Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

401–410 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#401

>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?

Here's a list of the common malware URLs. BE VERY CAUTIOUS. Also note that DarkSide's onionsite is down and has been for a while.

Babuk: http://wavbeudogz6byhnardd2lkp2jafims3j7tj6k6qnywchn2csngvtf...

Dopple: http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qn...

Maze: mazenews.top

AKO: http://37rckgo66iydpvgpwve7b2el5q2zhjw4tv4lmyewufnpx4lhkekxk...

Nefilim: http://hxt254aygrsziejn.onion/

Ragnar: http://p6o7m73ujalhgkiv.onion/

Clop: http://ekbgzchl6x2ias37.onion/

Netwalker: http://rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdr...

REvil: http://dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46...

Sekhmet: http://sekhmetleaks.top/

Pysa: http://wqmfzni2nvbbpk25.onion/partners.html

Conti: conti.news & htcltkjqoitnez5slo7fvhiou5lbno5bwczu7il2hmfpkowwdpj3q2yd.onion

Suncrypt: http://nbzzb6sa6xuura2z.onion/

DarkSide: darksidedxcftmqa.onion

Re: US passes emergency waiver over fuel pipeline cyber-attack

#402
post #357

Earlier quoted context omitted.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Will there be enough extra tanker-hours and tired tanker-hours to see a statistically significant upturn in accidents and deaths?

It's definitely a good natural experiment on the efficacy of these types of laws.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#403

Brought to you by Bitcoin.

You're getting downvoted, but how many ransomware attacks would be successful if a bank account was required?

Bitcoin's not the problem, America's shitty corporate culture around not treating cybersecurity as a priority is the problem.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#404
post #355

Earlier quoted context omitted.

Lol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra

Yes, because the Russian state has nothing better to do then inconvenience the operation of a foreign fuel pipeline for a few days.

Russia and China have been suspected of doing things like this for years. And who says it's just to inconvenience them? There will other things happening because of this and this could impact other nations in a postive manner.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#405

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

When you said “the gang”, I had an image of the gang from “It’s Always Sunny” writing their first virus and this being the result. I’d watch that episode.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#406
post #380
post #357

Earlier quoted context omitted.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Don't trucks transport fuel like this all the time? Or maybe it's the quantity.

Absolutely they do, but with the pipeline down its a volume and distance issue.

Normally the pipeline would pump huge amounts of fuel around to various distribution centers where trucks and tankers would then haul it the last leg to e.g. gas stations and other end users. Now there will be far fewer distribution centers to pick up the load from, and much longer distances to drive to deliver the product.

Naturally a pipeline has much greater capacity than a string of trucks, not to mention the impacts on traffic and safety concerns that go with pushing the truck drivers that far. The limited number of distribution points with the pipeline offline will probably have a logistical impact as well since there will be an imbalance re: how many trucks are arriving to get filled up.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#407
post #330

Earlier quoted context omitted.

It's a lot easier to pull the plug on on-premise systems.

Is it though? We have plenty of cases of on-prem and in-cloud going down. And we have also plenty of evidence that some companies do actually manage to do disaster recovery pretty well. Not all, of course, usually those that experience frequent disasters.

My environment is mostly on-prem, and it's nearly always the cloud services that drop out and leave us high and dry. In fact, not long ago, a cloud service we don't use went down, and it took one of our vendors down, and their cloud service went down, because of an outage with a completely unrelated service we don't use! The cloud is a house of cards that is run by companies that should have disaster recovery down, and really don't even come close.

Meanwhile, I can unplug one cable to isolate our site, and everything that isn't a cloud service is pulled offline. (And delightfully, almost all of it would still be independently operational until I plugged it back in, too.)

Re: US passes emergency waiver over fuel pipeline cyber-attack

#408
post #354
post #320

Earlier quoted context omitted.

We regret to inform you that language is mutable.

Now introducing, TypeLang! A strictly typed spoken language with core emotional concepts built into the standard library and immutablity as default. Easily transpiled into dozens of different languages, such as English, Japanese, JavaScript, and Smooth Jazz.

see https://en.wikipedia.org/wiki/Esperanto not exactly what you are looking for, but :)

Also French has an official body that authorizes words.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#409

Earlier quoted context omitted.

What are EVMs, ERC2, and sDAI? I do not believe your objective is to confuse or obstruct, but additional context would help understand the unique value of your contribution. This is coming from someone with a recent BSc in Computer Engineering yet still completely unaware of these acronyms & references.

Only a few universities are teaching this stuff right now. In any case: EVM is "Ethereum Virtual Machine", a similar concept to the JVM "Java Virtual Machine". EVMs are one the most common technology for deployment of arbitrary execution within distributed networks. These kinds of functions and applications are colloquially called smart contracts. The biggest distributed network with this technology being simply call…

Where can someone learn more about this? Any resources?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#410
post #201

Earlier quoted context omitted.

I like those people. The problem being sometimes you need logs or data off tools. I’m far from an IT wizard so I don’t know what other solutions exist but the flash drives to get stuff off tools was the easiest

It makes some things more difficult. CD/DVD's are generally used instead. Sometimes other computers could be connected but in that case there would be some organizational procedure for attempting to make sure that other computer was as low risk as possible. You can't eliminate the possibility of malicious action, Stuxnet proves that. It's my opinion that at least for critical infrastructure we can probably make thing…

I'd be lying if I claimed I knew...but I would be willing to bet that cost-benefit analysis was made a long time ago before these concerns became so timely.
Post reply on HN