We can be glad we have cars, trucks and roads that are a bit more resistant to attacks.
We can be glad we have cars, trucks and roads that are a bit more resistant to attacks.
It's frightening how easy it is for an foreign actor to knock out a country's railway system
The attack on SNCF was not "easy". This was a methodical, large scale, coordinated attack. They knew what to take down. How to take it down with least collateral damage. And when each should be taken down. (Order likely counts here. You're trying to plug up tracks.) Point being, these attacks are not "easy". In a place with as much unrest and discontent as France has bubbling beneath the surface, the trains would go down twice weekly, every week, if it was "easy" to do so.
A similar methodical, large scale, coordinated attack on our bridges would shut the system down as well. I won't even mention some other infrastructural assets that, if targeted, easily will shut us down for months because I think they are just that soft as targets. I honestly believe it would be irresponsible to even put the idea out into the ether.
The takeaway here is that if you're dealing with large organizations, with even a modest amount of resources, and a grievance, you're likely dealing with orgs that have a lot of young people they can send to successfully carry out such attacks. Thankfully, these attacks still require a level of technical knowledge that seems to elude such groups. So it's just matter of keeping that information as secure as possible on the one hand. While working towards security and resilience of those assets on the other.
It looks more like an elaborately prepared barbecue party: careful planning, getting all the details figured out ahead of time, coordination and, well, relatively calm execution.
The only novel thing here is coordination, but it doesn't seem like a huge stretch of the imagination to target the 4th most frequent high speed rail crossroads, which is exactly what they did.
Maybe foreign agents could do it with 50? If they were supported by satellites and other tools to which these attackers likely did not have access. But foreign agents are operating in relatively large teams even for simple missions. I don't think with this level of coordination, and this number of targets, spread over this large a geographic area, any intelligence agency is going to send one guy/gal per target. It only works like that in Bourne and 007 movies.
Um, sabotaging any city's water tunnels would make the city uninhabitable for years.
Most frightening experience I ever had as engineer in my life:
I was intern. At a place in a midwestern city where a city's water infrastructure can be monitored. Long story short, I heard "PING". Then three more "PING"s. Then another "PING". Then 2 more. Even as an idiot intern, I knew what the implications were with respect to tensioned concrete. I was thinking in my head, "8 feet diameter. 96 inches." But I couldn't remember the PSI because I probably had already soiled myself. Thankfully there was a grey beard there who coolly looked over at me and said, "Probably want to start shutting that down son."
2 things I learned. Calm is contagious. And our infrastructure is way more frail than should be the case.
How are you counting this? If you mean Hudson River crossings between NJ and Manhattan, there are five: two road tunnel groups (Holland and Lincoln) and three rail grops (Upper/Lower Hudson and North River). When Gateway is complete (2030s), there will be four rail groups.
But if you mean the entire NYC metro area, there are significantly more: Manhattan <-> Brooklyn alone has the Hugh L. Carey for road traffic, and then six active subway tunnel groups. Manhattan <-> Queens has a similar number.
Can totally picture
Extra points for putting the large bus or truck on it's side, requiring a crane or much more work to get it on its wheels.
And you don't have to walk off, you can unload your electric scooter and zip away to start your new life as a fugitive.
Real world has lot to learn from IT infrastructure management. :-)
A mere decade ago this was pure science fiction, but over the past few years it has become a possibility.
Basically every modern car can have software that says "slam the gas pedal as far as possible". Combine that with cars that are heavily integrated into their infotainment system or even include built in wifi and you've got the "over the air signal" covered.
I also believe that drive by wire systems are going to become even more commonplace in the future and eliminate the possibility of a driver attempting to muscle the car back into control.
That's why they were able to get some of the trains back to operation: they can't run them as close together as before, but can still use the tracks.
Meanwhile if someone throws spike strips on a busy highway/tunnel/bridge between two chokepoints, you're effectively screwed. If this is done in a concerted manner it will probably take at least a day to fix.
If you have more resources (say a state actor attacking a nation that isn't on a wartime footing), you can also exploit the fact that asphalt is a petroleum fraction and therefore soluble : spill a lot of diesel or hydraulic oil, for example (and optionally set it on fire) and you will unrecoverably ruin that section of asphalt, which could take weeks to fix: this is why gas stations are paved with concrete.
