The Colonial Pipeline Was Fine, Shutdown to Make Sure Its Owner Would Get Paid
jalopnik.com
jalopnik.com
Yes, in fact, if a store's computers go down they don't just let customers walk out the door with products and hope they get paid eventually?
As far as I understand colonial is basically a big gas station connected with a series of tubes. Look ma, the gas pump still works but it doesn't keep track of how much we pumped or charge us any more!
Of course they shut down if they couldn't bill?
It's being treated like some kind of greed when in reality they didn't want to give away millions of dollars of fuel they couldn't track or bill for.
The colonial pipeline was fine... except it couldn't do the thing it does which is sell gas to distributors, it could only give it away.
Sigh.
This isn't "fake news", but it is... shitty news? News which gives facts and a ridiculous analysis?
I'm still trying to find out what actually happened in Israel but god forbid a news source or commentator actually lay out the details of a complicated situation... (if you're not getting everybody pissed off about X, then you're not doing your job as a reporter?)
This is exactly what we expect them to do in a crisis situation. This is also how Hollywood portrays ethical behavior. The store owner in Jericho (2006 TV series) is the first to come to mind, but there should be plenty of other examples.
And good deeds come back to us.
It's not too far fetched either to hope that their customers would be willing to self-report. Sure you might get some people who'd take advantage of the situation, but it's not a the total loss scenario of giving away your product for free that you're talking about. Add in the opportunity cost and shutting down delivery if you have alternatives that may not be 100% accurate billing is probably a net loss for the company, though it's impossible to say.
> I'm still trying to find out what actually happened in Israel but god forbid a news source or commentator actually lay out the details of a complicated situation... (if you're not getting everybody pissed off about X, then you're not doing your job as a reporter?)
It's a bit ironic to take a morals-over-profit stance on reporting right after having taken the profit-over-morals stance of gas pipelines.
Would you bet millions of dollars on the goodness of the typical person?
Somewhere in that question is an answer to the Fermi paradox!
They are all literally trusting in the goodness of the typical person. And then doing some careful analysis and planning. And fraud detection for the rare misdeeds.
Yes, the system would fall apart if you disputed every single transaction and made them supply irrefutable evidence you did in fact authorise the transaction - but it doesn't revolve entirely on the trust that people will keep their own account of what they think they spent.
And before everything was networked, there was no way for a store to check with the credit card company that the card wasn't reported stolen. That's the trusting people part, it's the store that is trusting people without the ability to even verify that the card hasn't been reported stolen.
Yes, there is a paper trail, but the situation I'm talking about is analogous to a bad check or a counterfeit bill -- there's no recourse if the bad actor can't be found and the store is on the hook.
I am just about old enough to remember this time - it’s funny to think that security hinged on checking if the signature looked ‘right’. For cheques I remember here at least for yours to actually be accepted anywhere you needed a ‘cheque guarantee card’ which was basically just a debit card but with a fancy hologram - so a certificate of your ‘goodness’ - up to a certain limit per cheque. The shop would copy the details and this would supposedly guarantee they’ll be paid.
I was going to say that shops could have asked for ID - but at this time driving licences didn’t have a picture and weren’t cards - so no one carried them anyway. There was probably a lot of ‘subjective’ acceptance around the place (‘does this person look trustworthy, would they really be given a credit card or did they steal it?’) come to think of it…
This is about business to business, not business to consumer. I suggest to talk to a financial/accounting person in a big company. Often enough there are mistakes in payments that are only noticed by the other business. This despite all the various layers that should've prevented the entire problem.
I don't mean small mistakes either, I mean where someone wanted to enter something like 1234.56 (two decimals), but it ended up as 1234560.00. Basically a mixup between the decimal and thousand separator; such mistakes happen way more often than you'd think. I've heard various stories of a vendor notifying the company that they've been overpaid, e.g. the 1000 times what it should've been, but also various other kinds of mistakes.
Some companies have been working together for various decades. Employees might've switched between the companies, people know each other. It really isn't uncommon to have quite a bit of trust between companies. Obviously, this does depend on the country. In some parts of the world there's more trust than other parts.
I'm not taking a position on the similarity or dissimilarity between shutting down a service because you can't bill accurately and shutting down a service because you refuse to interoperate with other providers.
All I'm saying is Texas customers did get their electricity cut off recently.
At any rate you are just looking for something to cry about. You asked for a hypothetical counter example not expecting to get one and now are splitting hairs to qualify big tears.
