May 23, 2008

Vulnerabilities in the Tennesse Valley Authority Power Grid

Recently, in a disclosure by the US Government Accountability office- the UAO makes the following statement.

"Until the TVA fully implements these security program activities, it risks disruption of its operations as the result of a cyber incident, which could impact its customers," the GAO says. TVA delivers electricity to an area that includes most of Tennessee and parts of Alabama, Georgia, Kentucky, Mississippi, North Carolina and Virginia -- an area with a population of 8.7 million people.

The Authority Power grid is essentially not separate from its corporate network. The latter is ripe with vulnerabilities, including faulty hardware, Anti-virus free machines, poorly patched control systems and a myriad of other issues. The network has "Limited intrusion Detection" and ineffective management. Basically, if you happened upon a Wireless Access Point, with WEPCrack- Your have access to the world's largest public power grid.

I find this to be disgusting, and an absolute slap in the face for the IT community. How hard is it, admins, to set a 14 digit pass code, configure a router, or even mass install a freaking Anti-Virus? Remember, people depend on you for their livelihoods- take the responsibility seriously.

No comments: