Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

71–80 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#71
post #68

Earlier quoted context omitted.

Please explain why shutting down the pipeline will contain the hack?

You need the SCADA systems to run the pipeline. They control the pumps, valves, product sequencing, etc. So Colonial purposely shut down the pipeline to prevent the SCADA system from getting affected, which might cause physical damage that truly would be a catastrophe.

[deleted]

Re: US passes emergency waiver over fuel pipeline cyber-attack

#72
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> if you are a critical service ... for each occurances 10% of your total revenue ... are forfeited

You can achieve the same effect without all the arbitrary political decision-making inherent in this proposal by requiring these companies to buy delivery insurance or something. The insurance company will charge them proportionally to the risk of attack, which will internalize the cost.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#73
post #53

Earlier quoted context omitted.

Pound for pound I'd say Israel. In absolute terms I'm pretty sure China has us at sea and in cyber so... Not the US

Pretty sure china doesn't have the oceans - might want to check up on your stats.

Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans.

>Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships.

[1](https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...)

Re: US passes emergency waiver over fuel pipeline cyber-attack

#74
post #58

Earlier quoted context omitted.

Yes we should. There is no justification for why we meekly let them have at it cyberspace. It should be pain for pain. Russians will never learn until they feel pain.

I like the concept of holding Russia (as with any country) responsible assuming they are, but your reply didn’t address the escalating pattern of tit for tat, and how to deal with that.

Perhaps a sort of cyber-MAD comes out of the escalation and the Russian government cracks down on the group to prevent their own serious infrastructure disruptions.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#75
post #25

The government is incompetent, especially when it comes to cybersecurity. It will be interesting to see how this plays out.

Who was it again that has the most effective intelligence community and military in the world?

I hope you're not talking about the CIA, whose network of agents in China (to pick one example) was rounded up and killed due to either shoddy IT work or a mole in the Agency. Either possiblity reflects poorly on the American intelligence community:

https://www.reuters.com/article/us-usa-china-espionage-idUSK...

>Investigators remain divided over whether there was a spy within the Central Intelligence Agency who betrayed the sources or whether the Chinese hacked the CIA’s covert communications system, the newspaper reported, citing current and former U.S. officials.

>The Chinese killed at least a dozen people providing information to the CIA from 2010 through 2012, dismantling a network that was years in the making, the newspaper reported.

>One was shot and killed in front of a government building in China, three officials told the Times, saying that was designed as a message to others about working with Washington.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#76

Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. Not Breaking: Citizens’ disappointment in the aforementioned, particularly given their direct contribution to said budget. The Unsaid: Much of this will not change, unless incentives are realign…

> Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. I'm not sure what technology industry you are in, but in the one I'm in software engineers are fooled by phishing attacks extremely consistently, people routinely expose critical systems and d…

Basic security practices like 2FA and not using VPNs/trusting the network would be a great start. There is no excuse for private business like Facebook and Google being more secure than the f*@& United States of America.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#77
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I have no idea why they would do that unless the system was not airgapped properly or it was hard to untangle the admin network from the control network (in which case, the control network is effectively not airgapped).

Flash drives.

I used to work in fabs and every couple of years some tool or other would get a virus, sometimes it spread through the network.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#78

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Lol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra

Re: US passes emergency waiver over fuel pipeline cyber-attack

#79
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> That will get them serious about security.

My guess is that they only get serious about security after a breach occurs.

You can view it all as strengthening an immune system. Without attacks, and the occasional successful ones, nobody is going to bother to harden anything.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#80
post #68

Earlier quoted context omitted.

Please explain why shutting down the pipeline will contain the hack?

You need the SCADA systems to run the pipeline. They control the pumps, valves, product sequencing, etc. So Colonial purposely shut down the pipeline to prevent the SCADA system from getting affected, which might cause physical damage that truly would be a catastrophe.

I'm really confused: the pipeline is resilient to a hack: they just shut down the pipeline so it won't be 'affected' (hacked?)?
Post reply on HN