So while it's not as easy to do this as it is to derail a train or screw around a signaling system, it's far more difficult to repair professional roadway sabotage than railway sabotage, and in the end the railways are probably more resilient.
Now that Russia's invasion of Ukraine has occurred, and cheap armed quad-copters are a publicly known thing, I can say this openly:
Are you kidding me? Because we are still petro-centric, we are extremely fragile. For example, the West Coast has a handful of oil refineries. To shut down the West Coast's road traffic it would take one guy, and less than $10,000 in equipment. This could all be accomplished in 3 days, and there are no deployed defenses for this attack vector.
I have been trying to argue that the transition to EVs is a natsec issue for 10+ years. However, I am just some forum schmuck, and it has not been going well. Any help with moving this thinking up the chain would be greaty appreciated.
A possible analogy: The Internet was designed to be a multi-path, decentralized, and distributed communications system to withstand attack. That's what EVs are for transportation.
https://www.youtube.com/watch?v=pL9q2lOZ1Fw&pp=ygUSaGFja2luZ...,
Meanwhile, FERC found that knocking out just nine strategically located substations, of 55,000 at the time they did the assessment in 2014, would plunge our country into darkness.
https://time.com/6244977/us-power-grid-attacks-extremism/ https://www.wsj.com/articles/SB10001424052702304020104579433...
There is no way that I can be off-grid with oil. Meanwhile, 6 months after the apocalypse all oil products have degraded, and my solar panels and LiFePo batteries still have years left.
Also, post-attack, there is a huge difference in supply chain lag between setting up some solar panels vs a refinery.
If we lose, according to FERC (Federal Energy Regulatory Commission)... nine... of our 55,000 substations; the entire nation could lose power in almost all areas. Maybe our situation has improved since 2014, I definitely hope so, but think about this:
33% causing ~33% damage, or 0.016% causing ~90% damage. Which one is preferable?
Here's a genius idea if you're Russia. Maybe things have improved and are 10x better. In that case, knocking out 0.16% of our substations, 90 in total, in strategic locations should do the trick. Combine that with rail sabotage so the parts to fix them don't arrive, and then you've done it. Just smuggle about 500 soldiers among the 2.2 million illegal border crossings every year, and that'd be enough to assign a team of 5 to each task.
What I didn't include in my original argument is distributed, off-grid capture of electrons. I would still argue that a national security priority should be increasing the share of EVs and distributed PV generation. If every person, and Amazon distribution center for example, could go off-grid and continue at least partial capacity.. that would be a good thing, wouldn't it?
Thank you for phrasing my previous awkward statements so succinctly.
This should be a goal for natsec. As in, actual Defense Budget should be applied to this goal.
This is not theoretical, it is TRL 9. None of our soldiers die. We can actually do this starting today. It vastly improves our national security.
The only thing that prevents this is our fossil fuel economic inertia.
Cars with so much electronics on board are just vulnerable as the worst cellphone out there; always connected may seem a cool buzzword, but in reality means always ready to be exploited. The reason they're not commonly exploited is that usually who is motivated to do that would rather look for bigger targets that give back more media coverage or potential ransom money.
Which shows a cultural disaster - an idiocracy - that should be taken as a priority.
The march to touchscreen controls in cars has happened despite massive consumer complaints across the board.
Edit: myself, I have seen an overwhelming majority of users that just shrug. (Plus, a number of shocked users that could not believe the situation when told - but that does not mean they will not conform when pressed by the lack of options.)
Now: there are documented proofs of people in pornographic delight handling cars through smartphones; the facts are reachable of gadgets in contemporary premium cars that would be refused by a seventies' pimp; there are definite anecdotes of large amounts people not having the slightest idea of the security and privacy faults of contemporary cars (etc.).
To discuss how «hopeless» a population is we should probably assess and throw numbers in: "uninformed | unaware | drooling | flabbergasted, etc.". Even if the number of the «cool buzzword» enthusiasts were smaller than thought by some, the elements are there for concern and societal action.
