SCADA Vulnerabilities In Prisons Could Open Cell Doors
Orome1 writes "Many prisons and jails use SCADA systems with PLCs to open and close doors. Using original and publicly available exploits along with evaluating vulnerabilities in electronic and physical security designs, researchers discovered significant vulnerabilities in PLCs used in correctional facilities by being able to remotely flip the switches to 'open' or 'locked closed' on cell doors and gates."
The SCADA system isn't flawed, the whole prison system in U.S. is. Not only have studies shown that there is no need for such locked down prison facilities, but it's also demonstrated by real life experiences in Norway. Almost all of Norway's prisons are open. Their objective isn't locking down people but correct behaviour. The purpose is to create real life environment, complete with saunas, sunbeds and own rooms and furniture. It makes much more sense too. If you just lock down people for years they are always going to stay criminals. If you try to correct their behaviour and reintroduce them to system and proper behavior, they will learn and also stay out of prisons in future. It's very telling that U.S. has one of the highest percentages of their people in prisons. That system clearly isn't working.
Covered back in November.
according to Mission Impossible.
Is Slashdot's submission system running on SCADA? I ask because we this "duplicate story" vulnerability keeps popping up.
#DeleteChrome
Flip digital switches with electronics, the apocalypse is near!
thanks for the FUD slashdot, could you not fucking dupe it next time?
http://it.slashdot.org/story/11/11/08/0136230/vulnerabilities-discovered-in-prison-scada-systems
Cripes half the wikipedia article is based on this
http://en.wikipedia.org/wiki/SCADA#Security_issues
And yet its still probably simpler to hold a guard at knife-point with a toothbrush handle filed down on the concrete floors
would these systems even be accessible from the internet in any way shape or form? are government IT and contractors that friggin stupid?
you can add redundancy with magnetic boots! flip the switch when the gates go haywire, and everybody is locked down. face/off!
i find myself completely agreeing and disagreeing at the same time.
there are many problems with the prison system in the US. almost none of them relate to whether or not there are saunas.
That's right HAL should run the prisons in the USA and also look after the Prison Guards.
All cows eat grass!
Wake me when they find an exploit that allows them to just kill all the criminals.
So we can stop paying to keep them locked up forever.
I went to this talk at CCC's 28c3. First of all the talk was horrible, the vulnerability stupid, and the speaker is an attention wh**** that doesnt understand hacking. This is a non event.
Due to budget downsizing and the retirement of high tech incarceration facilities, American prisoners will henceforth be housed in Russian gulags, where door locking vulnerabilities do not matter, since the main security algorithm depends only on thousands of kilometres of snow and ice...
wasn't this report a couple of months ago???
There was an unknown error in the submission.
Now get off my lawn
Sent from my ASR33 using ASCII
Why exactly are prison door control systems connected to the Internet anyway?
I did the crime. Did I deserve punishment for what I did? Definitely, I hurt a lot of people through my actions, not just my victim. However, while I cannot speak for the system in other countries, the system here is very flawed. It gives lip service to rehabilitation, but does very little to actually produce it. In my experience, most of the teachers and counselors in prison are there for two reasons. One, they could not hold a real teaching or counseling job because they were incompetent, lazy, or both. Two, the prison system gives them a place where they can sit, collect great benefits and have inmates do most of the work. I tutored in a Software class for 7 years while I was inside and the the teacher could not even be bothered to learn windows XP (her mind was stuck on DOS and didn't know that well). She was well meaning, but also ignorant and clueless. There are exceptions to this, but it is largely the rule.
The system is hugely exploitative. In the Virginia system you have Virginia Correctional Enterprises. In the Feds you have FPI, and other states have similar programs. They pay more than any other job in prison (I made
The system is corrupt. I am not just talking about low level corruption of correctional officers accepting bribes or smuggling contraband, which havens daily. But on and up to the top. From administrative staff skimming commissary funds to hold officer parties, to buying equipment for a band room on state funds, never opening the band room then selling the equipment. I saw the latter one happen myself. Hell in VA the state code gives the director of DOC the permission to take bribes and kickbacks!
5. To accept, hold and enjoy gifts, donations and bequests on behalf of the Department from the United States government and agencies and instrumentalities thereof, and any other source, subject to the approval of the Governor. To these ends, the Director shall have the power to comply with such conditions and execute such agreements as may be necessary, convenient or desirable, consistent with applicable standards and goals of the Board;
I have to give a view (somewhat) from the other side as well. I have seen posts recommending separating the 'bad' criminals from the ones who can be rehabilitated. How do you propose to do that? Based on the crime? Their behavior while imprisoned? I spent ten years inside and there are people who are so good at gaming and manipulating ANY system it would make your jaw drop. I personally am not good at manipulating people and don't want to be, but in order to survive there were many times I had to bend and break the rules. For me, it was making my own soldering gun and tools and collecting contraband parts to repair other inmates electronics. (Most people don't want to fuck with the guy who can fix their TV for them cheaply when it breaks). For others it might be stealing supplies or running a gambling pool. Finding the right way to classify and group prisoners is an exceedingly difficult prospect, and to be quite frank, most of the staff and administration at these facilities (at least in my exp
But we really don't know if it's flawed or not until something really happen now do we? http://www.alycesshoppingmall.com/
For others it's better then living on the street.
For most people in for drug offenses there are much better and cheaper way to deal with them and it free up room for people like rapists and child abuses to do some hard time.
For what he did should not lead to jail or prison but as he pissed off a city they throw the book at him and the city is the one that took a job dispute up to that level.
Older prisons had a lot of big lever or EM based systems for opening doors and they where not setup in way for the people at the controls to see where the doors are.
But let's a the basic level at the alot of the SCADA boards hookup up to the cells are likely real basic more so in older prisons just some kind of network hook up + switches + relays or SCR hooked to them. Now say you run that to a center control room then you have a network there. Now let's say you want to run camera feeds to same control room now you can put them on the network as well.
Also on some older lockup / inside prison shows I say some systems running what looked like windows 3.1 or NT 3 now how old is that hardware anyways?
Now let's say the internet / out side network came at a later time and some just put it on the same network to save costs. You need the outside network for stuff like looking up inmate records / doing paper work / the inmate e-mail systems. Now a lot of stuff in prisons in from 3rd party venders and with 3rd party venders they want there own hardware with there own outside / remote techs.
Think of all the potheads we'd have roaming the streets! It would be chaos, I tell you!
If you feel that the system is that flawed, then run for office and get the system changed.
Om, nomnomnom...
what we got here, is a failure to firewall communication
capital punishment."
How about if you hang the fucker I'll GUARANTEE you he will not rape and murder again, EVER.
Wait until you have experienced some of these "poor, misunderstood" criminals, then we talk again.
an article being taken seriously on /.? As someone who formerly worked in private prison IT, I can personally tell you there is no physical or logical connection between the pc's that are connected to the scada system and the pc's that are connected to the public internet.
If he did 10 years in prison he most likely has a felony conviction. In most states a felon cannot run for government office. What now?