Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

291–300 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#291

Earlier quoted context omitted.

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

Well, whatever they used to do before they connected everything to the internet. What about just do that?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#292

Earlier quoted context omitted.

Intelligence I'd say probably Russia right? They've made America look quite incompetent the past decade or so. Military I'd say America although I don't think SEAL team 6 is going to be hunting down these attackers

> They've made America look quite incompetent the past decade or so This itself is American propoganda; the strategy is to be absolutely all over your opponents, knowing that they can't complain about it for fear of looking weak, while complaining loudly about how their meagre attempts are the end of the world, getting public and Congressional support for more spending. Before the Snowden leaks, someone suggesting th…

I don't believe the way America has embarrassed itself on the world stage is American propaganda. Russia has repeatedly exploited the stupidity of a few within the upper echelons of the elected American government with a few well placed agents and bots backing up those messages online.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#293

Earlier quoted context omitted.

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.

Allowing remote monitoring and troubleshooting is too convenient

Re: US passes emergency waiver over fuel pipeline cyber-attack

#294

Earlier quoted context omitted.

Pipelines run for thousands of miles and operate 24/7. What do you imagine? Keeping a fleet of helicopters on standby to pick up a technician at home, and drop him wherever the equipment is, in case something needs to be adjusted at night?

You could have an air-gapped system and still have remote access. Just not external access. I don't think it's unreasonable to have a couple of people in a control booth monitoring a computer that regulates the pipeline 24/7. The recommendation is, however, that we should not have that monitoring computer connected to any other network besides the internal one. If you're running pipeline, surely you can run some data…

> You could have an air-gapped system and still have remote access

You're suggesting the gas company run their own network, and then you assume no employee will connect that network to the general internet for their own convenience? Not happening.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#295

Earlier quoted context omitted.

Generally it's been the opinion that the control systems need to be modifiable. For example if you add a single valve in a facility which has 4,000 valves already, it would be nice to just add add a controller for that valve to the current SCADA system. However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small mod…

Another thing that can be done is to divide the pipeline into several sections, not just one long one. So if one section gets compromised, it doesn't propagate to the next.

I'm not sure how that would work-- each section would still need to send its petroleum products to the next section, making it effectively still one pipeline. Unless I misunderstand your statement?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#297
"Multiple sources have confirmed that the ransomware attack was caused by a cyber-criminal gang called DarkSide, who infiltrated Colonial's network on Thursday and took almost 100GB of data hostage."

re: "infiltrated Colonial's network"

I have been reading some of the other reports of this incident from different publications.

Many of the stories include a line about attackers downloading "100 GB in only 2 hours" as if that was being downloaded from the company's on premises servers.

Eventually I found a story that disclosed the data was actually downloaded from a cloud provider.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#298
post #226

Earlier quoted context omitted.

> and this an act of war What an absurd statement. And what do you suggest we do? Attack them and hope they don't respond with nukes?

Solarwinds hack, Mueller report, this... I don't know what the best response is. First we have to wake up that we are under attack.

You say “under attack,” I say “standard world power shenanigans”

Re: US passes emergency waiver over fuel pipeline cyber-attack

#299
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Lost revenue would be justified by execs as cost of doing business. And they'd probably buy hacker-insurance to cover some/all of that risk. They'd pay for the hacker-insurance by getting a shittier employee benefit plan, and cutting the employee 401k match by 2%. For each quarter they aren't hacked, they'd probably receive a credit from the hacker-insurance company, which would be distributed to execs via performance bonuses.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#300
post #191

Earlier quoted context omitted.

> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…

> Attach a fine to the discovery and disclosure and you disincentivise that prudence. Sue them. Failure to disclose key documents in the discovery phase of a trial carries hefty fines and jailtime. And quadruple the fine for misrepresenting the cause. People act like the government doesn't have the power of subpoena. They can absolutely compel you to tell the truth.

Yes. I've worked in a very regulated industry before and it ended up being less secure than any other I've worked in. Checking your secure email required so many hoops people would just text each others personal phones instead, etc.
Post reply on HN