Showing posts with label Reader Comment. Show all posts
Showing posts with label Reader Comment. Show all posts

Friday, May 15, 2026

Looking Back – 10-7-24 – Reader Comment

 Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today, a blog post from October 2024, Reader Comment – DrayTek Advisories, made the list. It discusses a comment where a reader pointed out a mistake that I made in an earlier blog post. Now, I do not like such comments, but that is because I do not like making mistakes. I really do appreciate it when readers allow me the chance to correct those errors. 

I do moderate reader comments, but that is generally done to keep out SPAM, including SEO ‘I love your post’ comments, and hate speech of any kind. Other than that, if you catch me in a mistake, I will acknowledge it and correct it. And, if appropriate, expand upon the reason. 

Thursday, December 11, 2025

Reader Comments – S 1071 Whistleblower

Yesterday I approved publication of four comments to my initial post about S 1071, the FY 2026 National Defense Authorization Act. All four comments come from the psunominous DAVE, who claims to be The Whistleblower about the bill. I am not sure which provisions in the bill DAVE is blowing about, but the comments meet the loose rules that I have for moderating comments; nothing abusive and no naked spam. I have not followed up on any of DAVE’s comments, and my posting of them to the blog does not indicate support for the content or belief in the claims.

Having said all of that…. One of the problems with sausage bills like S 1071 is that with over 3,000 pages of bill that was crafted behind closed doors, and with little time for detailed review, and effectively no public debate, all sorts of interesting tidbits have a tendency to get added to the bill (see for example this article at TheHill.com) to encourage support from key members of Congress. And I am sure that there are more disclosures to come.

The problem is compounded by the fact that Congress is nearly evenly divided and has become so hyperpolitical that it consumes the available time counting political coup (House) and approving fringe political appointees (Senate), that serious law making is for the most part no longer being accomplished. So, when legislative sausage is made, all sorts of odd stuff gets thrown into the grinder.

Perhaps it is time to look at Robert Heinlein’s suggestion for a bicameral legislature made in his book “Moon is a Harsh Mistress”. One of his revolutionaries proposed a legislature where one house passed bills by a supermajority and the other repealed legislation by a simple majority. Obviously that government would be in constant turmoil, but that was the point; that turmoil would limit the capacity for oppression.

Friday, November 14, 2025

Reader Comment – Advisory Formats

Earlier this week David Spinks, moderator of the Cyber Security in Real-Time Systems group on LinkedIn, left a comment in that group about my short post on the changes in Siemens advisory formats. He noted that:

“If I were a Siemens customer I would want to understand the reason for these changes. If you have a PDF document then you can detect any changes whereas in HTML format that is very difficult! UK HMG are in the same mode they DO NOT like to issue PDFs because it provides and audit trail ....”

Siemens had provided the following explanation for reason for dropping the .pdf and .txt version of their advisories and updates:

“As expected, the CSAF format is now the dominant standard for machine readable advisories, and the HTML format provides much better readability for humans due to interactive content like product grouping. Due to these improvements, the download rates of PDF and TXT advisories decreased further.”

Not explicitly stated here, but certainly implied is the fact that the storage and maintenance of the number of advisories that Siemens issues every month (November 2025 was a relatively light month with 7 new advisories and 18 updates) in multiple formats has got to be a rather significant business expense. Having said that, it would seem to me that the storage cost for .html files would be higher than .pdf files.

David does make an important point though about changeability issues. Even ignoring any possibility of nefarious intent, it is easier to correct minor mistakes and typos in an .html document than in one in a pdf format. And that could lead to management of change issues as people inevitably (and not necessarily with malice aforethought) incrementally expand the scope of ‘minor mistakes and typos’ that are acceptable to change.

We, as consumers of these advisories, have little chance to influence the decision-making processes of companies as large as Siemens, but if you have concerns similar to those that David has voiced, at least let your sales/service reps know about them. In the meantime, to keep your internal management of change documentation in good shape, save the Siemens .html documents to .pdf when you first access them, and each time you do a formal review (risk assessments, etc) of that vulnerability in your system, download (and date) the advisory again from the Siemens site. That way you will be sure to have the latest version, with any ‘minor changes’ that may have crept in without notification.

