Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

211–220 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#211

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Doesn't every cyberattack get attention from the U.S. government? After all, carrying out a cyberattack is a federal crime.

How could it? There are thousands of cyberattacks against US companies and infrastructure every day.

There are cyberattacks and then there's going after the most important domestic energy line of a superpower.

This is quite different from your run of the mill cyberattack, they're not all created equal.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#212

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

> That gang ... Maybe it's another government, trying to sow chaos, disrupt markets, test US response capabilities, etc.

maybe it's the CIA, trying to increase hostilities between the united states and some other country.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#213

It's my understanding that Dark Fail is a Russian criminal gang and that Russia does not extradite, stop, or punish these criminal gangs. To me that makes the Russian government culpable and this an act of war.

where did you get this understanding?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#214

Earlier quoted context omitted.

I have heard some plane infotainment systems use a 1-way optical link to solve this problem to get the speed/altitude/etc to the displays. It just receives the data as a downlink (no 2-way communications) and being optical its electrically isolated as well as impossible to transmit or even interfere the other way.

If you don’t allow 2-way comms to SCADA devices, how can you set values on those devices. For example, open valve 9881 to 10% … how would that be done? SCADA devices are not read-only.

You don't let remote systems open valve 9881.

That would be like deploying the landing gear of the airliner, because someone triggered a bug while changing the channel on the in-flight entertainment system.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#215

Earlier quoted context omitted.

I have heard some plane infotainment systems use a 1-way optical link to solve this problem to get the speed/altitude/etc to the displays. It just receives the data as a downlink (no 2-way communications) and being optical its electrically isolated as well as impossible to transmit or even interfere the other way.

If you don’t allow 2-way comms to SCADA devices, how can you set values on those devices. For example, open valve 9881 to 10% … how would that be done? SCADA devices are not read-only.

I think the original use-case was delivering data for use in dashboards or other business systems, not the SCADA network in general (where you’d want write access). So, places where you might want to get read-only data from a secured system, but not allow write access. These business/reporting systems might be internet connected, hence the desire for better isolation.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#216

Earlier quoted context omitted.

Are pipelines something we invented after the internet? Have we lost the knowledge we used to support infrastructure before the 90s?

Before the 90s? Hmm. Well, if you believe Thomas C. Reed's account, the US was using trojans to sabotage Soviet oil pipelines in 1982.

Is that the one when the CIA got wind of a Soviet industrial espionage operation, and seeded it with a legit-looking but subtly flawed schematic, which the Soviets ended up actually building to spec, and it exploded shortly after?

That wasn't an internet trojan, fyi.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#217

Earlier quoted context omitted.

This isn't a counter-argument against the person you're replying to, though. One can pick from numerous examples of the inverse(though the US doesn't round them up & disappear them, they go through the court system)

> though the US doesn't round them up & disappear them, they go through the court system Yeah, unless you are suspected for terrorism. I recommend the movie named The Mauritanian. > Mohamedou Ould Slahi (Arabic: محمدو ولد الصلاحي‎) (born December 21, 1970) is a Mauritanian man who was detained at Guantánamo Bay detention camp without charge from 2002 until his release on October 17, 2016. > The book, Guantánamo Diary…

In a country of 330 million people, with massively global interests, you're going to have to do a lot better than rare examples.

In a country so large with so many different government agencies, entities, organizations, and interests, just about anything you can think of will have happened at some point. The question is whether it's going on at large scale, whether it's the common practice or rare.

You're trying to use one example to prove that the practice is common, when in fact that's false, it's not common it's rare. It's the exception, not the rule; which is exactly why it makes for an attention getting story.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#218

Earlier quoted context omitted.

Before the 90s? Hmm. Well, if you believe Thomas C. Reed's account, the US was using trojans to sabotage Soviet oil pipelines in 1982.

Is that the one when the CIA got wind of a Soviet industrial espionage operation, and seeded it with a legit-looking but subtly flawed schematic, which the Soviets ended up actually building to spec, and it exploded shortly after? That wasn't an internet trojan, fyi.

According to the story, this was some Canadian pipeline control equipment or software which the USSR purchased from some Canadians, but the CIA modified the software somehow before it was delivered. A supply-chain attack on a computer system.

I understand there's nonzero doubt as to the credibility of this story.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#219

Earlier quoted context omitted.

Couldn't the pipeline have it's own network connected to a monitoring station. At the station employees could access the pipeline network but never connect it to the network from which they could communicate with the people who would be dispatched to make repairs or adjustments?

Is this even safe enough, though? They had one of those in the Iranian uranium enrichment facilities, and it still didn't work out for them.

I remember they got past the Iranian air gap using a USB stick. It’s a mistake to think air gaps are safe but they are certainly better than having your network open to the internet.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#220

Earlier quoted context omitted.

I have heard some plane infotainment systems use a 1-way optical link to solve this problem to get the speed/altitude/etc to the displays. It just receives the data as a downlink (no 2-way communications) and being optical its electrically isolated as well as impossible to transmit or even interfere the other way.

If you don’t allow 2-way comms to SCADA devices, how can you set values on those devices. For example, open valve 9881 to 10% … how would that be done? SCADA devices are not read-only.

That functionality would be local, before the one-way isolator. A human at a terminal located near the valve could still press a button to make that happen. That system could even be running windows (most are!).

But a hacker wouldn't be able to use their access to the Timeseries database for supply chain and logistics, to pivot to the SCADA system because their attempts would be blocked by a lack of a physical layer connection in that direction.

It would significantly reduce the attack surface of the OT systems.

Post reply on HN