Toyota suspends domestic factory operations after suspected cyber attack
reuters.com
reuters.com
- Cloud-based factory automation? Unsafe now.
- Mandatory remote diagnostics? Unsafe now.
- Remote updates? Questionable, and need to be blockable during crisis periods.
True story, had to manually fix vehicles (using SSH)
We've been doing B2B business for banks and we eschew any cloud/remote infrastructure as part of our offering because no one would pay for it. Everyone demands on-prem hosting of our software and it has to exclusively flow through their network security appliances.
I had a conversation with more than one CIO who would rather suffer arbitrary DDOS attacks than allow cloudflare the ability to decrypt their application traffic.
I am more than happy to work with these kinds of customers. There is no excuse to compromise on security when the stakes are this high. Everyone is willing to take their time to get it right.
I feel like I must have slept through the point where that was ever a safe option rather than just a compromise for convenience sake.
"Web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication." (Yes, they actually put a web server in a device which directly controls high voltage relays in power grids.)
"UR IED with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user."
...
Those particular bugs were supposedly fixed.
[1] https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02
I was also told that most Cloud-based providers have a shared responsibility model when it comes to security, wouldn't that jeopardize some of the existing relationship between the business and the Cloud Platform?
First, companies lie. I've been through a few companies that were audited for security compliance and simple truth was the company made great pains to keep the auditors away from but a few key people who will say what the auditors want to hear. Once, I was even told what I would need to say if I were asked (and it was blatantly untrue). Companies see security as a cost, not as an investment for on-going operations. So, the goal is to check it off the list that you're complying, not actually do it.
Second, best practices actually aren't. For instance, in my company I talked with the head of security after a presentation. I said that having passwords rotated was a horrible practice. It forces users to come up with something memorable. We should be using password managers and start using a long, random, gibberish passwords. He agreed, but "this is (such and such's) standard of best practices we contracted to support so we have to do this."
...and that's about the whole article.
How is this even considered an article? Can't find the author too, perhaps it's automated?
It really could be either, and they have very different implications!
I know clicking through will tell me, but even without taking 'cyber' into account, meaning in 'simplified' news headlines is hard to find with the huge amount of specifics and context required with a lot of global news coverage.
Supplier is apparently Kojima Industries, their website is being hammered: https://www.kojima-tns.co.jp/en/. Or maybe it's down because of the attack?
Article says a plastics supplier was hit, which isn't the same as Toyota being hit.
No where did they imply Toyota was hit, however to believe it is any less serious because a Supplier was hit vs them directly shows ignorance of how manufacturing works
Supply Chain attacks are very serious and are how a lot of malware is moving because the primary targets are getting very good at preventing direct attacks however supplier are often overlooked as an attack vector, and even if they are aware of the risk, that risk is often very much understated
I agree. The title is click bait.
I, too, thought it was an attack on Toyota based on the title. I see where you're coming from in saying that it's not, but because many of us have stated that we were confused by the title, I don't think it's fair to say that it's "not at all" click bait. It is, at least just a teensy bit.
Was there a cyberattack? Yes. Did Toyota suspend domestic factory operations after it? Also yes. I'm content.
Moreover, geopolitically, there is a HUGE difference between random plastic company being a random extortion victim, and Japan’s largest company being the target of Putin’s retaliation.
Not saying it was not, but the idea that only Russia would attack Toyota directly, and only random attacker hi suppliers is not true
> Toyota wasn’t directly targeted
GP is trying to say this is the assumption you’re making. Supply chain attacks can be a clever way to disguise a direct target as an indirect one.
I agree with you though, the headline could be more clear.
If someone were to attack a major private utility in the US, for example electricity, they would not be directly attacking the US Government but I do not think most would find a title similar to this being clickbait.
From their about page [1], assuming you can take it at face value.
That depends, has the NSA ever given us reason not to trust them..?
China on the other hand, has a new auto industry to take over the world.
Why is your supply chain so vulnerable that a cyberattack on business partner (or multiple) causes you to close down *all* plants in your country? That's insane.
That sounds like your supply chain is the key problem here, and the cyberattack is just a smokescreen that is compounding the problem.
It's obviously not perfect and can get caught up in systemic issues like a pandemic, but as mentioned in a sibling comment it's still cheaper than the alternatives.
However, the article suggests that Toyota has to shut down all operations the minute their plastic doohickey supplier goes down - ie they have 0 buffer. That doesn’t seem optimal. Given that there are dozens or hundreds of suppliers, on any given day, isn’t at least one of them having issues?
Today there's all of these metrics available that give it the feel of an exact science, but its not. It's educated guesswork, but there's enough evidence showing it works that its worth substantially increasing the costs and friction of doing business to align with its outputs.
Usually.
In this case something arguably failed in the process. It's noteworthy but it's not an existential threat to Toyota. They will learn from it, someone's probably going to 'seek opportunities outside the firm' and they'll get back to making great products.
https://www.france24.com/en/live-news/20210512-lessons-from-...
In short, FMEA is a way to calculate risks and prepare for supply chain issues to a certain degree. When done correctly those FMEAs get very large and extensively lay out where risks are high so plans can be made to minimize them.
1: https://en.wikipedia.org/wiki/Failure_mode_and_effects_analy...
American factories are closed because of “chip shortages.” It seems way too early to say it was a cyber attack, much less for it to already impact production.
That’s a funny way to spell “Russia’s war on Ukraine”. :)