Display:
OK. First on your general vision of a nuclear plant security open source community. It is compelling, and would certainly mean an improvement upon today, but it fits my original argument about secrecy as necessary characteristic of nuclear power. You do include a security perimeter, and consequently a line behind which outsider's measurements can be barred and inside which files can be kept. Those that make such decisions aren't the system operators, for whom information exchange about system vulnerabilities is a two-way street, peer-to-peer; but people who have to care about balance sheets (where I note that addressing security problems can cost a lot more than changing computer code), public reactions, and the continuation of projects: the equivalents of CEOs and administrators hiding company/state secrets on servers running Linux. This is cause for concern in case of chemical plants, but the stakes are higher and outside control is qualitatively more difficult for nuclear.

Regarding effective security, even with your definition focussed on human access, I don't think current open source community standards are sufficient [with which, note, I didn't meant they couldn't be an improvement]. The worst case scenario with a system vulnerability for a Linux OS would be a few ten thousand computer crashes, which the sysadmins have to repair by debugging, running a different Linux version, or getting a patch through another internet-connected computer. Addressing system vulnerabilities includes ticking your own system. In case of nuclear facilities, the equivalent worst case scenario should be better avoided. (Staying with the mischievous human factor, you needen't think of al-Qaida. In the USA in the first half of the eighties, there has been a case of sabotage of safety pumps and two cases of sabotage of back-up diesel generators by insiders, and one sabotage of external power lines.) Meanwhile, ticking your own system can be done only in a limited way, you have to rely on simulations and assumptions.

*Lunatic*, n.
One whose delusions are out of fashion.

by DoDo on Fri May 26th, 2006 at 01:05:27 PM EST
[ Parent ]
I do include a "security perimeter". You do lock your door at home, don't you? And the office where you work is not 100% accessible to the public, is it? And it gets locked at night. Your computer's security is "a line behind which files can be kept". I don't know what it is that makes any of this evil. Since nuclear power plants (and chemical plants) involve a risk to the public health, they are subject to government regulation and audit. Everyone and every activity is similarly subject to regulation and audit because it impacts society in one way or another. But there is no requirement to keep everything in display for everyone to see.

Why is outside control qualitatively more difficult for nuclear?

guaranteed to evoke a violent reaction from police is to challenge their right to "define the situation." --- David Graeber citing Marc Cooper

by Migeru (migeru at eurotrib dot com) on Fri May 26th, 2006 at 03:16:52 PM EST
[ Parent ]

Display:
Login
. Make a new account
. Reset password
Occasional Series