TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack

258 pointsby opaqueabout 4 years ago

26 comments

tidydataabout 4 years ago
There’s nothing in this article indicating the operator has a recovery plan in place involving restoring backups to get these systems online. Seems grossly negligent on their behalf, and made almost satiric by the fact that Fireye can be mentioned without reference to their own massive security lapses.<p>Too much focus always on the “hackers” and never the obvious security lapses solved by diverting executive pay to more bodies and training to cover them, but oh well right?
评论 #27092991 未加载
评论 #27092683 未加载
评论 #27092972 未加载
评论 #27229860 未加载
评论 #27092777 未加载
评论 #27092977 未加载
评论 #27092826 未加载
评论 #27092730 未加载
jtchangabout 4 years ago
In a twisted sort of way I am happy to see these types of ransomware attacks making headlines. Before it was much harder to quantify how much a breach might cost but with ransomeware you get a fuzzy lower bound. Also the prevalence of these attacks might actually make us all safer in the long run.
评论 #27089083 未加载
评论 #27088161 未加载
评论 #27101349 未加载
评论 #27090433 未加载
motohagiographyabout 4 years ago
Let&#x27;s see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don&#x27;t suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulnerability facilitating it.<p>The global chip shortage for replacement parts if they are needed seems like a strategic coincidence. Definitely an evolving story.
评论 #27086943 未加载
评论 #27087236 未加载
koheripbalabout 4 years ago
Washington Post reported it was a ransomware attack.<p>It may not have been a targeted attack.
评论 #27088682 未加载
评论 #27087816 未加载
nfozabout 4 years ago
I hope this ransomware called itself the Da Vinci virus? Because this sounds a whole lot like the plot of Hackers [1].<p>The greatest movie of all time, btw.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Hackers_(film)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Hackers_(film)</a>
评论 #27093064 未加载
评论 #27092753 未加载
评论 #27092903 未加载
评论 #27092835 未加载
mikewarotabout 4 years ago
Connecting infrastructure to the internet is something that is done for many reasons. It would be a vast improvement of security if most of those connections went through a data diode[1] and only allowed monitoring.<p>Knowing what is happening now with critical infrastructure, through the internet, can be done in a completely safe manner. It is a solved problem.<p>[1] - <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Unidirectional_network" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Unidirectional_network</a>
评论 #27090200 未加载
评论 #27088322 未加载
Xunxiabout 4 years ago
It&#x27;s only a matter of time, there&#x27;s gonna be physical casualties at some point in time. We&#x27;ve all seen it in the movies. Experts have warned of the dangers of tethering vital utilities controls to the internet.<p>Is it not possible to develop protocol or device that operates outside of the web but functions like the&#x27;two-man&#x27; rule used to launch nuclear bombs?
评论 #27087809 未加载
评论 #27087965 未加载
评论 #27088086 未加载
评论 #27087477 未加载
评论 #27087468 未加载
评论 #27092715 未加载
v8dev123about 4 years ago
All these attacks usually caused by two things, office macros and mimikatz.
评论 #27092946 未加载
t3rabytesabout 4 years ago
A few years back we had two different instances of this pipeline getting shut down from newly-found leaks. While they say it won’t cause gas shortages, these articles tend to drive people to the pumps in droves in the southeastern states served by it (like mine, NC!).
rossdavidhabout 4 years ago
So, two possible responses by the government to the current increase in these kinds of attacks:<p>1) blame the lack of computer security in our infrastructure, and work on improving that<p>2) blame cybercurrencies, and try to eliminate them<p>Any bets on which one our government will choose?
评论 #27087617 未加载
评论 #27087378 未加载
评论 #27087224 未加载
评论 #27087152 未加载
评论 #27093234 未加载
评论 #27087065 未加载
评论 #27087567 未加载
评论 #27087193 未加载
ArkanExplorerabout 4 years ago
Given Government inaction on climate change, could we begin to see motivated individuals or groups taking matters into their own hands and targeting fossil fuel infrastructure in this manner?
评论 #27087286 未加载
bourgwaletariatabout 4 years ago
