Hackers Are Targeting Nuclear Facilities, Homeland Security Dept. And F.B.I. Say
nytimes.com
nytimes.com
Their most automated port, Maasvlakte II in Rotterdam, is still processing imports only; no exports. Some containers there are stuck in the stacks; they have a list of which containers can be reached. They're requiring paper customs forms and a paper commercial release, instead of their usual paperless system. Earlier, they were so down that the automated cranes could not unload ships. This is what Maasvlakte II looks like in normal operation. There are no people on the quay at all. All those cranes and AGVs are automated.[1]
Maersk's financial side is still down. They're not sending out invoices, which means zero revenue. They just announced a price cut, to keep shippers. Some of their phone and email systems are still down. The booking side is now up, so they can take new shipping orders.
This is the first time we've seen real-world outages of this magnitude. It may not be the last.
(Where's the Flexport guy who posts on here? He has to deal with all these problems. Flexport is a freight forwarder, which means that when something goes wrong with freight they are forwarding, it's their problem to fix it.)
Had this been several of the big shipping companies at once the world would be reeling by now, especially economically.
I suspect this hit many B2B companies that we're not hearing about because they're small and we aren't customers.
There's coverage on gcaptain.[1] Mentions on Reuters.[2] There's lots of coverage on the sites that cover container shipping. Most of the people in that business are probably working overtime right now. With Maersk down, cargo all over the world had to be re-routed.
All the status info is on line, but not in a journalist-friendly form. Maersk has a temporary "Operational Update" page.[3] You have to read through a lot of material to see what's up and what's down. As of late today, almost everything is at least limping along except at Maasvlakte II in Rotterdam. Their web site for booking and tracking has a banner which says "Submit Shipping Instructions and Booking are available but without email confirmation. Tracking, Online Quote and Binder are unavailable. Schedules last updated 27th Jun so may be inconsistent." This is not "back to normal".
Here is the Port Authority of New York and New Jersey's latest alert page for truckers: [4] That's a good read, because it's a no-bullshit source of info. Somewhere at the Port Authority, there's someone with a clue who gathers that info and gets it out. Staying open late and operating Saturday is not normal. Maersk APM's status page for LA is totally bogus; it hasn't changed in the last week.[5] The online gate webcams at Maersk's port in LA are still down.
(I've followed this subject because I'm interested in mobile robots which do something useful. Maersk's Maasvlakte II terminal is one of the largest mobile robot operations in the world. Probably the biggest by tonnage. Downtime on this scale is a major event in robot history.)
[1] http://gcaptain.com/maersk-hopes-full-cyber-recovery-early-n... [2] https://www.reuters.com/article/us-cyber-attack-maersk-idUSK... [3] http://www.maersk.com/en/operationalupdate [4] https://www.paalerts.com/recentmessages.aspx [5] http://www.apmterminals.com/en/operations/north-america/los-...
Incidentally, that seems like a pretty fundamental issue with news in general.
but I also can't quit the paranoid thought that this would be the perfect cover to conduct a secret operation requiring tons of material delivered all over the world. it's much easier to abuse/manipulate/bribe when everyone users paper records.
Victim blaming is bad at the outset of a problem. It's certainly bad in its usual context of sexual assault of the "ideal victim" by the "ideal perpetrator" [1]. But this isn't a case of an ideal victim. It's more like going on a safari in the Darfur region of Sudan. Have you not read the news at all?
"Hack me once, shame on you - hack me twice, shame on me". When shipping conglomerates, energy facilities, and manufacturing plants across the globe continue to be victims of hacks, and continue to devote little effort or funds to security, it's no longer the fault of the hackers.
> None of the SCADA for nuclear power plants will be on Windows thankfully.
I think the problem that is that the SCADA for nuclear power plants probably doesn't have the security you think it should. Download some Rockwell software, hook up to the Ethernet or set up a VPN on one of the office PCs, and enter "admin" and "password" and you'll probably be in at a lot of places. Perhaps, we can hope, not at a nuclear plant - but definitely for, say, an old coal plant, local government's municipal water, sewer, or traffic control, low-margin industrial manufacturing...the list goes on. The whole economy is cobbled together by networks that the engineers were pleased to just get to work in the few hours that their quote allocated for that task.
