Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

361–370 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#361
Who decides how many hours we're allowed to work, driving trucks, fixing jet engines, taking care of children, or doing anything else?

Our and our employer's liability for errors is enough motivation to maintain safety at a reasonable level.

Put another way, is there statistical evidence of the efficacy of these regulations in reducing trucking accidents? Not that I could find!

Re: US passes emergency waiver over fuel pipeline cyber-attack

#362
Nothing to do with this article, but...

when did "legitimate interest" become the thing advertisers^Wtrackers are (ab)using to keep tracking on by default? It's not due to a change in legislation afaikt, the GDPR hasn't changed in this regard, right?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#363

The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.

This is why “it’s just like cash but better, and humanity has been using cash for centuries” is not a valid argument for adoption of cryptocurrencies. Cash has fundamental scale-limiting properties; cash without those properties is a qualitatively different beast for which there’s no precedent in humanity’s history. The above argument actively conceals the sheer scope of unknown unknowns.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#364

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

That almost sounded like a hollywood like prologue. Nothing interesting, nothing the average joe doesn't know, just your fantasies.

Good

Re: US passes emergency waiver over fuel pipeline cyber-attack

#365
post #357

So, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Could be that, or the heightened sensitivity to all issues cyber we’re experiencing right now

Re: US passes emergency waiver over fuel pipeline cyber-attack

#366

Earlier quoted context omitted.

> though the US doesn't round them up & disappear them, they go through the court system Yeah, unless you are suspected for terrorism. I recommend the movie named The Mauritanian. > Mohamedou Ould Slahi (Arabic: محمدو ولد الصلاحي‎) (born December 21, 1970) is a Mauritanian man who was detained at Guantánamo Bay detention camp without charge from 2002 until his release on October 17, 2016. > The book, Guantánamo Diary…

In a country of 330 million people, with massively global interests, you're going to have to do a lot better than rare examples. In a country so large with so many different government agencies, entities, organizations, and interests, just about anything you can think of will have happened at some point. The question is whether it's going on at large scale, whether it's the common practice or rare. You're trying to u…

> In a country of 330 million people, with massively global interests, you're going to have to do a lot better than rare examples.

USA doesn't have massive global interest. Maybe its companies, but not it's state. USA is a very insular, and static system of a state.

It's a good example what happens in those very few cases when the machine of US state moves, and what is characteristic of it.

A meaningful political reform will start with somebody starting to uncork it, and forcefully subjecting it to contact with outside world.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#367

This is depressing and not going to stop because it is so lucrative and relatively easy for these malware companies to find victims. It makes me wonder if cybersecurity should be considered a state responsibility and infrastructure so it will be uniform and available for every business like electricity or police protection.

If it is uniform then when a weakness is found, the whole economy can be exploited; rather than isolated companies.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#368

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

I'm not super-knowledgable about cybersecurity, but shouldn't simply using TOR make it nearly impossible for the US government to track them down? If they want to go overkill, they can additionally use a public VPN account purchased using walmart giftcards bought on ebay using a stolen identity and then mailed overseas. They can also perform the hack using a brand new computer that they never use again afterward. It…

As a rule, there is no off-the-shelf software solution that you can simply use to avoid being detected by the NSA or other powerful nation intelligence services. Even if there were, they are not limited to tracking you through technological means - they very much know how to find people the old-fashioned way as well.

That's not to say that it is impossible to hide from them, but it's never simple, when they're actively looking for you.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#369
post #357

So, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Armchair take: The pipelines handle a lot of fuel, and the US needs / uses a lot of fuel; to move the same amount, you need a lot of trucks. And if that need is not met, the economy etc will be disrupted heavily, price of fuel will go up, and the price of fuel going up has caused massive issues in the past.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#370

Earlier quoted context omitted.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

I’m curious — how would something like a data-diode work in real life? It makes sense, but what about something like TCP where the sending side needs the ability to receive ACK messages? Is a firewall (dedicated, if need be) enough? Or would this be some other kind of physical interface that took some kind of read-only data (serial?) and sent it up the layers using TCP/IP, where only this box would be at risk? Edit:…

> I’m curious — how would something like a data-diode work in real life?

Low, fixed-bitrate transfer over unidirectional fiber optics. Unidirectional transcievers are the norm for long-haul fiber.

My local electrical utility is still running 11.52kbps RS-232 over fiber for exactly this reason. At those bitrates you don't need backpressure -- your disk will never fill up and if the CPU can't handle that bitrate you already have much larger problems.

It's kind of funny that they have sheaths where one strand is running this piddly dozen-kilobit protocol and other strands in the same sheath are doing 10gbit/sec * 16-channel CWDM.

Most electrical utilities are into fiber optics in a very big way; they already (usually) own the poles and unlike copper it's nonconductive. Many of them have vastly more strands of fiber between substations than they need.

Post reply on HN