Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

271–280 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#271

Earlier quoted context omitted.

I was a child when 9/11 happened but I still remember the experts on TV assuring us that Iraq had those weapons of mass destruction.

I was an adult, and I remember the experts on TV (and print and other media) debunking the “experts” you refer to, often in near real time. And, unlike the latter, the former often had the receipts (fairly literally, in the case of the debunking of the “Winnebagos of Mass Destruction”.)

I was also an adult, and the fervor over WMD was unreal. And not just WMDs, but stupid shit like "Freedom Fries" and "These colors don't run". The spike in nationalism was awful to behold.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#272
This is depressing and not going to stop because it is so lucrative and relatively easy for these malware companies to find victims. It makes me wonder if cybersecurity should be considered a state responsibility and infrastructure so it will be uniform and available for every business like electricity or police protection.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#273

They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.

> We should shut down Russian infrastructure as retaliation Sanctions against key people are probably more effective while not causing too much anti-American sentiment in the general population or a rally around the flag effect. Hard to rile up the people because a dodgy oligarch can no longer keep his roubles in a London bank, where Babushka Svetlana freezing to death 'cuz the Yankees cut the gas is a martyrdom even…

Not to mention sanctions cost real human lives. The people who will be starving aren't the same folks who are mounting highly complex, large scale ransomware attacks.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#274

Earlier quoted context omitted.

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

[deleted]

Re: US passes emergency waiver over fuel pipeline cyber-attack

#275

The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.

Cat is out of the bag I think.

Even if you shut down the cashing out infrastructure (exchanges) in the affected countries, it will quickly spring up again in countries belligerent to them. The FATF is the main global body trying to curb this, but my hunch is they will lose this battle long-term.

Imagine if you are on the FATF red list [1] and you announce a free-for all domestic exchange for local spending. It's free FDI.

[1] http://www.fatf-gafi.org/countries/#high-risk

Re: US passes emergency waiver over fuel pipeline cyber-attack

#276

The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.

I assume you're thinking of blockchain tech? How do you think the genie will be put back in the bottle?

BTC has value because people exchange it for "real" money. If BTC is heavily regulated or outlawed, a whole lot of folks are going to duck out. It's one thing to try and get in on the ground floor of the latest meme stock, it's another thing to buy into a currency/practice that's illegal in your country.

Add onto that making it illegal to pay ransoms in BTC, then there's really no value in using it as a ransomeware currency. No one is buying it so all you are getting are some random digits on a piece of paper.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#277
post #26

Earlier quoted context omitted.

IT/Security/Software is all secondary for a pipeline operator, who's main business is to move liquids from A to B over a set of fixed pipes put in place decades ago. Without some forcing function to have cybersecurity threats taken seriously, industrials are unlikely to suddenly develop tier-1 security protocols.

Given that this is preventing them from moving liquids from A to B they should realize that protecting their system isn't a secondary concern.

Would be interested in seeing if this does result in a change in their processes, or if they will just accept the risk of this happening as a "risk of doing business".

Re: US passes emergency waiver over fuel pipeline cyber-attack

#278

The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.

I assume you're thinking of blockchain tech? How do you think the genie will be put back in the bottle?

The US and other government wills outlaw all cryptocurrencies but the ones that they control (“Govcoin,” as The Economist refers to them). Game over.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#279

>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?

Here's a suggestion.

1. Don't use Windows 2. Use ZFS 3. Practice your distaster recovery plan 4. Laugh in the face of ransomware

Perhaps organizations that providfe critical services shold consider hiring competent IT security advisors? I'm a programmer, not a specialist in security, but everyone knows you need backups, and you need to test that you can recover from your backups quickly.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#280

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Doesn't every cyberattack get attention from the U.S. government? After all, carrying out a cyberattack is a federal crime.

Yes, in the sense that it gets reported to law enforcement and investigative agencies. Without being specific, I was a victim of identity theft and cybercrime. My incident was “reported to the FBI” but I’ve literally never heard anything back from them.

In practical terms there needs to be something special about the cyberattack for the government to devote any resources towards it.

Post reply on HN