U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
31–40 of 218 posts
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#32It's only a matter of time, there's gonna be physical casualties at some point in time. We've all seen it in the movies. Experts have warned of the dangers of tethering vital utilities controls to the internet. Is it not possible to develop protocol or device that operates outside of the web but functions like the'two-man' rule used to launch nuclear bombs?
It's like 100x more expensive. Would be nice to have separate data lines, running fiber optics sealed in pressurized conduits for double tamper detection. The military actually does this for their critical infra.
At least German Telekom has been doing this for ages for the trunk cables serving entire areas with analog phone service - although not for tamper detection as an anti-spionage measure, but rather to detect and pinpoint damage to the cables, e.g. from excavators, tree growth or splice seals degrading.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#33Its the chinese
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#34Earlier quoted context omitted.
I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…
The reason I'm going for firmware is while the HMIs could have had a solarwinds style exposure, but that's just any generically wormable OS vulnerability, and not something that should cause a physical shutdown. To shutdown a pipeline, it's not a management console issue, hence why I'd speculate it's in the ICS devices themselves, which probably use uClinux toolchains on SoCs from one or two large vendors. I did some…
Additionally, if there was a whiff of malicious software or unintended access I would imagine they would want to make sure it didn't get into other systems. That would involve isolating and possibly shutting down machines and equipment.
I guess we'll see when they release more information. I would imagine that we'll get more details since this is critical infrastructure.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#35So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
That's quite a strawperson - it creates a fictional story and then criticize the characters. The U.S. government has been addressing computer security in infrastructure for a long time.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#36So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#37Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulner…
I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…
I've said it a thousand times, all the security in the world will not defend a SCADA system if someone left TeamViewer running somewhere.
Don't mean to pick on TeamViewer. It could be any number of packages, but I think security minded people get an idea of the type of attack vectors I'm talking about.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#38So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
The state of computer security is unacceptable and needs to be fixed. Today its profit-motivated extortionists, but anything they can do is also an option for spy agencies, and is it really that hard to imagine anti-oil activists pulling the same stunt some day?
On the other hand, crypto is the thing behind the profit motive. If crypto is impractical (if there were no way to convert it to real currency), the profit incentives for these attacks (and mining, for that matter) break down.
I realize this isn't a popular opinion around here, but we should probably do both.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#39Earlier quoted context omitted.
I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…
This. I've said it a thousand times, all the security in the world will not defend a SCADA system if someone left TeamViewer running somewhere. Don't mean to pick on TeamViewer. It could be any number of packages, but I think security minded people get an idea of the type of attack vectors I'm talking about.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#40So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
Both are correct. The state of computer security is unacceptable and needs to be fixed. Today its profit-motivated extortionists, but anything they can do is also an option for spy agencies, and is it really that hard to imagine anti-oil activists pulling the same stunt some day? On the other hand, crypto is the thing behind the profit motive. If crypto is impractical (if there were no way to convert it to real curre…
Get out of here with this.