August 7, 2026
Tapped Out and Totally Exposed
Water system controllers don't belong on the internet, says ex-NSA chief
America’s water scare sparks a comment war over why these systems were online at all
TLDR: A former NSA chief says water system controls never should have been exposed online after hacks hit facilities in 12 states. Commenters turned that warning into a roast, arguing over whether old equipment should be unplugged entirely or protected better, with plenty of sarcasm about who let this happen.
A former National Security Agency boss just dropped a very blunt warning at DEF CON: water system controllers should not be on the internet. The alarm comes after hacks hit water systems in at least 12 US states, with many security researchers strongly suspecting Iran, even if US officials are still being careful about saying that out loud. For regular people, the scary part is simple: these are the systems that can watch tank levels and switch pumps on and off. Yes, the stuff tied to your water.
But the real fireworks were in the comments, where readers turned the story into a full-on blamefest. One camp basically said, what did you expect? The iciest response was a brutal “you reap what you sow,” while another commenter twisted the knife with a joke implying the NSA only likes security when it’s convenient: “Other countries start securing their water … nsa: what no, stop that.” Ouch.
Then came the fight over whether these systems should be online at all. Some argued the answer is an immediate no, especially when old equipment is involved: cut the lines, go back to old-school monitoring, and stop pretending ancient machines belong on the modern web. Others pushed back, saying remote access is useful if it’s done carefully, because otherwise somebody has to physically drive out for every little problem. And just when that debate seemed settled, another commenter barged in to say, basically, even if it’s not online, insecure radio links and Bluetooth can still be a mess. Translation: the internet isn’t the only villain, but the community agrees the current setup looks way too flimsy for something as basic as public water.
Key Points
- •Paul Nakasone said water-system PLCs should not be connected to the internet and called for higher cybersecurity standards.
- •The FBI said in late July it was investigating attacks by malicious cyber actors targeting operational technology devices, including PLCs.
- •The article says water systems in at least 12 US states have been hacked, with private-sector researchers suspecting Iranian involvement.
- •Neither the FBI nor the Trump administration had officially attributed the recent attacks to Iran at the time of the article.
- •Nakasone said the US water sector’s large, underfunded, and fragmented infrastructure requires partnership-based defense efforts such as DEF CON Franklin and Project Chimera.