• pudgywalsh an hour ago

Sadly this instantly became a political football, with the states pointing fingers at Iran, but Trump was not wrong in this case. This is gross incompetence at all levels — IT malpractice if you will.

CISA and its predecessors have been warning utility operators about critical infrastructure vulnerabilities for what, 15 years at this point? That goes back to the first Obama administration.

Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords. You cross a threshold where you're being deliberately careless.

When you are putting more effort into securing your Plex server on your home network then public utilities are taking on machinery that dumps chemicals into the local water, something is not right and finger-pointing isn't going to fix it.

• Avicebron an hour ago

I think it's less carelessness and more the inability to attract (pay) people who have the technical knowhow to properly secure infrastructure. Even a lot of developers are poor network engineers and treat IT like magic at their own companies.

• moscoe an hour ago

You’re on the right track, I think. But, I wouldn’t say it’s about the pay to attract competent workers. I think it has more to do with the incentive structures once you’re in. Incentives and performance management are fundamental problem in civil service. The incentives to set high standards and hold individuals accountable simply do not exist.

The one and only exception is the military, because lives are literally on the line in a way that is not at all abstract.

• Avicebron 36 minutes ago

Usually when people say this they are dog whistling privatization. Which is the exact opposite thing people need in infrastructure, ask anyone who has to deal with PG&E.

Paying skilled people highly does actually incentivize people to do better work, especially if they are actually embedded into the community they are essentially working for. If being a civil servant was as "glorious" as being a techie is SF there would be a very different attitude around the work.

• moscoe 6 minutes ago

In an environment without accountability, higher pay is just more incentive to lay low and not take any personal risk. Why do anything other than the bare minimum when there is no upside? In a bureaucracy where responsibility is diffused and the culture is purely political and not merit/performance-based, few are willing to step out of line to do the right thing.

The people who climb to the top aren’t the ones who took a risk and got the reward. Quite the opposite, they’re the ones who learned to play the game and didn’t upset the power structure by rocking the boat. No one is going to tell the emperor he has no clothes when the path to power is political and has no grounding in reality.

Highly conscientious, intrinsically motivated people will do the right thing in any environment. And those people don’t last long in political/bureaucratic environments where the incentives are misaligned.

• cyanydeez 2 minutes ago

We just started replacing our PLCs. They absolutely were setup with default passwords, but weren't put on the public internet.

• pudgywalsh an hour ago

I've met info-sec / vulnerability researcher types that were egregiously reckless, like plugging Raspberry Pi's into the production network kind of thing.

Public sector has always paid low. But the problem is widespread, almost universal, and they've had a 15 year head start of the federal government telling them to get their shit together.

At some point it just became standard industry practice is my guess.

• lorreyfum 27 minutes ago

Absolutely 100% spot on. It’s not a political issue, it’s a technical issue. Disconnect them from the internet. Run your security patches. Check your logs. Water supplies are pretty important, do your job.

• cyanydeez 2 minutes ago

a broken clock, yada yada.

• andyjohnson0 an hour ago

> Yet here we are in 2026 and these utilities are still connecting these things to the raw Internet with default passwords.

I work with PLCs. Default passwords of not, the idea that such weakly secure devices are being made accessible from the public internet boggles my mind.

• pudgywalsh an hour ago

Yeah I meant the default passwords are simply the cherry on top of already egregiously poor security.

• idontwantthis an hour ago

Until the people in charge face jailtime for hurting innocent people, why would they care? The government shouldn’t be warning, it should be ordering and imprisoning. And funding and educating where there are genuine gaps.