I love that ThreatPost wedged that one in there -- anyone who has worked with SCADA systems knows the second rule is "don't expose your HMI's." (The first rule is "don't believe the vendor.")
Isn't that as good as saying "yes, the default password is always 100"?
http://support.automation.siemens.com/WW/llisapi.dll/4581536...