"As of Wednesday morning, when the power outages were at their most severe, the cold had snuffed out about 46 gigawatts, or about 40 percent, of power-generation capacity in the state."
Sounds a lot like the grid did in fact run out of "fuel" (as in the product that they deliver).
>You asked for a hypothetical counter example
Of an electricity provider cutting power of its own accord because their billing service was not functioning, not because the electricity production in Texas dropped due to freezing while demand shot up.
The only approach I see is perhaps to have written into contracts with all buyers some kind of compensation for the pipeline being unavailable per hour.
Then colonial will prefer to have the pipeline turned on handing out free fuel because it's cheaper than the compensation for turning off.
Spoken like someone who has never done business.
They better do that if they get the permission from the gov't to operate the only grocery store in the area, and people weren't able to get food otherwise.
Providing service without hope of ever being paid is stupid. The market is pretty good at selecting against stupidity.
Instead, set up strict SLAs with harsh fines; make it more expensive to shut down than to provide free service.
One company which suffered a cyber attack solved this partly by transferring a rough estimate of what a vendor should've been paid as a bank transfer. This up front. They did similar things for smaller vendors (smaller vendors might have bigger issues not getting paid on time). Not for everyone due to the amount of work involved. They got agreements in place to sort out the exact amounts afterwards. This required a huge trust and at the same time it created a great amount of goodwill from those vendors. Meaning, these vendors took over work on behalf of the company.
Afterwards the exact costs can be figured out. What is important that business continues as much as possible, if you completely stop your business you'll also not have any revenue you could maybe charge later.
I think the pipeline action on first hand is a rather stupid action. Loads of business is pretty predictable, plus often you already had the insight on the orders for the coming period. The cost of some mishaps and the economic damage to the country should be considered as well. It seems a case of "penny wise, pound foolish".
Regarding "payment processing" breakdowns: there are various things in place in NL for that, though most don't know. Simply stated: you fill out a paper form, sign it, done.
It's one thing with a supermarket and anonymous masses of customers, but an oil pipeline where each customer is supposed to have meters running on their side as well (as double verification to protect against technical issues)? If you can't trust your known (!) customers enough to not rip you off, something is very much off.
And even in that case: the government could have told the pipeline owners "we'll pay off any differences after settling, now go and get that pipeline up and running again".
it whats likely happened was that the hardened industrial control network was pretty much fine meaning that engineers inside of the pumping facilities could manually direct/redirect flow with all the required safeguards still in place, but that they had no plan for where to direct the flow as all information about who needed/ordered what sat in the unhardened corporate network.
This is kind of similar to what happens to warehouses and "just in time" factory lines when the order printer/queue ceases up, or is no longer fed data from the back end system, and while one might expect that the operators of critical infrastructure have a plan for minimal services when/if the unhardened corporate network fails but that plan(even if it existed) likely sat on the same unsecured and now encrypted network.
Pipes are useless without something to flow through them, and no oil producer is going to fill the pipe without a system to get paid.
If the pipeline is seen as a piece of critical infrastructure [1] - where its closure can damage other parts of the US - then if Colonial didn't tell the FBI, CISA, the Department of Transport (or whoever is in charge of that part of infrastructure) that the reason they were closing it was because they couldn't bill their customers rather than it being a safety issue, I imagine they are in trouble.
They were lucky in that it was only down for a short period, perhaps its OK - if it had been down long enough so ambulances stopped running and food and goods weren't delivered - then I'm sure the government would have told them to restart the pipeline and billing would have been sorted out some other way.
[1] https://en.wikipedia.org/wiki/Critical_infrastructure_protec...
That doesn't at all come for free. Entire departments and businesses revolve around making that complexity disappear. Gettting locked out of your infrastructure to do that is essentially paralysis of your business period. It isn't a case of "Just put some meters on the tap of the pipe" .
You have to be able to read them, you have to know to read them and when, you've got to know where the invoice goes, what terms were negotiated, etc. If you don't have access to that dataset, the only physical way for the human network to recreate that web is by people picking up phones and blowing up and slamming your point of contact which runs into the issue of having enough people on your end to handle things in the meantime, and your customers actually knowing who to call, and javing planned a procedure for a massive degradation in your info system, even if it means going back to pen and paper.
You can order dozens of types of oil through the pipeline. With travel distances of thousands of miles, many destinations, and the need for product segregation, the pipeline knows where all the oil is going.
