Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

151–160 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#151
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

I also wonder why nobody who has secure computing issues demands physical write-enable switches for ROM, rather than using software switches that are inevitably corrupted.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#152

Earlier quoted context omitted.

Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1]( https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...…

without significant aircraft carrier fleet i'm not sure china has dominant control of any seas, despite best efforts in south china seas [1]( https://en.wikipedia.org/wiki/Chinese_aircraft_carrier_progr... )

https://www.cnn.com/2021/03/05/china/china-world-biggest-nav...

I am not sure what your point is. By number of ships, they are the biggest. I have no idea how important aircraft carrier fleet is.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#153

Forgive my ignorance, but is it incredibly hard to determine the actual identities of the people behind this? I don’t know why a government wouldn’t simply assassinate culprits who were guilty of crimes at a level that would qualify as an act of war.

Given that this is a ransomware attack, the data is probably encrypted, so if they did find the person behind it, they would probably use "rubber-hose cryptanalysis" to extract encryption keys before...

https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Re: US passes emergency waiver over fuel pipeline cyber-attack

#154

Earlier quoted context omitted.

Do you think Colonial identified some "physical world" risk, as in the possibility of a pressure overload or pipeline leak? I imagine that verifying the integrity of these SCADA systems is a very complex task, so I'm wondering if they've already identified a possible attack vector/entry point or if this was entirely preventative.

I have no idea. Shutting down preventatively would be smart, and they had good leadership in their IT space while I was there. Friendly people who could make the hard decisions quickly, weren't afraid to pick up the phones to call people, and supported the growth of struggling employees without letting shoddy work get approved. They were also good at managing large multi-year and nation-wide project campaigns - a rar…

That's why physical write-enable switches are a must for ROMs. If it's "off", the malware won't survive a reboot.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#155
post #53

Earlier quoted context omitted.

Pretty sure china doesn't have the oceans - might want to check up on your stats.

Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1]( https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...…

Bath Iron Works is hiring people on the spot right now. They are probably going to hire 3k people in the next year. I imagine this is happening at other shipyards around the country. Expect those ship numbers to be revised upwards.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#156
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> It needs to be asked again, why are critical services on the Internet?

From TFA:

Digital Shadows thinks the Colonial Pipeline cyber-attack has come about due to the coronavirus pandemic - the rise of engineers remotely accessing control systems for the pipeline from home... believe DarkSide bought account login details relating to remote desktop software like TeamViewer and Microsoft Remote Desktop.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#157
post #133
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited. Make it a crime to pay the ransom in a ransomware attack. Make it a crime to fail to report a ransomware attack in a timely manner. Ransomware attacks (and companies with poor security practices) wi…

Make it a crime to possess, consume, or distribute substances that are bad for people.

Make it a crime for people to knowingly withhold information about such activities from the authorities.

Abuse of substances, trafficking, and associated criminality will go away.

But seriously...

> Make it a crime to pay the ransom in a ransomware attack.

Ok, so ... what should a company do? File a report with some government agency or with an insurance company and wait until the bureaucratic process maybe results in being able to pay the ransom to resume business operations? Punishing the victim of a crime? Really?

> Make it a crime to fail to report a ransomware attack in a timely manner.

Further punishing the victim of a crime? Really?

> Ransomware attacks (and companies with poor security practices) will go away.

lol

Re: US passes emergency waiver over fuel pipeline cyber-attack

#158

Earlier quoted context omitted.

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Can an individual not accidentally or intentionally infect a computer not connected to the internet?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#159

Earlier quoted context omitted.

Do you think Colonial identified some "physical world" risk, as in the possibility of a pressure overload or pipeline leak? I imagine that verifying the integrity of these SCADA systems is a very complex task, so I'm wondering if they've already identified a possible attack vector/entry point or if this was entirely preventative.

I have no idea. Shutting down preventatively would be smart, and they had good leadership in their IT space while I was there. Friendly people who could make the hard decisions quickly, weren't afraid to pick up the phones to call people, and supported the growth of struggling employees without letting shoddy work get approved. They were also good at managing large multi-year and nation-wide project campaigns - a rar…

Thanks for the response. It's amazing to have a community where "subject-matter experts" like yourself just pop up.

I'm quite surprised and comforted to hear that the leadership there is competent and knows how to manage people. I've heard from friends/acquaintances who have worked in the energy industry about how terribly things are put together on an IT front (PG&E being a prime culprit), so I was expecting the same here.

I really like your "data-diodes" concept. Interested to see if such a thing takes off especially as these attacks evolve.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#160

Earlier quoted context omitted.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

I also wonder why nobody who has secure computing issues demands physical write-enable switches for ROM, rather than using software switches that are inevitably corrupted.

Generally it's been the opinion that the control systems need to be modifiable. For example if you add a single valve in a facility which has 4,000 valves already, it would be nice to just add add a controller for that valve to the current SCADA system.

However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small modifications. That would move the target of vulnerability up the supply chain.

Some of the things which matter though are necessarily run-time variables like "is the valve commanded open or closed?" and "what are the tuning parameters for this PID control loop?". It's always theoretically possible for a buffer overflow/rowhammer/etc to flip the bit responsible for the valve's open/closed command. Even with an OS/Application stack burned into ROM. You still need RAM.

At least power cycling a readonly-storage device would remove any malicious RAM changes.

Post reply on HN