05-10-2021, 03:21 PM | #1 |
Banned
12873
Rep 2,983
Posts |
Cyber hacking. Your thoughts?
This most recent event involving Colonial Pipeline (based here in Alpharetta, GA) is the latest example but it's very concerning to say the least. With so much of our critical infrastructures dependent upon IT systems and their vulnerabilities. This case involves a ransomware group known as DarkSide, but there are plenty out there. It does seem that some experts are suggesting this particular group wasn't aiming to cause chaos as much as it was just trying to get money. I hope authorities can get to the bottom of this and nail these bastards no matter what.
With that being said, we really need to be prepared for this kind of thing as it's just going to happen more and more. We've all read the stories about corporations and even local municipalities getting shut down and being victimized by these so-called ransomware groups. I just wonder how many of them are in China or Russia. Perhaps even N. Korea. Of course they may very well be right here in our back yard as well. Scary thought. |
05-10-2021, 03:34 PM | #2 |
Captain
24759
Rep 892
Posts |
You may find this article interesting TiMSport It seems that DarkSide is avoiding any IT system that the language is set to Russian.
https://www.bbc.com/news/business-57050690
__________________
Wha' da ya mean? No brakes never stopped anyone before!
|
Appreciate
2
TiMSport12872.50 Littlebear3527.00 |
05-10-2021, 03:37 PM | #3 |
Brigadier General
5589
Rep 3,361
Posts |
This crap is going to continue until there are fines and penalties (which may be as extreme as jail time) for critical industries to put money into INFOSEC. No one is talking about this. I've been harping about this for a long time both in various online forums and with my job as a technology advisor for various clients. These rules need to be similar to HIPAA, PCI, and FedRAMP.
Talking about beefing up security is not going to do a damn thing as putting money into security doesn't reflect in the balance sheets or ROI of executives. But what will is if they don't upgrade their systems to established minimum guidelines that those making decisions on implementation and budgeting get fined personally or thrown in jail. I bet you this whole thing will turn around within in a few months. I don't need to go that far back to bring up a classic example of the failure of how things are being done by bringing up Equifax. The idiots in management knew they had vulnerabilities in their systems and chose not to patch their systems. |
Appreciate
0
|
05-10-2021, 03:39 PM | #4 |
Colonel
3941
Rep 2,560
Posts |
as long as they keep hacking nudes, I'll allow it
__________________
|
Appreciate
3
|
05-10-2021, 03:41 PM | #5 | |
Banned
839
Rep 674
Posts |
Quote:
|
|
Appreciate
1
Buug95924759.00 |
05-10-2021, 03:46 PM | #6 |
Recovering Perfectionist
22377
Rep 1,034
Posts |
Colonial Pipeline's IT architects should be unemployed on the spot if their control infrastructure was accessible for any type of remote exploit via the public Internet! This is a no-brainer, and the feds have been publishing warnings to utilities and others that all of their infrastructure needs to be air-gapped to prevent this very thing from happening.....
__________________
Currently BMW-less.
|
Appreciate
5
|
05-10-2021, 03:52 PM | #7 | |
Banned
12873
Rep 2,983
Posts |
Quote:
|
|
Appreciate
3
|
05-10-2021, 03:56 PM | #8 |
Banned
12873
Rep 2,983
Posts |
|
Appreciate
1
TheWatchGuy3940.50 |
05-10-2021, 04:13 PM | #9 | |
First Lieutenant
549
Rep 384
Posts |
Quote:
|
|
Appreciate
1
vreihen1622377.00 |
05-10-2021, 04:15 PM | #10 |
Major
7700
Rep 1,265
Posts
Drives: 04 z4 3.0 Sport & 15 X5 35i XD
Join Date: Aug 2013
Location: Sedalia, MO
|
We have no fingers to point here........
Great watch if you've never seen it! https://www.imdb.com/title/tt5446858/
__________________
2015 X5 XDrive 35i - 2004 Z4 3.0 Sport
|
Appreciate
1
TiMSport12872.50 |
05-10-2021, 04:26 PM | #11 |
New Member
85
Rep 7
Posts |
The problem is, as a career field, IT is a dumpster fire that should be avoided at all costs. It intersects poor, ignorant management, skilled sales babes and smugly incompetent "IT" people put in charge of critical infrastructure. Hiring is generally done by certification and those doing the hiring couldn't determine if someone was competent if they tried.
