymous Coward · · Score: 4, Interesting

      I work at a company where we sell grid control sofware (SCADA software for in-market lingo)

      We had a product which used a particular UNIX, not a BSD or Linux, but the real high dollar, blessed by AT&T stuff. It hardly mattered because so many of our customers are not computer people, they are power engineers. They're not interested in event the user/group/everyone security model, they are interested in which breakers to open or close in the event a thunderstorm takes out this power line.

      As a result, many of the UNIX systems were set up for conveinence, not security, and anything that reduced conveinence created cries of frustration from our customers (and developers). Eventually we succumbed to pressure from our customer base, and now large portions of our system have been replaced with MS Windows systems. The customers (our power companies) love it.

      You can't sell security to those who don't want to buy it, but you can always complain when it's not there.

    5. Re:Scared yet? by digitalunity · · Score: 2, Insightful

      I highly recommend QNX real-time OS. It is top notch. We have embedded devices here where I work that have *never* failed and some of them are running QNX. Just amazing stuff.

      --
      You can't legislate goodness. Let each to his own destiny, by will of his freely made choices.
  3. We should all generate power by Anonymous Coward · · Score: 5, Interesting

    In most states, if you generate your own power (ie solar), you can feed it back to the grid, and the electric companies are required to credit you! Any excess power you have can make you money. Sure, it's an investment up front to move to solar, but it is doable, and some states even offer tax credits.

    1. Re:We should all generate power by segment · · Score: 4, Interesting
      Sure, it's an investment up front to move to solar, but it is doable, and some states even offer tax credits.


      It's a nice thought but unless you live somewhere country-like, it's unfeasible to most people. Here's why, now firstly sure it is expensive to set up, but you would have to live in a geographically correct place as well. Say Florida, California, Arizona, Texas. States where it is rather sunny as opposed to say Seattle.

      You could use alternatives such as windmills, but again you would need massive space. When I was in Sweden, the government there was trying to limit where windmills could be used, as they often killed birds, some of which may have been rare, or on the verge of existence.

      I wish I wasn't too lazy and tired to offer links to prove my Swedish claims, but I'm sure anyone can find it on Google.

    2. Re:We should all generate power by quacking+duck · · Score: 3, Interesting

      Always wondered why you couldn't just hook up say an exercise bike to a generator to feed the grid. Save money and stay in shape at the same time!

    3. Re:We should all generate power by TopShelf · · Score: 2, Interesting

      You're not the only one who's had such thoughts...

      --
      Stop by my site where I write about ERP systems & more
    4. Re:We should all generate power by cheshiremackat · · Score: 2, Interesting

      I just saw on TV (TLC I think) that Denmark was building wind generators offshore... Seems like a brilliant idea... use space that isn't really being used otherwise...

      The only problem with the current electrical grid is storage... electricity cannot be stored (duh) so peak demand has to = supply or brownouts...

      Here is my idea, we build a powerplant (hopefully wind/solar but nuclear is ok too) and hook the generator up to a hydrogen refinery (a la iceland)... that way the power can be stored (ok not perfect efficiency but still pretty good)... then when we need power we feed the hydrogen through fuel cells to generate power on demand...

      The benefit is that we can build smaller plants b/c they can run all day long at 100% output b/c the output is stored...

      The only downside is cost... but remember the current costs of power generation COMPLETELY ignore the environmental costs, which would be much lower if we used this wind/hydrogen idea

      --
      Bad spellers of the world untie!
  4. heh by Comsn · · Score: 5, Insightful

    Says Skroch: "If you have too much security [i.e., no network connections], then the power plant probably won't work."

    power plants worked long before the internet was created. no important computer controlling very important things should ever be put on the internet.

    1. Re:heh by Steinfiend · · Score: 5, Insightful

      I cannot agree more with this, it amazes me every time I hear of some important computer system being affected by an internet based infection or an internet routed hack.

      Surely the only people who need to control a power plant (or dam release valves, or weapons sytems or whatever) are the people in the facility working at that time? So why have any type of network access to the system other than what is required within the grounds of the facility?

      Of course I might be being naive, but I don't think so.

    2. Re:heh by segment · · Score: 2, Insightful

      So why have any type of network access to the system other than what is required within the grounds of the facility?

      It is a matter of convenience to be able to access offices from other offices, as we as people have become so lazy due to the boom in computer usage. It is much easier to be able to perform tasks using computers rather than doing things manually, and depending on what job duties you have, it can actually be a bit safer for the worker. However, in my opinion, people have just become lazy as shit and choose to use machines as an excuse for avoiding working. I say this as coincidentally (while I watch the news) a reporter just stated that 90% of working people are unhappy at their jobs. So why take an extra step when a computer could eliminate five steps.

    3. Re:heh by Jordy · · Score: 3, Informative

      power plants worked long before the internet was created. no important computer controlling very important things should ever be put on the internet.

      Network connections != internet connections. Current power systems have network connections since it is kind of nice to be able to monitor it from time to time. They typically run over fiber rings independent from the power grid itself.

      --
      The world is neither black nor white nor good nor evil, only many shades of CowboyNeal.
    4. Re:heh by delcielo · · Score: 4, Interesting

      Economics come in to play here a bit as well.

      The market for buying and selling excess power is VERY active and exists primarily on the internet. Multi-million dollar deals are made quickly, and while they can be made in advance, they may also be made at the whim of mother nature (excessive heat causing a company to purchase power, or a drop in temp making excess power available).

      Implementing the deal means interacting with control systems. I will admit to ignorance of how this happens exactly; but I suspect that the traders aren't driving to the power plant or transmission control centers and doing it themselves.

      For a company that has efficient generation, they can make a great deal of money selling excess power. This means their customers don't have to pay quite as much.

      Here is the real issue: Everybody wants better security; but just tell anyone that you're going to have to up their rates to provide it and see what the reaction is.

