44 ms·
US passes emergency waiver over fuel pipeline cyber-attack
- NaturalPhallacy 5y ago>The gang even has a website on the dark web where it brags about its work in detail, listing all the companies it has hacked and what was stolen, and an "ethics" page where it says which organisations it will not attack. And yet they don't give the URL. I wanna see this page. Does anyone have it?
- sodality2 5y agoMost people will probably be hesitant to post it for obvious reasons here. But it was helpful to me, to find a ransomware url, during the college leak a few weeks ago (https://dorper.me/articles/unileak.aspx https://dorper.me/articles/unileak.aspx) to find out which colleges were impacted because tons of people I know were in it. There are plenty of good reasons to want to have it. But I understand why BBC wouldn't post it...
- pm90 5y agoPeople that read Hacker News on their work machine: note that if you're on the org VPN (and even if you're not, if your org installs IDS tools or other spyware) many of those tools may flag your visit of such site as "malicious". Best to use a personal device.
- vmception 5y agoI don't have it, but I would go to dark.fail's onion address and browse there (http://darkfailllnkf4vf.onion/ http://darkfailllnkf4vf.onion/ verify this and get in the habit of doing so! dark fail's clearnet website just got hacked while their onion site was unaffected), and then I would go to Dread forum (onion reddit clone) and ask there. A little tedious but there is lots of commerce on onion sites, and a lot of valuable information in general that I've never seen anywhere else, so it can be worth it.
- sswam 5y agoHere's a suggestion. 1. Don't use Windows 2. Use ZFS 3. Practice your distaster recovery plan 4. Laugh in the face of ransomware Perhaps organizations that providfe critical services shold consider hiring competent IT security advisors? I'm a programmer, not a specialist in security, but everyone knows you need backups, and you need to test that you can recover from your backups quickly.
- curiousgal 5y agoWell the reason for that is that the website has dumps that you can easily download. Here is a text dump of their press page https://pastebin.com/fxJCaUDq https://pastebin.com/fxJCaUDq
- duckfang 5y agoHere's a list of the common malware URLs. BE VERY CAUTIOUS. Also note that DarkSide's onionsite is down and has been for a while. Babuk: http://wavbeudogz6byhnardd2lkp2jafims3j7tj6k6qnywchn2csngvtffqd.onion/ http://wavbeudogz6byhnardd2lkp2jafims3j7tj6k6qnywchn2csngvtf... Dopple: http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qn... Maze: mazenews.top AKO: http://37rckgo66iydpvgpwve7b2el5q2zhjw4tv4lmyewufnpx4lhkekxkoqd.onion http://37rckgo66iydpvgpwve7b2el5q2zhjw4tv4lmyewufnpx4lhkekxk... Nefilim: http://hxt254aygrsziejn.onion/ http://hxt254aygrsziejn.onion/ Ragnar: http://p6o7m73ujalhgkiv.onion/ http://p6o7m73ujalhgkiv.onion/ Clop: http://ekbgzchl6x2ias37.onion/ http://ekbgzchl6x2ias37.onion/ Netwalker: http://rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion/blog http://rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdr... REvil: http://dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd.onion http://dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46... Sekhmet: http://sekhmetleaks.top/ http://sekhmetleaks.top/ Pysa: http://wqmfzni2nvbbpk25.onion/partners.html http://wqmfzni2nvbbpk25.onion/partners.html Conti: conti.news & htcltkjqoitnez5slo7fvhiou5lbno5bwczu7il2hmfpkowwdpj3q2yd.onion Suncrypt: http://nbzzb6sa6xuura2z.onion/ http://nbzzb6sa6xuura2z.onion/ DarkSide: darksidedxcftmqa.onion
- murph-almighty 5y agoIt might help if you format these as "domain[dot]com" to avoid misclicks.
- duckfang 5y agoToo late.
- NaturalPhallacy 5y agoYou can edit your comments here.
- andreshb 5y agoI like how they "guarantee support in case of problems" after you pay them. God forbid they lose a customer. Are they going for repeat buys?
- vmception 5y agoThey want to ensure ransoms are paid by there being lots of sources that say they do what they say. The kneejerk reaction is to be skeptical and waste time. The only reaction is to determine if you have a backup or not, or if the consequences are favorable or not. In all of the “or nots” then you pay and move on. In the absence of consumer protection, word of mouth (or the compulsory google results) is key.
