Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

281–290 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#282

Earlier quoted context omitted.

where did you get this understanding?

MSNBC had a person on who purported to be someone knowledgeable. I also read the Washington Post. The act of war part was my idea. I realize I may not have the correct understanding yet, but based on the Solar Winds hack and the Mueller report, it seems to me they are attacking us. Isn't an attack an act of war?

Ask anyone who babysits boxes in the US that are critical - they've been at war for a while. But... Its not like it affects daily life in any meaningful, permanent way.

Didnt we read about this pipeline on HN, for being so painfully insecure relative to its value? And painfully outdated? I expect if/when the release drops, we're gonna see some niche/strange software archaeology, and some windows-shit layered on top.

But mostly? I remember reading on HN about how much this 1950s-era pipeline leaks like nobody would believe.

Perhaps its time we overhaul the rotting infrastructure under our feet. Maybe even try to make these massively centralized pipelines irrelevant. Theyre a weakness.

Then again, Im not fond of the idea of Lithium-Wars replacing the Oil-Wars.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#283

I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level

> I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state.

I would expect that most companies, even companies whose core product is technology, are not capable of what you describe.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#285

Earlier quoted context omitted.

Er, the victim here is a private company, not the government.

When 45% of the East Coast's supply of diesel, gasoline and jet fuel is impacted, the government has a problem.

Yes, the problem is "How quickly can we nationalize this company."

Re: US passes emergency waiver over fuel pipeline cyber-attack

#286
post #191

Earlier quoted context omitted.

> Attach a fine to the discovery and disclosure and you disincentivise that prudence. Sue them. Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime. And quadruple the fine for misrepresenting the cause. People act like the government doesn't have the power of subpoena. They can absolutely compel you to tell the truth.

I've actually worked in govt systems. If you think the whole endless threats of jail make for more secure systems you are truly clueless. These systems are RIDDLED with the WORST outdated crap you can imagine. Absolute insane hoop jumping so plenty of pressure to work around security just to get jobs done (seriously - start with the help desk if you want access - they are so used to password resets the procedures bec…

I want to add that the physical limits of how the design is done is as much as corruption/stupidity.

By physical limits I mean us, the wet ware in the middle of all this. These systems can be designed years if not decades before they are actually brought online. By simple temporal placement they get the materials and techniques of that time span. By the time these things are ageing out of the system they will have some old tech on them.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#287

Earlier quoted context omitted.

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Iran would like a word!

Re: US passes emergency waiver over fuel pipeline cyber-attack

#288
post #261

Earlier quoted context omitted.

This basically describes the Iranian nuclear system that was hit by stuxnet, which, as I recall, was spread via USB drive. The airgap certainly reduces the chances of getting hit with a joe-random ransomware attack, though. Defense in depth...

Stuxnet was built by a very well funded organization and was not targeting monetary gains. Getting ransomware spreading via USB drive is insanely expensive and complicated. You won't make money on it, whatever they are extorting will not cover development expenses

"and was not targeting monetary gains"

But in the end was it really though?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#289

Earlier quoted context omitted.

I also wonder why nobody who has secure computing issues demands physical write-enable switches for ROM, rather than using software switches that are inevitably corrupted.

Generally it's been the opinion that the control systems need to be modifiable. For example if you add a single valve in a facility which has 4,000 valves already, it would be nice to just add add a controller for that valve to the current SCADA system. However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small mod…

Another thing that can be done is to divide the pipeline into several sections, not just one long one. So if one section gets compromised, it doesn't propagate to the next.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#290
post #96

Earlier quoted context omitted.

> We should shut down Russian infrastructure as retaliation. How about, instead of causing harm to innocent Russian people by such pointless escalation, the US makes a serious and meaningful effort to secure their critical national infrastructure. As they should have done in the first place.

Yes, let’s meekly sit back and let other countries attack us, only playing defense. Russia caused this. If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves. You cannot expect to engage in acts of war without endangering your own citizens to at least some degree. To engage in war is to invite it to your homeland. Hell, if we don’t retali…

Yes, lets escalate! Maybe we can cool our warming planet with a nuclear winter.

Or... We could try locking our doors on the internet.

We could try limiting our attack surface. I would suggest NOT centralizing a large portion of our economy atop a leaky, damage-prone pipeline from the actual 1950s.

Post reply on HN