Thursday, October 22, 2015

Markup of HR 3763 Scheduled

Earlier today the House Transportation and Infrastructure Committee announced that it would be holding a markup hearing for HR 3763, the Surface Transportation Reauthorization and Reform Act of 2015. There are no amendments currently listed for consideration, but that will certainly change before the hearing starts tomorrow morning.

As I noted earlier today there are five sections in this lengthy bill that may be of specific interest to readers of this blog:

• Sec. 7005. Wetlines.
• Sec. 7010. Thermal blankets.
• Sec. 7011. Comprehensive oil spill response plans.
• Sec. 7012. Information on high-hazard flammable trains.
• Sec. 7014. Ensuring safe implementation of positive train control systems.

Wetlines

Section 7005 would require the Secretary to withdraw the proposed rule described in the notice of proposed rulemaking issued on January 27, 2011, entitled “Safety Requirements for External Product Piping on Cargo Tanks Transporting Flammable Liquids” (76 FR 4847-4854) {§7005(a)}. Paragraph (b) would allow the Secretary to initiate a new rulemaking on the subject.

Thermal Blankets

Section 7010 would require the Secretary to issue regulations requiring that each DOT 117 tank car and each unjacketed tank car modified to the DOT 117R specification be equipped with “an insulating blanket with at least 1⁄2-inch-thick material that has been approved by the Secretary” {§7010(a)} in accordance with 49 CFR 179.18(c).

Comprehensive Oil Spill Plans

Section 7011 would add §5111 to 49 USC Chapter 51 requiring the Secretary to draft new regulations “to require any railroad carrier transporting a Class 3 flammable liquid to maintain a comprehensive oil spill response plan” {new §5111(a)}. The plan would be made public, but the Secretary would allow certain information in the plan to be withheld from the public, including “security-sensitive information, including information described in section 1520.5(a) of title 49, Code of Federal Regulations” {new §5111(d)(2)(B)}. Nothing in this section address fire fighting planning.

Information on High-Hazard Flammable Trains

Section 7012 would require the Secretary to issue regulations implementing the SERC notification requirements set out in “Emergency Order Docket No. DOT–OST–2014–0067”. The bill would specifically require those regulations to address protection “from public release of proprietary information and security-sensitive information [49 CFR 1520.5]” {§7012(a)}

Positive Train Control System Implementation

Section 7014 is very similar to HR 3651 that I described earlier. There are two major differences. The provisions for allowing the Secretary to further extend the deadline past 2018 on a by railroad basis have been removed. Secondly there is a great deal more specificity in this version as to what information the railroads will be required to provide in their revised plan for implementing PTC by December 31st, 2018.

Commentary

I remain very disappointed in the failure of Congress to realize that there is a difference in responding to an oil spill (where the task is isolate and clean up the spilled oil) and dealing with the frequently fiery and explosive aftermaths that we have been seeing with many (certainly not all) of the crude oil train derailments.

There has not been any significant public outcry about the oil spilled in these accidents. With the exception of some very brief comments about oil getting into rivers, the news about these derailments has all been about the fires and explosions or the threat of fire and explosions. The public and news media have been focused on the more visible (and potentially more deadly) aspects of these accidents which the Congress has studiously ignored.


This bill should certainly at least have some sort of study requirement for planning on preventing and suppressing fires in these crude oil spills. 

Wednesday, October 21, 2015

HR 3710 Introduced – Methyl Bromide

Earlier this month Rep. LaMalfa (R,CA) introduced HR 3710, the Safe Agriculture Production Act of 2015. The bill would allow State, local and tribal officials to authorize the use of methyl bromide as a fumigant to respond to an emergency event without regard to EPA restrictions on the use of methyl bromide. The bill would completely rewrite the language of 7 USC 7719.

Authorization to Use Methyl Bromide

The new paragraph (a) in the bill would allow an undefined State, local or tribal authority to authorize the use of methyl bromide (subject to objection by the Secretary of Agriculture) “the use of methyl bromide for a qualified use if the authority determines the use is required to respond to an emergency event”. The authorizing authority would have 5 days to notify the Secretary and the Secretary would then have 5 additional days to object to the use.