- est31 5y agoNo but they want to get a reputation that paying them makes the problem go away. With that reputation, more people will pay instead of thinking it's a waste of money as the data are gone one way or another.
- edoceo 5y agoGotta honour the Pirate Code.
- philips4350 5y agoI saw a youtube video once of someone trying to communicate with ransomware attackers and their support was better than even some legit companies. It was funny as hell how they were so 'professional' about it
- dang 5y agoPrevious related thread: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack - https://news.ycombinator.com/item?id=27086403 https://news.ycombinator.com/item?id=27086403 - May 2021 (190 comments)
- jmclnx 5y agoIt needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited. That will get them serious about security.
- mcny 5y ago> The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited. I would love to see this but somehow I doubt it will happen any more than my pipe dream of holding the CXO and the board criminally liable for the criminal actions of management/employees/contractors/agents of a corporation during the course of their work for the corporation. It is nice to dream though. I would certainly welcome any kind of accountability.
- ruskimir 5y agoWe should also shut down Russian infrastructure through cyberattacks. The Russian government supports DarkSide.
- motoxpro 5y agoTotally, take out all the hospitals, education and basic needs for the rest of the innocent people. Or just nuke them, that will teach um. On a serious note, sure retaliate, probably don't hurt innocent people.
- pasquinelli 5y agoor maybe the notion that russia is even behind it is a lie aimed at stoking tensions between the united states and russia, probably for the sake of profitting companies like digital shadows--or wharever it was called.
- vmception 5y agoI like how they are charging 10% more if you pay with Bitcoin than with Monero. I think commerce would greatly improve if other networks had Tor clients, especially because of the stablecoin and private stablecoin availability as of this year. All EVMs as well as Tendermint networks have no out of the box solutions for Tor nodes and connectivity. But they both have ways for ERC20 tokens to have a great degree of privacy. One Tendermint network called Secret Network has private smart contract execution, and a variety of bridges. So as all tokens are smart contracts the metadata and variables would not be visible onchain. sDAI would be more useful for commerce if the nodes and wallets could easily resolve over Tor. Is anybody working on that?
- WrtCdEvrydy 5y ago> I like how they are charging 10% more if you pay with Bitcoin than with Monero. I smell a business opportunity... Kick off a ransomware attack and accept Bitcoin or a Shitcoin at a 30% discount. Some shitcoins have such little liquidity... a 50k buy would push their price off by hundreds of percentage points. You can even refund their money back after they pay... a modern day pump/dump. The thing about being an ethical player in unethical markets is coming up with ideas that could make you richer but not wanting break laws / be a terrible person.
- vmception 5y agoIlliquid asset pumping is the best way to launder the money in the crypto space. AccountA has bought or owns the illiquid asset using clean money, in advance. AccountB has the ransom proceeds in the more liquid digital asset. AccountB eventually buys the illiquid asset and pumps it. All the blockchain detectives are still following AccountB across many more addresses and blockchains, hoping and praying and imagining that one of the touched accounts needs fiat so that a human identity can be assigned to the funds. But that never happens. AccountA has the 8,000% or other arbitrarily high gain and nobody can distinguish them from any other crypto trader, as these kinds of gains are commonplace. All the trading can (and should) occur onchain without any financial intermediary, as there would be no transaction size limits or issue moving the funds, compared to odd activity on a business' centralized custodial exchange. AccountB connected accounts are saddled with the illiquid asset. Maybe organic growth has occurred from fear of missing out and AccountB can resell, but that is just an embellishment and icing on the cake. AccountB connected accounts can also create the liquidity pool, or create the yield farming opportunities to incentivize others to join the liquidity pool. And if AccountB really never cares about the funds, they can also burn the bearer liquidity pool share, providing confidence to the market that they can always trade at high volumes onchain.
- Enginerrrd 5y agoSomething doesn't quite add up. I feel like we don't have the full story: >After seizing the data, the hackers locked the data on some computers and servers, demanding a ransom on Friday. If it is not paid, they are threatening to leak it onto the internet. So... that constitutes a state of emergency? What data would they have that would be so sensitive? More likely they have hooks deep into the operation of the pipeline and may be threatening to shut it down/destroy it if not paid. Or, rather, they may be having trouble restoring operations without paying the ransom. Side note/speculation: Will the feds make a move against crypto?
- arkadiyt 5y agoAs per the article: > The emergency status enables fuel to be transported by road.
