It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…
US passes emergency waiver over fuel pipeline cyber-attack
91–100 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#92Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#93They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.
How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#94It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…
* What systems are affected by the hack?
* Could the shutdown be needed because of critical data the ICS gets from business?
* Or is it shut down because business needs real-time data from ICS it can't ingest?
In general, the idea of completely isolating an ICS from any other network is a tough one.My question is, how often are these critical suppliers audited by the federal government? I have worked in banking cybersecurity and the amount of auditing from federal and state regulators is mind boggling. If a single company controls 45% of fuel transport to the east coast, it should carry some designation as a quasi-state entity subject to federal cybersecurity audits like banks.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#95Re: US passes emergency waiver over fuel pipeline cyber-attack
#96They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.
> We should shut down Russian infrastructure as retaliation. How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.
Russia caused this. If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves. You cannot expect to engage in acts of war without endangering your own citizens to at least some degree. To engage in war is to invite it to your homeland.
Hell, if we don’t retaliate, we may be seen as a weak and an easy target. I argue that we already are, in the realm of cybersecurity, which is why state-sponsored attacks on American companies keep happening.
Furthermore, American infrastructure, companies, and civilians come first. It should be made clear that we will deal with aggressors and acts of war. Countries do not attack the US in the physical realm out of fear of retaliation, and it should stay that way in the cyber realm.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#97That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.
Lol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra
Re: US passes emergency waiver over fuel pipeline cyber-attack
#98Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.
Why is the network constructed in such a way that it allows things to spread?
Re: US passes emergency waiver over fuel pipeline cyber-attack
#99Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.
I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#100It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…
> That will get them serious about security. My guess is that they only get serious about security after a breach occurs. You can view it all as strengthening an immune system. Without attacks, and the occasional successful ones, nobody is going to bother to harden anything.
Obviously I agree about your dissatisfaction with the other proposed solution: that just lets corporate entities put a low (10%) ceiling on what should be unlimited liability, allowing them to say that failing catastrophically by utter neglect to security is reliably a survivable offense (I recognize that in reality the liability of course ends at the dissolution of the corporation.)
I don't know what the actual answer is.