When the project is behind schedule and over budget, all that management cares about is the black-and-white, yes-or-no answer to the question "does it work?" There is no time or money for security. And when you take those shortcuts, you'll have no one to blame but yourself when you get hacked eventually.
[1] https://en.wikipedia.org/wiki/Victim_blaming#Ideal_victim
I felt the comment was blaming in that they would serve as an example and that that would be okay as they were at fault somehow. We do not know the infrastructural constraints in terms of legacy software with regard to whether they can safely take patches and it is unrealistic to expect large organisations such as Maersk to be able to do so automatically in my view. Having some small inkling into the matter, I feel that people must be arguing from a point of ignorance to suggest otherwise. I have even seen these script kiddie fans cry 'patch your shit' as if it is okay to release malware to global scale companies and they are somehow absolved from blame. It certainly is not.
Even if the initial infection was caused by an infected software update, its spreading mechanism relies on misconfiguration or unpatched software.
> only consider non-proprietary software in future
I'm a big proponent of open source software, but how is this relevant here? Microsoft handled the initial disclosure perfectly and provided patches before the vulnerability was publicly disclosed. By the time this attack happened, the patches had been out for a few months.
I certainly hope that they recover from this, but it's not like that kind of attack is hard to prevent.
at some point someone was sloppy.
This looks like scale models to me. Check eg 32 seconds in.
That's the tilt-shift effect, but according to the video producer, it's real footage.
>"For video sequences, a way of strengthening the miniature impression is to run the video at higher speed than it was recorded. This appears to reduce the inertia which would normally limit the motion of large objects." https://en.wikipedia.org/wiki/Miniature_faking
So why are the film makers using multiple techniques that make this video look "fake"? I'd think they would want it to look real.
It would be slow as hell since they move rather slow than seen within the video.
This is a promotional, rather than informational video, for the most part. Style matters.
Wolf Creek officials said that while they could not comment on cyberattacks or security issues, no “operations systems” had been affected and that their corporate network and the internet were separate from the network that runs the plant.
Good, I'm glad they are not insane, but I also hope they have pretty stringent rules to keep personnel from plugging in unverified devices. Stuxnet should be a lesson to all.
Is it so naive to imagine there are tech firms who could/would lobby for a no bid contract to do it?
I'm not an expert but I think there are some interests aligned there. If Trump has enough political capital to push plans forward to overhaul everything, this doesn't seem that far fetched.
Today if infrastructure is not 100% airgapped (and even that isn't necessarily enough) then it should be considered criminal negligence.
While nothing is unassailable, everything I experienced made me feel generally better about the approach these people took to safety. They wouldn't allow people to use spreadsheets to make decisions... literally this was not allowed, you had to have an app with testing and verification systems. Also, they pointed large automatic weapons at me while searching every crevice of my car, using long sticks with mirrors and various other instruments. It was a relief to see that they take security and reliability more seriously than any other kind of outfit I've worked for, ever. The monitoring had monitoring.
I'm no expert in journalism by any means, and I guess this comment has nothing to do with the article itself, but it did spark some curiosity.
Secondly, even if I were to find an article that is related to some piece of legislation, it would only be speculative and wouldn't prove that it is a "hit piece" in support for or against it.
Thirdly, off the top of my head, I can only think of a few things: SOPA from January 2012, Patriot Act (as mentioned earlier), the iPhone/FBI encryption fiasco (which did not result in any legislation yet, afaik), Net Neutrality, and Snowden/Wikileaks stuff (again, did not result in legislation afaik).
More examples are always welcome, but as I said, it is really tricky to speculate on the existence of a conspiracy based on a few articles and some hindsight - you really open yourself to confirmation bias, subconsciously. And for the record, I'd love to prove this is true.
As I said, this kind of thing is extremely difficult to prove without a smoking gun (e.g. an email from the head of state to the head of NYT instructing them what to publish, when or why). And, as both you and I agree, it is impossible to prove without equating correlation/causation or having confirmation bias in retrospect.
and i dont need any examples to prove my point other then, read some history and get educated.