- deleted 5y ago[deleted]
- tidydata 5y ago> Or, rather, they may be having trouble restoring operations without paying the ransom. Usually your only option with a ransomware attack is restoration from backups. So no backups or bad backups means no system. It certainly sounds like this may be the case given that it’s triggering emergency orders. If so, it is being omitted from official accounts.
- westpfelia 5y agoThe Fuel company in question apparently handles 40% of all the fuel in the NE sea board. So thats probably a problem.
- arkadiyt 5y agoColonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.
- engineer_22 5y agoPlease explain why shutting down the pipeline will contain the hack?
- chiph 5y agoYou need the SCADA systems to run the pipeline. They control the pumps, valves, product sequencing, etc. So Colonial purposely shut down the pipeline to prevent the SCADA system from getting affected, which might cause physical damage that truly would be a catastrophe.
- deleted 5y ago[deleted]
- refulgentis 5y agoI'm really confused: the pipeline is resilient to a hack: they just shut down the pipeline so it won't be 'affected' (hacked?)?
- rckoepke 5y agoIt can be already hacked but while power to the valves and pumps are removed then the SCADA system hacks can't cause physical damage. I haven't seen any evidence that the "OT" side of their network was compromised in a way that would cause physical damage, a la Stuxnet.
- chiph 5y agoIt was intended to be airgapped, but we're talking about a pipeline that is several thousand miles long, with many pumping stations and delivery terminals. All it would take is one of the SCADA systems at one of those locations to suddenly open a valve and dump petroleum out into the environment to cause a disaster. Or worse - rapidly open & close valves in rhythm, and the water hammer effect (the inertia of the petroleum in the pipeline) would cause the pipeline to destroy itself. The repair costs would be astronomical - you'd naturally have to repair the damaged sections, but then also re-test all the welds to see if any had been weakened by the pressure pulses.
- unchocked 5y agoSo, a very limited state of emergency which allows fuel that is ordinarily piped to be transported by truck. Ancillarily, It's not evident this cyberattack actually compromised the industrial controls, but rather trashed the administrative system controlling the controls.
- bradstewart 5y agoIt's interesting to consider the human link between the admin systems and industrial control systems here. If we assume the controls are on an airgapped network, the attackers, in some sense, jumped the airgap and shutdown the pipeline. Obviously not as bad as an actual compromise of the control systems though, which presumably could cause leaks, explosions, etc.
- rckoepke 5y agoGenerally the controls are firewalled from the administrative/business systems, not air-gapped. Production data (like gallons per minute of flow through the pipeline) must be sent from the controls to the business analytics software. That's generally done through a firewall over TCP/IP.
- DrPhish 5y agoOften that kind of reporting data is delivered back via a “data diode” unidirectional network. That said, there is usually just a dmz between biz and prod to enable remote support of the controls system (ala the Purdue model), and not any real air gap.
- mysterydip 5y agoI've seen systems where data is sent via UDP and the physical connection was transmit-only (for example, only the transmit fiber plugged in to the port) to avoid potential firewall exploitation.
- daniellarusso 5y ago…and the controls still have internet access, but it is NAT’ed, and it still has a fresh copy of Internet Explorer 9. I have only witnessed this once, at a wastewater treatment plant, so very anecdotal.
- tgsovlerkhgsel 5y agoThat gang may have bitten off more than they can chew. They've now gotten the US government involved officially, which means that beyond the sheer mass of resources that will go into tracking this gang, the government also has something to prove now. Being at the center of an international incident is probably not good for business.
- op03 5y agoThe US Govt is fit for nothing beyond setting up social media offices these days.
- ackbar03 5y agoLol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra
- peteretep 5y ago"nation-state" is not just a fancy infosec word for country, and there's some debate as to whether the USA constitutes an actual nation state, rather than a state.
- maxqin1 5y ago> A nation state is a state in which a great majority shares the same culture and is conscious of it. It has been described as a political unit where the state and nation are congruent. It is a more precise concept than "country", since a country does not need to have a predominant ethnic group. [1] Interesting. [1] https://en.wikipedia.org/wiki/Nation_state https://en.wikipedia.org/wiki/Nation_state
- solipsism 5y agonation-state" is not just a fancy infosec word for country, This is pedantic and adds no value. In what sense could the precise definition of "nation state" matter? in this context everyone understands the phrase in exactly the way it's meant -- a resourceful national government.
