The Internet of Gas Station Tank Gauges
community.rapid7.com
community.rapid7.com
To this day, the most difficult software challenge I have had to tackle was to retrieve the data from the serial port of a controller called the DOMS 2000. It had been replaced a number of years earlier by a new model but was still in wide service.
We had very limited documentation and I spent weeks observing the data being transmitted from the serial port while performing actions using a simulator. Eventually I managed to reliably intercept and correctly interpret almost every command.
I believe, to this day, I may well be one of the foremost experts on the DOMS 2000 on the planet.
The NSA should be performing signal and human intelligence operations around the world to ensure the US can track global events. While the Internet is a key tool for this, it doesn't make them the "internet cops" of the US.
The FBI should be doing this, not the NSA, considering the FBI is actually the "US Police".
The FBI is an investigative agency. They aren't beat cops. They aren't soldiers. They do have a counter-intelligence role.
From a threat POV, consider how dependent on gasoline and diesel the US economy is, and what the impact of disruption would be. If an attacker could disrupt fuel supplies in key areas or highway corridors, they would cause all sorts of chaos and economic damage.
As Americans, we've been very lucky to have two oceans protect us from the shift in warfare from the battlefield to total war, with the exception of the US Civil War. Our global connectivity changed the threat landscape. That's not a police matter.
I was wrong, it should be the NSA who does this stuff.
http://www.dhs.gov/homeland-security-presidential-directive-...
In the NSAs charter, the term "National security information" refers to classified information and "sensitive but unclassified" information, and the scope includes those systems. The scope does not include protecting all systems that might have national security implications, the NSA has no regulatory authority or requirement to do this.
This should be an agreement between you and the rest of society (read: laws or standards). Government agencies responsible for the security of the nation should probably be looking into these types of things, and if they come across your RS232->Ethernet-dongle-that-explodes-Tampa they should a) notify you, b) offer assistance if required (for a price) and c) fine and/or arrest you if you are a serial offender.
Serial offender? I can't believe I just typed that...
Human intelligence operations have never been part of their mandate.
It was established in 1952 by a presidential directive from Harry S. Truman in which he specified its mission as
to provide an effective, unified organization and control of the communications intelligence activities of the United States conducted against foreign governments, to provide for integrated operational policies and procedures pertaining thereto.
"It's really stupid to expect every station owner to solve a physical security problem themselves."
what he proposed is more like defense. "cyber" defense. so perhaps better as a different agency or under DOD
"But they are vlanned off!"
"Why would anyone know to attack it, we keep that info confidential?"
"They wouldn't target us, we're a small company"
"The probability of this is too small to worry about, the cost/benefit is just not realistic"
"Can this really be used to do anything bad, the attacker wouldn't even know what to do"
We'd be much better off as a country if we split the NSA into half with one side basically being a sort of USDA/EPA/FEMA with the only goal of improving baseline security standards and a healthy budget for things like aggressively auditing widely used code and services.
You get industry-specific vendors that believe their solution is opaque to anyone that hasn't received their specific training and they run loose. The end-user doesn't care because their expert in [whatever automation] tells them it has a password or proprietary protocol and can't be accessed without a program that's only given to trusted (industry) insiders.
I doubt a discussion even gets that far. The end-user doesn't care because it works to do what they need, and they never even consider security.
Real question. Was this irresponsible disclosure? What should they have done? (Are those doing the disclosing risking criminal prosecution?). I don't know the answers.
If all this stuff is visible as a web service, you can take a regular old programmer and optimize inventory and delivery schedules. I'm sure that happens now, but i'm not sure how sophisticated it is. There's probably some value in a car being able to access the octane rating and price of gas on fillup, which would update your phone with price and performance metrics. I think there's also an aspect of service discovery you're overlooking.