If they couldn’t track segregation and destinations in the pipeline, that is a good reason to shut down. If they were just going to be delayed in sending out invoices or had to input some items into the system manually after recovery, they most definitely should not have shut down.
Wouldnt that then conceded the pipeline was not fine?
>If they were just going to be delayed in sending out invoices or had to input some items into the system manually after recovery, they most definitely should not have shut down.
I am willing to bet a signifigant number of "customers" (businesses in this case with teams of lawyers) would challenge the vailidity of invoices based on estimates and not actual usage. Theres no free lunch, the pipeline owners understand this and decided its in the best interest for their company to stop deliveries until the system that manages their order tracking is back online. Thats totally reasonable.
The US government (and states for that matter) made 0 guarantees of coverage of any thing. And even if they did, its not like the government does much to make anything a straightforward process.
What if billing is tied to metered usage and it was impossible to meter? Or what if the billing system is needed to shut off access when customer has reached a quota? The article is scant on details but "legal contracts and invoices" are not going to save a company legal fees with when multiple customers dispute their bills.
At some point, however, it starts impacting the economy and there would have to measures in place to get the fuel going regardless of whether the corporate bean-counters (and their malware infested computers) were fully "ready". I don't know what that point in time should be. But the fact that there were news stories of imbeciles hoarding gasoline and emptying fully loaded gas stations within a couple of hours certainly makes it urgent to get the pipeline running sooner. Can't we all just get along?
Now, this was a semi-independent franchise owned by a local family. Across the street, the chain big-box store had the same thing happen and they put a sign on the door saying "cash only".
I know it's a commercial operation but there's strategic reasons to keep it up. The attention it got from the US is evidence of that. Plus, they could have just made an educated guess on billing and resolved it later. Even the US could have made cash flow happen if that was an issue. And anyone who tried to take advantage of that would likely get the US's attention. Not worth it long-term.
But all this was overshadowed by the risk of ransomware possibly attacking the industrial systems which is really why it was shut down.
They should also be fined for letting their billing system get compromised.
To hack and shut down infrastructure does *not* require penetrating the actual infrastructure. Instead there are (likely far more vulnerable) "support systems" that if compromised will have the same effect. Why pick a hardened target when a soft one will do?
It's like arresting Al Capone. He didn't go down for all the violence, etc., instead it was tax evasion.
From the author's own sources...
> Colonial’s corporate IT network and the process control network are connected and exchange information about how much fuel each supplier or distributor receives in order to bill them for it.
> ...they could change [data about the] flow rates, they could modify the data
> Although infecting Colonial Pipeline’s process control network would be disruptive, it isn’t the only concern. Colonial’s control system also connects to the control systems at tank farms that feed fuel into Colonial’s pipeline.... An attacker can potentially pass through Colonial’s control systems into the control systems of these farms.
I really hate advocacy journalism. It's such a fundamentally dishonest medium.
Instead of having that discussion, we have no discussion because people like you have decided to flag this issue. This is the problem with HN.
Privatizing infrastructure is extremely positive if there's any chance for competition to arise - for instance, Italy has moved from a monopolistic state phone company to a well regulated and open free market, which has caused a boom of competing companies that has massively driven prices down. I now pay €27/mo for unlimited 1Gbps/300Mbps fiber and €7/mo for my phone plan with 50 GB of data, unlimited calls and unlimited SMS.
This is offset by the sad state of our highway system, which has been handed off to private companies a long time ago. There is obviously no way to create competition in highways (what are you going to do, build a cheaper highway next to the already existing one?), so the main company (API) has been neglecting mantaining infrastructures up to the point that a few bridges have collapsed, killing people and creating huge preventable disasters. Tolls are also crazy expensive, often amounting to half the cost of a road trip (and here petrol costs €1.50 per litre).
There's no incentive for a private company to invest a single cent as soon as it becomes a monopoly, it is something that has been known since the dawn of man.
This goes as far as privatizing toll collection on public streets. Unsurprisingly this always leads to badly maintained infrastructure and higher costs in the end.
Iliad helped lowering prices by offering a lower end service.
Colonial Pipeline is a common carrier, "moving gasolines, kerosenes, home heating oils, diesel fuels and national defense fuels" (the US military runs on something which has the additives to be used either as JET-A or diesel fuel) "to shipper terminals in 12 states and the District of Columbia." Some pipelines switch from one product to another, usually with a slug of water in between for separation. There's valve switching, tank filling, and tank emptying going on. If you can't coordinate that, the wrong product ends up in the wrong place. If they lost the system that tracks what's where and where it's going, they have to shut down, or, as they seem to have done, dropped the pumping speed way down so they could operate the system manually.
