<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Super-Sophisticated Computer Virus Apparently Targeted Iran&#039;s Power Plants</title>
	<atom:link href="http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/</link>
	<description></description>
	<lastBuildDate>Mon, 22 Apr 2013 21:34:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
	<item>
		<title>By: Jennifer Welsh</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22359</link>
		<dc:creator>Jennifer Welsh</dc:creator>
		<pubDate>Wed, 29 Sep 2010 15:01:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22359</guid>
		<description>Thanks everyone, for reading and leaving your comments. I hope this all works out in the end, but the more I learn about this virus, the more the idea scares me.

Jen</description>
		<content:encoded><![CDATA[<p>Thanks everyone, for reading and leaving your comments. I hope this all works out in the end, but the more I learn about this virus, the more the idea scares me.</p>
<p>Jen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian Too</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22358</link>
		<dc:creator>Brian Too</dc:creator>
		<pubDate>Tue, 28 Sep 2010 23:30:12 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22358</guid>
		<description>It&#039;s been a few years, but if the old methods still hold, Windows is less of a problem in these environments than you&#039;d think.  And process control is a pretty conservative business area.

These are SCADA environments.  The Windows OS and SCADA application functions as a Command &amp; Control system.  However it isn&#039;t what runs the plant on a moment-to-moment basis, the PLC&#039;s do that.  The PLC&#039;s are independent logic units that can run just fine for hours (or days, or weeks) without any contact whatsoever from the C&amp;C system.  You want the large scale oversight of course, it&#039;s just that you are not wholly dependent upon it.

With a layered control system like this you can suffer minor outages in any layer and the remaining layer can remain functional.  Not that systems failures are good of course!  However this is a very strong fault tolerant system design.

Also, and to be fair, Windows is much better than it used to be.  I speak from experience.  It&#039;s fully auditable, event logged and reasonably secure.  If you have a non-BS SCADA deployment, you can easily add ECC DRAM, RAID mass storage, test environments, application whitelisting, driver signing, even clustering.  All these go a long, long way to improving uptime performance.

On the other hand, if you are targeted by a spook as the OP suggested, chances are your security will be seriously tested.  Weak links exist in any system and a pro knows how to find them.</description>
		<content:encoded><![CDATA[<p>It&#8217;s been a few years, but if the old methods still hold, Windows is less of a problem in these environments than you&#8217;d think.  And process control is a pretty conservative business area.</p>
<p>These are SCADA environments.  The Windows OS and SCADA application functions as a Command &amp; Control system.  However it isn&#8217;t what runs the plant on a moment-to-moment basis, the PLC&#8217;s do that.  The PLC&#8217;s are independent logic units that can run just fine for hours (or days, or weeks) without any contact whatsoever from the C&amp;C system.  You want the large scale oversight of course, it&#8217;s just that you are not wholly dependent upon it.</p>
<p>With a layered control system like this you can suffer minor outages in any layer and the remaining layer can remain functional.  Not that systems failures are good of course!  However this is a very strong fault tolerant system design.</p>
<p>Also, and to be fair, Windows is much better than it used to be.  I speak from experience.  It&#8217;s fully auditable, event logged and reasonably secure.  If you have a non-BS SCADA deployment, you can easily add ECC DRAM, RAID mass storage, test environments, application whitelisting, driver signing, even clustering.  All these go a long, long way to improving uptime performance.</p>
<p>On the other hand, if you are targeted by a spook as the OP suggested, chances are your security will be seriously tested.  Weak links exist in any system and a pro knows how to find them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vel</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22357</link>
		<dc:creator>vel</dc:creator>
		<pubDate>Tue, 28 Sep 2010 15:25:47 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22357</guid>
		<description>why do people use Windows? Because it&#039;s out there and it has people supporting it that are paid to work on its problems, rather than freeware where you have to hope someone gets around to your particular bug.</description>
		<content:encoded><![CDATA[<p>why do people use Windows? Because it&#8217;s out there and it has people supporting it that are paid to work on its problems, rather than freeware where you have to hope someone gets around to your particular bug.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HW</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22356</link>
		<dc:creator>HW</dc:creator>
		<pubDate>Tue, 28 Sep 2010 14:54:07 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22356</guid>
		<description>There exists many Human-Machine Interfaces that are designed to run on Windows.  These (Windows based) intefaces are very common in almost every industry.</description>
		<content:encoded><![CDATA[<p>There exists many Human-Machine Interfaces that are designed to run on Windows.  These (Windows based) intefaces are very common in almost every industry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dante The Canadian</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22355</link>
		<dc:creator>Dante The Canadian</dc:creator>
		<pubDate>Tue, 28 Sep 2010 14:51:02 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22355</guid>
		<description>THAT is a GREAT Question Jennifer.   If it is so susceptible to viruses and malware why is it still being used?   Especially for infrastructure and military needs?