I wonder if this has anything to do with the Colonial gas pipeline leak? It&#x27;s been a problem for over 8 months now. Was in the news recently again. Over a million gallons spilled, but they don&#x27;t really know how much.<p><a href="https:&#x2F;&#x2F;www.msn.com&#x2F;en-us&#x2F;news&#x2F;us&#x2F;eight-months-later-colonial-pipeline-spill-continuing-to-impact-huntersville-residents&#x2F;ar-BB1fPAL6" rel="nofollow">https:&#x2F;&#x2F;www.msn.com&#x2F;en-us&#x2F;news&#x2F;us&#x2F;eight-months-later-colonia...</a>
CallMeMarcabout 4 years ago
On the good side, someday we’ll probably get an episode of Darknet Diaries on this one.
评论 #27092761 未加载
flakinessabout 4 years ago
After reading &quot;This Is How They Tell Me the World Ends&quot; [1], I feel the world working normally is rather a sheer luck. (Probably I&#x27;m very late to realize this, but anyway )<p>To me the only reasonable survival strategy is redundancy, but I have no idea how we can reach there.<p>[1] <a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;This-They-Tell-World-Ends&#x2F;dp&#x2F;1635576059" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;This-They-Tell-World-Ends&#x2F;dp&#x2F;16355760...</a>
dsyrkabout 4 years ago
I’d be curious to know how much ransom is being asked. Before Bitcoin something this big was impossible to try and pull off.
评论 #27093224 未加载
croesabout 4 years ago
Seems like this company has more than just IT problems <a href="https:&#x2F;&#x2F;newrepublic.com&#x2F;article&#x2F;161498&#x2F;huntersville-north-carolina-colonial-pipeline-spill" rel="nofollow">https:&#x2F;&#x2F;newrepublic.com&#x2F;article&#x2F;161498&#x2F;huntersville-north-ca...</a>
neonateabout 4 years ago
<a href="https:&#x2F;&#x2F;archive.md&#x2F;kEziH" rel="nofollow">https:&#x2F;&#x2F;archive.md&#x2F;kEziH</a>
mimikatzabout 4 years ago
We need to have military responses to these attacks. Ransomware is running rampant because they don&#x27;t fear any punishment for attacks. If people attacked our hospitals and pipelines with explosives we wouldn&#x27;t sit by and do nothing.
评论 #27093070 未加载
评论 #27093204 未加载
评论 #27093056 未加载
Griffinsauceabout 4 years ago
It&#x27;s hilarious to me that a country that invests so much in their military doesn&#x27;t seem to invest in the security of their infrastructure at all.<p>The entire war machine will grind to a halt without oil. It would be one of the first thing to attack.
评论 #27093043 未加载
protomythabout 4 years ago
Perhaps we should pass a law that no utilities &#x2F; infrastructure should be attached to the internet. Private networks are fine for this purpose.
评论 #27088105 未加载
评论 #27090036 未加载
wait_a_minuteabout 4 years ago
hmmm...might be time for me to develop a side-expertise in cybersecurity...always kinda scoffed at those electives before, but now I see that there are literal lives at stake if our nation doesn&#x27;t have excellent talent working in fields like cybersecurity for national defense.
joe_the_userabout 4 years ago
<i>&quot;This is as close as you can get to the jugular of infrastructure in the United States,&quot; said Amy Myers Jaffe, research professor and managing director of the Climate Policy Lab. &quot;It&#x27;s not a major pipeline. It&#x27;s the pipeline.&quot;</i><p>About that infrastructure security... this forum has gone over in detail the situation of infrastructure security in quite a bit of detail as other stuff has happened.<p>It&#x27;s easy to say &quot;you need to isolate your critical network from your office network&quot; but that costs dollars and time and letting things fall to shit is free &#x27;till the time comes and then other people the price rather than you.<p><i>The privately held, Georgia-based company is owned by CDPQ Colonial Partners L.P., IFM (US) Colonial Pipeline 2 LLC, KKR-Keats Pipeline Investors L.P., Koch Capital Investments Company LLC and Shell Midstream Operating LLC.</i><p>All the best names of neoliberalism!
评论 #27092947 未加载
Pfhreakabout 4 years ago
I&#x27;m surprised we don&#x27;t see more attacks on pipelines - both digital and physical. There are many folks out there who take issue with them or see them as a vulnerable part of our infrastructure.
dangabout 4 years ago
Url changed from <a href="https:&#x2F;&#x2F;www.bloomberg.com&#x2F;news&#x2F;articles&#x2F;2021-05-08&#x2F;u-s-s-biggest-gasoline-and-pipeline-halted-after-cyberattack" rel="nofollow">https:&#x2F;&#x2F;www.bloomberg.com&#x2F;news&#x2F;articles&#x2F;2021-05-08&#x2F;u-s-s-big...</a>, which points to this.
post_breakabout 4 years ago
Yikes, get ready for a huge jump in oil pricing.
评论 #27087189 未加载
评论 #27086787 未加载
评论 #27086755 未加载
Merrillabout 4 years ago
Why don&#x27;t critical infrastructure networks use a different CRC-32 polynomial for their IP packets?
评论 #27092932 未加载
评论 #27096857 未加载