Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

191–200 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#191
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

> Attach a fine to the discovery and disclosure and you disincentivise that prudence.

Sue them. Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime. And quadruple the fine for misrepresenting the cause.

People act like the government doesn't have the power of subpoena. They can absolutely compel you to tell the truth.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#192

Earlier quoted context omitted.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

Couldn't the pipeline have it's own network connected to a monitoring station. At the station employees could access the pipeline network but never connect it to the network from which they could communicate with the people who would be dispatched to make repairs or adjustments?

Sounds looks a solved problem, but it isn’t. The electrical grid isolates SCADA networks from the internet, so substations are interconnected via dedicated networks. But then at the command centers you have the entire monitoring and control systems with on site operators. Then, inevitably you will have some employees with vpn access, and now you have 2 vectors: remote admins getting hacked and local admins plugging in external devices. You’d think it’s easy to get rid of vpns, but things like the pandemic brought them all back to full force.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#193

Earlier quoted context omitted.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

I’m curious — how would something like a data-diode work in real life? It makes sense, but what about something like TCP where the sending side needs the ability to receive ACK messages? Is a firewall (dedicated, if need be) enough? Or would this be some other kind of physical interface that took some kind of read-only data (serial?) and sent it up the layers using TCP/IP, where only this box would be at risk? Edit:…

That can work. Or you can have A use TCP to B, C use TCP to D, and B and C are connected by a very short one-way cable, maybe something optical.

The US government term of art for this pattern is a “guard”, often with a regex or manual filter.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#194

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Doesn't every cyberattack get attention from the U.S. government? After all, carrying out a cyberattack is a federal crime.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#195

Earlier quoted context omitted.

I’m curious — how would something like a data-diode work in real life? It makes sense, but what about something like TCP where the sending side needs the ability to receive ACK messages? Is a firewall (dedicated, if need be) enough? Or would this be some other kind of physical interface that took some kind of read-only data (serial?) and sent it up the layers using TCP/IP, where only this box would be at risk? Edit:…

I have heard some plane infotainment systems use a 1-way optical link to solve this problem to get the speed/altitude/etc to the displays. It just receives the data as a downlink (no 2-way communications) and being optical its electrically isolated as well as impossible to transmit or even interfere the other way.

If you don’t allow 2-way comms to SCADA devices, how can you set values on those devices. For example, open valve 9881 to 10% … how would that be done?

SCADA devices are not read-only.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#196
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> companies are chasing profits at any cost Government systems get hacked all the time, too. Just because the government doesn't have a profit motive doesn't change a long list of human motivations that can be counterproductive. The profit motive also incentivizes improved quality. If the product is bungled, the company is not likely to get the next contract. If the government agency bungles the product, they'll get…

"If the product is bungled, the company is not likely to get the next contract."

Re: US passes emergency waiver over fuel pipeline cyber-attack

#199
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Critical services are on the Internet because they are provided by the lowest bidder.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#200
post #66

Earlier quoted context omitted.

Agreed. Our companies are driven to increase profit at all cost. Even cost to their function and utility. Our over financialization is squeezing everyone and everything.

To clarify: this is not from "financialization" generally speaking. This is specifically from consolidation for the sake of increasing efficiency and thus margins (as you pointed out). This is opposed to increased competition (which also increases volatility) in the markets. The reason why the markets are so consolidated is because it removes short-term risk. If there is an obvious market and only one (or a few) comp…

> To clarify: this is not from "financialization" generally speaking. This is specifically from consolidation for the sake of increasing efficiency and thus margins (as you pointed out).

??? Can you give an example of governments that continue to give back to their "shareholders" once they decide they have enough military capacity?

Post reply on HN