Seems like this company has more than just IT problems https://newrepublic.com/article/161498/huntersville-north-ca...
US passes emergency waiver over fuel pipeline cyber-attack
281–290 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#282Earlier quoted context omitted.
where did you get this understanding?
MSNBC had a person on who purported to be someone knowledgeable. I also read the Washington Post. The act of war part was my idea. I realize I may not have the correct understanding yet, but based on the Solar Winds hack and the Mueller report, it seems to me they are attacking us. Isn't an attack an act of war?
Didnt we read about this pipeline on HN, for being so painfully insecure relative to its value? And painfully outdated? I expect if/when the release drops, we're gonna see some niche/strange software archaeology, and some windows-shit layered on top.
But mostly? I remember reading on HN about how much this 1950s-era pipeline leaks like nobody would believe.
Perhaps its time we overhaul the rotting infrastructure under our feet. Maybe even try to make these massively centralized pipelines irrelevant. Theyre a weakness.
Then again, Im not fond of the idea of Lithium-Wars replacing the Oil-Wars.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#283I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level
I would expect that most companies, even companies whose core product is technology, are not capable of what you describe.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#284Remember evil exists.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#285Re: US passes emergency waiver over fuel pipeline cyber-attack
#286Earlier quoted context omitted.
> Attach a fine to the discovery and disclosure and you disincentivise that prudence. Sue them. Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime. And quadruple the fine for misrepresenting the cause. People act like the government doesn't have the power of subpoena. They can absolutely compel you to tell the truth.
I've actually worked in govt systems. If you think the whole endless threats of jail make for more secure systems you are truly clueless. These systems are RIDDLED with the WORST outdated crap you can imagine. Absolute insane hoop jumping so plenty of pressure to work around security just to get jobs done (seriously - start with the help desk if you want access - they are so used to password resets the procedures bec…
By physical limits I mean us, the wet ware in the middle of all this. These systems can be designed years if not decades before they are actually brought online. By simple temporal placement they get the materials and techniques of that time span. By the time these things are ageing out of the system they will have some old tech on them.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#287Earlier quoted context omitted.
> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…
I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#288Earlier quoted context omitted.
This basically describes the Iranian nuclear system that was hit by stuxnet, which, as I recall, was spread via USB drive. The airgap certainly reduces the chances of getting hit with a joe-random ransomware attack, though. Defense in depth...
Stuxnet was built by a very well funded organization and was not targeting monetary gains. Getting ransomware spreading via USB drive is insanely expensive and complicated. You won't make money on it, whatever they are extorting will not cover development expenses
But in the end was it really though?
Re: US passes emergency waiver over fuel pipeline cyber-attack
#289Earlier quoted context omitted.
I also wonder why nobody who has secure computing issues demands physical write-enable switches for ROM, rather than using software switches that are inevitably corrupted.
Generally it's been the opinion that the control systems need to be modifiable. For example if you add a single valve in a facility which has 4,000 valves already, it would be nice to just add add a controller for that valve to the current SCADA system. However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small mod…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#290Earlier quoted context omitted.
> We should shut down Russian infrastructure as retaliation. How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.
Yes, let’s meekly sit back and let other countries attack us, only playing defense. Russia caused this. If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves. You cannot expect to engage in acts of war without endangering your own citizens to at least some degree. To engage in war is to invite it to your homeland. Hell, if we don’t retali…
Or... We could try locking our doors on the internet.
We could try limiting our attack surface. I would suggest NOT centralizing a large portion of our economy atop a leaky, damage-prone pipeline from the actual 1950s.