Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

171–180 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#171

>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?

Most people will probably be hesitant to post it for obvious reasons here. But it was helpful to me, to find a ransomware url, during the college leak a few weeks ago (https://dorper.me/articles/unileak.aspx) to find out which colleges were impacted because tons of people I know were in it. There are plenty of good reasons to want to have it. But I understand why BBC wouldn't post it...

Re: US passes emergency waiver over fuel pipeline cyber-attack

#172

Earlier quoted context omitted.

Lol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra

"nation-state" is not just a fancy infosec word for country, and there's some debate as to whether the USA constitutes an actual nation state, rather than a state.

nation-state" is not just a fancy infosec word for country,

This is pedantic and adds no value. In what sense could the precise definition of "nation state" matter? in this context everyone understands the phrase in exactly the way it's meant -- a resourceful national government.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#173

>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?

I don't have it, but I would go to dark.fail's onion address and browse there (http://darkfailllnkf4vf.onion/ verify this and get in the habit of doing so! dark fail's clearnet website just got hacked while their onion site was unaffected), and then I would go to Dread forum (onion reddit clone) and ask there.

A little tedious but there is lots of commerce on onion sites, and a lot of valuable information in general that I've never seen anywhere else, so it can be worth it.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#174

Earlier quoted context omitted.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

Are pipelines something we invented after the internet? Have we lost the knowledge we used to support infrastructure before the 90s?

Before the 90s? Hmm. Well, if you believe Thomas C. Reed's account, the US was using trojans to sabotage Soviet oil pipelines in 1982.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#175

Earlier quoted context omitted.

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

Couldn't the pipeline have it's own network connected to a monitoring station. At the station employees could access the pipeline network but never connect it to the network from which they could communicate with the people who would be dispatched to make repairs or adjustments?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#176

Earlier quoted context omitted.

I hope you're not talking about the CIA, whose network of agents in China (to pick one example) was rounded up and killed due to either shoddy IT work or a mole in the Agency. Either possiblity reflects poorly on the American intelligence community: https://www.reuters.com/article/us-usa-china-espionage-idUSK... >Investigators remain divided over whether there was a spy within the Central Intelligence Agency who betr…

This isn't a counter-argument against the person you're replying to, though. One can pick from numerous examples of the inverse(though the US doesn't round them up & disappear them, they go through the court system)

> though the US doesn't round them up & disappear them, they go through the court system

Yeah, unless you are suspected for terrorism. I recommend the movie named The Mauritanian.

> Mohamedou Ould Slahi (Arabic: محمدو ولد الصلاحي‎) (born December 21, 1970) is a Mauritanian man who was detained at Guantánamo Bay detention camp without charge from 2002 until his release on October 17, 2016.

> The book, Guantánamo Diary, was published in January 2015. It is the first work by a still-imprisoned detainee at Guantánamo. It provides details of Slahi's harsh interrogations and torture, including being "force-fed seawater, sexually molested, subjected to a mock execution and repeatedly beaten, kicked and smashed across the face, all spiced with threats that his mother will be brought to Guantánamo and gang-raped.[1]

[1] https://en.wikipedia.org/wiki/Mohamedou_Ould_Slahi

Re: US passes emergency waiver over fuel pipeline cyber-attack

#177
A lot of people are talking about the the results of this hack and a little bit about the industrial control systems, but no one is really addressing the hack itself.

>James Chappell, co-founder and chief innovation officer at Digital Shadows, believes DarkSide bought account login details relating to remote desktop software like TeamViewer and Microsoft Remote Desktop.

>He says it is possible for anyone to look up the login portals for computers connected to the internet on search engines like Shodan, and then "have-a-go" hackers just keep trying usernames and passwords until they get some to work.

Nothing sophisticated, nothing difficult, you just need some capital in the bank to buy some leaked credentials someone else worked hard to poke at, that is, some academic security person on a PhD worked hard for months to find some bug in software back in 2014, that turned into code someone else copy and pasted back in 2017, that yielded a dump in 2019 that some other hackers actually probed for some sucker's old login details he probably didn't even realize was in a dump, or might not even use anymore! The only hard work in this story is that academic in 2014 did and he definitely probably no connection to the criminals who basically got the president to issue a national emergency.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#178

Earlier quoted context omitted.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

I’m curious — how would something like a data-diode work in real life? It makes sense, but what about something like TCP where the sending side needs the ability to receive ACK messages? Is a firewall (dedicated, if need be) enough? Or would this be some other kind of physical interface that took some kind of read-only data (serial?) and sent it up the layers using TCP/IP, where only this box would be at risk? Edit:…

[deleted]

Re: US passes emergency waiver over fuel pipeline cyber-attack

#179

Earlier quoted context omitted.

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

You can have a maintenance network that is disconnected from the internet.
Post reply on HN