      --
      Hot Damn! It's the Soggy Bottom Boys!
    5. Re:heh by canadian_right · · Score: 2, Informative
      I live in BC Canada and we are 90% Hydro power, and most of the dams are in the middle of no where. All sites have people locally, but actual "production and control" is centrally managed to optimise system utilization and profits. Remote control and monitoring is done on private networks (much of it microwave) - there is NO connection to the internet and the control networks. All critical systems are multiply redundant (opening the wrong gate full open could flood a town). But there is a mix of old, new, and inbewteen systems. Most systems are proprietary and it is hard to get information about them that would be useful to hackers. We do run some non-critical monitoring over our normal private intranet.

      I'm sure many other utilities are similar, but I think the real problem is that with deregulation there is zero incentive to build new reliable infratructure like transmission lines. Why would you spend a penny on a new transmission line when the current one is only 87% utilized 75% of the year? The old monopolies did do this kind of long range planning and upgrading. It still gets done, but not until the last minute.

      --
      Anarchists never rule
    6. Re:heh by ebuck · · Score: 3, Interesting

      Wish I had some mod points to add an insightful your way, because you're right.

      I've seen some of these "isolated" power-grid lans compromised because it was "critical" that the data be fed into the marketing department or server appliations which determined optimal generation schedules based on the ability to sell "excess" power when it's most profitable.

      The days of assuming you can secure via isolation are gone in the power market, but the debugging and testing cycles are so complete that it takes at least a year to implement a new anything. So despite CNN making this the "story of the year", a solution won't be available until well after the media decides that a particularly brutal murder is much much more newsworthy (or something to that efect).

      Meanwhile thousands of developers that have always assumed their code was safe from attack because of physical (ie isolation) security are now scratching their heads on how to refactor these systems while trying not to be sidetracked by the security rabble-rousers who are asking if the system will withstand the latest exotic attack X (which requires someone to duplicate almost valid messages via a morris code trainer attached to an ethernet cable).

      Unfortunately the most dangerous of these rabble-rousers come in two forms, lobbists and consultants. Although they complain the loudest about the problem, secretly they are in favor of keeping the problem around as long as possible because they only make money while it is still a problem. These people are rarely die-hard techs, but they know how to play the media like a violin.

  5. Security Vs Usability by Admiral+Justin · · Score: 3, Insightful

    The article does bring up a valid point. Many times, when large systems attempt are forced into security by fear, they overdo it, and the system becomes nearly unusable to the users, who have to run around in circles with security measures.

    The lesson? Security is nice, but lets not go biometrics and 30 different passwords just to check the email.

    --
    You will be baked, and there will be cake.
  6. Stock up on booze and smokes by soupforare · · Score: 4, Insightful

    "The situation is so bad, experts say, that bored script kiddies could soon be knocking out power stations as easily as they concoct viruses from toolkits available on the Web."

    Is it any easier now then it has ever been? It always seemed pretty simple to me. Go down to your local, unmanned, power station and blow it up. Get your buddies and some trucks and knock down some high tension wires. wheeeeee.

    Why do people get excited by this? It might be my misanthropic nihilism talking, but shit happens. Every day. Deal with it.

    You might lose power, you might lose running water, you might get hit by a bus.
    Even if you hole up in a shack to protect yourself from the script kiddies, psychopaths, terrorists and/or government... you're still gonna die!

    Have fun! :)

    --
    --- Do you believe in the day?
    1. Re:Stock up on booze and smokes by swschrad · · Score: 2, Funny

      no, that's always been booze and guns and ammo. the survivalists always tuck away hooch and hoglegs... whiskey for trading, bangsticks for defense... with their six-month dry food kits.

      now, now many valved gel-cell batteries should you stash to keep the MP3 server running when society collapses?

      --
      if this is supposed to be a new economy, how come they still want my old fashioned money?
  7. Well, what did they spend all my payments on... by BSOD+from+above · · Score: 5, Insightful

    The power industry needs to be reinvesting profits in infrastructure (powerlines), not stock dividends. The same companies should have been upgrading their command and control systems to prevent chain reaction blackouts. Am I expected to believe the computer systems that manage the cooling rods in the nearest nuke plant are secure?

    Seriously consider the economic impact of the grid failure compared to the recent worm problems. Then think about a nasty combination of the two.

    --
    Karma: Censored (mostly affected by decency laws)
    1. Re:Well, what did they spend all my payments on... by johnpaul191 · · Score: 2, Interesting
      Am I expected to believe the computer systems that manage the cooling rods in the nearest nuke plant are secure?


      maybe not?
      there was a story after the blackouts that back in Febuary 2003 a nuke power plant in Ohio somewhere lost it's safety systems for over 5 hours because of a worm/virus that took down the M$ system they were running. The story was on the news the same day they were reporting the Blaster worm messing up the switches in a Baltimore train yard. yikes!
  8. Is Linux the latest "silver bullet"? by KNicolson · · Score: 4, Interesting
    That article read a bit like an advertorial for Verano (some Linux SCADA security company), with the "Oh, if we only had Linux all this wouldn't have happened!" conclusion.

    However, reading the text, the problem seemed more that the plant operators had indiscriminately attached critical systems to the Internet without proper firewall security in place, which seems to me to be a human, not a computer or OS, flaw.

  9. Leave Power Grid alone you big meanies! by GuyMannDude · · Score: 4, Funny

    Well of course Power Grid is feeling particularly insecure right now. I mean it's old and weak and obsolete and just got caught with it's pants down a few weeks ago. That kind of spectacular failure is bound to make anything or anyone feel pretty insecure. I doubt the last thing Power Grid wants is to have its insecurities examined publically! C'mon, people, let's not kick it while it's down!

  10. Re:canada? by metallicagoaltender · · Score: 2, Funny

    No, it was NASA's fault - when Canada sends power back down to us, it's in Canadian units. The boys at NASA just haven't mastered the concept of unit conversion yet.

  11. Very nice commercial by cspenn · · Score: 3, Interesting

    ... for Verano.

    And if you connect ANY critical operating system to the Internet, frankly, you're insane. There's no sensible reason to do so. Monitoring your systems is fine, that's what a management network is for... but the actual core of the critical system should be as close to that powered-down concrete encased computer as possible.

