Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

111–120 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#111
post #96

Earlier quoted context omitted.

Yes, let’s meekly sit back and let other countries attack us, only playing defense. Russia caused this. If we shut down Russian infrastructure and Russian civilians get caught in the crossfire, the Russian government can blame themselves. You cannot expect to engage in acts of war without endangering your own citizens to at least some degree. To engage in war is to invite it to your homeland. Hell, if we don’t retali…

This is the most "keyboard warrior" comment I've ever read.

And your lack of understanding around the need for offensive cybersecurity is one of the most naive things I’ve read on HN. I suppose it balances out.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#112
post #72
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> if you are a critical service ... for each occurances 10% of your total revenue ... are forfeited You can achieve the same effect without all the arbitrary political decision-making inherent in this proposal by requiring these companies to buy delivery insurance or something. The insurance company will charge them proportionally to the risk of attack, which will internalize the cost.

Like AIG insuring investments during the 2008 crisis? I think for critical infra you want some extra care and redundancy (not arbitrary though of course).

Re: US passes emergency waiver over fuel pipeline cyber-attack

#113

Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. Not Breaking: Citizens’ disappointment in the aforementioned, particularly given their direct contribution to said budget. The Unsaid: Much of this will not change, unless incentives are realign…

Er, the victim here is a private company, not the government.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#114

They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.

> We should shut down Russian infrastructure as retaliation

Sanctions against key people are probably more effective while not causing too much anti-American sentiment in the general population or a rally around the flag effect. Hard to rile up the people because a dodgy oligarch can no longer keep his roubles in a London bank, where Babushka Svetlana freezing to death 'cuz the Yankees cut the gas is a martyrdom event.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#116
post #67

Earlier quoted context omitted.

No we should not. We should hunt down those individuals that are responsible but if we get into this tit for tat escalation pattern it might end poorly for all parties involved.

And if “the individuals” turn out to be operatives of the Russian government? I find as world events unfold these last few years I have drifted away from my isolationist/non-interventionist views. I wouldn’t say I’d advocate for a military response (either electronic or physically destructive) at this point, but I wouldn’t think badly of our government if they did something like that. Americans have become a rather s…

Agreed. That said, we need to do it now before some populist lunatic is compelled to attempt it.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#117
post #68

Earlier quoted context omitted.

You need the SCADA systems to run the pipeline. They control the pumps, valves, product sequencing, etc. So Colonial purposely shut down the pipeline to prevent the SCADA system from getting affected, which might cause physical damage that truly would be a catastrophe.

I'm really confused: the pipeline is resilient to a hack: they just shut down the pipeline so it won't be 'affected' (hacked?)?

It was intended to be airgapped, but we're talking about a pipeline that is several thousand miles long, with many pumping stations and delivery terminals. All it would take is one of the SCADA systems at one of those locations to suddenly open a valve and dump petroleum out into the environment to cause a disaster.

Or worse - rapidly open & close valves in rhythm, and the water hammer effect (the inertia of the petroleum in the pipeline) would cause the pipeline to destroy itself. The repair costs would be astronomical - you'd naturally have to repair the damaged sections, but then also re-test all the welds to see if any had been weakened by the pressure pulses.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#118

Earlier quoted context omitted.

I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…

Do you think Colonial identified some "physical world" risk, as in the possibility of a pressure overload or pipeline leak? I imagine that verifying the integrity of these SCADA systems is a very complex task, so I'm wondering if they've already identified a possible attack vector/entry point or if this was entirely preventative.

I have no idea. Shutting down preventatively would be smart, and they had good leadership in their IT space while I was there. Friendly people who could make the hard decisions quickly, weren't afraid to pick up the phones to call people, and supported the growth of struggling employees without letting shoddy work get approved. They were also good at managing large multi-year and nation-wide project campaigns - a rare skill in this world.

That said, determining whether or not a system was compromised can be incredibly difficult. I'm sure they'll face massive pressure to turn the pipeline back on as it does supply almost half of the east coast with oil. I wouldn't want to be the person who has to make that call when it's impossible to prove a negative.

CPC had two explosions a few years back which caused gasoline shortages in new england, that may provide indication of the scale of disruption to expect.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#119
post #20

Is this event going to give Americans a new appreciation of pipelines? One of Biden’s signature issues was killing Keystone after all.

What makes you think Keystone and this pipeline are the same in any way?

They are not, and you should know the difference before dragging political nonsense totally irrelevant into the topic at hand.

I know, some people just can’t help themselves but to color everything in a political binary.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#120

Earlier quoted context omitted.

> companies are chasing profits at any cost What does that mean? This was addressed in the article. Critical services are on the internet because remote workers need access to them. I don't see how profits factor into it.

Those remote workers wouldn’t have to be ‘remote’ if there were other workers hired on site.

Many sites are in the middle of nowhere so it is inconvenient to go to them, so accessing them over a network saves a lot of travel time and cost.
Post reply on HN