Live data from Hacker News

U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

washingtonpost.com

11–20 of 218 posts

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#11

Yikes, get ready for a huge jump in oil pricing.

Why would oil prices jump? This isn’t an oil pipeline.

Because there was already a glut, now the places that feed this pipeline have to be backed up. Just because it’s gasoline doesn’t mean it’s not a link in the whole chain.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#12

So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?

Didn’t see anything about ransomware in the article?

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#13

So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?

That a pretty low effort dig at the government. What the hell does that have to do with something that is obviously state sponsored cyber espionage? Go troll somewhere else

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#14

Yikes, get ready for a huge jump in oil pricing.

> Colonial’s pipeline transports 2.5 million barrels each day, taking refined gasoline, diesel fuel and jet fuel from the Gulf Coast up to New York Harbor and New York’s major airports. Most of that goes into major storage tanks, and with energy use depressed by the pandemic, the attack was unlikely to cause any immediate disruptions.

https://www.nytimes.com/2021/05/08/us/cyberattack-colonial-p...

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#15

So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?

[deleted]

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#16

So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?

That's quite a strawperson - it creates a fictional story and then criticize the characters.

The U.S. government has been addressing computer security in infrastructure for a long time.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#17

Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulner…

Shutting down pipelines is insanely expensive. Under normal circumstances maintenance work, including welding, is done on live pipelines. The guys that do that job are extremely well compensated, last I knew hundreds an hour, and maybe a little crazy.

A shutdown is a huge deal and means they’re taking this extremely seriously.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#18

Given Government inaction on climate change, could we begin to see motivated individuals or groups taking matters into their own hands and targeting fossil fuel infrastructure in this manner?

That would be domestic terrorism and is an easy way to turn the entire population against the cause

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#19
post #4

Yikes, get ready for a huge jump in oil pricing.

Oh, what a surprise, another unexpected event pumping oil prices.

There's no need to use crude jokes here. It's a gasoline pipeline, so more refined jokes are appropriate.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#20

Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulner…

I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…

The reason I'm going for firmware is while the HMIs could have had a solarwinds style exposure, but that's just any generically wormable OS vulnerability, and not something that should cause a physical shutdown.

To shutdown a pipeline, it's not a management console issue, hence why I'd speculate it's in the ICS devices themselves, which probably use uClinux toolchains on SoCs from one or two large vendors. I did some smart meter and ICS security work in the 00's, and there were a few vendors who would be strategic targets. The attack tools available now are unbelievably better, while the attack surface is pretty much the same due to the long lifecycles of ICS components, and considering today we've got cheap SDRs and gnuradio blocks for most wireless protocols, AVR tools, buspirate and the good/greatfet, ghidra/ida, and python for reverse engineering, the vulnerability research on this stuff moves way faster than the industry ability to respond.

If this is a serious attack, the only way to respond will be if they are very lucky, it's a worm and they can stand up a honeynet with spare gear to catch a sample and any good infosec firm can pull it apart. But if it's an active APT group, there's probably a political solution, as given what's possible, this would seem to be just a shot over the bow.

Post reply on HN