U.S. Escalates Online Attacks on Russia’s Power Grid
nytimes.com
nytimes.com
Why are these systems even connected to the internet?
Decades ago, creating such connections might have been a forgivable oversight, since the internet was a much more peaceful place, and the idea of cyberattacks might have seemed like paranoid science fiction.
Today such attacks are happening in front of our noses and these systems are still connected to the internet?
It really boggles the mind.
On the electrical distribution side, there are a few things which may need internet connectivity. Getting map tiles for displays; having an externally contracted call center integrate with the outage management; automatic vehicle location (painting crew vehicles on the displays).
Adding to the last point, something that is coming to the industry is read only access to the system from a mobile device. This requires internet or a private network across the bounds of your network.
I don't want to talk too much about company specifics, but typically modern systems will have servers dedicated to only internet related functions. They will be internally firewalled from any servers which could make changes on the network. These systems aren't cheap though, a lot of what we replace is 15-30 years old. As such, it may not be as secure as it could be.
I've mainly talked about distribution. Transmission and generation also have functionality which requires the internet, or at the least a very large private network.
Otherwise, if you want to do it fully offline, it’s kind of a pain in the ass to run something like ArcGIS on prem and license navteq data.
It's been very useful to me personally, not sure what's unusable about it. I find the online version less usable because it nags me about GPS and obstinately only stores search history online, coupling it to the global Google Activity History setting.
If you have a GIS system, that is able to use Google Maps as the basemap, you still don't have the ability to save it for offline use. The APIs/libraries/license agreement with Google that these GIS systems use won't allow that.
Not that other providers (Bing, Here, etc) are any better. Your only way is to download OSM data/obtain local ortophoto and make your own tiles.
(Call me entitled, but I don't think it's too much to ask of an off-line map to offer point-by-point navigation and searching through the DB of addresses and POIs in the off-line map. When you can't do it, I get the feeling someone doesn't want you to use off-line mode, and is purposefully overcomplicating things.)
-- Sean McGurk, The Subcommittee on National Security, Homeland Defense, and Foreign Operations May 25, 2011 hearing.
If an apartment intercom can realize this is important, why can't an oil refinery?
Even larger utilities often have a rather small IT teams that are tasked with everything from keeping things running to change management, network design and architecture. And whether it is lack of time to focus on making the right things, or lack of time to even learn the latest right things<tm>, mistakes happen, all the time. And even when 'perfectly' implemented, it is far too often that we see that some one just decided that it's ok to run a cable from control room to open internet to make those night shifts a little less boring.
Person A: "but how will we know if one of our closed networks gets compromised?"
Person B: "I know, let's add remote monitoring capability!"
https://en.wikipedia.org/wiki/December_2015_Ukraine_power_gr...
I've done my fair share of inspecting critical infrastructure in different countries and 9 out of 10 times the reason is: cost.
Got a bridge / tunnel / trafostation that needs monitoring / interaction? DSL only costs 20 a month, let's do it! VPN and 2FA? Costs & our employees are going to kill us since that is too complicated. Updates of the OS and that application that was tailor made by the maker's daughter in law 10 years ago? Too risky and costly.
TL;DR Never attribute to malice that which is adequately explained by stupidity.
Given the state of play with security, a connection to the internet is pretty much going to always be more vulnerable.
The NYT decision to frame these efforts as “attacks” rather than “infiltration” is certainly an interesting one. In essence, the U.S. has built a (digital) mutually-assured destruction deterrent. We wouldn’t refer to past nuclear drills or tests as “attacks” on Russia, so I find the use of that phrase here intriguing. I assume they simply borrowed the vocabulary of security researchers, knowing that it would mean something different to much of their readership.
Regardless of your opinion US/Russia, we should all hold that words need objective meanings that can't be "bent" for convenience.
For some definitions:
https://www.beyondtrust.com/blog/entry/difference-between-a-...
That's not "testing nukes in your own desert", that is "sneaking into someone's factories and planting bombs", if we're looking for an analogy.
And I'm surprised that this is openly admitted by the US, and tolerated by both sides, instead of being treated as an act of war.
The analogy would be one guy telling a colleague that his fly is down before a client meeting. They both might want the same position but an unrecognized failure would make them both look bad.
Playing games with power grids etc is arguably much higher stakes than fighters messing with each other, or even with passenger planes. Or navy ships passing too closely.
Edit: I guess that it was more like a heads up for adversaries. As in "don't think that we won't". Just in case you didn't think we were that hardcore.
I guess that it was more like a heads up for adversaries. As in "don't think that we won't".
