Earlier quoted context omitted.
where did you get this understanding?
MSNBC had a person on who purported to be someone knowledgeable. I also read the Washington Post. The act of war part was my idea. I realize I may not have the correct understanding yet, but based on the Solar Winds hack and the Mueller report, it seems to me they are attacking us. Isn't an attack an act of war?
US passes emergency waiver over fuel pipeline cyber-attack
251–260 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#252Re: US passes emergency waiver over fuel pipeline cyber-attack
#253Keep your eyes on the oil major folks on twitter to see what happens:
Re: US passes emergency waiver over fuel pipeline cyber-attack
#254It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#255Earlier quoted context omitted.
You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data…
This basically describes the Iranian nuclear system that was hit by stuxnet, which, as I recall, was spread via USB drive. The airgap certainly reduces the chances of getting hit with a joe-random ransomware attack, though. Defense in depth...
Re: US passes emergency waiver over fuel pipeline cyber-attack
#256The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#257The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#258So, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.
Once they get in to the internal network, they could possibly have access to anything. Most organizations don't follow good practices for internal services and there's all kinds of unauthenticated crap that's accessible to anyone who knows where to look.
If its really a ransomware attack, they could have taken over some internal system, or maybe just locked out remote access. We will need to know more, but at first glance it doesn't look very good.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#259So, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.
It's interesting to consider the human link between the admin systems and industrial control systems here. If we assume the controls are on an airgapped network, the attackers, in some sense, jumped the airgap and shutdown the pipeline. Obviously not as bad as an actual compromise of the control systems though, which presumably could cause leaks, explosions, etc.
Production data (like gallons per minute of flow through the pipeline) must be sent from the controls to the business analytics software. That's generally done through a firewall over TCP/IP.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#260>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?
Most people will probably be hesitant to post it for obvious reasons here. But it was helpful to me, to find a ransomware url, during the college leak a few weeks ago ( https://dorper.me/articles/unileak.aspx ) to find out which colleges were impacted because tons of people I know were in it. There are plenty of good reasons to want to have it. But I understand why BBC wouldn't post it...
Best to use a personal device.