Monday, November 3, 2025

Reader Comment – Advisory Windows

This weekend a reader over on Substack, Robots and Chips,  left three comments (here, here, and here) on two of my blog posts (here and here) about CISA vulnerability advisories. They draw some interesting conclusions about how these vulnerabilities provide a window into cybersecurity problems with the energy sector. While I generally try to avoid drawing general conclusions from isolated advisories, the insights here deserve consideration and discussion.

I would, however, like to make one observation; I have seen very few of these energy sector related vulnerabilities show up in CISA’s Known Exploited Vulnerabilities catalog. That may just be a reporting anomaly (the KEV catalog is, after all, focused on problems potentially affecting federal systems), or a failure to report exploits by that sector, but I suspect that the overall cybersecurity posture of the major components of the electric grid may have something to do with that. But that is an outsider’s perspective, my knowledge of the grid does not extend much beyond being able to identify the GA Power distribution substation down at the end of my block.

Saturday, August 30, 2025

Reader Comment – CFATS Should Return

A long time reader and former CISA CFATS team member, Cheryl Louck, left a comment on an almost random post of mine on LinkedIn. It was a very short comment: “CFATS should return.” This is a very common comment that I have heard formally and otherwise from many Chemical Facility Anti-Terrorism Standards program alumni. And even more surprising, it is a sentiment that is also frequently heard from the regulated community. And it is certainly an idea that I support.

Having said that, it is, unfortunately, not an idea that is going anyplace soon. Now over two years since congressional inaction (effectively set in motion by one Senator’s objection in the Senate) there are several factors that ensure that the program will remain dead. First and foremost is the fact that Sen Paul (R,KY; the infamously objecting senator) is in a position of even more power to ensure that any program restoring legislation would not receive any consideration in the Senate.

But even if Paul was struck with overwhelming CFATS remorse, there would still be enormous obstacles to restarting the program. At this point most CFATS alumni are no longer working for the federal government, and I suspect that most would be reluctant to return because of the way government employees have been treated this year.

Perhaps a bigger problem than that is that since the enforcement of the CFATS program’s Site Security Plan program stopped on July 28th, 2023, facilities have not been treating the program requirements as a federally enforceable part of their security program, with the more onerous requirements falling quickly by the wayside. What security measures (almost certainly most of them at most facilities) remain active have been modified to meet changing facility operations and funding limitations. I would be surprised to hear that any of the 3,000 plus covered facilities as of July 27th, 2023, could pass an inspection of their approved site security plan today.

Any legislation to restart the CFATS program would have to take all of this into consideration. First off, it would have to provide for a period of time to train a corps of chemical security inspectors, backend regulatory, and technical support folks to replace those that were runoff by DOGE and the current administration. Then the bill would have to outline a timeframe for refiling Top Screens to reflect current chemical inventories, resubmitting vulnerability assessments and proposed site security plans to reflect current security issues. And, of course, a whole new inspection process would have to be initiated to support the renewing site security plans.

Finally, the start of the legislative process would inevitably restart the political debates that have long surrounded the CFATS process. Environmental folks are going to want to see inherently safer technology language added to the bill. Labor folks are going to want to see stronger whistleblower language and requirements for employee participation in the development of security processes. Cyber folks are going to want to see stronger cybersecurity requirements written into the program. Farm folks are going to want stronger exceptions for the agriculture industry. Chemical safety folks are going to want to see water treatment facilities added to the program. The chemical industry is going to want to see counter drone authority added. And, of course, there is going to be strong opposition to each and every one of these wants.

Last year, I did a series of blog posts about using the ChemLock program as a voluntary replacement for the CFATS program. Unfortunately, due to the emasculation of the infrastructure security division of CISA, that is no longer a realistic alternative.

So those of us that want to see CFATS restored to its earlier glory are just going to have to live with the memory. And remember to bite our tongues when everyone asks why nothing was done to prevent the inevitable attack on a chemical facility.