Example: https://en.m.wikipedia.org/wiki/R_(Factortame_Ltd)_v_Secreta...
It's the classic: "What are you going to do, hit me?" response after hitting someone. Just be glad most countries maintain some semblance of civility.
The original statement I could find [0]:
>recommending, in response to the "most extreme case" (described as a "catastrophic full spectrum cyber attack"), that "Nuclear weapons would remain the ultimate response and anchor the deterrence ladder."
I think this is referring to an unprecedented attack which intentionally kills many citizens. It's hard to imagine a scenario where nuclear weapons would be the warranted response, even if the cyber attack killed people, but I don't think the statement should be taken literally.
Either way, this is not that. These are the same espionage and sabotage games every big nation plays. Russia has been and probably is in many of our energy SCADA systems. China, too. And we're in theirs. That's just how things go in the 21st century. It will undoubtedly escalate; the real question is who will pull the trigger. (The US did at least once against the IRA, though that was in direct retaliation to disinformation campaigns aimed at destabilizing the US.)
From whom do they reserve that right?
Basically, the US has warned adversaries.
That didn't actually happen.
Edit: As in "WarGames".
Russia has been attacking critical infrastructure in the US for years. This is at best an incredibly latent response from a government who in many cases welcomes these attacks.
[1] https://en.wikipedia.org/wiki/Russian_interference_in_the_20...
[2] https://www.nytimes.com/2018/07/27/us/politics/russian-hacke...
https://theintercept.com/2016/12/31/russia-hysteria-infects-...
How do those contribute to national security? "control over internet"/gfw aka censorship isn't going to prevent any cyberattacks.
Same as having a centralised firewall on a corporate ISP, having a firewall on a country level can prevent / monitor traffic to whole segments of IT infrastructure.
Currently a lot of the microelectronics is still manufactured in Asia but there has been a steady progress in acquiring capabilities to manufacture them within Russia. The costs are usually much higher due to much lower volumes, but since these mainly go to military and government infrastructure, cost is not a concern.
Military might is what's keeping the peace. Any potential edge you give up can easily turn into an exponential advantage for your opponent. Ethics against similar force projection are a weak argument when defending your sovereignty.
The irony of mentioning treaties too. That's some next level true believer stuff.
Would love to have a chat about:
* Chemical weapons convention
* Mine ban treaty
* Rome Statute of the International Criminal Court
* Comprehensive Test Ban Treaty
* Anti-Ballistic Missile Treaty
* Biological and Toxin Weapons Convention
* Kyoto Protocol
* Reneging on the Iran deal and then forcing Europe to do the same despite US intel chiefs saying Iran they held up their end of the bargain.
* The half dozen worldwide commitments Trump has pulled out of in the last year, there's too many to count.
American foreign intel agencies have far more funding and skills than the next 10 largest countries combined. They do not play fair nor do they have to. Anyone claiming otherwise likely doesn't know much about it or wilfully ignores it out of nationalism.
If you consider how much power the U.S. has and how often it does not use that power to its fullest advantage, it's pretty remarkable how much it holds back.
Rules and reasons for why killing is okay are therefore all equally wrong.
I assume you're including the US in this, too.
This claim is repeated endlessly but I've yet to see any actual evidence of it. But that is par for the course in this era of disinformation.
It can only be beneficial.
Option 1: Use the intrusions to plug holes and learn best practices to apply across the industry. Come out stronger from it.
Option 2: Escalate, fight back and ruin innocent peoples lives thousands of kilometres away.
If you have time I highly recommend reading his book "When All You Have is Hope" - his transformation from an alcoholic to running a large coffee change and then later charitable work is heartening.
Why are mines in the Korean DMZ more important than mines anywhere else on earth? Because if that was all it was about then why are US violations of the (non-signed) treaty still carried out across the globe? Mines were used in Afghanistan.
Exceptionalism and nationalistic fervour that demands inequitable laws isn't something to proud of.
There's still thousands killed and maimed by US landmines each year in SE Asia and the sole country responsible has wiped it's hands clean of it. You don't have to look far in Cambodia to see old women missing limbs thanks to Uncle Sam.
The actual legal steps to ban landmine usage and production only occured in 2014 under Obama.
Everyone points to the south’s modern weaponry and US backing as reasons why the DMZ mines are not needed. However the US had a significant tech advantage in the Korean War and almost lost completely (even before China entered the war). They were saved only by a daring beach landing in the Battle of Inchon.
[1] https://www.abc.net.au/news/2019-02-02/us-to-suspend-cold-wa...
