Domestic Terrorists Could Use OSINT To Pinpoint US Substations For a Blackout (darkreading.com)
An anonymous reader writes: A project called 'Gridstrike' found that free and publicly available information can be used to determine the most critical electric substations in the US, which if attacked, could result in a nationwide blackout. Researchers from iSIGHT Partners used a combination of publicly available transmission substation information, maps, Google Earth, and grid congestion documentation, and drew correlations among the substations that serve the top ten cities in the US. They ID'ed 15 substations that if attacked and knocked offline would result in a nationwide blackout, they say. Their research took the spin of whether a homegrown terror group with little funding could get this crucial information. The study was inspired by the 2013 Federal Energy Regulatory Commission (FERC) study in 2013 that found that attacks on just nine electric substations in the U.S. could cause a blackout across the entire grid.
That's what you get when you let your critical infrastructure design by entities that care more about profit than providing that critical infrastructure.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Planned attack? It doesn't need that, just a couple of accidents or screw-ups at the same inopportune times. One mistake by a rookie engineer in Arizona took out the grid for most of southern California. One or two more mistakes or equipment failures while they were still trying to recover from the first one could've seen the entire grid west of the Rockies go down. And the main cause is frankly the profit motive: for the sake of efficiency and cost-effectiveness the generation and transmission companies have eliminated the majority of the redundancy in the system and put off expensive maintenance and upgrades as long as the system wasn't failing during normal operation. It wouldn't take a group of terrorists, just a couple of maintenance engineers more interested in getting home for dinner than in following every rule to the letter or system operators who haven't had their morning coffee and are still a bit groggy.
SARCASM_ON:
Because it tells you where to find the leaning tower of pisa, therefore you do now know how to damage the itallian economy by demolishing that building.
Threat cleared:
I call for a ban on all travel maps therefore nobody will be able to find these places.
More Threats
I call for a ban on teaching geography!
The maps show industrial buildings, transport infrastruture and natural resources!
SARCASM_OFF:
OSINT, INTINT, TINTINTIN
So long for calling public accessable information and teaching material OSINT, I call bull shit on this try to infiltrate the common language with this intelligence "cool" style new speak!
the solution to this is to completely decentralize our power, virtually destroying "the grid" by putting solar+battery at every home. it wont work for absolutely everyone but it will work for the vast majority of people. it comes with nice side effects too: it will cause people to buy more efficient electronics, lower the price of solar panels, devastate the coal/gas industry which in turn will cause a massive reduction in CO2 emissions and result in fewer mountain tops being blown up.
so you get security, energy independence, massive pollution reduction and preserving the environment. what's not to like? oh yeah, it doesn't pay congress critters to stay in office, so it wont happen. #BanCongress ;-P
Anons need not reply. Questions end with a question mark.
Yo dawg, I heard you like fear, so I got some fear to put on top of your fear next to your fear....
I went to a DHS conference in Boston a few years after 9/11, and it was a wall-to-wall exhibition of all the crazy ways the bad guys were going to get us. Grid attacks, bus attacks, backflushing municipal hydrants with poisoned water, poisoning drinking water supplies, spraying anthrax on the lettuce in the supermarket. 99% of it were "weaknesses" conjured up by security researchers to get some money from the golden spigot labeled DHS.
The DHS basically put the brakes on this and started demanding solutions, not a laundry list of insane attack vectors.
The upshot is, any reasonably complex distribution system will have security vulnerabilities, dependent on the definition of "vulnerability". Some "vulnerabilities" are highly improbable, difficult to exploit, and only cause temporary or low-level disruption. Other vulnerabilities are obvious, easy to exploit, and will take down society. Without getting hysterical about it, the sensible thing to do is to make the vulnerabilities hard to exploit i.e. get infrastructure control systems airgapped and off the fucking Internet (duh). Make the system fault tolerant - if they do blow up something, have a means to contain it.
Can we do this and get on with our lives, please? These vulnerabilities have been talked about for decades, we know what the solutions are, but no one wants to pay for it. Industry and government are staring at each other expecting the other to pick up the tab. If that is the situation nothing will get done, ever. Critical infrastructure needs to be nationalized so it is clear who is in charge of maintenance and security. Industry won't pay unless it hits their bottom line.
Left MS Windows for Linux Mint and never looked back!
Vote for Bernie in 2016!