It's similar to how consumer-grade dumb TVs do not really exist. And most consumers are not about to start a low-margin, multi-million dollar capex business and start building their own cars and tvs.
(Sorry, I missed that part.)
That is what we need. That is not something «most consumers are not about to start»: it should be a drive to have a few serving the rest.
An easier and (on an important side, fail-safe resilience aside) better solution would be a society that would not have let the situation happen in the first place.
Yes Bob. I also continually monitor that market. Europe here: the powers-that-be are restricting the use of old cars, and the new ones are unacceptable - as law and makers mandate. The scissor of usability is closing the gap between the blades. But that is the situation.
But this would not have happened if, wallets being holders of votes, people told the powers-that-be and the car makers to **** off.
At least in times of peace.
There are two issues here though. The first is that the Olympics is a special event and it is more likely for somebody to try to cause the disruptions, and as such more control is probably warranted.
The second is that somebody else (Russia) is not acting like they are at peace with us so we should act accordingly
This was at least 4 different actors, perhaps 4 different groups of actors, executing a coordinated action simultaneously.
I get phishing mail with very pertinent information only JR West would know any time I make train or rental car reservations with JR West.
Yes, I am willing to bet hard money that they've been backdoored and/or compromised at the human level. Standard fare for Japanese IT, honestly; see Kadokawa.
Cars/trucks/roads are so much more dangerous than train travel that it actually seems worth the tradeoff to me even if these sorts of attacks were a regular occurrence. Putin (or whoever did this) sucks but they have not killed 1,105 Americans in a single year. That's just the number of cyclists killed by cars in 2022. Deaths of pedestrians and drivers/passengers are significantly higher.
https://www.usnews.com/news/top-news/articles/2024-06-24/us-...
It's surprising how little people know about how cars came to be so prominent: https://web.archive.org/web/20230216004635/https://libraryar...
caltrops could also paralyse entire highways
also bridges
I could also imagine that it's not difficult to insert sugar into gas stations
If this were an internal political entity they would have already claimed responsibility and put out a manifesto.
In Belgium they arrested seven muslim terrorists who were planning a terror attack during the Olympics, they were from Chechnya (so, technically, russian but it sounded like the usual islamic terror attacks that was planned and not some "russia vs the west" thing).
It's frightening how easy it is to establish as a cultural norm that guessing is proper thinking.
If the past has shown anything, then that both politics and infrastructure providers greatly overestimate the skill required for disrupting/hacking such systems and networks...
“Simultaneous operations by 4 teams in different parts of the country” does not work well with “a disgruntled ex-employee or a crafty IT-security student” as a hypothesis.
I look forward to getting more detail a couple of years from now, when information will slowly filter out.
Hack traffic light controls and set them to all-green (assuming the safety interlock is done in software), all-red, or just off. Dumbass drivers will do the rest for free.
Alternatively, disrupt Google Maps and Waze. Barely anyone has a dedicated offline navigation system any more - take these two out or "suggest" fake traffic jams to overload side streets [1] will also cause a lot of chaos.
[1] https://www.theguardian.com/technology/2020/feb/03/berlin-ar...
It's not. There's a conflict monitor unit that is completely separate from the signal controller. It has direct inputs from all green or other permissive lights, and a diode matrix that determines which combinations are allowed.[1] If it detects a conflict, all signals go to flashing yellow. "This monitor uses a standardized programming card for channel compatibility (permissives), minimum flash time, per channel Minimum Yellow Change Disable, CVM latch, and 24 volt monitor latch. Programming of this card is accomplished through the use of soldered wire jumpers. The programming card plugs into the monitor through a slot in the front panel."
All 4-way intersections use the same interlocking pattern, so there's a standard card that covers most cases. Only unusual intersections need a custom programming card soldered up.
[1] https://www.editraffic.com/wp-content/uploads/2019/10/MMU2-1...
Have you never driven during a blackout? People get a little awkward figuring out four way stop priority, but it's not pure chaos.
Maybe I'm biased but I've seen incredibly dumb shit happening in urban areas (Munich in winter to be precise). People forget how to drive when lights go out and street markings are covered by snow.
Rural drivers in contrast have zero problems because they're used to driving without constant guidance.