- Barrin92 5y agoI seriously don't understand why the pipeline operators don't have some contingency plan or have simulated scenarios like this which enables them to roll-back systems immediately to some usable state. How the hell is some random ransomware gang able to shut down critical infrastructure at purely a software level
- Frost1x 5y agoThat sort of scenario preparation takes a lot of time for planning and design to support work-arounds. If the business thinks this is low risk, they won't invest, no matter how significant the scenario could be. Businesses train and prepare for scenarios that make money, not scenarios that may lose money. I used to do a lot of work related to safety across industries and I can assure you, every business I worked with was only interested in the bare minimum of legally required safety. It was rare to see a business interested in investing resources into things like safety or security vs something that might directly increase their revenue streams.
- lumost 5y agoIT/Security/Software is all secondary for a pipeline operator, who's main business is to move liquids from A to B over a set of fixed pipes put in place decades ago. Without some forcing function to have cybersecurity threats taken seriously, industrials are unlikely to suddenly develop tier-1 security protocols.
- tylersmith 5y agoGiven that this is preventing them from moving liquids from A to B they should realize that protecting their system isn't a secondary concern.
- pm90 5y agoWould be interested in seeing if this does result in a change in their processes, or if they will just accept the risk of this happening as a "risk of doing business".
- User23 5y agoIs this event going to give Americans a new appreciation of pipelines? One of Biden’s signature issues was killing Keystone after all.
- kmbfjr 5y agoWhat makes you think Keystone and this pipeline are the same in any way? They are not, and you should know the difference before dragging political nonsense totally irrelevant into the topic at hand. I know, some people just can’t help themselves but to color everything in a political binary.
- User23 5y agoI suppose I’m very naive, but I’m under the impression that they’re the same in the way that that they’re both meant to provide necessary fuel oils to local markets in an efficient way. And that maybe it would be good to have redundancy, which requires allowing new pipelines to be built. It’s not my fault that that’s somehow a “political issue,” which as far as I can tell means something that your preferred propaganda sources have conditioned you to have an emotional response to that overwhelms any hope of reasoning.
- oldgregg 5y agoFalse flag in the run up to a severe regulatory clamp down. Won't be the first or the last.
- ridethebike 5y agoMind if I asked where did you get this info?
- throwaway67765 5y agoHere’s the WEF head warning about a “cyber pandemic” that would make COVID look like a minor disturbance: https://www.youtube.com/watch?v=uD6C63ZuDlQ https://www.youtube.com/watch?v=uD6C63ZuDlQ This is the same group advocating for The Great Reset, and predicting people will “own nothing and be happy”. It does seem like there is a plan in place for the controlled demolition of industrial society to depopulate the planet and solidify a neo-feudal order of rule by a breakaway elite.
- deleted 5y ago[deleted]
- Thorrez 5y agoRegulatory clamp down as in higher regulations that companies must have good computer security? I think it's already potentially illegal to pay a ransom. Maybe governments could increase those penalties and make it more clearly illegal.
- drusepth 5y agoWithout knowing what OP is referring to, my guess is they're talking about a clamp down on cryptocurrency.
- cma 5y agoIt seems like the main new thing crypto has enabled as a currency so far is ransomware.
- toomim 5y agoThis was Mike Hearn's fear back in 2013: https://bitcointalk.org/index.php?topic=333824.0 https://bitcointalk.org/index.php?topic=333824.0
- pessimizer 5y agoAt least that's a real source of value.
- jb775 5y agoThey say crypto can't be anonymous due to the blockchain but this proves that isn't true. I wonder how they shuffle it around and eventually convert to fiat.
- xvector 5y agoThe government is incompetent, especially when it comes to cybersecurity. It will be interesting to see how this plays out.
- david-cako 5y agoWho was it again that has the most effective intelligence community and military in the world?
- ticviking 5y agoPound for pound I'd say Israel. In absolute terms I'm pretty sure China has us at sea and in cyber so... Not the US
- boringg 5y agoPretty sure china doesn't have the oceans - might want to check up on your stats.
- bob_theslob646 5y agoNot to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1](https://www.navytimes.com/news/your-navy/2021/04/12/chinas-navy-has-more-ships-than-the-us-does-that-matter/ https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...)
- edholland 5y agowithout significant aircraft carrier fleet i'm not sure china has dominant control of any seas, despite best efforts in south china seas [1](https://en.wikipedia.org/wiki/Chinese_aircraft_carrier_programme#Current_status https://en.wikipedia.org/wiki/Chinese_aircraft_carrier_progr...)