1. No news outlet is impartial, neither major nor fringe outlets. (Most fringe outlets are more partial, though.)
2. Major news outlets mostly report the truth and correct errors when they are discovered.
> read some history and get educated
I always ask critiques of major news outlets to suggest alternative news sources and they either come up with nothing or evidently ridiculous suggestions such as blogs, conspiracy sites, and fringe right-wing or left-wing news aggregators that barely employ journalists, let alone a network of correspondents.
The best way to keep yourself informed is to compare different major news outlets, and if they agree on a story, then it's most likely true, because there is only one reality. It's really as simple as that.
Has this been a pattern? Do you have examples? Are there stories that the nytimes covers that other papers don't cover that suddenly become bills? What inspired this?
Your post comes across as a lot of innuendo without providing any support... at all.
hackers? since may? ie. when all the shadow_brokers exploits were released that any script-kiddy could point and click at a box and pwn it..?
the article implies these are nation state actors trying todo harm. a BS article trying to push a political agenda.
"The purpose of this talk is to provide a comprehensive description of the technical details and approach used to discover multiple vulnerabilities that affect widely deployed radiation monitoring devices, involving software and firmware reverse engineering, RF analysis, and hardware hacking."
That will be July 26 at Black Hat USA 2017.
Go Nuclear: Breaking Radiation Monitoring Devices https://www.blackhat.com/us-17/briefings/schedule/index.html...
Wasn't one of the IS terrorists of Paris employed in Belgium at a nuclear powerplant?
I can't speak for Europe, but I know in America even if you worked at the place you're not pulling off an attack. You're not going to sneak a gun past the check point. If you do somehow sneak in a gun or a knife, you're not going to live very long before the guards kill you. You're not going to get into someplace where your keycard/job status doesn't let you. Overall the most likely outcome is you trigger an unscheduled reactor shutdown and throw your life away. I can't imagine anyone making a 6 figure reactor job salary throwing their life away. Money > religion.
Still I stand by my point. Attacking a nuclear power-plant as an inside job is virtually impossible. There's enough physical security and mechanical fail-safes that nothing bad would happen.
Edit: also what the other guy said. He was a weld inspector. Nevermind, everything makes sense now. Sensational scare article is sensational.
I don't know the specifics of this particular plant's security procedures, but it's unlikely he was in a position to do any significant damage to the plant, and his clearance process was likely much less involved than would be for someone who is in a position to do real damage.
Convenience always works to the attackers gain, and convenience is the name of the game for engineers and managers and support staff. Unless the system is physically isolated and protected and there is no kind of networking available, it is effectively crackable. Even if physically isolated, staff can still be bought.
What's going to be done about it is the real question.
Not quite as bad as a nuclear weapon detonated in a big city, but still very bad.
Also Chernobyl had no containment dome.
Even the old GenII designs in the U.S. have much better inherent safety than Chernobyl had. There's no way to hack away physical barriers. Even TMI, our worst accident ever with a full meltdown, did not breach the containment barriers.
And of course with any commercial plant, there's absolutely zero chance of an actual nuclear detonation, much less a thermonuclear one as mentioned in the comment above. The fuel just isn't enriched enough to work as a bomb.
I knew before clicking that there would be a baseless nod to *Bear attribution in this article, and it certainly didn't disappoint.
https://www.google.com/amp/s/www.forbes.com/sites/rrapier/20...
If they mean they are targeting some public facing BS server for some website they keep, OK, who cares...
But anything functional and touching controls should be very well out of bounds...
If North Korea is attacked militarily expect hell to be unleashed online. What we've seen is just experiments, not actual attacks. A full-out war could be vastly more damaging.
And frankly, hacking into Sony is not that hard to do.
And then there will be a massive refugee problem on both sides.
A future war here might make every war we've had in the sandbox lately look like a summer barbecue.
I'd like to think we can keep a lid on things and work it out in a more civil manner, economically it makes more sense, but you know, dictators don't really care about economics as much as they do ego.
As terrible as a shooting war in Korea would be, it's still a lot better than a potential full scale cyber war.
