Earlier quoted context omitted.
> Attach a fine to the discovery and disclosure and you disincentivise that prudence. Sue them. Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime. And quadruple the fine for misrepresenting the cause. People act like the government doesn't have the power of subpoena. They can absolutely compel you to tell the truth.
> Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime When you do this, the documents never get created. Not due to nefarious cover-ups. But because if little incentivises the creation of documentation, and everything penalises it in the edge case, you get rubber stamped compliance stacks for decades until a crash. If one has massive downside for reporting a potential…
US passes emergency waiver over fuel pipeline cyber-attack
351–360 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#352I'm a fan of pipeline shutdowns personally
Re: US passes emergency waiver over fuel pipeline cyber-attack
#353It seems like the main new thing crypto has enabled as a currency so far is ransomware.
I wonder how they shuffle it around and eventually convert to fiat.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#354Earlier quoted context omitted.
"nation-state" is not just a fancy infosec word for country, and there's some debate as to whether the USA constitutes an actual nation state, rather than a state.
We regret to inform you that language is mutable.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#355That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.
Lol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra
Re: US passes emergency waiver over fuel pipeline cyber-attack
#356The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
BTC will increasingly become viewed as playing a significant role in these incidents. Legislation antithetical to crypto currencies should be expected with bi-partisan support. I would imagine fairly soon.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#357So, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.
This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep.
I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#358Earlier quoted context omitted.
> Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime When you do this, the documents never get created. Not due to nefarious cover-ups. But because if little incentivises the creation of documentation, and everything penalises it in the edge case, you get rubber stamped compliance stacks for decades until a crash. If one has massive downside for reporting a potential…
All internal communications, unless they are with an attorney and are clearly marked "privileged" and pertain to actual legal advice, are discoverable.
If a communication doesn't exist, it's not discoverable. If you legislate penalties for a certain type of communication, it shouldn't be surprising when it ceases to exist. This isn't the product of cover ups. It's the long-term effect of penalties dissuading the looking into of certain things. If discovering a breach is penalized, nobody competent will look for breaches--that leaves no discoverable liability.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#359Earlier quoted context omitted.
Illiquid asset pumping is the best way to launder the money in the crypto space. AccountA has bought or owns the illiquid asset using clean money, in advance. AccountB has the ransom proceeds in the more liquid digital asset. AccountB eventually buys the illiquid asset and pumps it. All the blockchain detectives are still following AccountB across many more addresses and blockchains, hoping and praying and imagining…
I don't get how Account B gets to the point of extracting value from the illiquid asset after purchasing? Seems like they either, 1) sell periodically or as the assets value appreciates, but this is generally unreliable and tough or 2) create a liquidity pool or yield farming opportunities For 1, this isn't necessarily reliable but it seems like the most plausible popular case. For 2, given the previously mentioned c…
My understanding is, accounts A and B are both controlled by the same person/group. Account A always deals with clean money and pretends to do speculative investing; account B uses dirty money to pump illiquid assets. An example scenario, as a simplified list of transactions:
| Time | From | To | Amount | Note |
|------+---------+--------+------------+-------------------------------------------|
| 0 | Pocket | A | 10 $GOOD | Initial investment. |
| 0 | - | B | - | Created account for criminal activity. |
|------+---------+--------+------------+-------------------------------------------|
| 10 | A | Market | 10 $GOOD | Exchanged liquid $GOOD for illiquid |
| 10 | Market | A | 1000 $BAD | $BAD at 1:100. |
|------+---------+--------+------------+-------------------------------------------|
| 100 | Victims | B | 3000 $GOOD | Crime - e.g. ransomware payments. |
|------+---------+--------+------------+-------------------------------------------|
| 150 | B | Market | 3000 $GOOD | Buying up $BAD to generate interest and |
| 150 | Market | B | 1500 $BAD | pump its value. |
|------+---------+--------+------------+-------------------------------------------|
| 200 | A | Market | 1000 $BAD | Buying back $GOOD for temporarily liquid |
| 200 | Market | A | 5000 $GOOD | $BAD at 5:1. |
|------+---------+--------+------------+-------------------------------------------|
| 500 | B | Market | 1500 $BAD | If $BAD didn't collapse, recovering some |
| 500 | Market | B | 100 $GOOD | of more stable asset at 1:15; can be used |
| | | | | to repeat the trick later. |
In this scenario, criminals turned $3000 of dirty $GOOD in account B into $5000 of clean $GOOD in account A. If they were good with OPSEC, there's no connection between accounts A and B - from outside, it looks like the owner of account A got lucky speculating on crypto, and owner of account B was a dumb criminal that made a bad investment. Hell, if criminals are sure of their OPSEC, they could even go as far as paying taxes for their gains on account A, reinforcing the image that A is owned by some random, legitimate investor (but that could bite them hard if law enforcement realizes there's a connection between accounts B and A). Account B is never cashed out - it's used only for purposes of pumping illiquid cryptocurrencies, and eventually abandoned.Re: US passes emergency waiver over fuel pipeline cyber-attack
#360Earlier quoted context omitted.
I’m curious — how would something like a data-diode work in real life? It makes sense, but what about something like TCP where the sending side needs the ability to receive ACK messages? Is a firewall (dedicated, if need be) enough? Or would this be some other kind of physical interface that took some kind of read-only data (serial?) and sent it up the layers using TCP/IP, where only this box would be at risk? Edit:…
I have heard some plane infotainment systems use a 1-way optical link to solve this problem to get the speed/altitude/etc to the displays. It just receives the data as a downlink (no 2-way communications) and being optical its electrically isolated as well as impossible to transmit or even interfere the other way.
Apart from this being technologically impossible, if he would have really done it he would have been charged for endangering an aircraft and prosecuted. (So the only explanation why he isn't in prison is that it didn't happen). The technical reason is Data diodes are common in aviation to separate IFE and CAN bus or position data. (e.g in the ARINC)
[1] https://www.pentestpartners.com/security-blog/a-pen-testers-...