Hackers can infect network-connected wrenches to install ransomware
Network-connected torque wrenches used in factories are being criticized for shipping with numerous security flaws, raising the risk of sabotage or ransomware in safety‑critical manufacturing. Commenters debate whether such tools really need internet connectivity, noting that while they offer benefits like automated quality tracking and audit trails, they’re often deployed on poorly secured networks by overworked teams in organizations that treat software as an afterthought. Many argue that stronger defaults, air‑gapped networks, and possibly regulation or industry standards are needed, since market incentives alone aren’t producing secure industrial IoT devices.
Why torque wrenches are networked at all
- Used to track “critical fasteners” (which bolt, when, by whom, with what torque) and tool health for safety, reliability, QC, and audits.
- Networked tools can drive process flow: only advance the assembly step once each required bolt is confirmed correctly torqued.
- Factories want IIoT data for preventive maintenance and analytics; some value remote monitoring over air‑gapped, on‑site checks.
- Skeptics argue none of this fundamentally requires internet connectivity, only local networking at most, and traditional methods (paper logs, calibrated manual tools) have worked.
Internet vs local/air‑gapped networks
- Many argue the wrench should be on an isolated OT network or VLAN, not the public internet.
- Others note that even air‑gapped systems can be compromised (e.g., via USB), but agree the risk is still orders of magnitude lower than exposing devices online.
- Disagreement over how “hard” USB‑based attacks really are in practice; consensus that remote internet exposure is much easier for attackers.
Security practices and incentives
- Industrial/embedded software is seen as low‑quality: tiny overworked teams, treated as cost centers in companies that still think they “make wrenches, not software.”
- Devices ship with insecure defaults (e.g., weak passwords, SNMP public community, 23 CVEs in a wrench), minimal patching, and poor UX.
- Manufacturing IT security is often an afterthought; legacy systems run unpatched for years.
- Several commenters call for regulation, secure‑by‑default standards, long‑term patch support, and mandatory third‑party pen testing.
Value vs complexity of “smart” tools
- Pro‑smart side: automated torque application reduces user error and wrist injuries, gives consistent torque, simplifies fleet configuration, and eliminates manual data entry – especially vital in repeatable, safety‑critical assembly lines.
- Skeptical side: a mechanical or basic digital torque wrench with no network (or simple wired upload) has far fewer failure and attack surfaces and is easier to verify and calibrate.
- Some argue networking adds many new humans and systems (software, infra, cloud) whose mistakes or compromises can be catastrophic, possibly even enabling subtle sabotage of safety‑critical products.
Broader themes
- Recurring points about misaligned incentives, “lazy” reliance on public internet for convenience, and boilerplate corporate claims that “security is a top priority.”
- Thread mixes serious concern about systemic IIoT risk with humor about subscriptions, data‑harvesting wrenches, and far‑fetched “smart” devices.