Paragraph (h)(1) provides the definition of an ‘emergency event’ as a situation:

• That occurs at a location on which a plant or commodity is grown or produced or a facility providing for the storage of, or other services with respect to, a plant or commodity;
• For which the lack of availability of methyl bromide for a particular use would result in significant economic loss to the owner, lessee, or operator of such a location or facility or the owner, grower, or purchaser of such a plant or commodity; and
• That, in light of the specific agricultural, meteorological, or other conditions presented, requires the use of methyl bromide to control a pest or disease in such location or fa-cility because there are no technically or economically feasible alternatives to methyl bromide easily accessible by the owner, lessee, or operator at the time and location of the event.

The bill specifically allows the use of methyl bromide for the ‘emergency event’ “regardless of whether the intended use is registered and included in the label approved for the product by the Administrator of the Environmental Protection Agency under such Act” {revised §7719(d)}. Under the authority of this new language, such ‘emergency event’ authorization “shall be deemed an authorized production, distribution, sale, shipment, application, or use of such product under the Federal Insecticide, Fungicide, and Rodenticide Act”.

Limitations on the Use of Methyl Bromide

The only limitations on the use of methyl bromide beyond the definition of an ‘emergency event’ are that a maximum of 20 metric tons per event can be used at a specific location {revised §7719(e)(1)}, and no more than 150,000 metric tons can be used in the United States in a given year {revised §7719(e)(2)}. That second figure was based upon the critical use exception (CUE) amount set for 2011 by the EPA under the Montreal Protocol on Substances that Deplete the Ozone Layer and 40 CFR Part 82. For comparison the CUE recently set for 2016 is less than 1% of that amount (141 MT).

In order to ensure that there could be enough methyl bromide available for ‘emergency event’ use that is not covered by the current CUE authorization the bill would exempt methyl bromide from the current CUE limitations by stating:

Notwithstanding any other provision of law [emphasis added], it shall not be unlawful for any person or entity to produce or import methyl bromide, or otherwise supply methyl bromide from inventories (produced or imported pursuant to the Clean Air Act for other purposes) in response to an emergency event in accordance with subsection (a).” {revised §7719(f)}

Moving Forward

LeMalfa and five of his cosponsors are members of the House Agriculture Committee to which this bill has been referred. The sole Democratic cosponsor, Rep. Costa (D,CA) is the Ranking Member of the Livestock and Foreign Agriculture Subcommittee. There may be enough political pull to get this bill considered by the Committee.

There will be internal political issues with getting this bill to the floor of the House. The EPA’s regulation of methyl bromide was not specifically addressed in the bill, so it was not referred to the Energy and Commerce Committee. I do suspect, however, that that Committee may have objections to this bill moving forward because they were not asked to review it. It will be interesting to see if Ag Chairman Conway (R,TX) will get behind this bill to move it forward.

The environmental lobby will definitely work hard against this bill because methyl bromide is a chemical known to have effects on the ozone layer. That lobby would not be able to stop the House from passing the bill if it gets to the floor, but they would certainly be able to convince Senate Democrats from allowing the bill to be considered on the floor of the Senate.

The only way that this bill has any chance of getting through the Senate is if it were included in either the agriculture spending or authorization bills.

Commentary

 This is an interesting attempt by the agriculture lobby to get around the phase out of the use of methyl bromide. It is an excellent pre-plant fumigant for ridding the soil of pests that can destroy crops. The number of crops, however, on which the EPA has continued to allow the use of methyl bromide has continued to dwindle until next year it will only be allowed on strawberries and that will cease for 2017. Food and feed importers also have a long history of using methyl bromide to kill off pests in imported products and the EPA has reduced those uses until now the only post planting application with an approved CUE is cured bacon.

The Department of Agriculture’s Animal and Plant Health and Inspection Service (APHIS) service has a long history of approving the use of methyl bromide (herehere and here) for incoming agriculture product fumigation. And they have continued to essentially ignore the EPA’s efforts to eradicate the use of methyl bromide.

The most recent CUE notice, however, made it clear that after 2016 there will not be large stocks of methyl bromide left in inventory after the pre-plant season is over that can be pulled for uses approved by APHIS. In fact, at the end of 2016 the methyl bromide producers and distributors will be required to destroy any methyl bromide left over from the pre-plant authorization.

The other methyl bromide problem is that the California strawberry growers (and a number of other crop growers across the nation that have already been phased out of methyl bromide use by the EPA) are not in complete agreement with EPA that chloropicrin is going to be an effective replacement for methyl bromide in preparing their fields for planting. While they have lost the argument with the EPA and the Montreal Protocol folks, this bill was almost certainly drawn with the intent of allowing them to go around the EPA restrictions.