  12. Garbage by Anonymous Coward · · Score: 5, Informative

    Did anyone actually read this garbage before they posted it. This is absolute nonsense. The blackout had _nothing_ to do with computers, much less internet security. The blackout happened because a half-rate utility (First Energy) tried to squeak through an emergency without buying expensive power or shedding load. Period. They operated lines until the sagged into brush. Some small subtransmission and distribution lines had twice rated load. Do the math. That's four times the temperature or over 400C. That had zippo to do with M$ or any bleepin' computer.

  13. Spent on Enron-style energy trading companies by swb · · Score: 4, Insightful

    It used to be that the utilities were highly regulated entities that had their profit margins basically regulated by the states they were in. They had to provide a given amount of reliability, and rate increases (and occasionally refunds!) were carefully scrutinized as to where the money went. You couldn't raise rates without showing some meaningful improvement that resulted from it.

    Then along came degregulation, where the power seller and the power generator became two different things (which makes even less sense than the deregulated-but-shared local phone loop). Utility companies wanted out of the power generation arena -- too expensive, too many regulations, it was better to be in the new "commodity" end of the business, arbitraging power. So they split themselves into trading companies and generation companies, taking all the cash into the trading companies, who were deregulated and could spend it freely.

    And then 10 years later, Enron and the whole deregulated power "market" has collapsed, and we wonder why we're 15-20 years behind the curve on power grid and other key infrastructure elements. All the money got spent on speculating in the newly deregulated power markets, and its all gone.

    Nobody really pays any less for electricity, I don't have a bunch of people knocking on my door offering me their window electricity or biodiesel electricity or their pig shit methane electricity for that matter.

    I only have the sheepish looking local utility trying to explain to me how they're trying to fix the power infrastructure built in the 1970s with the cash made in the 1980s which was spent in the 1990s on the promise of getting rich in the new millenium. When in fact, they actually need me to pay the prices of the next millenium for the service delivered in the 1990s, and, oh, would I please only use as much power as I did in the 1970s?

    1. Re:Spent on Enron-style energy trading companies by slashdotcassius · · Score: 3, Interesting

      For purposes of this discussion, in the industry there are two things: generators and high voltage lines.

      Now, once upon a time in the good old US of A, an official of a steel plant woe'd the outrageous slings suffered at being forced to buy energy from a utility due to that fact that his plant was located in said utility's fiefdom. In the industry, this is urban-lore explanation of how deregulation started.

      Guv'ment steps in. There'll be no Ma-Bell style bust-ups; rather, generators will be managed seperately from HV lines. Energy from generators could be sold and purchased by company employees. The high voltage lines, however, were supposed to be managed by a company that also managed serveral other neighboring utilities lines, wherein a reliability advantage would be gained (by the super-regional managing entity) from seeing confidential, real-time, system information from several utilities.

      How does the guv'ment force this? It can't; want's to, but can't.

      How can the guv'ment encourage this? Money. Promiss to deregulate (remove price caps on) the renting of hv lines: be in a regional transmission organization (RTO) for two years or so, and regulate prices yo dam sef after that. As a taste, generation side price caps were removed right away.

      The other selling point was a feel-good tactic. The islands-of-monopolies system hasn't led to inftrastructure upgrades that match demand, as each company *optimizes* like crazy to compete with the neighbors. Structure a business environment wherein an entity can develope that is soley about transmission, and things will take care of themselves.

      With deregulation, and the price-wars over energy that immediately followed (i.e.: the greed that lured marketers - who control the generators - to prevent key generators from running, in kalifornia, just because they could make the 10000% mark-up (no joke) they felt they deserved and thereby causing a cooperation-dependent system to crash under the strain of all the bickering.) spurred a tremendous about of generation to be built, in both the form of large coal-fire plants as well as strategically placed gas-turbin "peekers".

      Should FERC's simple deregulation goal for transmission ever be realized, it stands that the transmission infrastructure will see the same boon. In fact, the only RTO to date, MISO, has already laid out plans for new lines, with strong numbers indicating improved reliability and improved energy market.

      On Enron . . . hehehe . . . deregulation did not take it down. Enron took Enron down. Bonuses were paid in advaced for deals made. Very DUMB in the high-activity, deregulated market! Many deals ran for years totaly tens of millions. Bonuses should have been paid out on a cash flow basis, i.e.: pay the bonus monies out as the energy (in the contract) is actually used and paid for). Secondly, too many *managers* were able to arbitrarily up the value on a previous contract. Why would they do this? It increased their group's bonus.

      The genius of deregulation lies not in the ethics or ethos of capatilism, nor in that it lies in direct opposition to monoplistic tendencies. Rather, like the Linux world, where a vast number of minds focussed on an issue and produced a superior product, deregulation will increase the number of greedy bastards trying to meddle with the infrastructure such that it will accomodate their business deals. It's the number of minds brought to the table, despite their market economy drive, that makes deregulation a positive thing.

      Oh, something worth noting: utilities are, for the most part, fighting deregulation. Compliances are half-heated at best and down-right subversive at the norm. "Believe everything you hear; nothing can be too impossibly bad." -Oscar Wilde

  14. The case for remote control by Beryllium+Sphere(tm) · · Score: 3, Insightful

    The valve at a dam probably doesn't need to be turned very often, so it's economically tempting to save the cost of 24/7 onsite coverage and have one central operations center.

    Remote monitoring is all but imperative. The plants are already in a cooperative network sharing their power. Everyone on the grid needs at least basic information about what's going on.

    None of which is ANY excuse for a direct or indirect connection to the public Internet. This is a job for a private network, and I don't mean a VPN that can be DOS'ed when a worm spreads through the public network.

  15. But first... by YrWrstNtmr · · Score: 2, Insightful

    We must encourage the development of high-end fusion generating stations

    First, you have to make fusion work. Just once.

    +1 Interesting? Who's smoking the crack out there?

  16. Legacy = Semi Safe, Microsoft = Unsafe by Bruha · · Score: 4, Interesting

    Legacy systems will provide more resistance to viruses than any MS based system mainly due to the lack of coders with the knowhow to write viruses for such systems. Though when paried next to and on networks containing Microsoft based systems a MSVirus could cause havoc just by crippling the network that those systems rely on.

