14 comments

  • londons_explore 27 minutes ago
    People use 1000x more water than they need to drink.

    If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted.

    Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope.

    It wouldn't cause the mass casualties an enemy might assume.

    • nerevarthelame 19 minutes ago
      Iran doesn't need to cause mass casualties. They just need to make US citizens hate the war in Iran.
      • genocidicbunny 4 minutes ago
        Trouble is, there's a good chance that a large portion of the population will then be in favour of ending the war by escalating it to the point of flattening Iran. And that portion of the population has somewhat of a correlation with the political base of the current administration.
    • BigTTYGothGF 20 minutes ago
      Exactly how big do you think those bottles would be?
    • mindslight 12 minutes ago
      Who exactly is this "we" in 2026 ?

      The only thing I can see is some political crony company getting a big payment from the federal budget to take on the "burden" of doing so. But then not actually distributing enough water so they can still price-gouge individuals because we wouldn't want people to become entitled, right?

  • firefax 1 hour ago
    Wasn't there a Defcon or Derby talk about this years back? (The insecurity, not the Persian angle)

    Struggling for a source.

    Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?

    • bradly 1 hour ago
      Not sure about defcon, but Buckminster Fuller wrote waay back in the sixties about the New York's vulnerability to a fresh water supply attack.

      If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books.

      https://archive.org/details/operatingmanualforspaceshipearth...

      • firefax 8 minutes ago
        I'll throw it on my list, I've got a pretty big backlog right now.
  • BoardsOfCanada 1 hour ago
  • cineticdaffodil 1 hour ago
    I think this landscape is littered with simulated systems as honeypot. Once you have it a normal adversary would stop searching, besides regular checks that the gun still works.
  • lorreyfum 30 minutes ago
    Where does all the money go? Not to cyber apparently.
    • nerevarthelame 12 minutes ago
      DOGE eliminated 1/3 of CISA staff in 2025. Trump reduced the 2026 CISA budget by $491 million (17%). Trump intends to slash their budget by an additional $707 million in 2027.

      The ICE budget was just increased by $70 BILLION, bringing its total to >$200 billion.

  • alwa 19 minutes ago
    I deplore all of this nonsense. But I can’t help but observe the symmetry. The US president threatened to destroy Iranian water plants; an Iranian water plant was destroyed…

    https://www.nbcnews.com/world/iran/water-energy-sites-hit-us...

    https://apnews.com/article/trump-iran-threat-desalination-pl...

    It sure reads like more of a tit-for-tat in that context.

  • lysace 1 hour ago
    The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.

    After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.

    https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...

    • radicality 1 hour ago
      Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!
      • hubbahubbahubba 38 minutes ago
        Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.
      • alwa 53 minutes ago
        I mean

        Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…

        It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.

        These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.

        [0] https://www.cisa.gov/topics/industrial-control-systems , and https://www.gao.gov/assets/d24106576.pdf for an idea of the staffing they’re doing it with…

        [1] https://www.epa.gov/dwreginfo/information-about-public-water...

        • zahlman 26 minutes ago
          Who connected the systems to the Internet in the first place?

          Why?

      • mmooss 11 minutes ago
        When will the public figure out that many IT exploits are the result of malpractice by developers and network adminstrators, and the businesses employing them? We're building and operating bridges that we know will collapse. Our products are nearly indefensible, literally - they can't realistically be secured except at great expense. We talk about the imbalance between costs of attack and defense; we made that imbalance.

        The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.

        The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.

      • toomuchtodo 46 minutes ago
        Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.

        https://news.ycombinator.com/item?id=39243560

        https://web.archive.org/web/20240409155326/https://www.awwa....

        (cybersecurity practitioner is a component of my professional persona)

  • phendrenad2 1 hour ago
    Is this the true reason for the cyclosporasis outbreaks?
    • jfengel 50 minutes ago
      Nah. Cyclospora is a parasite, not a virus.

      [Riffing on the gag, not an actual misunderstanding, just to be clear.]

