You’d be surprised how insecure some of these facilities are, especially to someone who has working knowledge of what a PLC (or other process controllers) does and how it works. You can easily look like a tech who belongs there either troubleshooting something or working on a project.
I’ve been doing industrial controls for 15 years and surprisingly infrastructure is some of the most poorly funded. I believe a lot of these places are run by operating companies, so it’s bidded out (we all know how bids work I think). I’m not surprised when I walk into these places and see the computers are running EOL operating systems and the networking is essentially flat.
Forgive my ignorance but isn't a PLC simply a computer with some GPIO ports? I.e., a Raspberry Pi could be called a PLC? Why are we talking about them as if they are something else? Is it an exotic OS that makes them different?
The term "PLC" is a lot more specific than "computer with some GPIO ports." No one that works with PLCs would consider a Raspberry Pi to be one.
These things are walled gardens. You never see the operating system. You can only change their behavior using the vendor's software. They generally run a single program (that you write using the vendor's software) on a fixed scan cycle. They read the inputs, run your program, write the outputs, then repeat.
While you're giving up the nearly infinite possibilities that an SBC gives you, the benefits more than make up for the lack of flexibility. They run (and have parts and support available) for decades. Modules are easy to diagnose and replace. An electrician who isn't a programmer can follow ladder logic and troubleshoot problems. Integrators can quickly come up to speed and understand your code.
There's a reason companies will pay tens or even hundreds of thousands of dollars for these things.
The point I was making is that PLCs have a software stack. You have to know the software and programming languages defined in IEC 61131-3. For all intents and purposes they are just very repeatable compute in an industrial setting, but if you don’t know ladder logic or how to interface with them you might be SoL. Most don’t have any sort of web interface and if they do it operates outside the controllable logic. Same goes for shells. If you want to program it you typically have to use the vendor software.
Technically it is, but in practice they often speak very obscure protocols over non-Ethernet links.
Honestly, I think it's an advantage at this point. Way too much diversity to easily attack remotely.
If a Raspberry Pi had industrial environment ratings and was certified hard real time, then yes it could be considered a PLC.
All the ones I've encountered in the wild ran VxWorks
> If a Raspberry Pi had industrial environment ratings and was certified hard real time, then yes it could be considered a PLC.
Ostensibly yes, but so far I haven't seen anyone really use a PLC in a way that requires hard real time (so far). The cycle on eg a siemens S7-1200 is anyway much too slow for anything really exciting, and a Pi might very well be more reliable in actual practice, were it not for the very unfortunate tendency to eat SD cards. :-P
(And revolution pi actually ships a hardened Pi for industrial use. So that's one way to go about it. I'm not a big fan of that brand, but it's a data-point. Meanwhile in personal experience some regular pi's left in industrial cabinets for one-off emergency monitoring purposes have managed to stay annoyingly alive over time.)
Not really, sure you can use a rpi to control some hw but they are not the same, a PLC usually run rtos, is deterministic (you can predict timing) while rpi relies on linux OS and its scheduler, the PLC also uses ladder language or function block compared to rpi high level language, and obviously PLC industrial grade I/O both analog and digital that also deal with voltage noise that usually happens by field sensors, and environmentally rugged and rated to run non stop compared to rpi.
Now, if you really want to use rpi as a plc, you need something like openplc or codesys as a runtime, add some HATs for I/O, and use protocols like modbus. It will be a software plc but you are missing the hardware certification and other features. Rpi is good as edge computing rather than plc, like processing vision or data logging, it’s why in drones you need the autopilot AND rpi or companion computer, each does certain functions.
I used to think codesys on raspberry pi was pretty much the pessimal application of an ARM processor (and nothing has changed my mind so far). Here you have a chip that is famous for staying stone-cold and doing interrupts in microseconds , and instead you run it hot on a 50Hz (default) PLC loop instead.
Okay but then is the RF connection really your biggest concern?
I'm kind of worried (probably unnecessarily) that posting ideas would get me on some list, but it seems like there would be many simpler terrorism opportunities once you have physical access.
Historically people just shoot pipelines and transformers.
WWII provides some interesting data points. On the one hand, yes, as Germany occupied numerous neighbours people - even sometimes in the face of group punishment, kept sabotaging the German military and its logistics. In some cases there are literally enemy agents, the Special Operations Executive† but often they're local partisans either working with the SOE or on their own.
But on the other hand, even though the Americans suspected that people who merely looked Japanese might be traitors, AFAIK there aren't any clear examples where the people who were sent to camps actually were enemy spies who'd have sabotaged America given the chance. And in Britain the counter-intelligence operation was so successful that when captured German spymasters revealed their list of agents in Britain, every name was already either working for Twenty Department (20 = XX = Double Cross, we can't resist a pun) or in prison for espionage or dead.
† notably in WWII if as a woman you say you want to be on a ship of the line, or crew front line aircraft and attack the Nazis you will be told women can't serve front line roles and at most you'll be doing delivery runs in relative safety. But if you know the right people to become a spy they will cheerfully send you behind enemy lines even though if caught you will almost certainly be horribly tortured and then probably killed and the government which sent you won't even acknowledge you existed for years.
So, maybe the risk from people who are already where your infrastructure is is much lower that you'd think if you haven't invaded them and occupied their land. On the other hand remote adversaries are definitely always a risk.