Earlier quoted context omitted.
Flash drives. I used to work in fabs and every couple of years some tool or other would get a virus, sometimes it spread through the network.
USB ports are generally disabled in BIOS or purposefully physically damaged on most OT systems I've worked on for oil/gas/chemicals. Many places are fond of using epoxy to block the ports.
US passes emergency waiver over fuel pipeline cyber-attack
201–210 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#202Earlier quoted context omitted.
I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.
Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?
Re: US passes emergency waiver over fuel pipeline cyber-attack
#203Earlier quoted context omitted.
without significant aircraft carrier fleet i'm not sure china has dominant control of any seas, despite best efforts in south china seas [1]( https://en.wikipedia.org/wiki/Chinese_aircraft_carrier_progr... )
https://www.cnn.com/2021/03/05/china/china-world-biggest-nav... I am not sure what your point is. By number of ships, they are the biggest. I have no idea how important aircraft carrier fleet is.
It’s the most important part of a modern blue water navy and has been since WW2. The US also has a world-dominating submarine fleet.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#204Re: US passes emergency waiver over fuel pipeline cyber-attack
#205That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.
> That gang ... Maybe it's another government, trying to sow chaos, disrupt markets, test US response capabilities, etc.
It's just a very profitable business model.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#206Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.
I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…
"OT" vs "IT":
"Operational Tech" (pipeline and safety-critical monitor and control)
and
"Information Tech" (payroll, email, other business stuff)
?
I could only imagine trying to tell a large corporation that their "IT" authentication system can't be linked to the access card keys for the front gate, or whatever other physical security they might have in place.
It doesn't matter if we can formally prove that a remote access system is sufficiently secure as to aloow engineers to operate valves and pumps from home... For inevitably, some months from now, a wildly insecure utility will be connected to that, and you lose the ability to reason about how to keep the streams from crossing.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#207Earlier quoted context omitted.
We should also shut down Russian infrastructure through cyberattacks. The Russian government supports DarkSide.
Totally, take out all the hospitals, education and basic needs for the rest of the innocent people. Or just nuke them, that will teach um. On a serious note, sure retaliate, probably don't hurt innocent people.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#208Re: US passes emergency waiver over fuel pipeline cyber-attack
#209Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.
I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#210Earlier quoted context omitted.
> Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. I'm not sure what technology industry you are in, but in the one I'm in software engineers are fooled by phishing attacks extremely consistently, people routinely expose critical systems and d…
Basic security practices like 2FA and not using VPNs/trusting the network would be a great start. There is no excuse for private business like Facebook and Google being more secure than the f*@& United States of America.