Pentagon and intelligence officials described broad hesitation to go into detail with Mr. Trump about operations against Russia for concern over his reaction — and the possibility that he might countermand it or discuss it with foreign officials, as he did in 2017 when he mentioned a sensitive operation in Syria to the Russian foreign minister.
Because the new law defines the actions in cyberspace as akin to traditional military activity on the ground, in the air or at sea, no such briefing would be necessary, they added. """
Way to bury the lede
Yes, way to bury the lede.
(current office-holder is no exception)
Trump just accused the NYT of treason for using the word ‘attack’
>Two administration officials said they believed Mr. Trump had not been briefed in any detail about the steps to place “implants” — software code that can be used for surveillance or attack — inside the Russian grid.
>Pentagon and intelligence officials described broad hesitation to go into detail with Mr. Trump about operations against Russia for concern over his reaction — and the possibility that he might countermand it or discuss it with foreign officials, as he did in 2017 when he mentioned a sensitive operation in Syria to the Russian foreign minister.
On a more serious note, does the US have red teams which try pen test our own power grid and other critical infrastructure? I don't believe I've ever heard of it, but I would have to assume at least one three letter agency does it right? (I hope)
I just open chrome to read the articles but if you want to be away from google, install a firefox derivative and setup to accept trackers and the like and delete all cookies on shutdown.
uMatix is invaluable, if you can install it.
But, really, asking about motives is just another way to ignore this. Motives will always be squishy and deniable. Look at what actually happens. They lied us into Vietnam with the Tonkin Gulf Deception. They lied us into the First Gulf War with the incubator babies. They lied us into the Second Gulf War with WMDs. We went to war in Afghanistan and Osama turned out to be in Pakistan. They lied us into Libya with some random exiles living in Switzerland plus a French philosopher. They lied us into Syria (thankfully not all the way) with gas attacks staged by our ally Al-Qaeda. They're trying to lie us into Venezuela with a recession caused by our own sanctions plus staged attacks on soi-disant "aid convoys". Now they're trying to justify a war with Iran with a video of CIA operatives in a boat. If you prefer older history, "remember the Maine!" was also a lie.
WTF
By the way, you can't derive story rank from points and submission time—HN's system is more complex than that. That's all that "WTF" means here.
In other words, HN is not ranking posts by votes, but by some (presumably handcrafted) algorithm that shapes which topics are more likely to make it to the front page. TIL.
This is how HN has always worked. There are three components to the system: community, software, and moderation. You need all three in order to keep a place like this functioning. None of this is secret; we post about it all the time and are happy to answer questions.
Which is a shame because I'm sure it is fascinating.
That's like blaming the dog for a fart.
The truth is that everyone operating HN would rather keep users in the dark about how and why stories land where they do. The idea being that if we could predict what the software might do, we'd try to manipulate the narrative, and if we knew when the hand of god intervened we might dare blaspheme.
But that gives up the truth anyway, because if we cannot know what "the software" will do, then we are prevented from knowing such facts, only in service to a false narrative, and that, in and of itself, is an unnatural intervention and willful deception.
When the software does a thing I say the software did it. When moderators do a thing I say moderators did it. Who knew that was controversial?
Who prevented you from asking how the rankings work?
Well, yeah. Did you think that was a secret?
Instead, to paper over the decrepit nature of the American political system, they are attacking civilian infrastructure in a nuclear armed nation. Insanity.
Uh, I think what you /really/ mean is:
In retaliation to numerous US Network Infrastructure incursions -from the same entity- the US has attempted their own software implantation within the attacker's networks.
Fixed that for ya! ;)
_____
Also, from the article itself which you apparently didn't read:
""" Two administration officials said they believed Mr. Trump had not been briefed in any detail about the steps to place “implants” — software code that can be used for surveillance or attack — inside the Russian grid. Pentagon and intelligence officials described broad hesitation to go into detail with Mr. Trump about operations against Russia for concern over his reaction — and the possibility that he might countermand it or discuss it with foreign officials, as he did in 2017 when he mentioned a sensitive operation in Syria to the Russian foreign minister.
Because the new law defines the actions in cyberspace as akin to traditional military activity on the ground, in the air or at sea, no such briefing would be necessary, they added. """
Edit: AFAICT both sides are "technically not wrong", homomorphic to the basic "free speech" argument, "it's technically not illegal".
I'm a bit flabberghasted that no one has constructed an ironclad technological solution to this wishy-washy dance of weak arguments, backed up by rhyme but not reason. Proof verifiers should come to politics.