Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

91–100 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#91
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> Digital Shadows thinks the Colonial Pipeline cyber-attack has come about due to the coronavirus pandemic - the rise of engineers remotely accessing control systems for the pipeline from home.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#92
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

Why is the network constructed in such a way that it allows things to spread?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#93

They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.

> We should shut down Russian infrastructure as retaliation.

How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#94
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

It's multi-dimensional. SCADA itself being networked, and it reaching other systems that may be internet-enabled.

  * What systems are affected by the hack?
  * Could the shutdown be needed because of critical data the ICS gets from business?
  * Or is it shut down because business needs real-time data from ICS it can't ingest?
In general, the idea of completely isolating an ICS from any other network is a tough one.

My question is, how often are these critical suppliers audited by the federal government? I have worked in banking cybersecurity and the amount of auditing from federal and state regulators is mind boggling. If a single company controls 45% of fuel transport to the east coast, it should carry some designation as a quasi-state entity subject to federal cybersecurity audits like banks.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#96

They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.

> We should shut down Russian infrastructure as retaliation. How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.

Yes, let’s meekly sit back and let other countries attack us, only playing defense.

Russia caused this. If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves. You cannot expect to engage in acts of war without endangering your own citizens to at least some degree. To engage in war is to invite it to your homeland.

Hell, if we don’t retaliate, we may be seen as a weak and an easy target. I argue that we already are, in the realm of cybersecurity, which is why state-sponsored attacks on American companies keep happening.

Furthermore, American infrastructure, companies, and civilians come first. It should be made clear that we will deal with aggressors and acts of war. Countries do not attack the US in the physical realm out of fear of retaliation, and it should stay that way in the cyber realm.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#97

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Lol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra

"nation-state" is not just a fancy infosec word for country, and there's some debate as to whether the USA constitutes an actual nation state, rather than a state.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#98
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

Why is the network constructed in such a way that it allows things to spread?

Super common. A lot of companies have this hard on the outside gooey on the inside model (aka flat network structure).

Re: US passes emergency waiver over fuel pipeline cyber-attack

#99
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

Do you think Colonial identified some "physical world" risk, as in the possibility of a pressure overload or pipeline leak? I imagine that verifying the integrity of these SCADA systems is a very complex task, so I'm wondering if they've already identified a possible attack vector/entry point or if this was entirely preventative.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#100
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> That will get them serious about security. My guess is that they only get serious about security after a breach occurs. You can view it all as strengthening an immune system. Without attacks, and the occasional successful ones, nobody is going to bother to harden anything.

Is that like how the banks all got serious about evaluating their risk carefully after the first time [1] they saw their models, and consequently their liquidity, evaporate?

Obviously I agree about your dissatisfaction with the other proposed solution: that just lets corporate entities put a low (10%) ceiling on what should be unlimited liability, allowing them to say that failing catastrophically by utter neglect to security is reliably a survivable offense (I recognize that in reality the liability of course ends at the dissolution of the corporation.)

I don't know what the actual answer is.

[1] https://en.m.wikipedia.org/wiki/List_of_economic_crises

Post reply on HN