Feeds

Electrical grid overlords take drubbing over cyber attack vulnerability

'Disorganized, ineffective'

Beginner's guide to SSL certificates

US lawmakers ripped into the organization that oversees North America's electrical grid, saying it isn't doing enough to prevent cyber attacks that could cripple the economy.

US Representative James Langevin, chair of the House Subcommittee on Emerging Threats, Cybersecurity and Science and Technology, said he had "little confidence" that the North American Electric Reliability Corporation (NERC) has fully addressed a vulnerability code-named Aurora, in which electric utilities generators and other equipment comes to a grinding halt.

"I still do not get the sense that we are addressing cybersecurity with the seriousness that it deserves," Langevin said, according to this report from IDG News Service. "I think we could search far and wide and not find a more disorganized, ineffective response to an issue of national security of this import. If NERC doesn't start getting serious about national security, it may be time to find a new electric reliability organization."

The public thrashing came after the release of a report (PDF) by the General Accountability Office (GAO) identifying numerous vulnerabilities at the Tennessee Valley Authority (TVA) that put the nation's biggest public power company at risk to cyber attacks.

Among other things, the TVA had firewalls that were improperly configured or bypassed, used poorly implemented passwords, and relied on logging practices that weren't up to snuff, according to the GAO report. TVA administrators had also neglected to install key software patches and ran intrusion-detection systems with "significant limitations." The GAO issued 92 recommendations for shoring up cyber security at the TVA, which supplies power to 8.7 million US residents in seven states.

The scrutiny comes as more and more electricity providers try to cut costs and boost efficiency by using so-called supervisory control and data acquisition (SCADA) systems, which allow workers to operate equipment remotely using the internet or telephone lines. The systems may save money, but they also potentially make the equipment vulnerable to cyber attack by extortionists, disgruntled employees and terrorists.

The TVA was already in the process of fixing the problems before investigators began their report, a TVA official said. And NERC, along with the Federal Energy Regulatory Commission, is in the process of implementing new rules for cybersecurity that go into effect in July. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.