Monday, June 2, 2025

Reader Comment – Water over Water-Reactive Chemicals

After reading an article on GPB.org about last week’s publication of the Chemical Safety Board’s 2nd update on the investigation of the September 2024 BioLab chemical fire in Conyers, GA, a long time reader (and one of the few that I have met IRL) asked me for my take on the situation. I have been pondering this response for three or four days now, but I am ready to address this now.

The reason for the delay is that the question about the use of a water fire-suppression system over an area used to store a water reactive chemical really deserves a lengthy technical discussion, covering the reaction mechanisms including the heat of reaction, the reaction rates under various scenarios and the byproducts of those reactions. This would then allow for an informed discussion about the design considerations for the fire suppression system. Unfortunately, I do not have any of that information, and from what the CSB said at the end of their report about what they were continuing to look at in their investigation, neither does the Board.

So instead, I am going to have to address this issue by using a series of analogies.

Add Acid to Water

One of the first-year chemistry safety lessons is summarized by the sentence: “Add acid to water, not water to acid.” Most mineral acids (for example sulfuric acid that I have dealt with frequently in my career) are soluble in water, so why should there be a safety issue about mixing the two. The problem is caused by something called the heat of solution, when mineral acids dissolve in water the ‘reaction’ produces a great deal of heat very quickly (nearly instantaneously for all practical purposes). If you add a drop of water to concentrated sulfuric acid, the heat will be sufficient to turn much of the drop of water to steam with the attendant expansion of the volume. This splatters undiluted sulfuric acid around, potentially injuring the person adding the water to the acid, a serious safety situation to be avoided.

The problem becomes much worse if you take a syringe and inject a stream of a couple of milliliters of water into the same concentrated acid. The force of the stream pushes the water further into the container of acid, resulting in a much larger ‘steam explosion’ that throws a significant amounts of acid further from the container increasing the chance and extent of potential injuries.

However, if you spill a gallon of concentrated sulfuric acid on the concrete in a chemical plant and then hit the puddle immediately with a stream of water from an industrial scale hose, there is no noticeable reaction caused by the heat of dilution. The volume of water is sufficient to spread the heat of solution over a wider area. Knowing the heat of dilution, it is a simple matter to calculate the minimum amount of water needed to safely add water to acid.

Water for Solvents

Another well known safety mantra is that you do not use water to fight fires in organic solvents that are not soluble in water. Since most of these solvents are lighter than water they float on top of water and are likely to spread the fire when water is applied to such fires. I worked in a chemical facility that used small quantities (a couple of drums) of such solvents. Rather than employ expensive foam suppression systems that are usually required to fight such solvent fires, the facility chose to use a deluge water suppression system. These systems use huge amounts of water flood the facility with water to eliminate the issue.

Waterproof Storage

One final thing to consider is that the facility stored the trichloroisocyanuric acid (TCCA) in water resistant storge containers. The material was stored in ‘supersacks’. These are made of an tightly woven plastic bag that sheds water and a water proof plastic inner liner. The twisted closures of the top and bottom openings of the bag are the only thing that stops the supersacks from being truly waterproof, if you submerged these bags in water over a period of time, there might be some leakage. A picture on page 11 of last week’s report shows some of the bags still intact after the walls collapsed over them (and under the further application of firefighting water).

SDS Information

According to the CSB report (pg 4) the TCCA Safety Data Sheet (I have not received a response from BioLab’s spokesperson about my request for a copy of that SDS):

“While TCCA and DCCA are not classified as water reactive per the Safety Data Sheets (“SDSs”), their SDSs indicate that contacting these materials with water or moisture may cause fire or explosion hazards. The SDSs also indicate that it is necessary to flood the area with large amounts of water from a distance to extinguish a fire involving these materials.”

