Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

461–470 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#461
post #437

Earlier quoted context omitted.

When you said “the gang”, I had an image of the gang from “It’s Always Sunny” writing their first virus and this being the result. I’d watch that episode.

The Gang "Solves" the Gas Crisis (2021)

I think it would have to be "Still Solving the Gas Crisis".

Re: US passes emergency waiver over fuel pipeline cyber-attack

#462

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

I'm not super-knowledgable about cybersecurity, but shouldn't simply using TOR make it nearly impossible for the US government to track them down? If they want to go overkill, they can additionally use a public VPN account purchased using walmart giftcards bought on ebay using a stolen identity and then mailed overseas. They can also perform the hack using a brand new computer that they never use again afterward. It…

> shouldn't simply using TOR make it nearly impossible for the US government to track them down?

Not even close. Tor kinda secures one aspect of very many, but kinda doesn't.

It attracts attention: Governments actively try to defeat Tor. And if they are looking for a criminal, they might look first at Tor users. In fact, they collect data on Tor use before a crime is committed.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#464
post #439
post #411

Earlier quoted context omitted.

Believe it or not, massive governments that employ hundreds of thousands of people are capable of doing multiple things simultaneously. I don't think there's any evidence this was state-sponsored, or even state-approved, but "oh there's better things to do" is not a good argument in the least.

I'll keep it in mind the next time a horse bolts from a barn in some foreign country - 'Clearly, this was the CIA's doing. There's no evidence for it, but they have the capability, and their motives are sufficiently sinister and shadowy, and while there's no reason for them to be engaging in medium-scale hooliganism on the other side of the world, they could be the ones responsible!'

The Russian Government had huge motive for this attack, they were not at all happy about the United States' retaliation for SolarWinds/Election interference. Shutting down a major oil pipeline in the United States is not "medium-scale hooliganism."

Also shouting 'No Evidence' is a typical tactic the propagandists use to cast doubt and muddy the waters; surely the attackers would love to see what evidence is available, so they can adapt - that's why evidence is largely kept private.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#465
post #357

Earlier quoted context omitted.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Will there be enough extra tanker-hours and tired tanker-hours to see a statistically significant upturn in accidents and deaths?

I don't think so. These drivers need more specialized training, and the type of equipment they haul is different. Plus I'd imagine your mindset is different when you have a swimming pool's amount of oil a few feet behind you compared to a bunch of toilet paper or whatever.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#466
post #439

Earlier quoted context omitted.

I'll keep it in mind the next time a horse bolts from a barn in some foreign country - 'Clearly, this was the CIA's doing. There's no evidence for it, but they have the capability, and their motives are sufficiently sinister and shadowy, and while there's no reason for them to be engaging in medium-scale hooliganism on the other side of the world, they could be the ones responsible!'

The Russian Government had huge motive for this attack, they were not at all happy about the United States' retaliation for SolarWinds/Election interference. Shutting down a major oil pipeline in the United States is not "medium-scale hooliganism." Also shouting 'No Evidence' is a typical tactic the propagandists use to cast doubt and muddy the waters; surely the attackers would love to see what evidence is available…

Why do you assume that propagandists only work for them?

What makes you think propagandists on our side would never use lack of evidence to make whatever they want up, and cite your exact reason as justification?

This is medium-scale hooliganism in the sense that the end result isn't going to accomplish more than a dedicated idiot with a toolbox, and a grudge against gas pipelines couldn't achieve. IT will clean things up, operations will resume, life will go on.

Not to mention that this gives the industry another, rather low-stakes kick in the ass to take IT security seriously.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#467
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

> I personally believe that DHS should make this sort of thing illegal for critical infrastructure.

I can't speak to non-electrical infrastructure, but the NERC CIP "high impact" standards already make it largely impossible to operate critical electrical infrastructure from anywhere other than a secured control centre. Operating from your laptop or iPhone from the kitchen table is however allowed for "low impact" assets like small power plants.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#468

Earlier quoted context omitted.

>The US and other government wills outlaw all cryptocurrencies but the ones that they control (“Govcoin,” as The Economist refers to them). Game over. Just like how outlawing drugs ended the drug trade.

Outlawing a thing except for when the govt controls it is just another way of saying governement regulation. Which is both common and successful. When was the last time you drank bootleg liquor? Answer: I don't know of course, but for most people in rich western countries I would think the answer is never.

It's a good point but that's a particularly bad analogy. Brewing and distilling are strongly culturally ingrained, at least in the west. I live in a state where (last I checked) no legal method exists to distill ethanol for personal use. Nonetheless, a surprising number of acquaintances over the years have had stills and offered me samples.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#469

Earlier quoted context omitted.

I don't get how Account B gets to the point of extracting value from the illiquid asset after purchasing? Seems like they either, 1) sell periodically or as the assets value appreciates, but this is generally unreliable and tough or 2) create a liquidity pool or yield farming opportunities For 1, this isn't necessarily reliable but it seems like the most plausible popular case. For 2, given the previously mentioned c…

> I don't get how Account B gets to the point of extracting value from the illiquid asset after purchasing? My understanding is, accounts A and B are both controlled by the same person/group. Account A always deals with clean money and pretends to do speculative investing; account B uses dirty money to pump illiquid assets. An example scenario, as a simplified list of transactions: | Time | From | To | Amount | Note…

Yeah we would be talking about paying taxes and having a record of the funds for more social benefits in society.

AccountA is just a speculator. Stuff you speculate on right now has other accounts pumping it from funds that just appeared out of Tornado.cash, or were just swapped from Monero. There is no way to distinguish between you controlling those or someone else, and there isn’t probable cause from this behavior to investigate the accounts that appeared with funds from obfuscated sources. Just some OPSEC considerations.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#470

Earlier quoted context omitted.

Outlawing a thing except for when the govt controls it is just another way of saying governement regulation. Which is both common and successful. When was the last time you drank bootleg liquor? Answer: I don't know of course, but for most people in rich western countries I would think the answer is never.

It's a good point but that's a particularly bad analogy. Brewing and distilling are strongly culturally ingrained, at least in the west. I live in a state where (last I checked) no legal method exists to distill ethanol for personal use. Nonetheless, a surprising number of acquaintances over the years have had stills and offered me samples.

Do you think your local circumstances are broadly generalisable? I would be surprised.
Post reply on HN