Live data from Hacker News

U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

washingtonpost.com

181–190 of 218 posts

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#181

Earlier quoted context omitted.

So then you're up against the halting problem at the "digital border" and you've only reduced the problem to say one in 300 million. There are many differences. I already mentioned locality and scale. Another is that it's possible to make secure software (aka math) that precludes undesirable behavior a priori, whereas such thing is impossible in the real world.

A) It's not a halting problem. B) Digital borders exist all over the net. We use them every day to secure all sorts of things.

> That's not the society I want. I don't want stronger doors everywhere. Tougher locks everywhere. Onerous security everywhere

> Digital borders exist all over the net. We use them every day to secure all sorts of things

Erm, how do you square these two sentences?

I took your first comment to be arguing against software security in general, presumably in favor of more post-facto enforcement when people violated authorization boundaries.

Your response then seemed to focus on mitigating the cross-jurisdictional issues that make post-facto enforcement hard, by having some sort of software-based security enforcement at a "border", and then relying on post-facto enforcement inside of that.

Now you seem to be supporting software-based security in the form of firewalls everywhere?

If we continue along this trend to even more local, we'll get to fewer firewalls (because they aren't that good of a technology), with security pushed out to the edges. Which is where best practices seem to be headed (BeyondCorp, etc), but is directly antithetical to your initial comment.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#182

Earlier quoted context omitted.

Companies like this are tax dodges that socialize risk. The limited partners enjoy fat returns with minimal downside.

I'm not sure about these, but there are public limited partnerships that anyone can buy like a stock. If you don't realize what you are getting into, you may regret it because you will get a K-1 at tax time. I don't know if it's any more of a tax dodge than an REIT.

These structures characterize cash flows as return on capital, which defer taxation.

There’s a bunch of games played.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#183
post #122

Earlier quoted context omitted.

Trust and integrity are irrelevant when it comes to professional cyber criminals who likely live in another country. Continually escalating cyber attacks are our new reality. There is no possible way to prevent the attackers from trying. Thus the only option is to harden our systems. I expect after a few major crises involving mass casualties or major economic losses the federal government will mandate that private i…

It's absurd to suggest there is only one option.

What is the other option?

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#184
post #183

Earlier quoted context omitted.

It's absurd to suggest there is only one option.

What is the other option?

> What is the other option?

letters of marque for the nation-state actors. bounty hunters for the criminals. There's a lot of options, I suspect using the financial systems to stop bad guys is probably going to miss the mark and produce emergent unintended consequences.

I.E. it's going to get bloody.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#185
post #37

Earlier quoted context omitted.

This. I've said it a thousand times, all the security in the world will not defend a SCADA system if someone left TeamViewer running somewhere. Don't mean to pick on TeamViewer. It could be any number of packages, but I think security minded people get an idea of the type of attack vectors I'm talking about.

It is mind boggling the lack of basic security principles some people have. I won't just put that on the plants and their IT/OT, or lack thereof. I've seen plenty of vendors and integrators do some cringe worthy stuff too.

> It is mind boggling the lack of basic security principles some people have.

OpSec - it's not just a buzzword, it's the Way.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#187

Earlier quoted context omitted.

I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…

The reason I'm going for firmware is while the HMIs could have had a solarwinds style exposure, but that's just any generically wormable OS vulnerability, and not something that should cause a physical shutdown. To shutdown a pipeline, it's not a management console issue, hence why I'd speculate it's in the ICS devices themselves, which probably use uClinux toolchains on SoCs from one or two large vendors. I did some…

Very interesting, kinda spooky.

Peer-to-peer threats from a world power perspective seem to be less bullets and more code. Any cyber warfare would just end in both parties destroying critical infrastructure until there's none left. War of attrition, skipping completely past the military and affecting the civilian population directly.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#188
post #183

Earlier quoted context omitted.

It's absurd to suggest there is only one option.

What is the other option?

You still think there's only one other option? There are probably at least dozens if you think about it.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#189
post #173

Earlier quoted context omitted.

Those things already exist in electrical plants/pipelines/nuclear reactors and other objects of critical infrastructure. Eliminating the ability of people to casually enter and access/alter/destroy this infrastructure isn't the issue. And yeah... we exactly can say that. We do it all the time. We almost blew up the world because Russia sent some missiles to Cuba. There's no reason the digital war can't have physical…

> There's no reason the digital war can't have physical repercussions. If a foreign nation invades our digital properties, we drop a bomb on their electric plant. > Simple as that. Do you think people would support a nuclear war ( because if the US bombs Russia or China, the response could very well be nuclear) as a response to hacking? And are you aware that the US is one of the most active countries on the cyber wa…

It's already happened. Remember Stuxnet?

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#190

Earlier quoted context omitted.

A) It's not a halting problem. B) Digital borders exist all over the net. We use them every day to secure all sorts of things.

> That's not the society I want. I don't want stronger doors everywhere. Tougher locks everywhere. Onerous security everywhere > Digital borders exist all over the net. We use them every day to secure all sorts of things Erm, how do you square these two sentences? I took your first comment to be arguing against software security in general, presumably in favor of more post-facto enforcement when people violated autho…

No it isn't. Arguing with people like this is just boring.

Not interested.

Post reply on HN