    In any case a system using NFS/NIS would be especially vulnerable to traffic floods by MSVirii due to the lockups that can happen when high traffic causes such file/security systems to fail.

    I've seen flapping interfaces on certain cisco equipment that have made messes of NFS and NIS based systems requireing a total reboot of the entire network from the top down. And the flapping can be caused by recent MSBlaster virii that has recently seen action.

    As a safety precaution the legacy networks should be extremely firewalled, and not allowed to work on any shared media that also caters to any Microsoft systems. Such seperation of the network would prevent either from spamming the other to death. Also in many critical areas private networks with private loops vs being carried over the internet should be considered with backups such a MicroWave or Sattelite communications to critical centers in case of any large infrastructure outages in your carriers network.

  17. Power Grid by hardburlyboogerman · · Score: 4, Informative

    I have taken myself off the grid years ago,using Solar,Wind,Hydro power(tapped into the abandoned Hardburly Deep mine and using the water to generate power) and have a 20kw diesel generator for backup.
    Most of the power grid problem stems from the fact that very little maintainence is being done.The Power lines out here have been here since the late 1950s or early 1960. Every time it rains,you can watch an electricial light show less than 50 ft from my home.(Phone calls to the power co.does no good,so I informed the Public Service Comission about it,sending a video tape of the light show.AEP now has 10 days to change the lines out or get fined to the tune of $50k/day!)
    Greedy utilities have brought this on themselves.Cutting jobs for the maintainence personell,doing nothing about aging lines, and then asking "WHY is this happening?

    "We call ourselves Homo Sapiens Spaiens.Our true name should be Home Stupidus"

    --
    Geek Hillbilly
    1. Re:Power Grid by Tailhook · · Score: 2, Insightful

      "Most of the power grid problem stems from the fact that very little maintainence is being done."

      "Greedy utilities have brought this on themselves.Cutting jobs for the maintainence personell,doing nothing about aging lines, and then asking "WHY is this happening?"

      There is nothing wrong with the "old" lines. The distribution grid carries some rated voltage and does it without much complaint. The problem is that there simply isn't enough of it, so most of the system is running at design capacity, and a small failure can cascade into a widespread failure.

      There isn't enough distribution capacity primarily because of NIMBY. Power companies around the country want to build more capacity. Most of the time they must spend years battling the locals for right of way. Environuts are often blamed unfairly when locals couch their resistance in bogus environmental claims, but the truth is that it's just NIMBY.

      And it's maintenance.

      --
      Maw! Fire up the karma burner!
  18. Re:Potential Social Implications? by dsanfte · · Score: 4, Insightful
    It is only then that we reach our full potential in our academic and athletic pursuits which substantiate our integrity in the grand scheme of things.


    Haha, what grand scheme of things?

    Humanity isn't trying to reach for the pinnacle of its capabilities, it's trying to find more comfortable ways to live and fuck.

    People want more power so they can do more cool shit, and do it cheaper. That's it.

    Yes, we can and we shall. It is what makes us the leading society in the western hemisphere and as history as proved, it is our greatest asset.


    Leading in all forms of waste and corruption. Nice example for the future. Here's a primer on human nature -- more of anything doesn't make people use it smarter, it makes them squander it faster. Western society is terrible for this.

    Your post is an attempt to be modded insightful by using big words to sound profound. Nothing you've said makes any sense.
    --
    occultae nullus est respectus musicae - originally a Greek proverb
  19. Quantum windmills by waynemcdougall · · Score: 4, Funny
    When I was in Sweden, the government there was trying to limit where windmills could be used, as they often killed birds, some of which may have been rare, or on the verge of existence.

    On the verge of existence? That must have been Schroedingers' Bird - the last of which may or may not be going to have been eaten by a cat.

    --
    Recycle PCs and build a wireless community network www.hillsborough.org.nz
    1. Re:Quantum windmills by Finni · · Score: 2, Funny
      may or may not be going to have been eaten

      Heisengrammer?

  20. Re:canada? by metallicagoaltender · · Score: 4, Funny

    No, it's a Canadian unit - 1 Canadian meter is only worth .8 standard meters. ;-)

  21. MS Blaster is NOT at fault!! by edison490 · · Score: 3, Interesting

    I work for a utility in protection and process engineering and we do not have any remote ability to change settings. As stated in the comment section of the article control and protection systems do not normally have any remote access even to on-site network operators. This philosophy protects everyone from the utility (employees/technicians) to the customer.
    One key issue that seems to be on everyone's mind is the latest MS Blaster virus, could it have caused the outage? Not likely. As stated above our protection and control systems send data via leased phone lines and/or private fiber and do not have any connection to the Internet. Thus no possible way of receiving a virus.
    Finally, to all of you who are dying and just can't understand why the investigation is taking such a long time...hang on! Part of my job is to study disturbances on the grid (ie why did the lights go out?). The studies take anywhere from a day to months to explain what happened. And remember the 1965 blackout study took over a year to finish.

  22. Finally... by rune2 · · Score: 2, Funny

    A vurnerability that isn't Microsoft's fault. I suppose that we could blame them anyways though.... just for the fun of it.

  23. Disconenct us Canadians... by WebCowboy · · Score: 5, Interesting

    ...and many of you are liable to freeze (or in southern parts bake) in the dark. If it weren't for BC Hydro selling power to California's PG&E over the common power grid on the west coast it would have been a certainty. Moreover, PG&E DEFAULTED on MILLIONS of dollars owed for said power to BC Hydro--so perhaps the proper term would be BC GAVE California power. Sooo...who uses who's power grid?

    Also, before you start singing a round of "Blame Canada" it has been determined to a high degree of certainty by industry experts that the most recent power outage originated in the US (notwithstanding out boneheaded prime minister's impulsive comments on the matter before anything was determined). One thing is for certain--it was the Homer Simpsons on BOTH sides of the border that allowed the outage to propigate to the extent it did (operator error, scheduled outages that left the whole system running at capacity, etc...).

