Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

61–70 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#61

Earlier quoted context omitted.

Who was it again that has the most effective intelligence community and military in the world?

Intelligence I'd say probably Russia right? They've made America look quite incompetent the past decade or so. Military I'd say America although I don't think SEAL team 6 is going to be hunting down these attackers

Russia is fair game now. Pipeline for a pipeline. We should take one of theirs offline as retaliation.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#62

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

The US Govt is fit for nothing beyond setting up social media offices these days.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#63
post #26

I seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level

IT/Security/Software is all secondary for a pipeline operator, who's main business is to move liquids from A to B over a set of fixed pipes put in place decades ago. Without some forcing function to have cybersecurity threats taken seriously, industrials are unlikely to suddenly develop tier-1 security protocols.

Given that this is preventing them from moving liquids from A to B they should realize that protecting their system isn't a secondary concern.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#64

Earlier quoted context omitted.

Who was it again that has the most effective intelligence community and military in the world?

Intelligence I'd say probably Russia right? They've made America look quite incompetent the past decade or so. Military I'd say America although I don't think SEAL team 6 is going to be hunting down these attackers

> I don't think SEAL team 6 is going to be hunting down these attackers

It would certainly reduce their enthusiasm for hacking.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#65
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> companies are chasing profits at any cost

What does that mean?

This was addressed in the article. Critical services are on the internet because remote workers need access to them. I don't see how profits factor into it.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#66
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

Agreed. Our companies are driven to increase profit at all cost. Even cost to their function and utility.

Our over financialization is squeezing everyone and everything.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#67

They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.

No we should not. We should hunt down those individuals that are responsible but if we get into this tit for tat escalation pattern it might end poorly for all parties involved.

And if “the individuals” turn out to be operatives of the Russian government?

I find as world events unfold these last few years I have drifted away from my isolationist/non-interventionist views. I wouldn’t say I’d advocate for a military response (either electronic or physically destructive) at this point, but I wouldn’t think badly of our government if they did something like that.

Americans have become a rather stupidly optimistic/ignorant people. Russia and China will absolutely destroy us if we don’t aggressively counter their military aggression. And that’s what attacks like this are: military aggression. We ought to start acting like it.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#68
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

Please explain why shutting down the pipeline will contain the hack?

You need the SCADA systems to run the pipeline. They control the pumps, valves, product sequencing, etc. So Colonial purposely shut down the pipeline to prevent the SCADA system from getting affected, which might cause physical damage that truly would be a catastrophe.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#69

Earlier quoted context omitted.

Intelligence I'd say probably Russia right? They've made America look quite incompetent the past decade or so. Military I'd say America although I don't think SEAL team 6 is going to be hunting down these attackers

Russia is fair game now. Pipeline for a pipeline. We should take one of theirs offline as retaliation.

No, one isn’t enough. At least two or three.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#70
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I have no idea why they would do that unless the system was not airgapped properly or it was hard to untangle the admin network from the control network (in which case, the control network is effectively not airgapped).
Post reply on HN