There are good people but they're usually shunned away and can't stand the idiots and go to work for the places that don't get hacked. |
05-10-2021, 04:34 PM | #12 | |
New Member
85
Rep 7
Posts |
Quote:
Laws/regulations/PCI/HIPPA all lag technology and are written by bureaucrats, not intelligent computer engineers. (yes, there is a HUGE difference between an IT weenie and a computer engineer). IT management is excited in nothing but reading blogs and the latest IT buzzword. I've seen all of this first hand in commercial industry. There are good people but for the most part it's a mess. |
|
Appreciate
1
vreihen1622377.00 |
05-10-2021, 04:40 PM | #13 |
Captain
4689
Rep 694
Posts |
We had a scary one locally, you guys may or may not have heard about. Some hacker got into the water system computer and raised the amount of LYE by 100 times. It triggered an alarm but other areas don't have the same alarm system apparently
https://www.wired.com/story/oldsmar-...-utility-hack/ |
Appreciate
4
|
05-10-2021, 05:00 PM | #14 | |
Major
7700
Rep 1,265
Posts
Drives: 04 z4 3.0 Sport & 15 X5 35i XD
Join Date: Aug 2013
Location: Sedalia, MO
|
Quote:
It's be like me trying to hire Stephen Hawkins for a job he was qualified for - how in the hell would I be able to vet him? Any real programmer has to be driven crazy by the request from their bosses - who always "know better".
__________________
2015 X5 XDrive 35i - 2004 Z4 3.0 Sport
|
|
05-10-2021, 05:54 PM | #15 | |
Banned
12873
Rep 2,983
Posts |
Quote:
|
|
Appreciate
1
unluky7699.50 |
05-10-2021, 06:11 PM | #16 |
Second Lieutenant
4448
Rep 284
Posts |
The problem is a combination of apathy and simple financials. I work in IT so I've seen it many times.
Companies are always reactive rather than proactive...and that's where the apathy as well as finances come in. A good CISO will assess the vulnerabilities of the company and then propose a remediation plan. That cost will make the board swallow their tongues. So a small percentage will be allotted each year towards proactive measures and some in just maintaining services/support....until a major incident happens. Then unfortunately, the blame has to fall on someone, - so the CISO usually has to fall on the sword and then miraculously the money is produced. |
05-10-2021, 06:38 PM | #17 | |
Major
7700
Rep 1,265
Posts
Drives: 04 z4 3.0 Sport & 15 X5 35i XD
Join Date: Aug 2013
Location: Sedalia, MO
|
Quote:
That is why a good CISO always......ALWAYS keeps emails. LOL
__________________
2015 X5 XDrive 35i - 2004 Z4 3.0 Sport
|
|
Appreciate
2
BMWGUYinCO4448.00 vreihen1622377.00 |
05-10-2021, 06:54 PM | #18 |
Banned
12873
Rep 2,983
Posts |
Came across this explanation of what makes a good CISO. Don't know anything about BMT but this article sounded legit.
https://www.bmc.com/blogs/ciso-chief...curity%20risks. |
Appreciate
0
|
05-10-2021, 08:10 PM | #20 |
Major
14097
Rep 1,336
Posts
Drives: Porsche 993
Join Date: Mar 2020
Location: Dog Lake, South Frontenac, Ontario Canada
|
Might be the rum talking but here goes. Why doesn't the command and control system for any infrastructure have a stand alone system for the expressed reason of avoiding hacking.
|
Appreciate
3
|
05-10-2021, 08:16 PM | #21 |
Recovering Perfectionist
22377
Rep 1,034
Posts |
Even with the rum and zero professional IT experience, Murf gets the stupidity of Colonial Pipeline's IT architectural blunder!!!!!
__________________
Currently BMW-less.
|
Appreciate
2
Murf99314096.50 BMWGUYinCO4448.00 |
05-10-2021, 08:32 PM | #22 | |
Major
14097
Rep 1,336
Posts
Drives: Porsche 993
Join Date: Mar 2020
Location: Dog Lake, South Frontenac, Ontario Canada
|
Quote:
Might be the rum talking but maybe I should go into consulting. |
|
Appreciate
1
vreihen1622377.00 |
Post Reply |
Bookmarks |
|
|