    Deregulation has been bungled in its implementation all over the continent, but moreso in the US and particularly in California (well...EVERYTHING involving goverenment in California is royally fscked and has been for the better part of the last decade). The process was always politicised and the fledgling market manipulated by the established players and governments no matter where deregulation happened.

    The concept is sound however...creaky old mandated monopolies should be broken up and the system made as open as technically possible to as many potential generation sources as possible. Decades of monopoly (in generation particularly) set us all up for the situation we are in now.

    As a result, we presently have a handful of creaky, large utilities running creaky, large power plants with obsolete technology--and newer technology tacked on with duct tape and baling twine with little attention to stability and security. This has nothing to do with what country you are in--it is the situation continent-wide.

    I've worked in the industry and have seen it first hand--and this was BEFORE the industry was deregulated (they still had several 1988-era 386s and a 286 in use--in 1996!). The argument then was that competition would compel established players to innovate and become more efficient. NOTHING has changed in these plants since deregulation--they are moving no slower OR faster in bringing new capacity to the grid. Only now demand has reached critical levels as predicted by some years ago. Only the argument has changed. Now instead of being the solution, deregulation is cited as the reason for problems (careless cost cutting rather than being sheltered from competition).

    I'm astonished (but not entirely surprised) that since I was last in a power plant that there has been enough integration of critical systems into the general network that blaster-like infections could disrupt operations. Back in the mid 90's where I was, there were two distinct networks with NO connection at all (be it physical or not). If course, the 'net wasn't what it is now either and dozens of on-site employees had to rely on a 56k leased line for outside access.

    Hopefully the blackout made everyone feel vulnerable enough to wake up and put at least as much or more into security and stability as they did into y2k compliance...

  24. "Virii" by jemfinch · · Score: 2, Informative

    Maybe I'm just being an anal-retentive grammar Nazi, but I simply can't respect an author who uses the non-word "virii" in his works.

    Sorry. It's simply not a word. He might as well be writing in l33tspeak.

    Jeremy

  25. Re:Hahahahaha by OpenSourcerer · · Score: 4, Funny

    The current problems with the grid are due to an un-ethical power struggle between the US and Canada. We need to phase into a system where a neutral party oversees the whole grid.
    Ohmygod, this thread is sick!

  26. That's only the warm up act by HangingChad · · Score: 2, Interesting

    The software and management side don't tell the whole story. Combine that with the power grid physical security and infrastructure issues and then you have a glimmer of how thin the electric thread we depend on really is. That's not being paranoid, that's being practical. It's a challenge from a cost position to be completely grid independent, no matter where you live. But it is feasible, at least technically, to be less grid dependent. The best cost/benefit balance I've found is to have enough wattage to run the refrigerator, water pump, computer (of course), furnace fan and some lights. Doesn't leave enough juice to run a central A/C, clothes drier, or the other big draws. You really learn just how much electricity we use when you design an alternative power system. And it costs a lot of money.

    --
    That's our life, the big wheel of shit. - The Fat Man, Blue Tango Salvage
  27. Re:The grid is over centralised by Angry+White+Guy · · Score: 2, Informative

    Covering your roof with solar cells is not a practical solution at this point. Covering your NEW house is. Retro-fitting tiles onto your house is generally not the easiest, cheapest, or safest way to generate power. The amount of tiles needed alone to power your house would be staggering, let alone the storage batteries, the need for the proper exposure (I believe that they reccomend a large southern exposure for most of the U.S. and Canada, for best results), or the power inverter which needs to be retro-fit into existing wiring.

    New construction and large office buildings are where solar should be targeted. Also, these buildings should be routinely inspected to make certain that they are not feeding power back into the grid in blackout conditions. Hydro workers have a hard enough time during a blackout without worrying whether some good samaratin numbnuts has just energized the segment he's working on or not.

    To feed the grid via private enterprise without safety precautions, well thought out implementation plans and regulation would be at best ill conceived, and at worst, homicidal.

    If you want power during the next blackout, buy a generator, and for the love of god, shut off the main!

    --
    You think that I'm crazy, you should see this guy!
  28. Data Networks & Realtime Requirements by Ichijo · · Score: 2, Insightful
    From the article:

    The worm's scanning slowed the internal network to a crawl, eventually crashing the plant's Safety Parameter Display System, according to reports.

    [snip]

    Control systems operate in real time, where processes, availability, and reliability are paramount.

    So they are imposing realtime requirements onto a shared medium (a computer network)? That's like not putting lights or sirens on emergency vehicles, and then complaining about not being able to get to the scene in time during heavy traffic.

    No wonder virii can cause so much damage to the power grid. The whole thing was badly designed to start with!

    --
    Any sufficiently unpopular but cohesive argument is indistinguishable from trolling.
    1. Re:Data Networks & Realtime Requirements by ebuck · · Score: 3, Interesting

      Actually, they were wonderfully designed.

      Read the research documentation that came out in the 80's, the pinnacle of SCADA system research.

      Oh, and then that pesky TCP/IP became available, so people moved from tons of serial cables to cheaper CAT3/5. If you didn't migrate your system, you went out of business. Problem is, who could afford to re-design their software from the ground up to use a non-realtime network in a manner resembling realtime?

      So SCADA has long moved from "real-time" to "really fast". Or they isolate the real-time requirements to parts of the system where it can still be achived.

  29. Bull. by Telecommando · · Score: 5, Interesting

    Hackers controlling the power grid? Utter and total bull.

    I work in IT for a major power company. Our control systems have never been hooked to our own network, let alone the Internet, and never will be. How stupid does this guy think we are?

    We've been running computerized control systems in nuclear and other types of generation plants for years. We've had computers in substations and control stations monitoring, controlling and reporting status before most industries even knew what to do with them. I saw my first Z-80 processor in a SCADA system shortly after the Z-80 came out. It could talk any of 5 different control protocols and replaced 2 seven-foot racks of hot, high-current RTL and DTL control logic. It was a thing of beauty.

    We're not newbs at this. And no way do any of our control systems run Windows. Get real.