- ruskimir 5y agoThey're based in Russia with tacit if not explicit government support. We should shut down Russian infrastructure as retaliation.
- daxaxelrod 5y agoNo we should not. We should hunt down those individuals that are responsible but if we get into this tit for tat escalation pattern it might end poorly for all parties involved.
- ruskimir 5y agoYes we should. There is no justification for why we meekly let them have at it cyberspace. It should be pain for pain. Russians will never learn until they feel pain.
- natch 5y agoI like the concept of holding Russia (as with any country) responsible assuming they are, but your reply didn’t address the escalating pattern of tit for tat, and how to deal with that.
- SoylentYellow 5y agoPerhaps a sort of cyber-MAD comes out of the escalation and the Russian government cracks down on the group to prevent their own serious infrastructure disruptions.
- elefanten 5y agoHere's the answer: it hasn't been tit for tat. It's been all tit. At some point, you have to tat.
- syops 5y agoI can think of some reasons why we should not retaliate against the Russian government. Perhaps we have more to lose in escalation. I don't know if this is true but it might be. If this is an attack at the behest/approval of the Russian government we don't know why they made the attack. It could be a response to something we did to them. We should not get riled up because what hasn't been reported is likely the real story. We just don't know and as citizens we ought not clamor for our leaders to respond. That sort of clamoring has in the past had very negative consequences.
- throwaway481048 5y agoBreaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. Not Breaking: Citizens’ disappointment in the aforementioned, particularly given their direct contribution to said budget. The Unsaid: Much of this will not change, unless incentives are realigned.
- Jweb_Guru 5y ago> Breaking: U.S. government is inept at carrying out procedures which are standard in the technology industry, including the proper safeguarding of important tools & data, despite a budget larger than any other entity on earth. I'm not sure what technology industry you are in, but in the one I'm in software engineers are fooled by phishing attacks extremely consistently, people routinely expose critical systems and devices to the internet, developers often expose databases with insecure defaults to the internet over well-known ports, customer data gets stolen on a regular basis, etc., etc., etc. Regardless of how one feels about the government, I don't think the average technology company does any better when it comes to securing its own infrastructure.
- throwaway3699 5y agoBasic security practices like 2FA and not using VPNs/trusting the network would be a great start. There is no excuse for private business like Facebook and Google being more secure than the f*@& United States of America.
- chrisco255 5y agoWell, FB, Google, et al. have sucked up all the talent.
- slongfield 5y agoThe NSA and CIA pay less than half of what a FAANG company pays for the same role. Sources: FAANG: Levels.fyi and personal experience NSA/CIA: https://work.chron.com/nsa-pay-scale-16399.html https://work.chron.com/nsa-pay-scale-16399.html and https://www.opm.gov/policy-data-oversight/pay-leave/salaries-wages/salary-tables/pdf/2021/GS.pdf https://www.opm.gov/policy-data-oversight/pay-leave/salaries...
- croes 5y agoSeems like this company has more than just IT problems https://newrepublic.com/article/161498/huntersville-north-carolina-colonial-pipeline-spill https://newrepublic.com/article/161498/huntersville-north-ca...
- pm90 5y agoIncredible. This company must be penalized, but I don't have any faith they're gonna change.
- christophilus 5y agoAmazing. I live in the Carolinas and hadn't heard of this. Sounds like maybe we should be thanking the hackers for shutting this thing down.
- splithalf 5y agoBrought to you by Bitcoin.
- SavantIdiot 5y agoYou're getting downvoted, but how many ransomware attacks would be successful if a bank account was required?
- JohnWhigham 5y agoBitcoin's not the problem, America's shitty corporate culture around not treating cybersecurity as a priority is the problem.
- mywittyname 5y agoTechnological advancements happen because of a confluence of different events, each contributing to its eventual success. Bitcoin is absolutely one of the components that allows for the proliferation of ransomware. The key to a ransom is the ability for the attacker to obtain payment in an way that doesn't put them at risk of being caught. BTC enabled that. In fact, anonymous payments are widely considered to be one of the major purposes of BTC. If ransomware was a positive thing, then BTC advocates would be talking about how BTC is the key technology that enabled malware to make the transition from hobby/annoyance/weapon to a full-fledged industry.
- RamshackleJ 5y agoyou never had to worry about ransomware back when we used clay tablets for accounting.