It's not just one pipe that carries one product.
Unix(tm) and mainframes predate windows server by a far margin and was never seen as inferior to windows by the wider sysadmin community, there might have been a time when windows server had merit as the discount solutions for people who could not afford highly available Unix boxen, but it was never seen as superior or particularly well suited for critical infrastructure.
I think that's kind of whats in play here, few finance systems were designed as critical as well finance was that department that generated a few reports that nobody really read and rarely interacted with the core productive business to the point where flaws/bugs in finance systems could have an real impact until very recently so what you have is a bunch of aging discount/non-critical system that have been promoted to critical infrastructure nearly by accident.
The same goes for the desktop support infrastructure build around AD and SMB file shares, where systems that used to be auxiliary nice to have for clerical workers ended up as critical for the actual productive divisions without ever receiving any real hardening.
I have personally been involved in more java fat client then activeX based fake webapps, but im also not an wintel admin with an background in non-critical mid sized business applications.
Trumpet Winsock was a very important piece of software for a bit, from Windows 3 to 98.
Serial ports were much more popular back then.
*nix OSes may have been as far superior to Windows as you can imagine, but the development ecosystem certainly wasn't. There were Delphi, VB and other RAD tools for Windows, with tons of GUI and general purpose libraries and toolkits. Bun on *nix you basically had just GCC and vim/emacs. There were no GitHub, no npm, no AWS, nothing. If you'd compare TCO of an enterprise app plus necessary infrastructure, the Windows-flavored one would come a clear winner. Even mixed environments were too much of a hassle, due to poor interoperability.
I am not sure what the registers ran, but they were IBM, all text-based.
Also, I remember my friend was a manager at AMC theatres at the time, and their system was entirely text-based. I remember watching him run end-of-day reports and you could see it zip up the files and hear the modem dial out and connect to corporate.
I dont think i can recall any commercial Unix even shipping gcc back in the day.
From the author's own sources...
> Colonial’s corporate IT network and the process control network are connected and exchange information about how much fuel each supplier or distributor receives in order to bill them for it.
> ...they could change [data about the] flow rates, they could modify the data
> Although infecting Colonial Pipeline’s process control network would be disruptive, it isn’t the only concern. Colonial’s control system also connects to the control systems at tank farms that feed fuel into Colonial’s pipeline.... An attacker can potentially pass through Colonial’s control systems into the control systems of these farms.
I really hate advocacy journalism. It's such a fundamentally dishonest medium.
What I don’t get is why they couldn’t gather the data manually to keep things running and sorted it out after the fact. They didn’t have any DR planning for something like this? Station people with clipboards and cameras at all meters. Measure the inputs and outputs as they occur. It seems there was just no real impetus to act responsibly here.
How quickly can you train them?
Where do they send the collected information?
How is the collected info processed and aggregated?
How much money is lost doing the above versus just shutting down?
I think their DR was fine. It is the HA that was not.
$5mil from net revenue of $400 mil is less than 2% of profits, and it has been operating for 80 years.
Honestly, I think the environmental damage the pipeline has caused is much worse.
I mean, I'm kinda old timey, so ot"s not infeasible from my point of view; but in today's hyper-optimized, bottom-line over-fault-tolerance world, I don't see that happen all that much.
Heck, I have trouble getting a straight answer out of the youngin's to "What is a filing system?"
Adjust the bill next month, in the light of figures.
Rather than bail out the company perhaps nationalizing it is the better recourse. It would certainly make other companies seriously reconsider how they invest in DR and security.
..., shut down ...
> [the] shutdown [was] to make sure
Or with your correction it would be read as:
> [it was] shut down to make sure
So it’s not incorrect in the source article, it is just using the noun shutdown, rather than the verb to shut down.
What? Did the author think that the ransomeware literally locked valves?
"the operational network that controls its pipelines and distributes fuel is separate from the corporate network and wasn’t infected"
The article thinks it matters whether the ransomware gets on the operational network, not your strawman.
In the early times of the pipeline shutdown this was exactly what was feared. Malware attacking, damaging, destroying or abusing industrial embedded devices to persist in to survive cleanups is nothing new. Stuxnet was just the tip of the iceberg.