Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

261–270 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#261

Earlier quoted context omitted.

You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data…

This basically describes the Iranian nuclear system that was hit by stuxnet, which, as I recall, was spread via USB drive. The airgap certainly reduces the chances of getting hit with a joe-random ransomware attack, though. Defense in depth...

Stuxnet was built by a very well funded organization and was not targeting monetary gains. Getting ransomware spreading via USB drive is insanely expensive and complicated. You won't make money on it, whatever they are extorting will not cover development expenses

Re: US passes emergency waiver over fuel pipeline cyber-attack

#262

Earlier quoted context omitted.

You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data…

This basically describes the Iranian nuclear system that was hit by stuxnet, which, as I recall, was spread via USB drive. The airgap certainly reduces the chances of getting hit with a joe-random ransomware attack, though. Defense in depth...

Let's not let perfect be enemy of good, especially since we can't never be perfect.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#263
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Also, why do critical services run Microsoft systems?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#264

Earlier quoted context omitted.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data…

This is what the financial industry does. There's a secured "extranet" that everyone runs FIX on top of. For the most part, it works.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#265
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> It needs to be asked again, why are critical services on the Internet? From TFA: Digital Shadows thinks the Colonial Pipeline cyber-attack has come about due to the coronavirus pandemic - the rise of engineers remotely accessing control systems for the pipeline from home... believe DarkSide bought account login details relating to remote desktop software like TeamViewer and Microsoft Remote Desktop.

So fast food workers were “essential workers” but oil pipeline control system engineers aren’t?

Projects that require a security clearance have to be done from inside of a secure facility. This clearly needs to be the same level.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#266

Earlier quoted context omitted.

Doesn't every cyberattack get attention from the U.S. government? After all, carrying out a cyberattack is a federal crime.

How could it? There are thousands of cyberattacks against US companies and infrastructure every day. There are cyberattacks and then there's going after the most important domestic energy line of a superpower. This is quite different from your run of the mill cyberattack, they're not all created equal.

This is exactly right.

It all depends on the attention these attacks get. Now that they've had a tangible effect on the news cycle, creating concern about the safety of US energy infrastructure, there will be more incentives for the Government to hunt them down and get credit for doing so.

I think I read somewhere that China based attackers have already penetrated networks of major US infrastructure systems but didn't do anything because whats the point of wrecking havoc now? Better wait for more opportune times.

Which also seems to indicate that this may not be a Nation State... they would be after a bigger prize than some bitcoins.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#267
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Critical services are on the Internet because they are provided by the lowest bidder.

They are not always the lowest bidder. Colonial Pipeline was known for selecting the higher bids sometimes in order to ensure quality of work. They'd generally evaluate risk vs. quality vs. price.

Colonial also kept multiple overlapping vendors for their last SCADA upgrade in order to make sure that no contractor was too overloaded during a "boom time". They'd generally stagger the work between locations (they had to upgrade dozens of stations along the pipeline) and keep track of the performance of everyone they hired and try to keep a steady workflow for everyone over a multi-year period.

It was generally not about the lowest bid.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#268
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

[deleted]

Re: US passes emergency waiver over fuel pipeline cyber-attack

#270
post #226

Earlier quoted context omitted.

> and this an act of war What an absurd statement. And what do you suggest we do? Attack them and hope they don't respond with nukes?

Solarwinds hack, Mueller report, this... I don't know what the best response is. First we have to wake up that we are under attack.

Take a deep breath, you are jumping at shadows and telling everyone that "they" are out to get us.

Thieves are thieves, organized crime is organized crime. You think there aren't major criminal organizations in the US committing ransoms in other countries?

Post reply on HN