The 20 metric ton per location limit in the bill was not aimed at any APHIS importation fumigation use. It was clearly aimed at pre-plant use as was the 150 MT annual use limit. But how do they expect to be able to get around the emergency event restrictions? Actually and quite simply, there is no requirement for an emergency in the ‘emergency event’ definition. All that is really required is for a determination to be made (by the field owner) that “there are no technically or economically feasible alternatives to methyl bromide”.

One other thing that needs to be considered with this bill is the status of methyl bromide vis-à-vis the Chemical Facility Anti-Terrorism Standards (CFATS) program. Methyl bromide was on the original proposed list of DHS chemicals of interest (COI) that trigger the requirement for filing a Top Screen data submission to DHS to determine if a facility was covered by the CFATS program. It was removed in the final rule due to the ‘fact’ that it was being phased out by the EPA. The current EPA plan is to have the national inventory down to less than 2 metric tons by 2017; an amount that is not much more than DHS would consider an actionable amount for a single facility.


Opening methyl bromide use back up to pre-plant activities (which is clearly the unwritten intent of this bill) would force DHS to reconsider their failure to list methyl bromide as a COI. This would very likely cause a number of new facilities and distributors to come under the purview of the CFATS program.

Bills Introduced – 10-20-15

With both the House and Senate in session yesterday there were 20 bills introduced. Of those only one will be of specific interest to readers of this blog:

HR 3763 Surface Transportation Reauthorization and Reform Act of 2015 Rep. Shuster, Bill [R-PA-9]

News reports indicate that this is the bill that has been coordinated between the House and Senate transportation committees. The ‘deadline’ for passing this bill is October 31st (though that might get yet another short term extension to allow this bill through the legislative process. The official copy of the bill is already available. It was co-sponsored by the Ranking Member of both the House Transportation and Infrastructure Committee and the Ranking Member of the Highways and Transit Subcommittee, so there will be significant bipartisan support for this bill when it comes to the floor.

A quick review of the table of contents show the following items of potential interest in Title VII, Hazardous Material Transportation:

• Sec. 7003. National emergency and disaster response.
• Sec. 7005. Wetlines.
• Sec. 7010. Thermal blankets.
• Sec. 7011. Comprehensive oil spill response plans.
• Sec. 7012. Information on high-hazard flammable trains.
• Sec. 7013. Study and testing of electronically-controlled pneumatic brakes.
• Sec. 7014. Ensuring safe implementation of positive train control systems.


I’ll have more details on this bill later.

Tuesday, October 20, 2015

ICS-CERT Publishes 3 Advisories

This afternoon the DHS ICS-CERT published three control system security advisories. Two of them were for products from IniNet Solutions and the third was from 3S.

CODESYS Advisory

This advisory describes another null pointer exception vulnerability in a CODESYS product, this time the Gateway Server. The vulnerability was reported by Ashish Kamble of Qualys, Inc. 3S has produced a new version that mitigates the vulnerability and Kamble has validated the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to crash the server.

This is the same type vulnerability that was reported last week by ICS-CERT in the CODESYS Runtime Tool Kit.

IniNet Solutions SCADA Web Server Advisory

This advisory describes three vulnerabilities in the IniNet Solutions GmbH’s SCADA Web Server. The vulnerabilities were reported by Kirill Nesterov and Aleksandr Timorin of Positive Technologies. IniNet Solutions has produced a new version that mitigates these vulnerabilities, but there is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three vulnerabilities are:

• Stack-based buffer overflow, CVE-2015-1001;
• Improper handling of URL encoding, CVE-2015-1002; and
• Path traversal; CVE-2015-1003

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to manipulate and delete files, execute arbitrary code, and initiate a denial of service condition.

ICS-CERT also reports that the affected web server is known to be used in a variety of Beckhoff Embedded PCs. Beckhoff is apparently not accepting any responsibility for the vulnerable application.

IniNet Solution embeddedWebServer Advisory

This advisory describes a password cleartext storage vulnerability in the IniNet Solution eWebServer. The vulnerability was reported by Aleksandr Timorin of Positive Technologies. IniNet Solutions has produced a new version that mitigates the vulnerability, but there is no indication that Timorin was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker with local access could exploit this vulnerability to obtain logon information.


ICS-CERT also reports that the affected web server is known to be used in a variety of Baumüller PCs and Beckhoff Embedded PCs. Baumüller does not plan on updating their affected PCs because they are being retired in December. Beckhoff is apparently not accepting any responsibility for the vulnerable application.

