Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

181–190 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#181

Earlier quoted context omitted.

I also wonder why nobody who has secure computing issues demands physical write-enable switches for ROM, rather than using software switches that are inevitably corrupted.

Generally it's been the opinion that the control systems need to be modifiable. For example if you add a single valve in a facility which has 4,000 valves already, it would be nice to just add add a controller for that valve to the current SCADA system. However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small mod…

Thanks for your many informative posts here. It's a pleasure reading from someone who knows what they're talking about :-)

I did say ROMs, but you can also use EEPROMs, which are erasable in-circuit, and you certainly put a physical write-enable in that circuit. Ideally, it would be a momentary push-button that has to be pushed in person on-site.

Back in college we used EPROMs, which are erased by putting them for 20 minutes or so under a UV lamp. EEPROMs came out later.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#182
post #115

Seems they got in through a password brute-force attack? It might be time to switch to hardware tokens, encryption keys or to enforce fully random passphrases or diceware/xkcd passphrases.

Anyone not using U2F/WebAuthn to protect all of their internal resources is behind the state of the art. It's really not that hard, especially when you're a BigCorp and already have an SSO system in place.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#183
post #53

Earlier quoted context omitted.

Pretty sure china doesn't have the oceans - might want to check up on your stats.

Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1]( https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...…

Air Craft carriers and jets were proven in WW2 to be the big differentiator. US took note and has more than the entire world combined. 'Battle force ships' is a very loose term and your source only includes navy resources. You forget we have Army, Air force, Marines and not to forget coast guard that all have their own watercraft. Also, don't know if you've been seeing some of the new SWISS ships the US have been developing. Very small, hyper fast ships with a crew of 6 or less with a crazy amount of firepower in terms of AA, 50 cal, even torpedos. Those aren't categorized as 'Battle Force Ships'.

Also, despite the huge waste that is inherent in it - no one has bases like the US does. We have forward operating bases all over the middle east, geographically separated units all over east europe, africa, asian pacific, and military bases all over europe and every key point of the united states. Nasa never quite got launches down but we do have some of the most advanced satellite, imagery and other military instruments. look up number of military spacecraft by country.

Whether it's moral or not is an entirely different question, but there is a reason the international monetary fund has a weight 44% USD; It's not because all the other countries like us that's for sure.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#184
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

>if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited.

The problem is that it matters less than we'd like to think how "serious they are about security".

I'm seeing a lot of discussion about the responsibility of the victims to secure their networks, and it's mostly valid.

But it's strange that we're talking about how to punish the victims versus the criminal conspirators. We virtually let the malicious, overtly criminal party off the hook. It's almost like we're saying we expect criminals to be criminals and these guys are so hard to catch that the onus is entirely on the targets to repel their incessant attacks, else they're negligently malicious themselves. Sure, most of these victims can do better in just about every case. But, people here know better than most how difficult it is to 100% secure every layer of the stack from software to firmware to hardware, with multiple vendors and vectors, OSS, zero days, etc. And the bad guys only have to be right once across this broad attack surface. It's impossible to defend completely. There will always be breaches.

So, there's another element of this that has to be addressed, and that's getting serious about punishing these people. As it is, there's zero disincentive for them to just keep trying until they get through, but the upside is massive.

Most if not all of this activity originates from nations that are adversarial towards the US. So, we need to start treating these instances as official sovereign actions, especially when they originate from nations wherein the government and their intelligence services exert control over (and outright sponsor) such criminal schemes, and wield these attacks as a projection of national power.

These regimes also tend to feature oppressive criminal justice systems and harsh reprisals for even political dissidents. So, the message is, "we're not going to argue whether you're sanctioning these acts, but we're also not buying that you can't stop them, so we'll treat each incident as an official act of the state. We're holding you responsible for your criminals when they attack us and we will respond accordingly".

Detailed discussion around exactly how the most recent exploit might be mitigated is interesting and useful. But the balance in these discussions between mitigation and reprisals for the perpetrators needs to be shifted much more towards the latter. Otherwise, we can expect these discussions ad infinitum.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#186
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

We should also shut down Russian infrastructure through cyberattacks. The Russian government supports DarkSide.

Totally, take out all the hospitals, education and basic needs for the rest of the innocent people. Or just nuke them, that will teach um.

On a serious note, sure retaliate, probably don't hurt innocent people.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#187

Earlier quoted context omitted.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

Couldn't the pipeline have it's own network connected to a monitoring station. At the station employees could access the pipeline network but never connect it to the network from which they could communicate with the people who would be dispatched to make repairs or adjustments?

Is this even safe enough, though? They had one of those in the Iranian uranium enrichment facilities, and it still didn't work out for them.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#188
post #96

Earlier quoted context omitted.

> We should shut down Russian infrastructure as retaliation. How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.

Yes, let’s meekly sit back and let other countries attack us, only playing defense. Russia caused this. If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves. You cannot expect to engage in acts of war without endangering your own citizens to at least some degree. To engage in war is to invite it to your homeland. Hell, if we don’t retali…

>If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves

A very naive statement. The Russian government doesn't work like that. They NEVER admit they were wrong. They don't care about civilians. They have culture of complete denial, even in the presence of indisputible facts. They will say US attacks on Russia is yet another proof of US' hostile, aggressive behavior towards Russia in a greater geopolitical game (especially when presented proofs of Russia's involvement are pretty weak, like "the hacker group never attacked Russian infrastructure" - I bet they never attacked North Korea either), giving Putin an excuse to crackdown on opposition and restrict/reduce Russians' freedom/human rights even more, further militarizing things and increasing attacks on US infra.

Actually strengthening security is the only proper solution, to make that kind of attacks futile and unprofitable. It's usually not some ingenious attacks but just simple negligence of the targets.

Source: I'm from Russia

Re: US passes emergency waiver over fuel pipeline cyber-attack

#189
post #2

I like how they "guarantee support in case of problems" after you pay them. God forbid they lose a customer. Are they going for repeat buys?

I saw a youtube video once of someone trying to communicate with ransomware attackers and their support was better than even some legit companies. It was funny as hell how they were so 'professional' about it

Re: US passes emergency waiver over fuel pipeline cyber-attack

#190
post #164

Earlier quoted context omitted.

Can an individual not accidentally or intentionally infect a computer not connected to the internet?

Air gaps didn’t save Iran. Air gaps are just one layer in the onion.

Is the argument that Iran was attacked on air-gapped network, so its not worth doing?
Post reply on HN