Self-Delusion

With this discussion in mind, I can see how the owners convinced themselves that the design of the water fire suppression system for the Conyers, GA, facility would be a safe system. Having said that, there is an interesting quote from the GPB.org article:

““I brought up questions about 'Why do we have a water-based fire system over water-reactive chemicals?'” Garcia told GPB. “I brought the risks that could come about, but we got approvals on everything. Management was like, 'No one is forcing us to change it.' [Rockdale] County's OK with it, they say OSHA gave the OK, nobody really raised any red flags, so nothing was really done about it.””

So, there may have been doubts in the minds of management about the adequacy of their fire suppression design, but those doubts would have been eased by the approvals of that design by various regulatory agencies. I doubt, however, that those agencies had any idea about the water reactive nature of TCCA especially if they relied on the BioLab SDS.

Wednesday, May 28, 2025

Reader Comment – BioLab Response

I received the following statement from a spokesperson from Bio-Lab in response to my post about the CSB’s second update on their investigation of the fires and chemical release at their Conyers, GA facility in September of 2024:

“BioLab has a strong track record of working constructively with regulatory agencies and will continue to cooperate with the CSB’s ongoing investigation, although we disagree with many of CSB’s statements. The health and safety of the communities within which we operate is a top priority, and we worked collaboratively with first responders and local, state, and federal authorities to complete the emergency response operation in October 2024. The clean-up of the site affected by the fire has also been successfully completed. In addition, consistent with our commitment to the community, we established support resources that over the course of six months were dedicated to continually fielding calls, emails, and in-person questions – helping area residents and business owners with processing claim requests and more.”

Having published their statement, I have forwarded some questions that I have about some the details disclosed in the CSB update. If/when I receive a response, I will address those questions and answers here.

Monday, May 26, 2025

Reader Comment – More on Deferred Resignation Program

This weekend an anonymous reader left a comment on my post about the introduction of HR 3026, the Protecting America’s Cybersecurity Act. With respect to HR 3026, the reader makes an important point:

“For any legislation to be effective DRP needs to be addressed before October and employees currently on administrative leave need to get back to work because every day that passes is another day for our adversaries to strengthen and our country becomes less secure.”

Employee by-out programs have a long history, both inside and outside of government. Typically, these programs have a tendency to self-select the most effective employees for termination. Those employees generally feel that they have good prospects for finding a new job, so they have the most to gain from a buy-out. The anonymous reader points out that that might not be the case here:

“The catch 22 is this was anything but voluntary and all made the decision under extreme duress created by management.”


Threatening folks with widespread (and indiscriminate) reductions in force certainly would encourage a wide number of people to accept this deferred resignation process. The self-selection process would still apply, but you would also tend to see larger participation by people who feel that they have less attractive prospects for finding a new job. Still, a large number of people remaining (not all by any means) are going to be coming from the lower portion of the employee bell curve because they will feel that they have very low prospects of finding a new job
.

Friday, May 16, 2025

Reader Comment – Senate Unanimous Consent Process

Yesterday an anonymous reader posted a comment to my post on “Reader Comment – CFATS Inspectors vs Admin”. The reader asked:

“PJ - With your legislative knowledge can you provide some insight into why senate leadership would not have taken any other routes to bypass the committee's unanimous consent agenda(?) requirement --as held up by those 1-2 senators. Not sure if I got the procedure correct but basically why couldn't they pass this on a majority vs universal concurrence.”

The unanimous consent process in the Senate is a way of avoiding the time consuming ‘regular order’ process. It provides a mechanism for passing less controversial legislation that does not require the full deliberative process.

Regular order in the Senate requires a piece of legislation go through three stages:

Debate on whether to consider the bill,

Debate on the content of the bill (where amendments are proposed and debated),

Debate on passage of the bill.

That final stage leads to an actual vote on the bill. Each of the above stages requires a 3/5ths vote to close the debate (cloture) before the next stage can begin. The final vote requires just a simple majority. And there are rules about how long each stage of the debate should continue, though there is no requirement for any actual discussion of the legislation during the debate. There are procedures for limiting each stage of the debate, but they require unanimous consent. The Senate leadership negotiates with various factions within the body about what amendments will be proposed during the second stage of the debate to minimize the time consumed during that process, but the 60-vote threshold to close that debate frequently favors the consideration of unrelated amendments (each amendment typically requires a 60-vote threshold for passage, though that can be waived to a simple majority vote by unanimous consent) to buy votes or silence on unanimous consent motions.

