Earlier quoted context omitted.
I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.
Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?
US passes emergency waiver over fuel pipeline cyber-attack
291–300 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#292Earlier quoted context omitted.
Intelligence I'd say probably Russia right? They've made America look quite incompetent the past decade or so. Military I'd say America although I don't think SEAL team 6 is going to be hunting down these attackers
> They've made America look quite incompetent the past decade or so This itself is American propoganda; the strategy is to be absolutely all over your opponents, knowing that they can't complain about it for fear of looking weak, while complaining loudly about how their meagre attempts are the end of the world, getting public and Congressional support for more spending. Before the Snowden leaks, someone suggesting th…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#293Earlier quoted context omitted.
> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…
I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#294Earlier quoted context omitted.
Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?
You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data…
You're suggesting the gas company run their own network, and then you assume no employee will connect that network to the general internet for their own convenience? Not happening.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#295Earlier quoted context omitted.
Generally it's been the opinion that the control systems need to be modifiable. For example if you add a single valve in a facility which has 4,000 valves already, it would be nice to just add add a controller for that valve to the current SCADA system. However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small mod…
Another thing that can be done is to divide the pipeline into several sections, not just one long one. So if one section gets compromised, it doesn't propagate to the next.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#296Re: US passes emergency waiver over fuel pipeline cyber-attack
#297re: "infiltrated Colonial's network"
I have been reading some of the other reports of this incident from different publications.
Many of the stories include a line about attackers downloading "100 GB in only 2 hours" as if that was being downloaded from the company's on premises servers.
Eventually I found a story that disclosed the data was actually downloaded from a cloud provider.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#298Earlier quoted context omitted.
> and this an act of war What an absurd statement. And what do you suggest we do? Attack them and hope they don't respond with nukes?
Solarwinds hack, Mueller report, this... I don't know what the best response is. First we have to wake up that we are under attack.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#299It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#300Earlier quoted context omitted.
> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…
> Attach a fine to the discovery and disclosure and you disincentivise that prudence. Sue them. Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime. And quadruple the fine for misrepresenting the cause. People act like the government doesn't have the power of subpoena. They can absolutely compel you to tell the truth.