I guess the point is, the words "internet of things" are goofy and overused, but it implies being more pervasive, open and standardized than scada.
e.g., I have a BeagleBone monitoring a mousetrap in my basement. Total cost about $60; would be half that with a Raspberry Pi. It's only on my internal network, but it would be trivial to put its webpage online or serve up the data to something like what Pachube used to be.
telnet, ctrl-A, I20100
Here's a fun search: http://www.shodanhq.com/search?q=Anonymous+access+granted
What can you do with an FTP site? Host your own phishing site. Modify the owner's own webpages.
Related to this article: if you can narrow the addresses down to ones that also have these gas meters, then you can modify their website to say "Hey; free gas!" and mark their tanks as 'always full'.
The key take-away here is that there is a literal TON of unsecured sites and multiple ways that something bad could be done.
A moderate county (roughly 2 million people in 800,000 households) has about a 2400MW power supply.
Compromising 6% of households' heaters would allow you to drive spikes on the order of 3% of the average power grid load (which includes things like business uses). With some targeting, you could probably get a larger influence on a localized portion of the grid.
Somehow, I think attackers causing high-ish frequency noise (on the order of ~1 minute waves, or less) with 3% of the average power could cause problems for the electric grid.
http://money.cnn.com/gallery/technology/security/2013/05/01/...
Request Method:GET https://community.rapid7.com/community/infosec/blog/2015/01/22/the-internet-of-gas-station-tank-gauges?hn-repost
Status Code:200 OKTiming, a better title, or both?
Are we talking about simple monitoring information here, or some kind of administrative access?
"In our opinion, remote access to the control port of an ATG could provide an attacker with the ability to reconfigure alarm thresholds, reset the system, and otherwise disrupt the operation of the fuel tank."
Remote access to a control port would indeed conceivably allow these activities, no "in our opinion" required. But you haven't told me whether this is indeed remote access to a control port.
Also, the ISP pie graph just looks like a typical distribution of customers across ISPs. How useful is this supposed to be?
It looks like the documentation's been taken down from the URL included in the OP. I'm sure it's available elsewhere, but I haven't tried to find it.
https://www.reddit.com/r/netsec/comments/2te5h8/the_internet...
While I like stuff like this, it's basically an open invitation to start messing about.
If 'the terrorists' really would like to do damage this would be an excellent target.
http://www.businessinsider.com/pie-charts-are-the-worst-2013...
Coordinated disclosure is to mitigate the effects of a particular case - but vendors routinely abuse it to sit on problems for months or even years (in their own interests), leading to a movement for full disclosure (in their customers' interests).
Also, you seem to be assuming the bad guys don't know already.
(This is why Microsoft's complaints about Google revealing their holes don't convince me: we already know Windows is peppered with holes that are unknown to the public but are literally commodities to criminals and national security organisations. Revealing all of them would increase our security and not decrease it even in the short term.)
A well-connected industry insider may be able to get things moving. But if industry insider exist who care enough, why hasn't this been fixed a long time ago?
For an outsider, bringing the issue up in public is probably the most effective way to get this fixed. And it's not like they published a script to exploit this.
Publishing security flaws can cause problems in the short term but it's in everyone's best interests in the long term. It is vital that our infrastructure is protected against attacks and we can't afford to allow companies to sell and operate insecure industrial systems. Making this information public is the best way we have to get these problems fixed.
Deleted comment
These are just monitors. That setting sounds like something to adjust the amount being reported in the station tank if it is very cold or very hot, as temperature slightly affects the volume of gasoline.
I can think of two possible attacks:
1) Falsely reporting the station tank is empty, when it is actually close to full, will cause unnecessary deliveries of gasoline for which the station owner will have to pay.
2) Falsely reporting the station tank is full, when it is actually close to empty, could cause a local - possibly regional - gas shortage if enough gas station in particular area are attacked.
I mean, sure, it's a more expensive chip, it's two ARM cores plus a WiFi MAC in a single package, but it's pretty much all the computing and connectivity you would need for a normal iot kind of application in a less than 1 cm^2.
Let's just say I could smell the security holes.