Industrial control system SCADA code review highlighting catastrophic failure states in municipal grids
secure coding

Destroy a City - secure code review

It should be noted that no ethically-trained software engineer would ever consent to write a DestroyBaghdad procedure

Key takeaways
  • Software errors in industrial automation translate directly into kinetic physical catastrophes.
  • Code reviews for critical infrastructure must assume untrusted inputs and adversarial actuators.
  • Air gaps are a myth; safety-critical systems must be resilient by design.

#

“It should be noted that no ethically-trained software engineer would ever consent to write a DestroyBaghdad procedure. Basic professional ethics would instead require him to write a DestroyCity procedure, to which Baghdad could be given as a parameter.”

— Nathaniel S Borenstein