Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

141–150 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#141

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

> That gang ...

Maybe it's another government, trying to sow chaos, disrupt markets, test US response capabilities, etc.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#142
Forgive my ignorance, but is it incredibly hard to determine the actual identities of the people behind this? I don’t know why a government wouldn’t simply assassinate culprits who were guilty of crimes at a level that would qualify as an act of war.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#144
post #117

Earlier quoted context omitted.

I'm really confused: the pipeline is resilient to a hack: they just shut down the pipeline so it won't be 'affected' (hacked?)?

It was intended to be airgapped, but we're talking about a pipeline that is several thousand miles long, with many pumping stations and delivery terminals. All it would take is one of the SCADA systems at one of those locations to suddenly open a valve and dump petroleum out into the environment to cause a disaster. Or worse - rapidly open & close valves in rhythm, and the water hammer effect (the inertia of the petr…

It was not intended to be air-gapped. These systems generally communicate to business layers through firewalls.

Onion-layer security rather than air gaps. Communication through the firewall isn't supposed to allow control over the valves, but it does communicate both ways (TCP/IP). This is the general practice in petrochemicals, at any rate.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#145
post #66
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Agreed. Our companies are driven to increase profit at all cost. Even cost to their function and utility. Our over financialization is squeezing everyone and everything.

To clarify: this is not from "financialization" generally speaking. This is specifically from consolidation for the sake of increasing efficiency and thus margins (as you pointed out).

This is opposed to increased competition (which also increases volatility) in the markets.

The reason why the markets are so consolidated is because it removes short-term risk. If there is an obvious market and only one (or a few) companies involved then everyone makes money (magic, I know). This is why Wall Street lobbies for regulations so hard. They have ownership in all the existing major companies that can afford those regulations and it consolidates the profits (and thus returns). De facto Crony Capitalism at its finest. Your aristocratic oligarchs.

So, stop giving your money to large index funds. (And every time there is a comment on HN telling you to, and there are plenty, downvote them and tell them a proper F-off).

The idea that no one can/should ever lose is what is killing the economy. It got its birth in the boomer-retirement-fund markets of the past few decades.

To recap, it is consolidation for margins that is the problem. That is not the same as general "financialization" (increased trading) that helps increase volatility in the markets and actually increases the size of the economy.

We desperately need real markets and not this crony capitalism that seems self-persistent.

The current system is such a marriage between corrupt politicians and wall street (which is now heavily extended into SV, btw) that it is absolutely disgusting.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#146
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#147

Earlier quoted context omitted.

> Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. I'm not sure what technology industry you are in, but in the one I'm in software engineers are fooled by phishing attacks extremely consistently, people routinely expose critical systems and d…

Basic security practices like 2FA and not using VPNs/trusting the network would be a great start. There is no excuse for private business like Facebook and Google being more secure than the f*@& United States of America.

Well, FB, Google, et al. have sucked up all the talent.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#148

Earlier quoted context omitted.

Many sites are in the middle of nowhere so it is inconvenient to go to them, so accessing them over a network saves a lot of travel time and cost.

This is true for nuclear weapons infrastructure. Paying for commutes and lodging are used there, might be useful to consider?

At one extreme a Nuclear weapons accident can kill millions of people and destroy the environment of a large area for a long time.

And then a sliding scale of risk and cost of getting hacked vs savings and increases in efficiency resulting from remote access.

Are you for or against Tesla having remote access to all of the Tesla vehicles? Are their OTA updates innovative or reckless?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#149
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

They aren't 'on the internet'. They are connected via several layers of networks with firewalls etc in between to a system which has direct access to the internet. There often is no practical way around this - data from these networks needs to be shared with business users, other companies, regulators and so on. Data diodes can be applicable in some situations, but I've never worked with a company that uses one. I do…

Indeed the best evidence supporting this view is that Natanz was fully air-gapped and still got destroyed by the Stuxnet hack.

That said I have heard of customers expressing desire to control valves and pumps using iPhones, and believe there are several initiatives at SCADA/PLC/DCS/System Integrator companies to provide this.

However I've seen as many of those in practice as I have data-diodes, which is to say, none/never.

Post reply on HN