    Why would we even want to hook up a generating plant or substation to a network just so it can be controlled from anywhere in the world, BY ANYBODY? No way. No how. Nuh-uh. Ain't gonna happen.

    We can't even monitor what's happening on the system from the company's own computer network. It's all totally seperate. And for good reason. Who wants a disgruntled employee or just some joker who's bored messing with the system? The only people who can make operational changes to the system are the people actually present at the secured control center or at the generation plants.

    We run quarterly modem audits, company-wide, looking for unauthorized lines with modem. We even restrict who gets an analog phone line and whether they can receive calls on that line. Computers attached to the control systems get NO modems. Never ever.

    Even our remote monitoring terminals at regional work centers require dedicated connections to the control center and are receive only. The control computers think the remote monitors are printers and only send data, not receive so they can't be hacked from there either.

    It's impossible to get to our control system through the Internet. It could probably be done to some degree (perhaps sending a 'breaker open' command to a key substation, if you know which one), but only by hijacking an existing dedicated connection undetected, which is getting harder as we connect stations via fiber optic.

    (Often we connect stations by installing the fiber near the high voltage lines on our towers, a security measure in and of itself. Imagine splicing a broken fiber hanging off a helicopter platform while the line 12 feet below you is energized to 350 thousand volts. No, I haven't done it, but I watched it being done and the crew earned every penny.)

    If any utility out there has their control systems connected to computers that can be reached via the Internet (or modem for that matter), the persons responsible should be taken out and shot. Then taken to a doctor, stitched back up and shot again. Same for their bosses all the way up to the CEO.

    Sorry if I seen a bit testy on this subject, the subject of keeping the control system secure has been drilled into me for more years than I care to remember. Now it's just automatic.

    However, on the subject of aging infrastructure, I totally agree. I blame deregulation. Every utility is now trying to cut each other's throat trying to grab customers away from each other. To cut costs (and thus lower their prices to better compete), most if not all utilities have cut their expenses by eliminting maintenance, lengthening replacement schedules and cutting staff, specifically skilled line workers). It's a race to the bottom to see who can provide the cheapest service. And it will probably go on until the whole thing blows up on them. And unfortunately, us as well.

    --
    Beta sux! Join the Slashcott! http://hardware.slashdot.org/comments.pl?sid=4760465&cid=46173047
  30. Bored script kiddies would never do this... by thepacketmaster · · Score: 3, Insightful

    A script kiddy would never bring down the power grid...If they did, they'd be bored out of their Internet-dependent minds. Can you imagine these types of kids playing scrabble or cards?!? Or worse yet, being forced to take the opportunity of a black-out to spend quality time with their families. The Horror!

    --

    --

    Luck is just skill you didn't know you had.

  31. No, we should do what we do best by Tau+Zero · · Score: 2, Interesting
    I just saw on TV (TLC I think) that Denmark was building wind generators offshore...
    If so, Denmark has joined Holland and now Ireland. Ireland is putting in the biggest wind turbines ever:
    http://www.gepower.com/corporate/en_us/aboutgeps/2 003releases/082103.pdf (press release)
    Here is my idea, we build a powerplant (hopefully wind/solar but nuclear is ok too) and hook the generator up to a hydrogen refinery (a la iceland)... that way the power can be stored (ok not perfect efficiency but still pretty good)...
    How do you know it's "pretty good"? Studied the efficiency of components? How about their cost and O&M requirements?

    I think we should do what makes the most sense. For instance, if we're burning fuel to make heat and we need electricity too, we should look at heat engines to convert a little heat to power along the way. It probably makes more sense to create storable fuels via chemical or biological processes (like crop wastes or the hydrogen from algae trick) instead of converting solar or nuclear electricity into hydrogen. Then there are the no-brainers, like compact fluorescent bulbs, hybrid vehicles, insulation and daylighting. None of this is rocket science, it's just attention to detail.

    --
    Time is Nature's way of keeping everything from happening at once... the bitch.
  32. Re:The grid is over centralised by Jerf · · Score: 2, Insightful

    A fundemental weakness of the grid is its over-centralisation. Another argument for environmentally friendly local power generation schemes.

    Actually, a fundamental strength of the grid is its centralization. A central facility generating gigawatts of power can afford to spend millions of dollars ekeing the last few percentage points of efficiency out, and wiping out the last few percent of emissions, because the economies of scale kick in.

    Local power schemes, since they will be purchase by The General Public, can not and will not spend the money on these extra niceties, and as a result will necessarily be less efficient and more polluting per watt then centralized power. There is no way around this, there is no argument that can wipe it away, it's a fundamental economic fact of life.

    Local power generation is one of the boondogles the bad environmentalists promote, without stopping for a moment to think that it's even worse then the alternative. (Altogether too many environmentalists aren't bothered by little things like "truth" or "evidence", which is why I can't call myself one, even though in theory I ought to be able to.)

  33. You all think too high tech... by Anonymous Coward · · Score: 3, Interesting

    If there's anything that 9/11 taught me (and should have taught the rest of us), it's that sometimes, the "best" attack is a low-tech one...

    We can have high-tech biochemical sniffers looking for anthrax and C4, etc., but who really would have thought of stealing a plane or two and flying it into a building? Really - think about it. It's pretty low tech, but extremely effective...

    Same thing with the power infrastructure - why worry about hacking in? Figuring out passwords and all that nonsense when the FUCKING INFRASTRUCTURE IS OUT IN THE OPEN!?!?!

    Drive down any road - and you're likely to see a power line, a transformer, etc... I'm sure we ALL know where at least one substation or transmission line is located. AND they're out in the open...

    Have the brains engaged yet? Think about it folks - dig out the old graph theory notes from your data structures classes and then plot out the national power grid -- just the big ole transmission lines...

    What happens if you make some cuts in that graph? Wanna bet that about 7 pieces of wire would do it?

    You don't even need explosives... some wire, maybe a bicycle chain or two and a modified potato launcher would do the trick... and blamo - lots of chaos and commotion... (and yes, I DO know someone who was a complete moron when he was 14 yrs old and tossed a bicycle chain into a transformer at a local substation.... but I digress).