    • hubbahubbahubba 44 minutes ago
      Can we still blame Mexico, Taylor Farms and Taco Bell as well?
    • xvxvx 25 minutes ago
      Taco Bell is secretly funded by Iran and North Korea and invented covid…
  • mannanj 1 hour ago
    If I was in a power position, I could theoretically channel this water into my own private reservoirs and locations like private land, bunkers, etc to weather a disruption, and blame Iran and it would be really hard to validate.

    I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.

    I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!

    • irishcoffee 1 hour ago
      I understand being mad, I also get mad.

      This is a bit unhinged.

      • throw1234567891 43 minutes ago
        We used to say that about some things before Snowden. And then there was Snowden.
        • krapp 38 minutes ago
          But they wouldn't need to false-flag an excuse to capture and privatize resources, they could and would just do that openly. The government can just take whatever it wants through eminent domain.
    • maxerickson 1 hour ago
      You know water is kind of big right?
  • malcolmgreaves 1 hour ago
    > “I think Minnesota is behind it,” Mr. Trump said on Friday in response to a reporter’s question about Iran’s possible involvement,

    What a coward and a traitor to the American people.

    • baron816 1 hour ago
      He knows he brought these attacks with his war, but he doesn’t take the blame for anything.
      • AnimalMuppet 1 hour ago
        Either he knows and doesn't want to take the blame, or he doesn't know. I'm not sure which one is worse.
        • jeroenhd 58 minutes ago
          He stopped going to security briefings before, maybe he simply doesn't care to know.
      • puttycat 55 minutes ago
        > he brought these attacks with his war

        I'm no Trump supporter and this war was a big mistake, but justifying a nation poisoning another's civilian water supply is a bit upside down.

        • mplanchard 46 minutes ago
          Yeah, what could we possibly have done[0] to justify an attack on our water supply????

          [0]: https://www.commondreams.org/news/iran-water-desalination-pl...

        • throw1234567891 41 minutes ago
          Ask the people of Flint, Michigan?
        • krapp 41 minutes ago
          We don't follow "rules" in war anymore, according to "Secretary of War" Pete Hegseth. We show no quarter and take no prisoners, we pursue "maximum lethality, not tepid legality."

          That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.

          • iwontberude 37 minutes ago
            I hope it gets bad enough people wake tf up and do something with me about it.
    • vjvjvjvjghv 1 hour ago
      It was probably the same (imaginary) people who damaged the lining of the Reflecting Pool.

      I think we should think about making blatant lies by politicians a crime.

      • dylan604 54 minutes ago
        What's one more crime compared to all of the ones they've already committed?
    • rozal 1 hour ago
      [dead]
  • aaron695 1 hour ago
    [dead]
  • krautburglar 1 hour ago
    They always point to a state actor to skirt liability for their own shitty IT work. Then the dim evil journalists swallow it whole, later regurgitating it for their eager little baby bird subscribers.

    If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.

    • dylan604 57 minutes ago
      <adjustsTinFoilHat> The Trump plan in Iran is not working. Gotta make them look like the evil bogeyman to get people to support further action.
      • Aurornis 52 minutes ago
        This conspiracy theory would make more sense if he wasn’t working so hard to divert blame away from Iran: https://www.politico.com/news/2026/07/31/trump-minnesota-wat...

        > “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”

        • zahlman 18 minutes ago
          The rest of the thread demonstrates well enough that flagging would have been a better response than trying to engage with it factually.

          But I do appreciate the attempt anyway.

        • garciasn 40 minutes ago
          As if it were only Minnesota. But his base doesn’t pay attention to details.
      • krautburglar 52 minutes ago
        Iran is beside the point. There is always a convenient bogeyman: China, Russia, North Korea… They sow discord between peoples to cover-up the ineptitude of domestic institutional assholes.
        • garciasn 41 minutes ago
          Blacks.

          Homosexuals.

          Communists.

          Islamics.

          Hispanics.

          Liberals.

          Intellectuals.

          There’s always an other. That’s what the Republicans have been doing for decades.

          • zahlman 20 minutes ago
            > There’s always an other. That’s what the [group I definitely don't belong to] have been doing for decades.

            Please reconsider your logic. And:

            > Please don't use Hacker News for political or ideological battle. It tramples curiosity.

  • neves 57 minutes ago
    In this war initiated by USA and Israel, it isn't Iran who's attacking civil targets.