This isn't about leaked emails or advance copies of movies, it's about attacking and permanently damaging large portions of infrastructure. If you can fiddle with a power plant you can destroy generators, transformers, and other extremely expensive equipment that could months to source, fabricate, transport and replace under ideal conditions. They don't have a warehouse full of spare turbines just sitting around.
Stuxnet showed what can happen if you pin-point target a particular system. If you broaden the scope of your targets, if you don't care about collateral damage, the stakes are very, very high.
Hacking into Sony wasn't hard and I have a sneaking suspicion that most infrastructure control systems are as bad or worse.
The black-out in eastern North America in 2003 shows how suddenly things can change if the grid goes down. That only lasted a day and yet the economic destruction was significant. Imagine if not only were the power plants offline, but they were crippled in such a way they couldn't come back without serious repairs. That is a possibility here. Months without power, without water.
I'm still not convinced cyber-war will lead to the coming of The Rapture.
[1]https://en.wikipedia.org/wiki/New_York_City_blackout_of_1977...
Imagine if not only is the grid down, but the phones are down, the water's down, and air travel is grounded because the control towers operators have been shut out of their systems.
Plus, as you're trying to restore the systems with what limited communications you have someone is actively trying to prevent you from doing your job, or there's enough booby-traps in the system that you basically need to re-install everything from scratch and reconfigure everything.
This also presumes no critical equipment was damaged in the attacks, which it probably will be. North Korea would want to wreck as much of everything as they possibly can if they're fearing a regime-ending invasion.
Just ask yourself which would be worse for you, say, a week or even a month without power or a rain of explosives randomly demolishing buildings in your city.
We can get stuff working one way or the other without networked computers but there is no reasoning with shells.
It stands to reason that the smaller towns will be hit the hardest since they're the least prepared for electronic warfare. Their IT department is going to be the same guy that tests the water and removes dead animals from the reservoir.
You have about 48 hours until things start to get really ugly. See also: Hurricane Katrina. They were able to minimize casualties by moving people to other hospitals that had power. Imagine if there weren't any.
It's not a great situation to be in, but many were able to flee to better places. If the entire grid is down there are no better places.
I just think their conventional military, their continually improving nuclear program, and their ballistic missile technology are a lot more real and a lot more dangerous than the cyber-pocaylpse people have been trying to scare everyone with since the nineties.
Now, when cars/trucks become fully self-driving ... now you have a scary scenario ripe for hackploitation.
Unfortunately we have not been as vigilant about security. We're barely able to handle script kiddies armed with a bot army of webcams. We're completely unprepared for when a nation-state actor declares electronic war.
You're right that as we get more and more automation going on our exposure surface grows dramatically.
So long and thanks for the propaganda, NYT.
In 2003 Davis-Besse had its SPDS disabled by SQL Slammer, a worm that congested the network on the site. So in answer to your question, yes these 1970s plants do indeed have devices interconnected in the contemporary manner, and compromises of these networks have already produced reportable events.
The core components of our power reactors are not at the mercy of software; operators have authority over reactor protection systems that are deliberately independent of complex digital controls. Nevertheless, a clever attacker could probably engineer enough confusion or interfere with ancillary systems badly enough to produce a notable incident such as a SCRAM. That would certainly make headlines and lead to a prolonged investigation.
Is it possible that greater damage could be done? Anything is possible. If so I'd imagine it might involve cooling pools, their circulation and alarms... who knows. Given enough time, knowledge and planning it might be possible to cause a serious problem.
It depends. Fission is complex. Factors include reactor design, fuel age, xenon accumulation, which parts of the RPS tripped, whatever axles the resident NRC inspector(s) wrap themselves around... those are few I can think of as a layman.
"Do they have any sort of fast recovery procedure?"
While operators do strive to minimize outage there is no general "fast recovery" procedure. There is a startup procedure and that's what you follow. If everything is optimal then 12-ish hours to begin the restart, several hours thereafter to become critical, then a relatively slow process of pulling rods until full power is achieved. "Hot xenon" startups are something you study and practice in a simulator.
The military has other prerogatives and naval reactors see rapid and frequent transients. Naval reactors are built (at great expense) to do this. They're also smaller than civilian power reactors; a 165 MWe naval reactor being thought "large" whereas a 600 MWe civilian power reactor is on the small side.