Hello,

We noticed you're browsing in private or incognito mode.

To continue reading this article, please exit incognito mode or log in.

Not a subscriber? Subscribe now for unlimited access to online articles.

Intelligent Machines

NSA Hacking Chief: Internet of Things Security Keeps Me Up at Night

The leader of the National Security Agency’s hackers says that putting industrial control systems online has made America less secure.

The trend to connect devices such as air conditioners and door locks to the Internet is making life easier for the National Security Agency’s hackers—but also keeping their boss awake at night.

Rob Joyce, chief of the NSA’s Tailored Access Operations unit, leads what is likely the best resourced group of hackers in the world. They are tasked with infiltrating computer networks to gather foreign intelligence, and also with probing U.S. government networks to improve their security.

Speaking in San Francisco Wednesday about how nation-backed teams like his operate, Joyce said that the so-called “Internet of things” is a major boon when the TAO group needs to attack a target. He singled out heating and cooling systems as examples of Internet-connected devices that offer national-level hackers a route into organizations that computer network administrators often overlook. Joyce spoke at the Enigma security conference.

However, Joyce also said that the poor security of such devices is one of his primary concerns when it comes to the safety of U.S. networks.

In recent years researchers have found that hundreds of thousands of industrial and commercial control systems—referred to as SCADA systems—have been blithely hooked up to the Internet without proper protections, including power plants and other critical infrastructure (see “What Happened When One Man Pinged the Whole Internet”).

“SCADA security is something that keeps me up at night,” said Joyce. He suggested that it might need new ideas from academia, which works on more fundamentally new ideas than industry, to improve the situation.

Nicholas Weaver, a computer security researcher at the International Computer Science Institute in Berkeley, California, who attended Joyce’s talk, said that he had correctly highlighted a significant problem, and an area where scary discoveries are easily made but possible solutions very scarce. “I don’t do SCADA research because I like to sleep at night,” said Weaver.

Researchers that do work on SCADA security have found evidence that there are groups trawling the Internet looking for industrial systems to infiltrate (see “Chinese Hacking Team Caught Taking Over Decoy Water Plant”). A recent report by the Nuclear Threat Initiative said that many nuclear power and weapons facilities are not adequately protected against computer-based attacks.

Learn from the humans leading the way in intelligent machines at EmTech Next. Register Today!
June 11-12, 2019
Cambridge, MA

Register now
More from Intelligent Machines

Artificial intelligence and robots are transforming how we work and live.

Want more award-winning journalism? Subscribe to All Access Digital.
  • All Access Digital {! insider.prices.digital !}*

    {! insider.display.menuOptionsLabel !}

    The digital magazine, plus unlimited site access, our online archive, and The Download delivered to your email in-box each weekday.

    See details+

    12-month subscription

    Unlimited access to all our daily online news and feature stories

    Digital magazine (6 bi-monthly issues)

    Access to entire PDF magazine archive dating back to 1899

    The Download: newsletter delivery each weekday to your inbox

/3
You've read of three free articles this month. for unlimited online access. You've read of three free articles this month. for unlimited online access. This is your last free article this month. for unlimited online access. You've read all your free articles this month. for unlimited online access. You've read of three free articles this month. for more, or for unlimited online access. for two more free articles, or for unlimited online access.