Live data from Hacker News

US passes emergency waiver over fuel pipeline cyber-attack

bbc.com

81–90 of 479 posts

Re: US passes emergency waiver over fuel pipeline cyber-attack

#81
post #8

Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.

I built some of the SCADA and IT systems for Colonial Pipeline.

Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how much do you trust the software?

I often advocate that industrial SCADA systems utilize "data-diodes", one-way opto-isolators, or other physically verifiable methods of confirming that no information/data/instructions can get from a "higher" layer (OSI Pi, PowerBI) to a lower layer (Allen-Bradley PLC, Siemens PLC, Emerson DeltaV DCS, etc).

Convincing the powers-that-be to do this has been incredibly impossible in most places and a large reason why I'm trying to transition to a different space - I simply have had ethical concerns about providing engineering services to critical infrastructure without building in best practices.

Stuxnet was over a decade ago - I don't understand how these protections aren't mandated by the DHS already.

Disclaimer: I don't think it's reasonable for non-involved people to assume the OT side has been compromised. I do think Colonial will need some time to verify the integrity of their SCADA systems and it makes sense to keep the power to the physical devices (valves/pumps) offline until they do. I understand why they chose to shut down but I don't think there's any evidence that they'll be unable to start back up again.

Lastly, I saw a quote in one article:

>>> Digital Shadows thinks the Colonial Pipeline cyber-attack has come about due to the coronavirus pandemic - the rise of engineers remotely accessing control systems for the pipeline from home.

I strongly doubt this. It's possible, of course. But it's extremely unlikely to me that employees would have remotely accessed OT/SCADA systems from home. No one I've worked with has had that capability enabled.

Many companies use products which have been shown to have flaws, like Citrix or various corporate VPNs. These could be compromised to get access "closer" to the OT layers but never directly into it.

Onion layer security is very much practiced everywhere I've been.

Edit: I have heard of some petrochemical facilities moving towards allowing operators and engineers to manipulate valves/pumps on their iPhones. This horrifies me for many reasons. I've never actually seen it implemented and I always bring up Stuxnet when I hear people mention it. I personally believe that DHS should make this sort of thing illegal for critical infrastructure. Many good engineers disagree with me.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#82

I like how they are charging 10% more if you pay with Bitcoin than with Monero. I think commerce would greatly improve if other networks had Tor clients, especially because of the stablecoin and private stablecoin availability as of this year. All EVMs as well as Tendermint networks have no out of the box solutions for Tor nodes and connectivity. But they both have ways for ERC20 tokens to have a great degree of priv…

Is it illegal to pay the ransom?

Re: US passes emergency waiver over fuel pipeline cyber-attack

#83
post #4

It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…

> companies are chasing profits at any cost What does that mean? This was addressed in the article. Critical services are on the internet because remote workers need access to them. I don't see how profits factor into it.

Those remote workers wouldn’t have to be ‘remote’ if there were other workers hired on site.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#84

Earlier quoted context omitted.

Intelligence I'd say probably Russia right? They've made America look quite incompetent the past decade or so. Military I'd say America although I don't think SEAL team 6 is going to be hunting down these attackers

> I don't think SEAL team 6 is going to be hunting down these attackers It would certainly reduce their enthusiasm for hacking.

Its just some 400 pound hacker in his mom's basement. Seems like overkill

Re: US passes emergency waiver over fuel pipeline cyber-attack

#85
post #68

Earlier quoted context omitted.

You need the SCADA systems to run the pipeline. They control the pumps, valves, product sequencing, etc. So Colonial purposely shut down the pipeline to prevent the SCADA system from getting affected, which might cause physical damage that truly would be a catastrophe.

I'm really confused: the pipeline is resilient to a hack: they just shut down the pipeline so it won't be 'affected' (hacked?)?

It can be already hacked but while power to the valves and pumps are removed then the SCADA system hacks can't cause physical damage.

I haven't seen any evidence that the "OT" side of their network was compromised in a way that would cause physical damage, a la Stuxnet.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#86

They're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.

No we should not. We should hunt down those individuals that are responsible but if we get into this tit for tat escalation pattern it might end poorly for all parties involved.

Actually, tit-for-tat is gametheoretic stable.

https://en.m.wikipedia.org/wiki/Tit_for_tat

Re: US passes emergency waiver over fuel pipeline cyber-attack

#87
post #68

Earlier quoted context omitted.

Please explain why shutting down the pipeline will contain the hack?

You need the SCADA systems to run the pipeline. They control the pumps, valves, product sequencing, etc. So Colonial purposely shut down the pipeline to prevent the SCADA system from getting affected, which might cause physical damage that truly would be a catastrophe.

And to add it’s perfectly possible that the pipeline networks were air gapped (Ed: which don’t believe them) but you still need to shut down.

I could imagine a situation where information another network (e.g. orders or incoming flows from another customer or user) is necessary to run the pipeline but unavailable to use to operate the pipeline control system.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#88

That gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.

Third administration in a row to do nothing. Read sandworm. The wolf is in the hen house now and nothing will still be done.

Re: US passes emergency waiver over fuel pipeline cyber-attack

#89

Earlier quoted context omitted.

Who was it again that has the most effective intelligence community and military in the world?

I hope you're not talking about the CIA, whose network of agents in China (to pick one example) was rounded up and killed due to either shoddy IT work or a mole in the Agency. Either possiblity reflects poorly on the American intelligence community: https://www.reuters.com/article/us-usa-china-espionage-idUSK... >Investigators remain divided over whether there was a spy within the Central Intelligence Agency who betr…

This isn't a counter-argument against the person you're replying to, though. One can pick from numerous examples of the inverse(though the US doesn't round them up & disappear them, they go through the court system)

Re: US passes emergency waiver over fuel pipeline cyber-attack

#90
post #58

Earlier quoted context omitted.

Yes we should. There is no justification for why we meekly let them have at it cyberspace. It should be pain for pain. Russians will never learn until they feel pain.

I like the concept of holding Russia (as with any country) responsible assuming they are, but your reply didn’t address the escalating pattern of tit for tat, and how to deal with that.

Here's the answer: it hasn't been tit for tat. It's been all tit.

At some point, you have to tat.

Post reply on HN