Norsk Hydro ASA Suffers Extensive Cyber Attack
bloomberg.com
bloomberg.com
This has hit Venezuela badly: https://twitter.com/AKurmanaev/status/1104141813936545793 "Today Venezuela basically crossed off an entire industry. In one day. No more industrial aluminum production. Just like that. It’s gone."
https://www.argusmedia.com/en/news/1863707-venezuelas-fragil... "State-owned aluminum smelter Venalum's remaining operational units and state-owned Bauxilum's alumina production units were destroyed by the blackout and likely will not be repaired for at least a year, a senior Venalum official said. "The primary aluminum and alumina sectors are dead for the foreseeable future." "
Now the power source of course... hard to manage that.
No source, though.
Well, for many of these plants they're actually built together with a big hydroelectric powerplant that can supply all the electricity needed.
EDIT: Their press release from 6h ago states "Hydro's power plants are running normally on isolated IT systems".
0: (In norwegian) https://e24.no/boers-og-finans/norsk-hydro/dataangrepet-lamm...
A diverse workforce can be a bonus when things go pear-shaped; with any luck Hydro (and others!) take the lesson to heart and train all staff in fallback measures as part of their disaster planning.
https://www.aluminiumtoday.com/contentimages/features/Oyeweb...
You get all sorts of problems, including from freeze-thaw[0] damage to the pots, the electrodes get oxidized, and the plant itself isn't fit to work in due to CO buildup (no fans!).
[0] It's weird to see freezing damage occurring at 900˚C, but I guess that is what happens.
Very soon we'll be talking real money. How do you price your ransom...we caused this much damage to Maersk, be smart...
I keep on hearing about the huge vulnerability they pose, which would make me expect a Y2K-level of focus by the industry.
We used to physically isolate security domains across the board. Everything is virtualized now, which makes it a whole lot less visible when boundaries are being violated, where it used to be obvious.
I would have thought that an imaginative prosecutor could find an existing law that could be applied to punish the payment of ransoms; even if it is only failing to pay some sort of tax or duty. Something like that is what is supposed to have brought down Al Capone.
https://www.intego.com/mac-security-blog/osxshlayer-new-mac-...
https://www.zdnet.com/article/eset-discovers-21-new-linux-ma...
(I'm going to guess it's a big NO on the first one, because no one uses Macs for critical systems.)
Microsoft Windows has got a major lock on the industrial control systems industry. Almost anything being produced today has a Windows machine in the workflow doing something critically important, from monitoring fluid flows to running microchip programmers and test stations.
"That's the way it's always been" isn't a valid excuse for continuing to make something unsafe.
They did not accept crippling ransomware by using Windows. Nobody does. This attitude is fatalistic and somewhat juvenile.
They may have implicitly accepted crippling ransomware by not having sufficient internal security processes.
Control software, or for that matter, software for a sufficiently narrow domain, tends to come "with bugs" and "for compatibility reasons you need to run this on OS/release version X (which is probably what the vendor ran at the point in time when the software were minted/released).
I've had the displeasure of crossing paths with both the linux and windows variety of this.
In some cases you can ignore the vendors and just upgrade, and jump through some amount of hoops to make it work.
I'm sure in most cases you could engineer around this with isolating it from the world, although it may be non-trivial since it'll probably want to communicate over a network of some sort. Although - exactly what is needed in terms of achieving that may be less than well documented, it costs time and money, and is maybe not really budgeted for, there's aggressive installation timelines, and the security part is probably the first thing to get slashed from when the installation timelines starts slipping.
The vendor just wants to sell you a black box, and preferably not touch it ever again after they've sold it to you. (Actually - some even do sell you a branded, badly engineered, stock PC running some variety of windows or linux or bsd, to control your winch/navigation/foundry/whatnot).
I have witnessed "IT for offshore", in which a vessel is docked for X days, here's a list of things that we need to do, after X days the vessel will depart. You may have a few days on top of X days if you can leave somebody at the vessel, after X+Y days, the vessel needs to be somewhere in an operable state, because we have a commissioned work to perform.
For say running a foundry, I'm sure much of this is similar, except the foundry doesn't have go anywhere - but having your foundry do nothing is exceedingly expensive, and making changes during production comes with a different set of risks.
People have probably complained somewhere along the road, disagreeing with the risks, and somewhere higher up in the chain, the choice were made to take on the risk.
https://securityledger.com/2015/10/fbis-advice-on-cryptolock...
I think things have shifted now to the where it's not something that's recommended.