CISA’s urgent warning about operational technology exposed to the public Internet is well founded: remove public-facing connections, change default credentials, restrict remote access, and strengthen network protections. Complete elimination of connectivity is often impractical, however, and an escalating reliance on stronger cryptography and heavier hardware is not the only option. Lightweight defenses that reduce attacker opportunity while using almost no controller resources deserve more attention. JANOS, the JNIOR operating system, has been run on public IPs as a worst-case testbed and reveals how relentless automated scans, protocol probes, and brute‑force login attempts rapidly consume CPU and networking resources. Even failed SSH handshakes force costly cryptographic work that can degrade deterministic OT functions and resemble a denial‑of‑service against the controller.
A practical distinction exists between targeted, sophisticated attacks and the background noise of indiscriminate scanners that simply enumerate reachable hosts. Internet‑facing does not only mean a public IP; port forwarding, misconfigured NAT, and open services create exposure. The right question is what paths allow unsolicited inbound connections. Devices can aid discovery: JNIOR’s NETSTAT -M shows real‑time incoming attempts and can reveal unexpected public IP traffic that warrants IT investigation. Defenses should prioritize preventing unnecessary traffic at the network edge - firewalls, VPNs, proxies, gateway controls - and adopt low‑cost in‑device mitigations so controllers remain focused on control tasks.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.