Needless to say this is a time consuming process and very few bills are actually passed under regular order. What it comes down to is a political decision about what bills are important enough to consume the Senate’s time. The CFATS reauthorization was never going to be important enough (except to those within the industry of course) to be considered in this way.

There is one other way that a bill can be passed without going through either regular order or the unanimous consent process, being added to another bill that is important enough. The text of a bill could be added to the bill as an amendment in the markup of the larger bill in Committee, the same committee that would consider the original bill. That process requires the cooperation of the Committee leadership (including, to a large extent, the Ranking Member of the Committee). Sen Paul (R,KY) was the Ranking Member of the Senate Homeland Security and Governmental Affairs Committee that would have considered HR 4470, the CFATS reauthorization bill, thus Paul would have some level of control over adding that language to some other bill. He could have been bypassed, but it would have come at some level of political cost. Again, this bill was not politically important enough to bear that cost.

There is one last method of adding the text of a bill to some more important bill, and that is offering the language as an amendment in the floor debate about the provisions of the bill. For important bills, there are a large number (sometimes hundreds) of amendments that are offered, but few are actually considered. The Committee Chair and Ranking Member of the Committee that would have jurisdiction over the subject of the amendment have an effective veto over the consideration of those amendments. Again, that veto could be ignored by the Senate Leadership, but at great political cost.

So, at the end of the day, once Sen Paul decided to object to consideration of HR 4470, there was no practical method of passing that bill without changing his opposition. And Paul is a very stubborn politician.

Thursday, May 15, 2025

Reader Comment – CFATS Inspectors vs Admins

This morning an anonymous reader left a comment on yesterday’s post, Industry Still Wants CFATS Back. Anonymous made a painful point that I failed to mention:

“Boots on the ground inspectors who truly hold the institutional knowledge is the significant loss.”

There is no doubt that facilities had Chemical Security Inspectors as their primary point of contact with the CFATS program. The experience and knowledge that these CSI accumulated and shared over the 15+ years of operation of the program were a major factor in smoothing the impact of the program on individual facilities. This is a major part of the industry’s acceptance and support of the program.

But it pains me to hear the negative comments that Anonymous had about the leadership. There will always be a disconnect between organizational leadership and the boots on the ground, but for organizations like the Alliance for Chemical Distribution, it was the leadership and headquarters staff that were the primary points of contact. The leaderships’ willingness to work with industry to craft how the program implemented the congressional requirements was also important for industry acceptance of the program. Both parts of the organization were important to the success of the program.

Still questions have been raised about the leadership’s role in ensuring the continuation of the program. In hindsight, the leadership at the Office of Chemical Security, CISA and DHS did a reasonable job ensuring that there was widespread, bipartisan support for a relatively minor chemical security program. What killed the program was the opposition of a single Senator {and perhaps one other Senator, Sen Johnson (R,WI) who might have taken the same action if Sen Paul had not stood in opposition to the consideration of HR 4470)}. People forget that HR 4470 passed in the House by a vote of 409 to 1. It is hard to fault the OCS or CISA leadership for achieving that ‘limited’ level of Congressional support.

Tuesday, April 8, 2025

Reader Comment – CVI and DOGE

Last night Carbon Unit left a comment on my Substack Notes announcement about my recent “Chemical Security Inspector Reduction in Force” post on Substack. The comment objected to the characterization of the DOGE access to Chemical Terrorism Vulnerability Information (CVI), noting that:

“The USDS team has been vetted and has already covered far more sensitive data than this.”

As I noted in my reply to that comment, CVI information in possession by CISA includes security plans for the 3,000+ chemical facilities that were covered by the CFATS program at the time of the program’s termination in July 2023. That is some of the most sensitive information not covered by national security classified information program in the possession of the government. In fact, according to 6 USC 623(d):

 

“In any proceeding to enforce this section, vulnerability assessments, site security plans, and other information submitted to or obtained by the Secretary under this subchapter, and related vulnerability or security information, shall be treated as if the information were classified information.”

