Live data from Hacker News

U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

washingtonpost.com

1–10 of 218 posts

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#6
Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulnerability facilitating it.

The global chip shortage for replacement parts if they are needed seems like a strategic coincidence. Definitely an evolving story.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#7

Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulner…

I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properly you're introducing attack vectors. I don't think it would be a firmware vulnerability, but instead something malicious affecting the computers they use to control the process.

Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

#10
So, two possible responses by the government to the current increase in these kinds of attacks:

1) blame the lack of computer security in our infrastructure, and work on improving that

2) blame cybercurrencies, and try to eliminate them

Any bets on which one our government will choose?

Post reply on HN