Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

121–130 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#121

I like how they are charging 10% more if you pay with Bitcoin than with Monero. I think commerce would greatly improve if other networks had Tor clients, especially because of the stablecoin and private stablecoin availability as of this year. All EVMs as well as Tendermint networks have no out of the box solutions for Tor nodes and connectivity. But they both have ways for ERC20 tokens to have a great degree of priv…

I recently learned of zkDai[1]. Do you have any thoughts on this or the Aztec protocol? [1] https://medium.com/aztec-protocol/introducing-zkdai-into-the...

It is just too expensive for the Ethereum network and not a large enough mixing set (haven't looked recently though) and nobody accepts it therefore requiring you to exit it if you want anything, but exiting will reveal who you are because there is nobody else it could be.

Privacy on the Ethereum network remains just Ether in Tornado Cash.

edit: oh cool Aztec actually transitioned to the Optimistic Rollup. That is different than their prior smart contract and requires new analysis. I recall their article last year or before about doing a "zk zk rollup" and I didn't keep following.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#122
post #53

Earlier quoted context omitted.

Pretty sure china doesn't have the oceans - might want to check up on your stats.

Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1]( https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...…

Your own link points out that they don't have allied support nor the capability to do sustained blue-water operations, and that the US retains naval dominance.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#123
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

I’m curious — how would something like a data-diode work in real life? It makes sense, but what about something like TCP where the sending side needs the ability to receive ACK messages? Is a firewall (dedicated, if need be) enough?

Or would this be some other kind of physical interface that took some kind of read-only data (serial?) and sent it up the layers using TCP/IP, where only this box would be at risk?

Edit: looks like you answered part of this below — you suggest switching to UDP protocols.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#124

Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. Not Breaking: Citizens’ disappointment in the aforementioned, particularly given their direct contribution to said budget. The Unsaid: Much of this will not change, unless incentives are realign…

Er, the victim here is a private company, not the government.

When 45% of the East Coast's supply of diesel, gasoline and jet fuel is impacted, the government has a problem.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#125

Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. Not Breaking: Citizens’ disappointment in the aforementioned, particularly given their direct contribution to said budget. The Unsaid: Much of this will not change, unless incentives are realign…

How is the US government inept? This is a private company sucking ...

Re: US passes emergency waiver over fuel pipeline cyber-attack

#126
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

They aren't 'on the internet'. They are connected via several layers of networks with firewalls etc in between to a system which has direct access to the internet. There often is no practical way around this - data from these networks needs to be shared with business users, other companies, regulators and so on. Data diodes can be applicable in some situations, but I've never worked with a company that uses one. I don't know the details of this situation, but demanding that it be impossible to compromise infrastructure networks is ridiculous. If you throw enough money and resources at it, no network is secure.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#128
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited

This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical damage. Attach a fine to the discovery and disclosure and you disincentivise that prudence.

Better: make it easier for industry to build securely and incentivise redundancy.

[1] https://en.m.wikipedia.org/wiki/Perverse_incentive#The_origi...

Re: US passes emergency waiver over fuel pipeline cyber-attack

#129
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> companies are chasing profits at any cost

Government systems get hacked all the time, too. Just because the government doesn't have a profit motive doesn't change a long list of human motivations that can be counterproductive.

The profit motive also incentivizes improved quality. If the product is bungled, the company is not likely to get the next contract. If the government agency bungles the product, they'll get a budget increase next time.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#130
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

It's multi-dimensional. SCADA itself being networked, and it reaching other systems that may be internet-enabled. * What systems are affected by the hack? * Could the shutdown be needed because of critical data the ICS gets from business? * Or is it shut down because business needs real-time data from ICS it can't ingest? In general, the idea of completely isolating an ICS from any other network is a tough one. My qu…

This question of missing cyber security audits came up for me in discussion of the Verkada hack. That’s the startup providing security cameras inside hospitals, prisons and schools.

It seems like cybersecurity and audits of security readiness need to be demanded from any authority over companies operating in sensitive areas.

Post reply on HN