Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

221–230 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#221
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Couldn't a service provider use an internet backbone with a one time pad comms protocol to essentially have a secure controls channel?

Then once a year a rep could fly out a few terabytes of OTP to each location and all comms would be impenetrable.

Sure beats a parallel physical comms system cost wise.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#222

Earlier quoted context omitted.

Basic security practices like 2FA and not using VPNs/trusting the network would be a great start. There is no excuse for private business like Facebook and Google being more secure than the f*@& United States of America.

Well, FB, Google, et al. have sucked up all the talent.

The NSA and CIA pay less than half of what a FAANG company pays for the same role.

Sources: FAANG: Levels.fyi and personal experience

NSA/CIA: https://work.chron.com/nsa-pay-scale-16399.html and https://www.opm.gov/policy-data-oversight/pay-leave/salaries...

Re: US passes emergency waiver over fuel pipeline cyber-attack

#223
post #96

Earlier quoted context omitted.

> We should shut down Russian infrastructure as retaliation. How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.

Yes, let’s meekly sit back and let other countries attack us, only playing defense. Russia caused this. If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves. You cannot expect to engage in acts of war without endangering your own citizens to at least some degree. To engage in war is to invite it to your homeland. Hell, if we don’t retali…

I was a child when 9/11 happened but I still remember the experts on TV assuring us that Iraq had those weapons of mass destruction.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#225
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

Security through obscurity is almost always a bad idea. There are exceptions: namely nuclear missiles.

There are counterarguments to this, but they're mostly academic: https://core.ac.uk/download/pdf/228618432.pdf.

Stuxnet, by contrast is very real

Re: US passes emergency waiver over fuel pipeline cyber-attack

#226

It's my understanding that Dark Fail is a Russian criminal gang and that Russia does not extradite, stop, or punish these criminal gangs. To me that makes the Russian government culpable and this an act of war.

>and this an act of war

What an absurd statement. And what do you suggest we do? Attack them and hope they don't respond with nukes?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#227
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Couldn't a service provider use an internet backbone with a one time pad comms protocol to essentially have a secure controls channel? Then once a year a rep could fly out a few terabytes of OTP to each location and all comms would be impenetrable. Sure beats a parallel physical comms system cost wise.

Maybe that'd make sense if it was the encryption that was broken. I wouldn't suggest a one-time pad for anything where modern encryption works just fine.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#228

Earlier quoted context omitted.

> though the US doesn't round them up & disappear them, they go through the court system Yeah, unless you are suspected for terrorism. I recommend the movie named The Mauritanian. > Mohamedou Ould Slahi (Arabic: محمدو ولد الصلاحي‎) (born December 21, 1970) is a Mauritanian man who was detained at Guantánamo Bay detention camp without charge from 2002 until his release on October 17, 2016. > The book, Guantánamo Diary…

In a country of 330 million people, with massively global interests, you're going to have to do a lot better than rare examples. In a country so large with so many different government agencies, entities, organizations, and interests, just about anything you can think of will have happened at some point. The question is whether it's going on at large scale, whether it's the common practice or rare. You're trying to u…

I have no idea whether it is happening or not at a large enough scale. I did not mean to prove anything, just wished to shed light on it.

How do we know it is not happening though? Think about pre-Snowden.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#229
post #201

Earlier quoted context omitted.

USB ports are generally disabled in BIOS or purposefully physically damaged on most OT systems I've worked on for oil/gas/chemicals. Many places are fond of using epoxy to block the ports.

I like those people. The problem being sometimes you need logs or data off tools. I’m far from an IT wizard so I don’t know what other solutions exist but the flash drives to get stuff off tools was the easiest

It makes some things more difficult. CD/DVD's are generally used instead. Sometimes other computers could be connected but in that case there would be some organizational procedure for attempting to make sure that other computer was as low risk as possible.

You can't eliminate the possibility of malicious action, Stuxnet proves that. It's my opinion that at least for critical infrastructure we can probably make things much more difficult for our adversaries at a relatively low cost. This pipeline is purported to carry half the gasoline/diesel/heating oil to the east coast, but I'd be lying if I said I knew exactly where the cost-benefit equilibrium should land.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#230
post #36
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

If we define critical system as "necessary to the operation of the business" then the corporate system is absolutely critical. It doesn't matter if the SCADA system is airgapped if you can shut down the capability by crashing the corporate systems.

Their approach makes a lot of sense. Corp network hacked - so to be careful shut down pipeline until you've really made sure that you are fully safe pipeline side as there now may be more attack vectors.
Post reply on HN