Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

391–400 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#391

Earlier quoted context omitted.

I assume you're thinking of blockchain tech? How do you think the genie will be put back in the bottle?

The US and other government wills outlaw all cryptocurrencies but the ones that they control (“Govcoin,” as The Economist refers to them). Game over.

>The US and other government wills outlaw all cryptocurrencies but the ones that they control (“Govcoin,” as The Economist refers to them). Game over.

Just like how outlawing drugs ended the drug trade.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#392

The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.

This would be terrible in the long term because without ransomware companies regularly carrying out such attacks, vulnerabilities would remain unaddressed until a rival nation decides to use them. Much better to have one pipedown temporarily shut down now than for China or Russia to shut them all down at once sometime in future.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#393
post #354
post #320

Earlier quoted context omitted.

We regret to inform you that language is mutable.

Now introducing, TypeLang! A strictly typed spoken language with core emotional concepts built into the standard library and immutablity as default. Easily transpiled into dozens of different languages, such as English, Japanese, JavaScript, and Smooth Jazz.

We really need SI units for emotions. Something that can be based on reproducible observations.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#394
post #248

Earlier quoted context omitted.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

Dan Kaminsky spent an enormous amount of time and effort on creating a secure hardware framework 10 years ago. It went nowhere for a lot of the same reasons you discuss in this comment. The government and industry are all talk. Until we see actual enforcement / incentives for secure hardware, just assume everything (and I mean everything ) can get shut down at any time. The only people who think this is an exaggerati…

> Dan Kaminsky spent an enormous amount of time and effort on creating a secure hardware framework 10 years ago.

Can someone please link me to a page that goes into more detail about this secure hardware framework? Not a month from his passing, and we get a national-security-level attack that might have been prevented if US business took more seriously software engineering and security engineering from back then.

Also, I cannot help but wonder if Dan would still be with us if the irretrievably broken US healthcare system was a national system that supplied him with an inexpensive CGM and insulin no matter his employment situation.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#395
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

is there indication of speculation the Ransomeware is on the Contoller HMI's or is it Enterprise

Re: US passes emergency waiver over fuel pipeline cyber-attack

#396

Earlier quoted context omitted.

The USA is absolutely a nation state. Cocal-cola, mcdonalds, Christmas, enlgish, etc. are well dispersed throughout the entire population. We have a uniform culture, although not as uniform as much smaller countries, but uniform nonetheless.

> Cocal-cola, mcdonalds, Christmas, english These are well dispersed throughout the world...

Cultural dominance isn’t an argument against national cohesion.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#397
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

is there evidence of suspicion the Ransomeware is on the controller HMI's, infected from Enterprise connections

Re: US passes emergency waiver over fuel pipeline cyber-attack

#399

This is depressing and not going to stop because it is so lucrative and relatively easy for these malware companies to find victims. It makes me wonder if cybersecurity should be considered a state responsibility and infrastructure so it will be uniform and available for every business like electricity or police protection.

If it is uniform then when a weakness is found, the whole economy can be exploited; rather than isolated companies.

Isn’t this already the case? Like SolarWinds?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#400

Who decides how many hours we're allowed to work, driving trucks, fixing jet engines, taking care of children, or doing anything else? Our and our employer's liability for errors is enough motivation to maintain safety at a reasonable level. Put another way, is there statistical evidence of the efficacy of these regulations in reducing trucking accidents? Not that I could find!

Drowsy driving: https://www.nhtsa.gov/risky-driving/drowsy-driving
Post reply on HN