A couple of weeks back I posed the question as to what the role might be of the federal government in securing the Internet.  This week it was brought to light that there is a WORM running around the Internet that is capable of infecting SCADA (Supervisory Control and Data Acquisition) systems that run a particular Siemens software. The WORM installs a rootkit and then tries to ‘phone home’ to an external server information including layout designs and control files.  All of this believed to be the result of a default password that is widely known.

If we cannot trust those who create, install, and maintain software that impacts critical infrastructure, and we don’t want the government to do it for us, what then?

Share your thoughts.