 

Additionally, the chemical inventory data on the 300 most sensitive chemicals (from a weaponization point of view) submitted under the CFATS’ Top Screen program on over 45,000 facilities is also held on those same CVI servers.

 

While the DOGE team members may have been vetted (I am not sure what vetting process has been used, but from public reporting it does not meet the access requirements outlined for CVI access, because of the training requirements) that does not mean that they have the ‘need to know’ the facility chemical security information held by CISA.

 

CISA and the employees working in and around the CFATS program took the CVI program very seriously. Unauthorized access, and certainly unneeded access, to that information would be expected to offend the sensibilities of those employees. More importantly, it would strike fear in the facilities that provided that information to CISA in the understanding that the information would be closely held and protected by CISA.

Thursday, March 13, 2025

Reader Comment – Fla Ground Water Petition

Every time I publish a post for this blog or over at CFSN Detailed Analysis I post notices about the publication on my various social media feeds, including Substack Notes. Earlier today on Notes, Karl Deigert attached a comment to my NOTE about a blog post from a week ago on “EPA Withdraws Worst Case Discharge Rule ICR”. The topic was a petition that Karl is apparently supporting, the “Florida Right to Clean Water Petition

I am not going to delve into the details of the petition (I do not typically cover State issues), but Karl makes an interesting point:

“The federal protections against hazardous metals (like arsenic and mercury) getting into groundwater are getting rolled back.  Wouldn't it be nice to have a constitutional right to stop that?  Even if it meant that the industry might have to pay a bit more to NOT poison our water system?  Or are the people expected to just live and be happy with increased cancer rates and lower IQs?”

The thing that caught my attention, however, is the link to an AP article about the ‘federal protections’ that are being rolled back by the Trump administration. There are pros and cons to each of these issues, but taken as a whole, these are actions that clearly mark an administration that is unabashedly more concerned about corporate profits than the health and welfare of its constituents. In addition to continuing court cases about the way the new administration is going about its business, perhaps we also need to see more petitions like this one in Florida.

Monday, March 3, 2025

Reader Comments and SPAM

I ‘moderate’ comments to this blog, I have since its inception. For the most part, I have rejected comments that are purely efforts to trade on the ‘popularity’ of this blog to drive traffic to other websites that are unrelated to the topic at hand. Today, I ran into a fringe case, one where it was an obvious attempt to drive traffic, but it was related to the blog topic. So, gritting my teeth, I approved the comment and I am now calling further attention to it.

The comment in question came from himaram and it was posted to July 14th, 2022 post on CISA control system security advisories. The comment included a generic positive comment about the post and then provided links to 11 training programs for the Siemens Mendix system. Those training programs were at least thematically related to three CISA advisories for vulnerabilities in Siemens Mendix products discussed in that post. I have not looked at any of the training programs, and I certainly do not endorse them.

Is this comment SPAM? Probably. It is certainly advertising, ads for which I am receiving no compensation (and no, I am not soliciting ads for this site). But, it was notionally on topic, so it met my less than stringent moderation guidelines.

In my view, the whole point about reader comments is that they should be a mechanism to expand the discussion that I have started with a blog post. I want to encourage readers to correct me when I make a mistake or provide additional information on topics where their experience or expertise is different than mine. In the broadest interpretation this comment fulfils that last requirement. I would have preferred more discussion beyond just listing the courses available, but in the interest of encouraging discussion, I allowed this comment to be posted to the blog.

