German Nuclear Plant Infected With Computer Virus (reuters.com)
archatheist shares a Reuters report: A nuclear power plant in Germany has been found to be infected with computer viruses, but they appear not to have posed a threat to the facility's operations because it is isolated from the Internet, the station's operator said on Tuesday. The Gundremmingen plant, located about 120 km (75 miles) northwest of Munich, is run by the German utility RWE. The viruses, which include "W32.Ramnit" and "Conficker", were discovered at Gundremmingen's B unit in a computer system retrofitted in 2008 with data visualization software associated with equipment for moving nuclear fuel rods, RWE said.
Windows machines are world famous for both stability and security. Over a billion devices can't be wrong!
"As an example, Hypponen said he had recently spoken to a European aircraft maker that said it cleans the cockpits of its planes every week of malware designed for Android phones. The malware spread to the planes only because factory employees were charging their phones with the USB port in the cockpit.
Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger."
Okay for a system to spread a virus it must execute code...
So does this mean that F_Protect have no idea what they are doing or are they just spreading FUD.
See my blog http://ilovecookes.blogspot.com/ for light hearted technical information.
I gave up after OS-9
OS-9 was/is a great OS. I used it to run a full multi-user multi-tasking system (with preemptive multi-tasking) on my Tandy CoCo back in the day (with 256kB of memory!), and also used it in many industrial embedded systems using a 68K.
Perhaps you are thinking of OS 9?
I am Slashdot. Are you Slashdot as well?
The systems were setup in 2008. They probably do run Windows XP.
And don't forget that most industrial control systems are not modified after installation. Vendors are notoriously reluctant to support any changes at all, including basic OS updates.
My employer has equipment connected to unpatched XP SP1 systems because the vendor won't support anything else, and the organization is not willing to spend $200K+ to replace machines that are doing their jobs.
They are standalone systems because of issues exactly like this one. If someone took an infected file over, it would be a long time before we noticed. There is no value in traditional antivirus without signature updates---which might be a consideration if the vendor supported it with antivirus in the first place.
This is what a lack of competition looks like. They don't have to support basic security measures because there are only one or two other companies in the world that make comparable equipment, and they offer the same level of support. So our security is screwed until the government decides to regulate it.
And nevermind all the man-hours we waste doing data transfers to/from these systems. That's just a cost of doing business.
---
According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.