Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

241–250 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#242

Earlier quoted context omitted.

Well, FB, Google, et al. have sucked up all the talent.

The NSA and CIA pay less than half of what a FAANG company pays for the same role. Sources: FAANG: Levels.fyi and personal experience NSA/CIA: https://work.chron.com/nsa-pay-scale-16399.html and https://www.opm.gov/policy-data-oversight/pay-leave/salaries...

For sure, and worse because there's no stock grants that subsequently go up several times in value after distribution. I get that it's a compensation problem as well as a supply problem: software engineering talent is hard to come by and world class software security talent is even harder to come by.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#243

Earlier quoted context omitted.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data…

This basically describes the Iranian nuclear system that was hit by stuxnet, which, as I recall, was spread via USB drive.

The airgap certainly reduces the chances of getting hit with a joe-random ransomware attack, though. Defense in depth...

Re: US passes emergency waiver over fuel pipeline cyber-attack

#244
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

it's always means it is (or it was); it's never possessive.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#245

It's my understanding that Dark Fail is a Russian criminal gang and that Russia does not extradite, stop, or punish these criminal gangs. To me that makes the Russian government culpable and this an act of war.

If you believe this is somehow unprecedented, or that the United States does not also exploit extralegal methods for proxy conflict/geopolitical subterfuge when convenient, you need to read more

Re: US passes emergency waiver over fuel pipeline cyber-attack

#246

Earlier quoted context omitted.

Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1]( https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...…

Air Craft carriers and jets were proven in WW2 to be the big differentiator. US took note and has more than the entire world combined. 'Battle force ships' is a very loose term and your source only includes navy resources. You forget we have Army, Air force, Marines and not to forget coast guard that all have their own watercraft. Also, don't know if you've been seeing some of the new SWISS ships the US have been dev…

Can’t find anything about the SWISS ships but curious to learn more, if you could provide a link.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#247
post #164

Earlier quoted context omitted.

Air gaps didn’t save Iran. Air gaps are just one layer in the onion.

Is the argument that Iran was attacked on air-gapped network, so its not worth doing?

Tradeoffs. Air gaps come with other costs of their own.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#248
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

Dan Kaminsky spent an enormous amount of time and effort on creating a secure hardware framework 10 years ago. It went nowhere for a lot of the same reasons you discuss in this comment.

The government and industry are all talk. Until we see actual enforcement / incentives for secure hardware, just assume everything (and I mean everything) can get shut down at any time. The only people who think this is an exaggeration are those who haven’t seen what things actually look like on the inside.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#250

Earlier quoted context omitted.

Are pipelines something we invented after the internet? Have we lost the knowledge we used to support infrastructure before the 90s?

Before the 90s? Hmm. Well, if you believe Thomas C. Reed's account, the US was using trojans to sabotage Soviet oil pipelines in 1982.

There's a big difference between the capabilities of a criminal organization (like the one involved here) and that of a nation state. Such attacks are also responded to differently, and it's not going to be send some Bitcoin to this address.
Post reply on HN