Saturday, February 15, 2025

Reader Comment – Vulnerability Reporting Discrepancies

An anonymous reader left a comment on my blog post about the latest batch of CISA advisories from February 13th. The reader expresses some confusion about the product nomenclature used in the advisory. Readers will be further confused because the CISA advisory referred to in the comment is actually from February 4th and a different blog post. In any case, the anonymous reader noted:

“I'm baffled by the discrepancy between the ICSA-25-035-02, about vulnerabilities in Rockwell PLC's, and the original Rockwell advisory. The ICSA mentions 1756-L3zS3, while Rockwell talks about Compact GuardLogix, which has catalog 5069 not 1756 (https://www.rockwellautomation.com/en-us/products/hardware/allen-bradley/programmable-controllers/small-controllers/compactlogix-family/compactlogix-5380-controllers.html)”

In my article from February 4th over on CFSN Detailed Analysis (subscription required) on these advisories I provided part of the answer to that confusion:

“NOTE 1: The CISA advisory reports the Allen-Bradley product names for the affected devices, the Rockwell advisory provides the Rockwell product names I used above.”

The reader went on to note:

“Rockwell itself doesn't make life any easier while on the webpage it appears that they refer to the whole GuardLogix 5580 range, but the downloadable JSON file for CVE-2025-24478 specifically mentions "GuardLogix 5580 SIL3".”

I cannot help with that issue. I am confused as well, at least now that the JSON file issue was pointed out.

Monday, January 13, 2025

Reader Comment – TSDB Screening for ChemLock

I got some feedback yesterday on LinkedIn on my weekend post on ChemLock and Tiering.  Philip Polios left a comment that suggested that ChemLock authorization should include allowing facilities to vet employees using the Terrorist Screening Database (TSDB).

The CFATS program had this as part of their personnel surety program, and lots of people in the chemical industry have commented on the lack of this vetting process since the CFATS lapse as one of the major reasons that they wanted to see the program reinstated.

I had always planned on including this in the discussion about ChemLock, but it is helps to get this sort of feedback from readers.

As always, anyone with further suggestions about this series of blog posts, or chemical security/safety in general, feel free to contact me either through my social media feeds or using my contact information on LinkedIn. 

Monday, December 9, 2024

Reader Comment – Future of CSB

On Saturday, a long-time reader, Richard Rosera, left a comment on my Chemical Incident Reporting post pointing at the Chemical Safety Board’s FY 2024 Performance and Accountability Report that was recently posted to the CSB’s website. As Richard notes: “Not a lot of controversy here”.

The more important part of Richard’ comment looks at the future of the CSB. He notes:

“,,, but the overall question remains of what will happen when Trump becomes President. The terms of all three current Board members will expire before Trump leaves office, and Trump sought to eliminate the CSB entirely during his previous term.”

While Trump did zero out the CSB funding in his first two budgets submitted to Congress, there was broad, bipartisan support in Congress to keep the Board operating. Trump did end up nominating (and the Senate approved) Katherine A. Lemos as the new CSB Chair. In hindsight that appointment did little to advance the operations of the CSB.

There are still two open positions on the five-member Board. How soon (or even if) Trump  moves to fill these positions will signal what the future might hold for the Board under the new administration. I would suspect that any Republican nominees would be from industry rather than having an environmental and worker safety focus that the three current board members have.

Monday, November 18, 2024

Reader Comment – Medical Device Cybersecurity and FDA

Last week, Christopher Sundberg left a comment on my post (removed from paywall) at CFSD Detailed Analysis on CISA’s advisories published on Thursday. He noted that:

“The Baxter LIfe2000 device, with the software version noted in the advisory, is also part of an FDA recall (https://www.fda.gov/medical-devices/ventilator-correction-baxter-healthcare-updates-use-instructions-life2000-ventilation-system-due)”

I just had a chance to look at the ‘recall notice’ (I wish the FDA would call this a ‘software update’ notice, but there are regulatory issues related to the term ‘recall notice’ that would not apply to the more technically correct term). While there certainly appears to be a software-related issue involved in the recall, it does not appear to be a cybersecurity issue.

The FDA and CISA both acknowledge that (different) workarounds should be implemented (the FDA requires that the recall specific workarounds be applied, CISA can only report that the cybersecurity workarounds are available) pending Baxter’s development of a new version of the Life2000 Ventilators software. The wording of the recall notice is sort of vague, however, when it comes to whether updating the software will be specifically required when Baxter makes it available.

