Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

371–380 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#371

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Doesn't every cyberattack get attention from the U.S. government? After all, carrying out a cyberattack is a federal crime.

The difference between "the FBI will look into it if they find some spare time" and "you've made the top 10 target list of the NSA".

Re: US passes emergency waiver over fuel pipeline cyber-attack

#372
post #263
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Also, why do critical services run Microsoft systems?

The real question right here. When will the US government finally take Linux seriously and invest heavily in it instead of relying on Microsoft solutions?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#373
post #325

Earlier quoted context omitted.

> I'm not super-knowledgable about cybersecurity, but shouldn't simply using TOR make it nearly impossible for the US government to track them down? PSA: There are known traffic correlation attacks against Tor. It's not magic security dust you can sprinkle on a system. If you're doing thoughtcrimes, assume any G10 intelligence service can track you down. (If you're into extortion, human trafficking/exploiting childre…

Yes, you can pick tunnel length in I2P.

But, can you allow some nodes to queue messages for a longer period of time?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#374

Earlier quoted context omitted.

The US and other government wills outlaw all cryptocurrencies but the ones that they control (“Govcoin,” as The Economist refers to them). Game over.

You're assuming the US and other government are not using cryptocurrencies for their own covert transactions.

So what? Many governments have nuclear weapons arsenals but they don't make it legal for everyone to buy or manufacture atomic bombs.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#375

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

I'm not super-knowledgable about cybersecurity, but shouldn't simply using TOR make it nearly impossible for the US government to track them down? If they want to go overkill, they can additionally use a public VPN account purchased using walmart giftcards bought on ebay using a stolen identity and then mailed overseas. They can also perform the hack using a brand new computer that they never use again afterward. It…

That would work against network tracking of the actual connection, but that is not the main means of attribution and tracking culprits.

One way is to look at any tools and artifacts used/deployed - it's not common that only "off-shelf" tools are used, and as soon as there's anything custom, most likely it's not a one-off thing that never ever appears anywhere else; if you got it from someone, that's a potential lead; if you wrote it yourself, you're likely to use it (or a modified version) elsewhere, so if you make a mistake in one "gig" then it can relate to all your other activities as well.

Another is people - those things are often not done alone, and people talk, especially if they get detained for something else. And last but not least, the money trail sometimes leads to results as well.

But the key thing is that even if you do everything securely enough, it can work once or a couple times if you're careful enough, but nobody is careful enough to sustain proper opsec all the time, everyone makes mistakes every now and then. These things often take years to resolve, but the legal system has sufficient patience to link something done five years ago to a mistake you'll make next year.

There's sort of an asymmetry for an attack - that if the defender closes 99 vulnerabilities but leaves one, that one is enough for an attacker to get in; but there's a similar asymmetry for detection; if the attacker hides their trail in 99 ways but leaves one, that one is enough to find them afterwards.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#376

Earlier quoted context omitted.

"nation-state" is not just a fancy infosec word for country, and there's some debate as to whether the USA constitutes an actual nation state, rather than a state.

nation-state" is not just a fancy infosec word for country, This is pedantic and adds no value. In what sense could the precise definition of "nation state" matter? in this context everyone understands the phrase in exactly the way it's meant -- a resourceful national government.

:thums-up:

Some people can’t stop fighting “blasphemy,” even if they aren’t in a classic religion.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#377
post #373

Earlier quoted context omitted.

Yes, you can pick tunnel length in I2P.

But, can you allow some nodes to queue messages for a longer period of time?

No, it is designed for low latency communication.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#378

Earlier quoted context omitted.

If you don’t allow 2-way comms to SCADA devices, how can you set values on those devices. For example, open valve 9881 to 10% … how would that be done? SCADA devices are not read-only.

You don't let remote systems open valve 9881. That would be like deploying the landing gear of the airliner, because someone triggered a bug while changing the channel on the in-flight entertainment system.

The whole point of SCADA systems is that you can open and close valves remotely, without requiring to drive hundreds of miles along the pipeline to wherever the particular valve is located.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#379

Earlier quoted context omitted.

Generally it's been the opinion that the control systems need to be modifiable. For example if you add a single valve in a facility which has 4,000 valves already, it would be nice to just add add a controller for that valve to the current SCADA system. However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small mod…

Another thing that can be done is to divide the pipeline into several sections, not just one long one. So if one section gets compromised, it doesn't propagate to the next.

Do you propose that each section gets their own control/monitoring facility staffed 24/7 ? If not, the shared control/monitoring facility is the most likely place of compromise anyway, and it by design can control all the pipeline hardware.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#380
post #357

So, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.

> It means drivers in 18 states can work extra or more flexible hours when transporting gasoline, diesel, jet fuel and other refined petroleum products. This means truck drivers hauling 45,500+ lbs of an extremely flammable liquid aren't required to sleep. I worked in the supply chain industry for a few years, dropping these restrictions is unheard of. My instinct tells me this issue is a lot worse than it seems now.

Don't trucks transport fuel like this all the time? Or maybe it's the quantity.
Post reply on HN