Live data from Hacker News

U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

washingtonpost.com

111–120 of 218 posts

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#111

Earlier quoted context omitted.

While I wholeheartedly agree with what you're saying for the physical world, the digital world is completely different. In the physical world, the scope of any action is inherently localized. But with digital systems it takes just one person out of seven billion (or even just the right software bug) to create a global scale problem. The Internet is best treated as a source of malicious noise.

The main purpose of government is to protect its citizens from foreign invaders. I don't see any difference here.

So then you're up against the halting problem at the "digital border" and you've only reduced the problem to say one in 300 million.

There are many differences. I already mentioned locality and scale. Another is that it's possible to make secure software (aka math) that precludes undesirable behavior a priori, whereas such thing is impossible in the real world.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#112

Earlier quoted context omitted.

I think you’re going to see this more and more (at least with wealthy nations). And I think the motivation for war has always been primarily about profit.

It's been motivated by profit, but this harms the motivation Right now it is profitable for us to go to war. Contracts are signed, jobs are created, it is good for powerful wealthy people for the country to be at war. And if you're powerful enough the risk of retaliation is so low that it's all gain and no cost (outside of human cost which is never enough apparently) With this type of war the equation would be switch…

I agree and you make some good points.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#113

So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?

(2) isn’t wrong though. Ransom ware dates to 1989 but the uptick goes hand in hand with the rise of crypto currencies for the obvious reason that you don’t steal what you can’t fence and cryptocurrency has changed the risk and feasibility dramatically. I’m not saying I support government action here but we should be honest about the situation.

How did criminals pull off international blackmail, kidnapping, and extortion before cryptocurrencies? Did it always require a local bagman? Could ransomware criminals not resort to the same tactics?

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#115
post #95

Earlier quoted context omitted.

While you’re probably right on the zeitgeist aspect of this, I think you’re missing the practical aspects of what OP is talking about. We have major vulnerabilities to key infrastructure components. Publicly exposing these helps harden them. Yes 9-11 added a ton of security theater and fear, but it also resulted in armored doors on airplane cockpits. I’d like to see the armored door of the energy infrastructure imple…

That's not the society I want. I don't want stronger doors everywhere. Tougher locks everywhere. Onerous security everywhere. I prefer a society where passengers are free to chit chat with the pilots when they aren't busy. Where children who might be interested in being a pilot can see a cockpit in the air and how it's done. I remember reading about the history of security in ancient Rome. The lengths to which normal…

Do I want security cameras/metal detectors/metal doors and other police state security measures everywhere? No. Do I want to have all that in electrical plants/pipelines/nuclear reactors and other objects of critical infrastructure - yes. If that means employees there would need to spend more time for annoying security checks(additional password prompts, 2FA, metal detectors, etc) - sure, I did all of that when working for one of British banks, mildly annoying but feasible. If that means more taxes - I'm ready to pay.

One can't just tell russians/chinese/iranians "we have open and free society do please don't hack into our electric grid" and expect it to work.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#116
"This is as close as you can get to the jugular of infrastructure in the United States," said Amy Myers Jaffe, research professor and managing director of the Climate Policy Lab. "It's not a major pipeline. It's the pipeline."

About that infrastructure security... this forum has gone over in detail the situation of infrastructure security in quite a bit of detail as other stuff has happened.

It's easy to say "you need to isolate your critical network from your office network" but that costs dollars and time and letting things fall to shit is free 'till the time comes and then other people the price rather than you.

The privately held, Georgia-based company is owned by CDPQ Colonial Partners L.P., IFM (US) Colonial Pipeline 2 LLC, KKR-Keats Pipeline Investors L.P., Koch Capital Investments Company LLC and Shell Midstream Operating LLC.

All the best names of neoliberalism!

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#117
post #84

Earlier quoted context omitted.

It could do more harm than good, but it remains possible that someone will do it anyway. It's a legitimate scenario for these types of companies to consider in their cyber-security planning and preparation (assuming they have any).

Domestic attacks would be somewhat more difficult to carry out without being detected. It’s much easier for the Government to track domestic actors since there’s so much data collected on them both Nationally and by local law enforcement. That’s why international attacks are more prevalent and bold: they’re not as easily traceable. However, that also comes with its downsides: if the USG wants, it might just use letha…

1/6 looked pretty easy. It also looked like it was pretty easy to catch the most gods-awfully expensive intelligence agencies in the world completely flat-footed.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#118
There’s nothing in this article indicating the operator has a recovery plan in place involving restoring backups to get these systems online. Seems grossly negligent on their behalf, and made almost satiric by the fact that Fireye can be mentioned without reference to their own massive security lapses.

Too much focus always on the “hackers” and never the obvious security lapses solved by diverting executive pay to more bodies and training to cover them, but oh well right?

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#120

There’s nothing in this article indicating the operator has a recovery plan in place involving restoring backups to get these systems online. Seems grossly negligent on their behalf, and made almost satiric by the fact that Fireye can be mentioned without reference to their own massive security lapses. Too much focus always on the “hackers” and never the obvious security lapses solved by diverting executive pay to mo…

IT is typically grossly understaffed and underfunded in these businesses. At the site-level, you'll see some very out of date tech running critical systems. IT is a cost-center to be reduced as much as possible, oversight is non-existent.
Post reply on HN