- pabs3 5y agoSeems they got in through a password brute-force attack? It might be time to switch to hardware tokens, encryption keys or to enforce fully random passphrases or diceware/xkcd passphrases.
- sneak 5y agoAnyone not using U2F/WebAuthn to protect all of their internal resources is behind the state of the art. It's really not that hard, especially when you're a BigCorp and already have an SSO system in place.
- andreaaybar 5y agoAre a fan of word game, I have developed Word unscrambler online tool created to help you win word games with friends, and have fun. https://wordunscramble.co https://wordunscramble.co
- projectileboy 5y agoForgive my ignorance, but is it incredibly hard to determine the actual identities of the people behind this? I don’t know why a government wouldn’t simply assassinate culprits who were guilty of crimes at a level that would qualify as an act of war.
- Valgrim 5y agoGiven that this is a ransomware attack, the data is probably encrypted, so if they did find the person behind it, they would probably use "rubber-hose cryptanalysis" to extract encryption keys before... https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
- projectileboy 5y agoI think it’s odd that I’m being downvoted.. I’m not advocating murder, I just wonder if ransomware criminals (assuming they aren’t actually state actors) wouldn’t be at risk.
- choppaface 5y agoAaaand to what extent might this state of emergency require corporate welfare for US Oil?
- noobermin 5y agoA lot of people are talking about the the results of this hack and a little bit about the industrial control systems, but no one is really addressing the hack itself. >James Chappell, co-founder and chief innovation officer at Digital Shadows, believes DarkSide bought account login details relating to remote desktop software like TeamViewer and Microsoft Remote Desktop. >He says it is possible for anyone to look up the login portals for computers connected to the internet on search engines like Shodan, and then "have-a-go" hackers just keep trying usernames and passwords until they get some to work. Nothing sophisticated, nothing difficult, you just need some capital in the bank to buy some leaked credentials someone else worked hard to poke at, that is, some academic security person on a PhD worked hard for months to find some bug in software back in 2014, that turned into code someone else copy and pasted back in 2017, that yielded a dump in 2019 that some other hackers actually probed for some sucker's old login details he probably didn't even realize was in a dump, or might not even use anymore! The only hard work in this story is that academic in 2014 did and he definitely probably no connection to the criminals who basically got the president to issue a national emergency.
- boomboomsubban 5y ago> who basically got the president to issue a national emergency. *got the Department of Transportation to... Further, aren't such blind credential attempts really noticeable if anyone is checking the access logs?
- throwitaway1235 5y agoCritical data belongs on magnetic tape. Should have also kept nuclear launch codes on floppy.
- DoomHotel 5y agoMy inherent cynicism leads me to believe the real reason they shut down the pipeline was because the attackers took down the accounting system.
- technick 5y agoI looked at their available posted jobs on Friday as news broke about the attack. Colonial has had a position for Cybersecurity Manager open for over 30+ days. I wonder what happened to the old manager....
- yourapostasy 5y ago…first to be questioned by the Feds no matter what terms they left under. Too important an attack for that institutional knowledge to stay out of the fray.
- dukeofdoom 5y agoClearly they should have hired the guys that made the elections the most secure in history, to secure the pipeline.
- oliv__ 5y agoI like your sense of humor
- okareaman 5y agoIt's my understanding that Dark Fail is a Russian criminal gang and that Russia does not extradite, stop, or punish these criminal gangs. To me that makes the Russian government culpable and this an act of war.
- pasquinelli 5y agowhere did you get this understanding?
- okareaman 5y agoMSNBC had a person on who purported to be someone knowledgeable. I also read the Washington Post. The act of war part was my idea. I realize I may not have the correct understanding yet, but based on the Solar Winds hack and the Mueller report, it seems to me they are attacking us. Isn't an attack an act of war?
- walleeee 5y agoLarge corporate or state media outlets are unlikely to provide the historical context or the epistemic humility required to follow geopolitics with nuance
- pizzazzaro 5y agoAsk anyone who babysits boxes in the US that are critical - they've been at war for a while. But... Its not like it affects daily life in any meaningful, permanent way. Didnt we read about this pipeline on HN, for being so painfully insecure relative to its value? And painfully outdated? I expect if/when the release drops, we're gonna see some niche/strange software archaeology, and some windows-shit layered on top. But mostly? I remember reading on HN about how much this 1950s-era pipeline leaks like nobody would believe. Perhaps its time we overhaul the rotting infrastructure under our feet. Maybe even try to make these massively centralized pipelines irrelevant. Theyre a weakness. Then again, Im not fond of the idea of Lithium-Wars replacing the Oil-Wars.
