this post was submitted on 10 Jan 2024
62 points (95.6% liked)

Technology

59589 readers
3148 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Hackers can infect network-connected wrenches to install ransomware | Researchers identify 23 vulnerabilities, some of which can exploited with no authentication::Researchers identify 23 vulnerabilities, some of which can exploited with no authentication.

you are viewing a single comment's thread
view the rest of the comments
[–] JeeBaiChow@lemmy.world 39 points 10 months ago (18 children)

Ok. Why tf does a wrench need to be network connected?

[–] ricecake@sh.itjust.works 23 points 10 months ago (9 children)

I'm assuming it's a torque wrench, which can apply variable force to a bolt.

Scan a barcode next to the hole, insert bolt, wrench applies correct force for the piece.
They can also similarly check the tightness of the bolt and record what it measured for quality control.

Every bolt doesn't use the same torque, and manually inputting the value is slower and more error prone.
Similarly, checking the torque and recording that it was correct and fixing any errors is slower and more error prone with manual lookup.

[–] Unicode13051@lemmyf.uk 12 points 10 months ago (8 children)

Scan a barcode next to the hole, insert bolt, wrench applies correct force for the piece.

The why not just have the barcode have all of that information encoded in it and not reference a database on a network?

[–] MechanicalJester@lemm.ee 3 points 10 months ago (1 children)

But of a slippery slope. What else do we need to encode?

A barcode doesn't have enough bits to be unique and also contain useful information. It's just a unique identifier that can be used to look up a wide variety of information.

For bolts, it could be metal grade, thread pitch, load ratings, manufacturer info etc

[–] merc@sh.itjust.works 2 points 10 months ago

Also, say Boeing discovered that the doors were flying off their airplanes because the specified torque was too low for the bolts. If the barcode contained the torque, the barcodes would all have to be replaced. If the barcodes point to a database entry that contains the correct torque, you can update the DB and the wrenches will get the new value when they look it up.

Having said that, this should definitely be an air-gapped system. There's no need for the wrenches to be able to talk to Bing or OnlyFans. It shouldn't just be behind a firewall, because, again, it's not like the wrenches only need to access someof the Internet, they really never need the Internet, just the local network.

I'm not a network engineer, but my guess is that a good network engineer could design a network that makes it really unlikely that a wrench ever exchanges packets with the real Internet. For example, design a flat network and use a very small TTL so that even if somehow the Internet is connected to the network the wrenches live on, the packets expire before they leave the local network.

If you can't isolate and protect the network you're using, you're just asking for trouble, because that means that every single piece of industrial equipment with a TCP/IP stack is properly patched and hardened against the latest vulnerabilities.

load more comments (6 replies)
load more comments (6 replies)
load more comments (14 replies)