Live data from Hacker News

U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

washingtonpost.com

21–30 of 218 posts

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#21

So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?

That a pretty low effort dig at the government. What the hell does that have to do with something that is obviously state sponsored cyber espionage? Go troll somewhere else

'obviously'? Meh.

One argument you can make is to partly defund the surveillance-based departments and agencies and put together a cybersecurity agency who is tasked with hardening the country's systems. I have no idea how someone would build a legislative and personnel firewall to protect it from the existing need to peep through keyholes, it's probably not possible.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#23

So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?

(2) isn’t wrong though. Ransom ware dates to 1989 but the uptick goes hand in hand with the rise of crypto currencies for the obvious reason that you don’t steal what you can’t fence and cryptocurrency has changed the risk and feasibility dramatically.

I’m not saying I support government action here but we should be honest about the situation.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#24
It's only a matter of time, there's gonna be physical casualties at some point in time. We've all seen it in the movies. Experts have warned of the dangers of tethering vital utilities controls to the internet.

Is it not possible to develop protocol or device that operates outside of the web but functions like the'two-man' rule used to launch nuclear bombs?

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#25
A few years back we had two different instances of this pipeline getting shut down from newly-found leaks. While they say it won’t cause gas shortages, these articles tend to drive people to the pumps in droves in the southeastern states served by it (like mine, NC!).

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#26

Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulner…

I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…

>> but instead something malicious affecting the computers they use to control the process.

I bet there is a layer of windows XP machines involved in a legacy control system. XP machines that weren't supposed to connect to the internet somehow have malware on them. It doesn't even have to do anything. Simply the detection of anything in such circumstances is enough to warrant them being shut down.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#27
post #24

It's only a matter of time, there's gonna be physical casualties at some point in time. We've all seen it in the movies. Experts have warned of the dangers of tethering vital utilities controls to the internet. Is it not possible to develop protocol or device that operates outside of the web but functions like the'two-man' rule used to launch nuclear bombs?

One such example... a test done at the Idaho National Lab

https://www.wired.com/story/how-30-lines-of-code-blew-up-27-...

That lab tends to specialize in cybersecurity and infrastructure.

https://www.wired.com/2011/10/idaho-national-laboratory/

The critical infrastructure part of the lab:

https://inl.gov/critical-infrastructure-protection/

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#28
post #24

It's only a matter of time, there's gonna be physical casualties at some point in time. We've all seen it in the movies. Experts have warned of the dangers of tethering vital utilities controls to the internet. Is it not possible to develop protocol or device that operates outside of the web but functions like the'two-man' rule used to launch nuclear bombs?

It's like 100x more expensive.

Would be nice to have separate data lines, running fiber optics sealed in pressurized conduits for double tamper detection. The military actually does this for their critical infra.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#29

Earlier quoted context omitted.

I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…

>> but instead something malicious affecting the computers they use to control the process. I bet there is a layer of windows XP machines involved in a legacy control system. XP machines that weren't supposed to connect to the internet somehow have malware on them. It doesn't even have to do anything. Simply the detection of anything in such circumstances is enough to warrant them being shut down.

Totally agree, see it all the time. I even know of a few NT systems floating around out there. At least most companies are getting their IT involved to mitigate (usually they work with the vendor because they know nothing about control systems). They usually provide funding to the automation groups. People are starting to take it seriously.
Post reply on HN