Earlier quoted context omitted.
I was a child when 9/11 happened but I still remember the experts on TV assuring us that Iraq had those weapons of mass destruction.
I was an adult, and I remember the experts on TV (and print and other media) debunking the “experts” you refer to, often in near real time. And, unlike the latter, the former often had the receipts (fairly literally, in the case of the debunking of the “Winnebagos of Mass Destruction”.)
US passes emergency waiver over fuel pipeline cyber-attack
271–280 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#272Re: US passes emergency waiver over fuel pipeline cyber-attack
#273They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.
> We should shut down Russian infrastructure as retaliation Sanctions against key people are probably more effective while not causing too much anti-American sentiment in the general population or a rally around the flag effect. Hard to rile up the people because a dodgy oligarch can no longer keep his roubles in a London bank, where Babushka Svetlana freezing to death 'cuz the Yankees cut the gas is a martyrdom even…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#274Earlier quoted context omitted.
I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.
Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?
Re: US passes emergency waiver over fuel pipeline cyber-attack
#275The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
Even if you shut down the cashing out infrastructure (exchanges) in the affected countries, it will quickly spring up again in countries belligerent to them. The FATF is the main global body trying to curb this, but my hunch is they will lose this battle long-term.
Imagine if you are on the FATF red list [1] and you announce a free-for all domestic exchange for local spending. It's free FDI.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#276The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
I assume you're thinking of blockchain tech? How do you think the genie will be put back in the bottle?
Add onto that making it illegal to pay ransoms in BTC, then there's really no value in using it as a ransomeware currency. No one is buying it so all you are getting are some random digits on a piece of paper.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#277Earlier quoted context omitted.
IT/Security/Software is all secondary for a pipeline operator, who's main business is to move liquids from A to B over a set of fixed pipes put in place decades ago. Without some forcing function to have cybersecurity threats taken seriously, industrials are unlikely to suddenly develop tier-1 security protocols.
Given that this is preventing them from moving liquids from A to B they should realize that protecting their system isn't a secondary concern.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#278The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
I assume you're thinking of blockchain tech? How do you think the genie will be put back in the bottle?
Re: US passes emergency waiver over fuel pipeline cyber-attack
#279>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?
1. Don't use Windows 2. Use ZFS 3. Practice your distaster recovery plan 4. Laugh in the face of ransomware
Perhaps organizations that providfe critical services shold consider hiring competent IT security advisors? I'm a programmer, not a specialist in security, but everyone knows you need backups, and you need to test that you can recover from your backups quickly.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#280That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.
Doesn't every cyberattack get attention from the U.S. government? After all, carrying out a cyberattack is a federal crime.
In practical terms there needs to be something special about the cyberattack for the government to devote any resources towards it.