Hacker News new | ask | show | jobs
by swarfield 876 days ago
Should we be marking key infrastructure, utilities don't distribute this information for a reason.
4 comments

People used to get really upset about such datasets because terrorism/vandalism/etc. But eventually more sane opinions prevailed as attackers don't use this type of data - they either have insider knowledge already or just drive around to scope out targets.

DHS now publishes a ton of open datasets to help with disaster planning, emergency response, and infrastructure hardening. https://hifld-geoplatform.opendata.arcgis.com/search?collect...

Used to?

A lot of that still happens, just instead of "terrorism", it's "crime". FOIA requests for locations of camera, alpr, and other massively used and unaudited surveillance equipment are routinely denied because it will "allow criminals to circumvent". It's all silly and benchmark moving.

Yes, used to. 15 years ago trying to publish research on critical infrastructure vulnerabilities would get you a visit from the FBI (ask me how I know). Now you get invited to DC to present it in person and your remediation suggestions are taken seriously.
...that still doesn't mean they've stopped as a practice, on the whole, or through other intimidation methods. Hell, I'd argue that its current and subtle manifestation is more harmful on-the-whole than it used to be. Like, sure, the DHS voluntarily releases information, but that's discretionary and at their will. Eg, I sued the Chicago for database columns and table names after they argued it would be a security risk -- DHS gives that info about their own systems voluntarily. And that's even with case law from an ICE lawsuit that says schemas are exempt.
Ok, mike_d, but how do you know?
Second that!
:+1:
Yes we should. Security through obscurity is a myth
And any above ground stuff is rather visible in any case, and mapped extensively on OpenStreetMap.
Doh, thinking about it through that lens makes it obvious!
I rather appreciate knowing where the key electrical substations are in my area: helps me to understand exactly who can screw with things and where they would do it -- which makes me pay closer attention when I pass by substations and see someone lurking about. Not knowing that the location is critical I wouldn't think twice about someone loitering; knowing the location is sensitive and critical makes me look twice, take an active interest, and perhaps phone in a suspicious activity reports. Some people while about this information enabling terrorists: I think it enables all of us to open our eyes and protect our own interests.
I get the feeling an adversary who wants to know where they can cause the most mayhem of this nature already does. I think a map is ultimately unnecessary anyway; I'd guess it's more appealing to sabotage remotely using computer networking vulnerabilities than to risk a field agent.