Does anyone doubt that the US had a hand in this?   For a nation which has sworn a &#039;war on terror&#039; this sure stinks of terrorism.</description>
		<content:encoded><![CDATA[<p>THAT is a GREAT Question Jennifer.   If it is so susceptible to viruses and malware why is it still being used?   Especially for infrastructure and military needs?</p>
<p>Does anyone doubt that the US had a hand in this?   For a nation which has sworn a &#8216;war on terror&#8217; this sure stinks of terrorism.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jennifer Welsh</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22354</link>
		<dc:creator>Jennifer Welsh</dc:creator>
		<pubDate>Tue, 28 Sep 2010 13:26:08 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22354</guid>
		<description>The real question is: Why are they using Windows to control our infrastructure?

Jen</description>
		<content:encoded><![CDATA[<p>The real question is: Why are they using Windows to control our infrastructure?</p>
<p>Jen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nick</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22353</link>
		<dc:creator>nick</dc:creator>
		<pubDate>Tue, 28 Sep 2010 03:57:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22353</guid>
		<description>&quot;Thousands die, plant still spewing toxins.&quot; Yeah, it is a bit on the melodramatic side because we&#039;ve seen what happens. It happened in Russia a couple years back, it happened in the Gulf of Mexico this summer. A few people died, there was a cleanup effort.

&quot;And some experts, like Eugene Kaspersky, co-founder and CEO of the Russian cyber-security firm Kaspersky, worry that this is just the first of a string of government-mediated software attacks.&quot;

Same thing was said about atomic bombs. Somehow, despite all the hand wringing and pants-sh***ing, we survived.

[moderator&#039;s note: edited the cuss word.] </description>
		<content:encoded><![CDATA[<p>&#8220;Thousands die, plant still spewing toxins.&#8221; Yeah, it is a bit on the melodramatic side because we&#8217;ve seen what happens. It happened in Russia a couple years back, it happened in the Gulf of Mexico this summer. A few people died, there was a cleanup effort.</p>
<p>&#8220;And some experts, like Eugene Kaspersky, co-founder and CEO of the Russian cyber-security firm Kaspersky, worry that this is just the first of a string of government-mediated software attacks.&#8221;</p>
<p>Same thing was said about atomic bombs. Somehow, despite all the hand wringing and pants-sh***ing, we survived.</p>
<p>[moderator's note: edited the cuss word.] </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vermont Hermit</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22352</link>
		<dc:creator>Vermont Hermit</dc:creator>
		<pubDate>Tue, 28 Sep 2010 01:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22352</guid>
		<description>Why do I get sick to my stomach, thinking about the possibilities?  Next major terrorist attack on country &quot;x&quot;  sends chemical plants out of control.  Thousands die, plant still spewing toxins.  Mass evacuations.  Ok mabye a bit on the melodramatic side but you get the point.</description>
		<content:encoded><![CDATA[<p>Why do I get sick to my stomach, thinking about the possibilities?  Next major terrorist attack on country &#8220;x&#8221;  sends chemical plants out of control.  Thousands die, plant still spewing toxins.  Mass evacuations.  Ok mabye a bit on the melodramatic side but you get the point.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rhacodactylus</title>
		<link>http://blogs.discovermagazine.com/80beats/2010/09/27/super-sophisticated-computer-virus-apparently-targeted-irans-power-plants/#comment-22351</link>
		<dc:creator>Rhacodactylus</dc:creator>
		<pubDate>Tue, 28 Sep 2010 00:20:24 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/80beats/?p=20615#comment-22351</guid>
		<description>Sweet, I&#039;ve seen this movie, this is the one where Angelina Jolie gets topless right?</description>
		<content:encoded><![CDATA[<p>Sweet, I&#8217;ve seen this movie, this is the one where Angelina Jolie gets topless right?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
