Live data from Hacker News

Norsk Hydro ASA Suffers Extensive Cyber Attack

bloomberg.com

31–40 of 45 posts

Re: Norsk Hydro ASA Suffers Extensive Cyber Attack

#31
post #14

Earlier quoted context omitted.

Were the affected systems running Windows? They should make it illegal to run critical systems on Windows.

Ah the immunity of non-Microsoft operating systems: https://www.intego.com/mac-security-blog/osxshlayer-new-mac-... https://www.zdnet.com/article/eset-discovers-21-new-linux-ma...

Any actual incidents of these things causing real outages for critical systems anywhere?

(I'm going to guess it's a big NO on the first one, because no one uses Macs for critical systems.)

Re: Norsk Hydro ASA Suffers Extensive Cyber Attack

#32
post #14

They should make it illegal to pay ransoms.

Were the affected systems running Windows? They should make it illegal to run critical systems on Windows.

The problem isn't just windows - it's more along the lines of "narrow software" being very much sold "as is" with "strict and boneheaded compatibility requirements (run known vulnerable software/os)", combined with either consciously or unconsciously taking on the risk of doing so, with or without appropriate mitigations in place.

Control software, or for that matter, software for a sufficiently narrow domain, tends to come "with bugs" and "for compatibility reasons you need to run this on OS/release version X (which is probably what the vendor ran at the point in time when the software were minted/released).

I've had the displeasure of crossing paths with both the linux and windows variety of this.

In some cases you can ignore the vendors and just upgrade, and jump through some amount of hoops to make it work.

I'm sure in most cases you could engineer around this with isolating it from the world, although it may be non-trivial since it'll probably want to communicate over a network of some sort. Although - exactly what is needed in terms of achieving that may be less than well documented, it costs time and money, and is maybe not really budgeted for, there's aggressive installation timelines, and the security part is probably the first thing to get slashed from when the installation timelines starts slipping.

The vendor just wants to sell you a black box, and preferably not touch it ever again after they've sold it to you. (Actually - some even do sell you a branded, badly engineered, stock PC running some variety of windows or linux or bsd, to control your winch/navigation/foundry/whatnot).

I have witnessed "IT for offshore", in which a vessel is docked for X days, here's a list of things that we need to do, after X days the vessel will depart. You may have a few days on top of X days if you can leave somebody at the vessel, after X+Y days, the vessel needs to be somewhere in an operable state, because we have a commissioned work to perform.

For say running a foundry, I'm sure much of this is similar, except the foundry doesn't have go anywhere - but having your foundry do nothing is exceedingly expensive, and making changes during production comes with a different set of risks.

People have probably complained somewhere along the road, disagreeing with the risks, and somewhere higher up in the chain, the choice were made to take on the risk.

Re: Norsk Hydro ASA Suffers Extensive Cyber Attack

#33

None of this type of equipment should be on the internet.

From the looks of the Twitter thread pointed out by @ 0xDEFC0DE, looks like the ransonmware was spread by Active Directory group policies, probably by organized crime, as opposed to a random drive-by download infiltrating an entire organization.

Re: Norsk Hydro ASA Suffers Extensive Cyber Attack

#35

None of this type of equipment should be on the internet.

IMHO it was all downhill once VLAN use became the default and viewed as equally secure as physically disparate networks.

We used to physically isolate security domains across the board. Everything is virtualized now, which makes it a whole lot less visible when boundaries are being violated, where it used to be obvious.

Re: Norsk Hydro ASA Suffers Extensive Cyber Attack

#37
post #30
post #21

Earlier quoted context omitted.

Aside from being outdated advice, this is also globally impossible. Microsoft Windows has got a major lock on the industrial control systems industry. Almost anything being produced today has a Windows machine in the workflow doing something critically important, from monitoring fluid flows to running microchip programmers and test stations.

Then people shouldn't be too surprised when stuff like this happens, and they should just pay the ransom: it's what they accepted by using Windows. "That's the way it's always been" isn't a valid excuse for continuing to make something unsafe.

The advice is outdated because it is entirely possible for Windows machines to be secured well enough for this work. Windows security, like Linux security, is not a binary state with either a zero for no security or a one for security.

They did not accept crippling ransomware by using Windows. Nobody does. This attitude is fatalistic and somewhat juvenile.

They may have implicitly accepted crippling ransomware by not having sufficient internal security processes.

Re: Norsk Hydro ASA Suffers Extensive Cyber Attack

#39
post #12
post #6

Aluminium plants are particularly vulnerable because the electrolysis "pots" must be kept hot, requiring a continuous supply of electricity. Supply interruptions can be a disaster. This has hit Venezuela badly: https://twitter.com/AKurmanaev/status/1104141813936545793 "Today Venezuela basically crossed off an entire industry. In one day. No more industrial aluminum production. Just like that. It’s gone." https://www.…

These seems like systems where the impact of disruption is so severe that it should be effectively offline as much as possible. Now the power source of course... hard to manage that.

> Now the power source of course... hard to manage that.

Well, for many of these plants they're actually built together with a big hydroelectric powerplant that can supply all the electricity needed.

EDIT: Their press release from 6h ago states "Hydro's power plants are running normally on isolated IT systems".

Re: Norsk Hydro ASA Suffers Extensive Cyber Attack

#40

Are there any companies in the business of hardening SCADA systems? I keep on hearing about the huge vulnerability they pose, which would make me expect a Y2K-level of focus by the industry.

Dragos Inc., I interviewed one of their senior threat hunters on Cyber Talk Radio (text recap with link to podcast audio) https://www.jungledisk.com/blog/2017/06/27/industrial-cybers...
Post reply on HN