Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

201–210 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#201
post #77

Earlier quoted context omitted.

Flash drives. I used to work in fabs and every couple of years some tool or other would get a virus, sometimes it spread through the network.

USB ports are generally disabled in BIOS or purposefully physically damaged on most OT systems I've worked on for oil/gas/chemicals. Many places are fond of using epoxy to block the ports.

I like those people. The problem being sometimes you need logs or data off tools. I’m far from an IT wizard so I don’t know what other solutions exist but the flash drives to get stuff off tools was the easiest

Re: US passes emergency waiver over fuel pipeline cyber-attack

#202

Earlier quoted context omitted.

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data cables with it?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#203

Earlier quoted context omitted.

without significant aircraft carrier fleet i'm not sure china has dominant control of any seas, despite best efforts in south china seas [1]( https://en.wikipedia.org/wiki/Chinese_aircraft_carrier_progr... )

https://www.cnn.com/2021/03/05/china/china-world-biggest-nav... I am not sure what your point is. By number of ships, they are the biggest. I have no idea how important aircraft carrier fleet is.

> I have no idea how important aircraft carrier fleet is.

It’s the most important part of a modern blue water navy and has been since WW2. The US also has a world-dominating submarine fleet.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#205

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

> That gang ... Maybe it's another government, trying to sow chaos, disrupt markets, test US response capabilities, etc.

Could be, but ransomware gangs are a dime a dozen, and many are simply financialy motivated.

It's just a very profitable business model.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#206
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

Excellent info, thanks.

"OT" vs "IT":

"Operational Tech" (pipeline and safety-critical monitor and control)

and

"Information Tech" (payroll, email, other business stuff)

?

I could only imagine trying to tell a large corporation that their "IT" authentication system can't be linked to the access card keys for the front gate, or whatever other physical security they might have in place.

It doesn't matter if we can formally prove that a remote access system is sufficiently secure as to aloow engineers to operate valves and pumps from home... For inevitably, some months from now, a wildly insecure utility will be connected to that, and you lose the ability to reason about how to keep the streams from crossing.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#207

Earlier quoted context omitted.

We should also shut down Russian infrastructure through cyberattacks. The Russian government supports DarkSide.

Totally, take out all the hospitals, education and basic needs for the rest of the innocent people. Or just nuke them, that will teach um. On a serious note, sure retaliate, probably don't hurt innocent people.

or maybe the notion that russia is even behind it is a lie aimed at stoking tensions between the united states and russia, probably for the sake of profitting companies like digital shadows--or wharever it was called.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#209
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

Easiest opto-isolator is to epoxy the sfp into the socket, and then fill the rx port on the critical side with epoxy, and then just run one fiber. The epoxy may seem excessive, especially if the sfp dies and you have to swap a whole nic, but it makes people stop and think.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#210

Earlier quoted context omitted.

> Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. I'm not sure what technology industry you are in, but in the one I'm in software engineers are fooled by phishing attacks extremely consistently, people routinely expose critical systems and d…

Basic security practices like 2FA and not using VPNs/trusting the network would be a great start. There is no excuse for private business like Facebook and Google being more secure than the f*@& United States of America.

Well, to be fair, the government doesn't control the pipeline...
Post reply on HN