Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

341–350 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#341
post #333

Ransom ware seems like a potential antidote to vulnerable US digital infrastructure. It provides a persistent, material bug bounty which incentivises the C-suite to fix them.

> which incentivises the C-suite to fix them.

It doesn’t. It provide C-Exec material to increase significantly Cyber Defense budget not overhaul Information System.

For those executives these are two different topics with different budget.

Of course for regular engineers it’s not, legacy infrastructure is probably much simpler to hack than modern one.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#342
post #325

Earlier quoted context omitted.

I'm not super-knowledgable about cybersecurity, but shouldn't simply using TOR make it nearly impossible for the US government to track them down? If they want to go overkill, they can additionally use a public VPN account purchased using walmart giftcards bought on ebay using a stolen identity and then mailed overseas. They can also perform the hack using a brand new computer that they never use again afterward. It…

> I'm not super-knowledgable about cybersecurity, but shouldn't simply using TOR make it nearly impossible for the US government to track them down? PSA: There are known traffic correlation attacks against Tor. It's not magic security dust you can sprinkle on a system. If you're doing thoughtcrimes, assume any G10 intelligence service can track you down. (If you're into extortion, human trafficking/exploiting childre…

Yes, you can pick tunnel length in I2P.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#343

Earlier quoted context omitted.

Thank you for the elaboration. Your humble willingness to do so is much appreciated.

You're welcome! One of the highest growth areas and highly demanded is in building bridges for assets to move between blockchains. Particularly Liquidity Pool shares and other asset backed derivatives. If you would like to apply yourself here. The market-based rewards are direct, swift, and very high. More than what FAANG pays their E5's and L5's.

I was reading about DOT and decided to start learning rust. I've used python in a couple automation tasks before, but besides that have very little programming ability. Rust has been hard so far but very rewarding. What technologies would you suggest learning if i wanted to get into blockchain programming?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#344

Earlier quoted context omitted.

Illiquid asset pumping is the best way to launder the money in the crypto space. AccountA has bought or owns the illiquid asset using clean money, in advance. AccountB has the ransom proceeds in the more liquid digital asset. AccountB eventually buys the illiquid asset and pumps it. All the blockchain detectives are still following AccountB across many more addresses and blockchains, hoping and praying and imagining…

I don't get how Account B gets to the point of extracting value from the illiquid asset after purchasing? Seems like they either, 1) sell periodically or as the assets value appreciates, but this is generally unreliable and tough or 2) create a liquidity pool or yield farming opportunities For 1, this isn't necessarily reliable but it seems like the most plausible popular case. For 2, given the previously mentioned c…

AccountB doesn't have to make more money as it directly or indirectly transferred all the liquid assets to AccountA (and many other people). In a liquidity pool kind of exchange, AccountB would have simply put all its liquid assets into the liquidity pool, in exchange for removing the illiquid asset into AccountB's custody. The liquidity pool maintains prices based on a ratio of two assets in the pool, so the illiquid asset would have quite how price after this activity. AccountA would have just sold its holdings of the illiquid asset back into the liquidity pool at a coincidentally favorable time. AccountA can also have been a liquidity provider, and when they unbundle their liquidity pool share it will have more of the liquid asset and less of the illiquid asset. Many possibilities, permissionless.

If it must be said, AccountA is yours too and is just for reintegrating the illicit proceeds into the economy without trying to do something more convoluted like running a permissionless SaaS business with fake customers spending Monero for domain name lookups.

But, AccountB can attempt to make its assets more liquid again. You just go on Telegram and pump it in speculator groups, buy off some youtubers. How much are you laundering? You can keep a few thousand dollars in liquidity for negotiations. AccountB should also provide liquidity itself. Just launch a yield farm contract, copy and paste, change the input and output token address, redeploy, lock a substantial portion of the illiquid token inside of it (or pay off a more coveted yield farming project like Pancake or Polygon to list a farm and pay farmers in their token). Make the yield high.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#345

Earlier quoted context omitted.

Thank you for the elaboration. Your humble willingness to do so is much appreciated.