“The firm is currently working on a software update to address this issue and will contact all impacted customers to update their devices once the update is available.”

If the update is required, this would be the first time that the FDA mandated the correction of an unreported (to them anyway) cybersecurity issue in a medical device. The last time that they deliberately mandated a cybersecurity mitigation was in September 2022.

Monday, October 14, 2024

Reader Comment – Missing Link

Last night Brandon left a comment on my Saturday ‘Short Takes’ post. He reported that “the poppy seed item is missing the link to the article.” The whole point of this series of posts is sharing information with my readers. While the post includes brief extracts from the articles listed, the intent is to provide readers with links to the underlying articles. Thanks to Brandon, I have gone back and added the necessary links to this article. While I do not like admitting my mistakes any more than most folks, I do appreciate sharp-eyed readers helping me stay on the editorial straight and narrow.

Monday, October 7, 2024

Reader Comment – DrayTek Advisories

Earlier today an anonymous reader left a comment on my Saturday ‘Public ICS Disclosure’ blog post pointing out a mistake in my reporting on the second DrayTek advisory. I had reported that the advisory described “seven classic buffer overflow vulnerabilities in multiple Vigor routers”. As the anonymous commentor noted, the number should have been 16 not seven. My mistake arose because of the way that I read the advisory listing of the vulnerabilities:

“The Buffer Overflow Vulnerabilities have been discovered, which could potentially allow an authenticated attackers to cause a Denial of Service (DoS) via a crafted input. The vulnerabilities have been announced under CVE-2024-46550 CVE-2024-46568, CVE-2024-46571, CVE-2024-46580 CVE-2024-46586, CVE-2024-46588 ~ CVE-2024-46598.”

The highlighted ‘~’ is what I overlooked. To be fair, DrayTek used the same convention for listing consecutive CVE’s in their first advisory and I caught their meaning there, I just missed it here. Mea Culpa. And many thanks to the anonymous commentor for catching that error.

Looking at the NVD.NIST.gov listings for all 16 CVE’s, these are all ‘Classic Buffer Overflow’ vulnerabilities. The CNA for the CVE’s are all listed as ‘MITRE’ with a publication date of September 18th, 2024. They were apparently reported to Mitre by the researcher as the only link provided on the CVE record is to variations to “(https)://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-XXXX” where the ‘XXXX’ is a unique alpha-numeric string for each CVE. Access to the linked sites is restricted. The CVE record does list the parameter and file where the unique buffer overflow occurs.

Saturday, September 21, 2024

Review - Reader Comment – Advisory Mistakes

Yesterday, an anonymous reader left a comment about my Thursday blog post on CISA advisories published that day. The reader notes:

“About the Rockwell advisory: on that vendor's publication for that vulnerability there is a reference to a JSON to help you automate the vulnerability handling, but the JSON refers to another vulnerability. Looks like the webpage is copy/pasted.”

If you look at the bottom of the Rockwell Advisory you will find the following:

ADDITIONAL RESOURCES

 

The following link provides CVE information in Vulnerability Exploitability Exchange (VEX) format, which is machine readable and can be used to automate vulnerability management and tracking activities.    

 

·      ·       JSON CVE-2024-7847

To be clear that CVE is for the vulnerability discussed in the advisory. On the advisory, that last line ‘JSON CVD-2024-7847’ has an active link to https://cveawg.mitre.org/api/cve/CVE-2024-45825. Obviously, that is the wrong CVE number. Interestingly Rockwell is using the Mitre JSON document instead of developing their own tool to produce JSON pages.

Now, as to how this happened, the cut and paste suggestion by the anonymous reader who noted the problem could easily be right. As I well know, there are numerous ways that errors in links can creep into documents. That is where good editors provide an invaluable service to writers. Unfortunately, blog writers do not usually have editors, and I suspect that the corporate writers of advisories are similarly lacking that type of support. We have to rely on readers like my anonymous friend here to catch the mistakes that we miss.

 

For more information about the machine readable alternatives, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/reader-comment-advisory-mistakes - subscription required. 

 
/* Use this with templates/template-twocol.html */