Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

381–390 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#381

Earlier quoted context omitted.

> companies are chasing profits at any cost What does that mean? This was addressed in the article. Critical services are on the internet because remote workers need access to them. I don't see how profits factor into it.

Those remote workers wouldn’t have to be ‘remote’ if there were other workers hired on site.

What "on site"? The various valves that need to be controlled remotely often are just a box, perhaps even underground, in a place where's no buildings for people to stay - a mechanical team can access the hardware on-site, but building and maintaining an actual office on each site is not practical. The same applies for power grids - you can't staff every substation with people.

A remote operator can manage dozens of such sites, a single "local" person might be close to one point, but the next control point is going to be miles away, so you either need much, much more people to station one at every valve, or have a situation where flipping a switch in all the "sites" is very slow because requires the "local" person to drive many miles visiting each location.

No, there's a reasonable objective need for this management to be actually remote - there's a discussion on how this should be implemented in a secure way, but it does have to be remote.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#382
post #380
post #357

Earlier quoted context omitted.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Don't trucks transport fuel like this all the time? Or maybe it's the quantity.

They do, but to me GP's issue is with relaxing the requirements for rest.

IE, the issue isn't that drivers transport fuel, but that possibly tired drivers do so.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#383

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

I'm not super-knowledgable about cybersecurity, but shouldn't simply using TOR make it nearly impossible for the US government to track them down? If they want to go overkill, they can additionally use a public VPN account purchased using walmart giftcards bought on ebay using a stolen identity and then mailed overseas. They can also perform the hack using a brand new computer that they never use again afterward. It…

Getting operational security right is surprisingly hard.

The really hard part is that you need to have gotten it right some years ago already.

I remember that I read that other day that a bitcoin tumbler operator was charged for money laundering. The way they got to him was tracking initial funds that started the tumbler, which was purchased from an exchanged and not obfuscated.

There are all kinds of things you can get wrong: your build tools could accidentally store compromising meta data in your malware; payments from previous campaigns could be tracked, a single non-TOR access to the command&control infrastructure could get you busted, as could a single login to an email provider you used to communicate with somebody related to the ransomware operation.

All in all, if you have a larger team, the chances of at least one person messing up aren't too small, and then it's a matter of the investigators pouring enough money and attention into the case to find it.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#384

>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?

Well the reason for that is that the website has dumps that you can easily download.

Here is a text dump of their press page https://pastebin.com/fxJCaUDq

Re: US passes emergency waiver over fuel pipeline cyber-attack

#385

I looked at their available posted jobs on Friday as news broke about the attack. Colonial has had a position for Cybersecurity Manager open for over 30+ days. I wonder what happened to the old manager....

…first to be questioned by the Feds no matter what terms they left under. Too important an attack for that institutional knowledge to stay out of the fray.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#386
post #333

Ransom ware seems like a potential antidote to vulnerable US digital infrastructure. It provides a persistent, material bug bounty which incentivises the C-suite to fix them.

Yes! The ultimate bug bounty program! Instead of ranking on some hackerone or bugcrowd leader board you rank on the FBIs most wanted list!

Re: US passes emergency waiver over fuel pipeline cyber-attack

#387

Earlier quoted context omitted.

It's interesting to consider the human link between the admin systems and industrial control systems here. If we assume the controls are on an airgapped network, the attackers, in some sense, jumped the airgap and shutdown the pipeline. Obviously not as bad as an actual compromise of the control systems though, which presumably could cause leaks, explosions, etc.

Generally the controls are firewalled from the administrative/business systems, not air-gapped. Production data (like gallons per minute of flow through the pipeline) must be sent from the controls to the business analytics software. That's generally done through a firewall over TCP/IP.

I've seen systems where data is sent via UDP and the physical connection was transmit-only (for example, only the transmit fiber plugged in to the port) to avoid potential firewall exploitation.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#388

Earlier quoted context omitted.

It's interesting to consider the human link between the admin systems and industrial control systems here. If we assume the controls are on an airgapped network, the attackers, in some sense, jumped the airgap and shutdown the pipeline. Obviously not as bad as an actual compromise of the control systems though, which presumably could cause leaks, explosions, etc.

Generally the controls are firewalled from the administrative/business systems, not air-gapped. Production data (like gallons per minute of flow through the pipeline) must be sent from the controls to the business analytics software. That's generally done through a firewall over TCP/IP.

…and the controls still have internet access, but it is NAT’ed, and it still has a fresh copy of Internet Explorer 9.

I have only witnessed this once, at a wastewater treatment plant, so very anecdotal.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#389
post #263

Earlier quoted context omitted.

Also, why do critical services run Microsoft systems?

The real question right here. When will the US government finally take Linux seriously and invest heavily in it instead of relying on Microsoft solutions?

so then we rely on linux solutions instead? I've seen lots of control systems running linux and windows, personally I'd rather keep a mix of the two. Something about eggs and baskets.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#390
post #357

So, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Will there be enough extra tanker-hours and tired tanker-hours to see a statistically significant upturn in accidents and deaths?
Post reply on HN