You're welcome! One of the highest growth areas and highly demanded is in building bridges for assets to move between blockchains. Particularly Liquidity Pool shares and other asset backed derivatives. If you would like to apply yourself here. The market-based rewards are direct, swift, and very high. More than what FAANG pays their E5's and L5's.

That seems interesting, and rewarding. Any pointers on how one can get into this area. Thanks

Re: US passes emergency waiver over fuel pipeline cyber-attack

#346

"Multiple sources have confirmed that the ransomware attack was caused by a cyber-criminal gang called DarkSide, who infiltrated Colonial's network on Thursday and took almost 100GB of data hostage." re: "infiltrated Colonial's network" I have been reading some of the other reports of this incident from different publications. Many of the stories include a line about attackers downloading "100 GB in only 2 hours" as…

It's a lot easier to pull the plug on on-premise systems.

It’s really not. SME branch office is dead easy. Multinational corporations virtually impossible.

In the cloud you can stop your whole VM estate, nuke roles and access and pull an audit trail and access logs for everything in a few minutes. Without even getting off your butt. Or having to negotiate with a branch office IT team who disagree with you.

In the 20 or so years I’ve been running ops for corporates, the cloud is the nearest we’ve come to half decent DR and emergency response capability. It has got to the point now where compliance and audit is built in and I can actually write some code here and there rather than arguing about trivial stuff like “what happens if X happens” with people who are only in it for the pension.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#347

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Doesn't every cyberattack get attention from the U.S. government? After all, carrying out a cyberattack is a federal crime.

Not this kind of attention. Oil pipelines are considered critical energy infrastructure. This will likely be viewed as a national security threat.

The US government will have to respond to deter others. They have "poked the bear".

Re: US passes emergency waiver over fuel pipeline cyber-attack

#348

Earlier quoted context omitted.

"nation-state" is not just a fancy infosec word for country, and there's some debate as to whether the USA constitutes an actual nation state, rather than a state.

The USA is absolutely a nation state. Cocal-cola, mcdonalds, Christmas, enlgish, etc. are well dispersed throughout the entire population. We have a uniform culture, although not as uniform as much smaller countries, but uniform nonetheless.

> Cocal-cola, mcdonalds, Christmas, english

These are well dispersed throughout the world...

Re: US passes emergency waiver over fuel pipeline cyber-attack

#349
post #191

Earlier quoted context omitted.

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

> Attach a fine to the discovery and disclosure and you disincentivise that prudence. Sue them. Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime. And quadruple the fine for misrepresenting the cause. People act like the government doesn't have the power of subpoena. They can absolutely compel you to tell the truth.

> Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime

When you do this, the documents never get created. Not due to nefarious cover-ups. But because if little incentivises the creation of documentation, and everything penalises it in the edge case, you get rubber stamped compliance stacks for decades until a crash.

If one has massive downside for reporting a potential risk, one better be 100% sure that risk is manifest before pulling the trigger. That delay and omission is the cost of such draconianism.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#350

Earlier quoted context omitted.

You're welcome! One of the highest growth areas and highly demanded is in building bridges for assets to move between blockchains. Particularly Liquidity Pool shares and other asset backed derivatives. If you would like to apply yourself here. The market-based rewards are direct, swift, and very high. More than what FAANG pays their E5's and L5's.

I was reading about DOT and decided to start learning rust. I've used python in a couple automation tasks before, but besides that have very little programming ability. Rust has been hard so far but very rewarding. What technologies would you suggest learning if i wanted to get into blockchain programming?

Solidity or the Javascript frameworks that compile down to solidity. EVMs are heavy in this.

Rust is good too. I'm not too familiar with the Polkadot ecosystem, but the main thing you need to know is that every financial app that has been popular on EVMs needs to be rebuilt on those other ecosystems. There can be multiple of the same things too, no different than multiple grocery stores in a town, or multiple actual bridges. Nothing unique needs to occur, just more. Its literally a global boom town you don't need to go anywhere for and your competition would rather argue about how a MySQL database is better for yield farming than a blockchain.

Post reply on HN