- pasquinelli 5y ago
- kordlessagain 5y agoHacks, not skill or ethics. Losers!
- breakyerself 5y agoI'm a fan of pipeline shutdowns personally
- DyslexicAtheist 5y agounderrated comment. especially this company which was in the news for a major spill not so long ago.
- kingsuper20 5y agoI've always wondered about that theory. Is the point to move liquid shipments to trucks/ships because it's safer somehow? or simply to make it so difficult to transport liquid fuels that people quit using them? I suspect that pipeline activism mostly results in the former.
- breakyerself 5y agoConstrained supply or higher cost of transportation = higher prices = incentive to consume less. I'd prefer to see this dynamic produced by carbon taxes so the price difference isn't going back to the fossil fuel companies, but I'll take what I can get. Also installation of new fossil fuel infrastructure like pipelines implies a long term commitment to the status quo or even increased production which I find unacceptable. If the neccessary changes were underway there would be zero demand for new pipelines.
- kube-system 5y agoAssuming the pipeline shutdown doesn't result in even more dangerous transportation alternatives being used instead.
- magnusss 5y agoThe reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
- cheese_van 5y agoBTC will increasingly become viewed as playing a significant role in these incidents. Legislation antithetical to crypto currencies should be expected with bi-partisan support. I would imagine fairly soon.
- deleted 5y ago[deleted]
- DistressedDrone 5y agoI assume you're thinking of blockchain tech? How do you think the genie will be put back in the bottle?
- Pfhreak 5y agoBTC has value because people exchange it for "real" money. If BTC is heavily regulated or outlawed, a whole lot of folks are going to duck out. It's one thing to try and get in on the ground floor of the latest meme stock, it's another thing to buy into a currency/practice that's illegal in your country. Add onto that making it illegal to pay ransoms in BTC, then there's really no value in using it as a ransomeware currency. No one is buying it so all you are getting are some random digits on a piece of paper.
- magnusss 5y agoThe US and other government wills outlaw all cryptocurrencies but the ones that they control (“Govcoin,” as The Economist refers to them). Game over.
- 5y ago
- fortran77 5y agoI don't see this being called a "State of Emergency" anywhere but that BBC article. There's nothing on the Whitehouse.Gov briefing room, google news, etc. https://www.whitehouse.gov/briefing-room/ https://www.whitehouse.gov/briefing-room/
- MilnerRoute 5y agoIt's not clear to me that this is actually a "state of emergency". The BBC has now quietly amended their headline to say "US passes emergency waiver over fuel pipeline cyber-attack." (The web page calls it a "Regional emergency declaration.")
- kumarski 5y agoI know exactly what stocks I'm buying at 930am tomorrow morning. Keep your eyes on the oil major folks on twitter to see what happens: https://twitter.com/anasalhajji https://twitter.com/anasalhajji https://twitter.com/calvinfroedge https://twitter.com/calvinfroedge
- sswam 5y agoImagine if major companies used secure operating systems, backed up their data, and tested their disaster recovery plans? There's this thing called ZFS, and it's not rocket science.
- beemboy 5y agoThis is depressing and not going to stop because it is so lucrative and relatively easy for these malware companies to find victims. It makes me wonder if cybersecurity should be considered a state responsibility and infrastructure so it will be uniform and available for every business like electricity or police protection.
- aembleton 5y agoIf it is uniform then when a weakness is found, the whole economy can be exploited; rather than isolated companies.
- elliekelly 5y agoIsn’t this already the case? Like SolarWinds?
- marsven_422 5y agoThis should suprise no one. The same elites that was talking about pandemics a few years ago at their gathering has already moved on to talking about cyberattacks..... Remember evil exists.
- snambi 5y agonice timing for this "cyber" attack on an oil pipeline company.
- 1vuio0pswjnm7 5y ago"Multiple sources have confirmed that the ransomware attack was caused by a cyber-criminal gang called DarkSide, who infiltrated Colonial's network on Thursday and took almost 100GB of data hostage." re: "infiltrated Colonial's network" I have been reading some of the other reports of this incident from different publications. Many of the stories include a line about attackers downloading "100 GB in only 2 hours" as if that was being downloaded from the company's on premises servers. Eventually I found a story that disclosed the data was actually downloaded from a cloud provider.