    How are you planning to protect the entire infrastructure against attack? Even if it's redundant, and resiliant - a bit of thought and you're right back where you started....

    I don't have solution to this intractable problem - Do You?

  34. OK, let's do the math by SysKoll · · Score: 2, Insightful
    I know that for enviro-dreamers, math is a dirty word because it always derail their gravy train. But humor me. I'm in a place where I get 120 sunny days a year average. I have 50 square meter (500 sq ft) of root at my disposal Assume I can use half of it and buy a 25 m^2 solar cell panel, at a great cost. With good cells and orientable panels (an eye sore but you don't care), I can get a 20% efficiency, for a glorious 150 W/m^2 peak. Assume a 70% efficiency in power conversion (widly optimistic). So far, I have 25 * 150 * 0.70 = 2625 W peak. With an average of 8 hours a day useable, 120 days a year, I get 2625 *8 *120/365 = 6.9 kWh avg a day, call it 7. Never mind the 15 car batteries I need to store that.

    Well, the problem is, my 2 computers alone (400 watt power supply each), and my fridge use about 10 kWh a day. And they don't run 24h a day. So I'm afraid that after this use investment, I still need the grid.

    And did I mention the snow storms that will put the contraption out of use for days?

    Did I also mention that solar cells need to be replaced every 10 years at least, when they degrade? And that manufacturing a solar cell costs actually more power than the thing will ever generate?

    Aaaah, so that is why there aren't solar cells on every roof. It's not a conspiracy by Exxon and the Bush family.

    It's because when you do the math, you see it is not worth the trouble.

    Of course, the solution is simple: don't do the math and keep pushing solutions that don't work, then blame the oil companies.

    Alternately, you might want to wonder why France is generating 75% of its energy with nuclear plants licensed from Westinghouse and still doesn't glow in the dark. Naaah, wouldn't work elsewhere.

    -- SysKoll
    --

    --
    Mad science! Robots! Underwear! Cute girls! Full comic online! http://www.girlgeniusonline.com/

  35. Re:Bull back at you by Anonymous Coward · · Score: 2, Informative

    Not a troll.

    I also work installing SCADA control centers, and yes this does happen. However, usually there's a extreme lack of windows hosts on our control systems so virii are not much of a problem.

    The parent works in a company where they're doing things right. Audits, checks, and a lot of hard work to ensure that the system stays secure.

    But sometimes I install a software upgrade, only to notice a new host on the system... Well, someone was only trying to leverage the "extra" ports on the switch. Or marketing needs access to the historical records for analysis. Big companies which are prepared to take security seriously have no problem, but there are others...

    Horrible others, which have personnel connecting homebrew "proxy" boxes so they can view the web after hours. Systems where every operator has the same dictionary password. Systems where the security camera video feeds get "rerouted" to allow the viewing of Sienfeld. Systems where the SYSTEM ADMINSTRATOR can't remember how to change directories in UNIX or the difference between a command, and that command's argument.

    These dark corners are usually cash strapped companies, so yes they scheduled to replace X five years ago, but hey, it sill works, so let's get our money out of it.

    Unfortunately I have to post anonymous, as I still intend to make my living scrambling to refactor for security

  36. Canada Who??? by magical22 · · Score: 3, Interesting

    I am sick of control, this might not be the right place to talk out about canada's problems in general but lets say the US already has control of our power, as proven with the california state vs bc hydro, they also control our lumber industry (softwood trade agreement), our wheat industry, our cattle industry (thanks to mad cow), we might aswell give it up or get invaded at this point. No one cares about us and we are so small that we get bullied into everything anyways. I say divert all the rivers leading into the states into the lower half of Alberta and Saskachewan (to those not familiar with canada its the 2nd and 3rd most western provinces) cut the power lines (thus fixing the grid problem), stop all exports and imports to the states, and give them the middle finger.

  37. Poor analysis, but there are real problems by Animats · · Score: 5, Insightful
    That's not a "long and careful look". It's more like "general mouthing off".

    We're starting to see a few problems appear more than once, though.

    • Telecom vulnerability to power failure.

      AT&T was determinedly independent of the power grid in the days of Ma Bell. Every central office ran on 48VDC storage batteries, with backup generators. The backup generators were started once a week, and run for several hours once a month. Once a year, each central office ran for 24 hours cut off from external power.

      That was a long time ago, back when AT&T was a regulated monopoly common carrier. In the new, competitive era, that depth of backup can no longer be assumed. Carriers in trouble (WorldCom, Adelphia) tend to cut things like that.

      The details aren't in yet, but it's beginning to look as if, during the recent big blackout, some comm links went down very early, so that the fault information that's supposed to divide the grid cleanly into islands didn't get through. Once all the logs have been correlated, it will be clear what happened.

    • "Non-critical" systems that aren't.

      A few weeks ago, CSX, the railroad, had a shutdown due to a virus. Railroad signalling has used "code lines" for decades, for remote control of switches and signals. These are basically serial links over which commands and responses are sent. The safety logic is local, but if you lose a code line, the dispatcher can't throw switches and route trains.

      The tendency to centralize train control has resulted in a need to transmit code line signals hundreds or thousands of miles. So they tend to be multiplexed over telecom-like facilities. CSX apparently routed theirs over their in-house general purpose network. The routers in that network were managed by a network management system that ran on Windows. When the Windows machines went down, system management of the routers stopped, and, after a while, this apparently took some key routers down. So a "non-critical" system actually stopped train movements.

    • Cross-connection between business systems and control systems

      It's really convenient to be able to see what the plant is doing from your desktop. Order processing is more efficient if the sales network connects to the factory network. Energy traders need to be able to see what the power plants are doing, and give directions to power dispatchers. These things all create vulnerable paths.

