Live data from Hacker News

U.S. Forecast as No. 2 Economy but Energy Independent

nytimes.com

21–24 of 24 posts

Re: U.S. Forecast as No. 2 Economy but Energy Independent

#21
post #2

"The study warns of the risk that terrorists could mount a computer-network attack in which the casualties would be measured not by the hundreds or thousands killed but by the millions severely affected by damaged infrastructure, like electrical grids’ being taken down." I wonder about this. It seems like every study about the dangers of terrorism mentions this kind of cyber-attack as a possibility, and I just don't…

A number of folks have argued that if it so easy to do this level of damage with a cyber attack why hasn't a terrorist done so in the last 10 years? Its not like you have to 'sneak' into the country or get pass the security theatre at the airport to mount such an attack. Hacking toolkits and websites are at least as easy to find as bomb making web sites.

For good or for bad, terrorists have, by and large, ignored targets on the Internet.

Hactivists exist, obviously, but your brand-name terrorists like Al Qaeda have not used the Internet as an attack vector.

Yet.

Re: U.S. Forecast as No. 2 Economy but Energy Independent

#22
post #20
post #8

Earlier quoted context omitted.

You may be under-appreciating the interconnected nature of the power grid. A huge swatch of the north-east US lost power for a couple days, not all that long ago, because of a tree branch. And efforts to contain the problem were hampered by an obscure bug in the management software. If a freak accident can expose a cascade of unexpected fail-over behavior, do you really think the grid is hardened against deliberate m…

I think that major question here is: Why is control of the electrical grid accessible to the internet? People usually have delusions of grandeur over hackers causing a meltdown at a nuclear plant or something, but no one seems to question why the ability to control a nuclear plant needs to be hooked up to the internet.

I'd agree, but disagree.

There are people asking that question, it just doesn't get press. Because the reality is quite likely that there are solid business reasons for some access and the real problem is piss-poor security on that access [1].

So you either report on computer security details or alarmist disaster scenarios [2]. And one of those lines of reporting will sell more copies than the other.

[1] If there was no business value in access, they wouldn't have paid to install data lines. I'd imagine remote administration, monitoring and centralized reporting are quite useful, particularly when observing large swaths of the grid.

[2] Which means, yes, people tend to get caught up in infeasible scenarios like hackers causing nuclear meltdowns. But the unlikelihood of those types of catastrophes does not mean that there are no catastrophes that can be caused by compromised infrastructure control machines.

Re: U.S. Forecast as No. 2 Economy but Energy Independent

#23
post #2

"The study warns of the risk that terrorists could mount a computer-network attack in which the casualties would be measured not by the hundreds or thousands killed but by the millions severely affected by damaged infrastructure, like electrical grids’ being taken down." I wonder about this. It seems like every study about the dangers of terrorism mentions this kind of cyber-attack as a possibility, and I just don't…

A number of folks have argued that if it so easy to do this level of damage with a cyber attack why hasn't a terrorist done so in the last 10 years? Its not like you have to 'sneak' into the country or get pass the security theatre at the airport to mount such an attack. Hacking toolkits and websites are at least as easy to find as bomb making web sites.

Obscurity. It's not like these machines are clearly marked with signs and access points as with Airports.

So the challenge is on par with saying "find a particular unsecured box on the internet". Without per-target research, you don't have a whole lot to go on. You can find tons and tons of targets. But the odds of them being the one you wanted, or even of the type you wanted, are pretty low.

Which isn't to say it's less a threat. But, rather, it's a threat that isn't likely to be casually exploited. Anyone who goes through the trouble of per-target research and exploitation of a number of such targets, isn't likely to pull the trigger for the lulz.

Even a "trial run" of an exploit would be a risk. You'd be inviting scrutiny of the trial machine, including logs at the ISP (and NSA) going back cheney-knows-how-far, and if nothing else, have drawn attention to the very problem you're hoping continues to be ignored.

Re: U.S. Forecast as No. 2 Economy but Energy Independent

#24
post #23

Earlier quoted context omitted.

A number of folks have argued that if it so easy to do this level of damage with a cyber attack why hasn't a terrorist done so in the last 10 years? Its not like you have to 'sneak' into the country or get pass the security theatre at the airport to mount such an attack. Hacking toolkits and websites are at least as easy to find as bomb making web sites.

Obscurity. It's not like these machines are clearly marked with signs and access points as with Airports. So the challenge is on par with saying "find a particular unsecured box on the internet". Without per-target research, you don't have a whole lot to go on. You can find tons and tons of targets. But the odds of them being the one you wanted , or even of the type you wanted, are pretty low. Which isn't to say it's…

So I suppose my original comment should have just outright asked: What can a hacker actually do with (hypothetical) remote access to the electrical infrastructure? Open switches under load to effect an arc blast? Blow up a few substations?

Once hackers start mucking around with the grid, things start shutting down by themselves (cascading failures like in the 2003 blackout that you mentioned in another comment). In this situation, damaged equipment can be replaced fairly quickly (far quicker than if, say, a $60 billion storm throws trees across the wires).

I guess I was just looking more for responses from actual electrical engineers with knowledge of the problem. Otherwise we're all just talking out our collective asses, right?

Post reply on HN