- ocdtrekkie 5y agoIt's a lot easier to pull the plug on on-premise systems.
- bdamm 5y agoIs it though? We have plenty of cases of on-prem and in-cloud going down. And we have also plenty of evidence that some companies do actually manage to do disaster recovery pretty well. Not all, of course, usually those that experience frequent disasters.
- ocdtrekkie 5y agoMy environment is mostly on-prem, and it's nearly always the cloud services that drop out and leave us high and dry. In fact, not long ago, a cloud service we don't use went down, and it took one of our vendors down, and their cloud service went down, because of an outage with a completely unrelated service we don't use! The cloud is a house of cards that is run by companies that should have disaster recovery down, and really don't even come close. Meanwhile, I can unplug one cable to isolate our site, and everything that isn't a cloud service is pulled offline. (And delightfully, almost all of it would still be independently operational until I plugged it back in, too.)
- hughrr 5y agoIt’s really not. SME branch office is dead easy. Multinational corporations virtually impossible. In the cloud you can stop your whole VM estate, nuke roles and access and pull an audit trail and access logs for everything in a few minutes. Without even getting off your butt. Or having to negotiate with a branch office IT team who disagree with you. In the 20 or so years I’ve been running ops for corporates, the cloud is the nearest we’ve come to half decent DR and emergency response capability. It has got to the point now where compliance and audit is built in and I can actually write some code here and there rather than arguing about trivial stuff like “what happens if X happens” with people who are only in it for the pension.
- rurban 5y ago* There exists a decryption tool for DarkSide https://labs.bitdefender.com/2021/01/darkside-ransomware-decryption-tool/ https://labs.bitdefender.com/2021/01/darkside-ransomware-dec... * Critical infrastructure should not be allowed to run on Microsoft Windows * The remote workers, through which the attack was performed, didn't even use a VPN, just TeamViewer and MS Remote Desktop.
- ineedasername 5y agoAny chance this acts as a catalyst to face the ransomware problem head-on? Someone in a position of power in US intelligence agencies has to know this won't be the last time that a massive piece of infrastructure is taken down.
- sabujp 5y agoWe knew about this since before 2000 probably, earliest articles I could find : 2007, 2009 : https://www.cfr.org/backgrounder/americas-vulnerable-energy-grid https://www.cfr.org/backgrounder/americas-vulnerable-energy-... , https://www.wsj.com/articles/SB123914805204099085 https://www.wsj.com/articles/SB123914805204099085
- dang 5y agoAll: please don't post flamebait such as calls for war and whatnot. It's incredibly tedious. We're trying for interesting conversation here. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- piker 5y agoRansom ware seems like a potential antidote to vulnerable US digital infrastructure. It provides a persistent, material bug bounty which incentivises the C-suite to fix them.
- asien 5y ago> which incentivises the C-suite to fix them. It doesn’t. It provide C-Exec material to increase significantly Cyber Defense budget not overhaul Information System. For those executives these are two different topics with different budget. Of course for regular engineers it’s not, legacy infrastructure is probably much simpler to hack than modern one.
- ackbar03 5y agoYes! The ultimate bug bounty program! Instead of ranking on some hackerone or bugcrowd leader board you rank on the FBIs most wanted list!
- calkuta 5y agoWho decides how many hours we're allowed to work, driving trucks, fixing jet engines, taking care of children, or doing anything else? Our and our employer's liability for errors is enough motivation to maintain safety at a reasonable level. Put another way, is there statistical evidence of the efficacy of these regulations in reducing trucking accidents? Not that I could find!
- elliekelly 5y agoDrowsy driving: https://www.nhtsa.gov/risky-driving/drowsy-driving https://www.nhtsa.gov/risky-driving/drowsy-driving
- black_puppydog 5y agoNothing to do with this article, but... when did "legitimate interest" become the thing advertisers^Wtrackers are (ab)using to keep tracking on by default? It's not due to a change in legislation afaikt, the GDPR hasn't changed in this regard, right?
- deleted 5y ago[deleted]
- crazypython 5y agoNote that the group has an ethics page. They only attack large, for-profit corporations.
- crazypython 5y agoAlso, they donate part of proceeds to charity.
- lucioperca 5y agoI would love to read the IEC 62443 risk analysis of IT-infrastructure of the pipeline.