    That's a more realistic picture of what's going on.
    1. Re:Poor analysis, but there are real problems by joe_cisco_was_here · · Score: 2, Informative

      Telephone companies are the only real carriers in the US. (ATT, SBC, Sprint, MCI, etc..) By Federal law telco's must stay up in the event of disaster. There is a direct relationship between communication and death in the event of a disaster. When the WTC fell in NY the ATT telco switch in the basement was still up. Comm links went down because telcos and businesses are trying to save a buck or two. So they sign contracts and pass communications through "wanna-be" carriers like Verio, Cogent, Level3, etc... these guys are not phone companies people, wake up. Also, UPS systems must link to generators. If a faliure in this chain then power problems happen. 79% of most power outages are caused by failed UPS systems, generators no kept warm and tested. Comm links also went because the general power infrastructure of the facilities they use sucks. Comm facilities or CO's should be using this power system: "Hitec CPS (Continuous Power Systems) units on-site, identical to power backup systems utilized by the U.S. Department of Treasury, NATO Radar Silo installations, Intel, IBM and the air forces of Israel and Brazil. 60,000 gallons of fuel stored on-site for 72 hour full-load power capacity." This power system is also provided in the Internet Data Center I use via Pacific Business Solutions. You should check out Sfcolocation at www.sfcolocation.com or pb-solutions.com (pretty pictures of HITEC power systems and more details)

      --
      "I wish everyone would stop quoting stupid nerd crap at the bottom of their signatures" --Curious George
  38. Re:The grid is over centralised by sbryant · · Score: 2, Informative

    It's hardly something I'd want to rely on as a primary source of power, but it would definately help on those hot sunny days when everyone is running an air-conditioner.

    On a hot sunny day, a solar panel will help you much less than you think. Their efficiency decreases when it gets hot (ie: direct sunlight). On the other side of the scale, solar panels are still quite effective on overcast autumn days.

    A normal set of panels on a house roof will generate enough electricity for 3-4 houses during the day. You still have the main grid as your backup, and you can often sell your excess back to the power company. A lot of setups have battery installations, which can run your house at night.

    -- Steve

  39. Re: But the article doesn't even come close. by geekman2000 · · Score: 2, Interesting

    While the article was right when it comes to internal networks to the control stations (such as ISOs) the extent of insecurity in the energy bussiness is far greater that most people can think of. The fact of the mater is the reason most of the grid is immune to hacker attacks these days are the devices that control power transmission at the lowest level (relays, they control the circuit breakers) are all vt100/rs-232 terminal devices hooked up to aging modems 19.2 is the fastest I know of. Theses relays form the base level of what the power industry calls SCADA (system control and data acquisition). Unfortunately, the vast majority of relays still use the default password, and of course even if it is changed the password is probably going to be the same across all of a companies relays (I haven't seen a relay that has a password attempt lockout either). Of course nobody war-dials anymore so these devices go untouched. Security through antiquity.

  40. Ethernet is a bad choice in this environment by RevMike · · Score: 3, Interesting
    While legacy control systems are often UNIX-based ... and thus immune to MS worms and virii, their 10-megabit networking technologies can easily be overwhelmed.

    ...corporate firewalls tend to focus on protecting data integrity and are not suitable for protecting control systems. Control systems operate in real time, where processes, availability, and reliability are paramount.

    I'm assuming whenthey say 10 megabit they mean 10 megabit ethernet.

    Repeat after me: "Ethernet is not an appropriate networking technology for industrial control systems!"

    This is exactly the type of environment that tokenbus (IEEE 802.4) was designed to handle. Tokenbus can guarantee QoS and does not require a "master" node, so it is immune to that kind of single point of failure. Tokenbus was designed with factory automation in mind - IIRC the major auto manufacturers in the US were big players in the committee - so it is optimized for the industrial environment.

    FYI, tokenring is similar, but not identical. Tokenring is a simpler standard that requires a master node. A ring can be locked up if the master node goes into a strange state. Rings are fit for applications where a network failure would be inconvenient, not tragic.

  41. Real problems with the grid by tjstork · · Score: 2, Informative


    The real problem with the grid is that the midwest and the south have not modernized their --people- systems. The PJM grid and to some extent NEPOOL have been moving to a more RTO model that allows for a good balance between a clear market and the command and control necessary to avert disasters.

    First Energy made the wrong decisions during the blackout. Let us recall the sequence of events.

    a) High voltage lines from Canton to Cleveland drop off line
    b) Cleveland begins pulling power from the rest of the grid
    c) Normally outbound power from the midwest begins to "flow" back to the midwest.
    d) This causes power plants in Michigan to trip off line... by this time the regional disaster was largely guaranteed.

    The correct move for First Energy would have been to disconnect Cleveland from the grid off line, immediately.

    Even better, had First Energy had a decent vegetation removal program, the transmission line would not failed in the first place.

    So basically, had First Energy kept the lines clean and been willing to bounce Cleveland from the grid, their would have been no wider blackout.

    But they didn't. They are a utility, not a regional grid operator.

    Had this happened to say some power lines from some place to Philadelphia, PJM would have yanked Philly from the grid, told the utility to fix the lines, and there would be no wider blackout.

    And, by the way, PJM has a more transparent networking market. Just look at the whose got the better web site, PJM or Midwest ISO?

    --
    This is my sig.
  42. Re:SACTA by EuropeanSwallow · · Score: 2, Insightful

    I still believe the security issue is not an issue. I think you can separate the worries in two:

    1. Fake measures: This is solved by what is called a State Estimator in the SCADA, that in simple terms, tries to reduce measurement errors and to infer on unavailable ones using measure redundancy. That means that, even though the RTU message to the SCADA would be tapped, and measures faked, the SCADA would filter it out. Only chance would be to fake them on a geographically large area, with coherence, and that would be, to say the least, complicated.
    2. Tele-command: Since SCADA also involves the tele-control of grid equipments, ex: breakers, a fake order could be sent to the RTU. This is complicated because:
      • You would need to also fake measurements (previous point).
      • Not all kind of maneuvers and maneuvering sequences are allowed by the local controllers or apparatus.
      • Given the fact that measures are hard to fake, the control center would detect the error quickly and call the local units or send a team to see whats happening.




    In the end (see previous post about stolen servers), it would be easier to just, for example, tear down a line post with a truck, to short the line or to sabotage the facility...