DDoS Attack Halts Heating in Finland Amidst Winter (metropolitan.fi)
A Distributed Denial of Service (DDoS) attack halted heating distribution at least in two properties in the city of Lappeenranta, located in Eastern Finland. In both of these events, the attacks disabled the computers that were controlling heating in the buildings. An anonymous reader writes: Both of the buildings were managed by Valtia, the company which is in charge of managing the buildings overall operation and maintenance. According to Valtia CEO, Simo Ruonela, in both cases the systems that controlled the central heating and warm water circulation were disabled. In the city of Lappeenranta, there were at least two buildings whose systems were knocked down by the network attack. According to Rounela, the attack in Eastern Finland lasted from late October to Thursday -- the 3rd of November. The systems that were attacked tried to respond to the attack by rebooting the main control circuit. This was repeated over and over so that heating was never working.
I know it's cold in Finland this time of year, but the first day of winter is still a month and a half in the future.
1. Why are these infrastructure computers reachable from the Internet?
2. Why this system doesn't fail safe if the controller is taken down?
Yet another cautionary tale of IoT woe, but also some seemingly bad design...
My eyes reflect the stars and a smile lights up my face.
Sorry but if your heating system is 100% cloud based so that a DDOS attack or internet outage will stop heat control, then it was designed by the worlds biggest morons.
Cloud based is great for toys, for anything important it's 100% shit.
Do not look at laser with remaining good eye.
Let a mechanical thermostat be the default control when the computer fails, regardless of why!
You don't really get global warming, do you?
Not true. If you want to secure it with competence then you separate the two domains, not connect them.