House Passes HR 3350

This evening the House passed HR 3350, the Know the CBRN Terrorism Threats to Transportation Act, after only 9 minutes of debate earlier in the day. The final vote was 416 to 0.


This is a feel good bill without much substance and that is reflected in the vote. The report required by the bill is also likely to be a feel good report without much substance. That is not because of any specific shortcoming of TSA. Rather it is because the bill only provides 90 days to complete the report and at least half of that time will be taken up by bureaucratic reviews and rewrites. But since there are no real requirements for content in the report, no one at the TSA will spend much time or effort on the report.

Monday, October 19, 2015

HR 3669 Introduced – Drone Crime

Earlier this month Rep. Garamendi (D,CA) introduced HR 3669, the Safety for Airports and Firefighters by Ensuring Drones Refrain from Obstructing Necessary Equipment (SAFE DRONE) Act of 2015. The bill would make it a Federal crime to operate a drone near a hub-airport or federal firefighting scene.

The bill would add §40A to 18 USC. It would make it a crime (punishable by fines and/or 1 year in prison) to operate “a drone in a restricted area” {new §40A(a)}. The bill defines a drone as an unmanned aircraft as defined in §331(8) of the FAA Modernization and Reform Act of 2012 (PL 112-95); so this definitely includes both commercial and hobby unmanned aerial vehicles.

The bill provides its own definition of ‘a restricted area’ {new §40A(c)(2)}:
• Within a 2-mile radius of a small hub airport, medium hub airport, or large hub airport;
• Within 2 miles of the outermost perimeter of an ongoing firefighting operation involving the Department of Agriculture or the Department of the Interior; or
• In an area that is subject to a temporary flight restriction issued by the Administrator of the Federal Aviation Administration.

There is no language in the bill that allows for authorized use in restricted area except for operations by Federal, State, or local unit of government (or their contractors) in support of firefighting activities. This would seem to mean that drones could not be used, for instance, in perimeter security operations at a hub airport.

Moving Forward

Garamendi is not a member of the House Judiciary Committee (the committee of jurisdiction for this bill), but one of his co-sponsors, Rep. Lofgren (D,CA) is a fairly influential member of that Committee. This means that there may be enough political pull to get this to a Committee hearing. The fact, though, that none of the ten cosponsors are Republicans tends to weigh against that possibility.

It is not clear at this point how much opposition there would be to this bill from commercial drone services or manufacturers. Any that does arise may be able to be placated by the addition of the word ‘unauthorized’ as a modifier of ‘operation’.

Commentary

This bill is obviously a response to several reports of interference in aerial firefighting operations by drones being sighted in the area combined with vague FAA reports about drone operations around airports. Something clearly needs to be done, but a tad bit more attention to detail needs to be paid in the construction of criminal statutes. Why for example is operation in an area covered by a temporary FAA flight restriction a crime operation in an area covered by a permanent FAA flight restriction is not?

The way this bill is currently written a child playing with a remote controlled helicopter in his yard within two miles of an airport could be made a felon. While one would like to think that a prosecutor would have more sense than that, stranger things have happened.


The one thing that does disturb me, however, is that there are no provisions in the bill that would make unauthorized operation of a drone over critical infrastructure facilities a crime. Again, some careful attention to the wording would be required, but this is clearly an area that needs to be addressed and a bill like this would seem to be the ideal vehicle.

Committee Hearings – Week of 10-19-15

Both the House and Senate are back in Washington this week after their Columbus Day Recess (excuse me; ‘district work session’). There are three hearings currently scheduled that may be of specific interest to readers of this blog; two cybersecurity related hearings and one terror threat briefing.

Cybersecurity

The Commerce, Manufacturing and Trade Subcommittee of the House Energy and Commerce Committee will be holding a hearing on Wednesday looking at “Examining Ways to Improve Vehicle and Roadway Safety”. The discussions will be centered on a committee draft of new automotive safety legislation that includes a title specifically addressing cybersecurity issues.

The witness list includes:

• Mitch Bainwol, Alliance of Automobile Manufacturers
• John Bozzella, Global Automakers
• Joan Claybrook, Former Administrator, NHTSA
• Greg Dotson, Center for American Progress
• Maneesha Mithal, Federal Trade Commission
• Mark Rosekind, Administrator, NHTSA
• Peter Welch, Automobile Dealers Association
• Ann Wilson, Motor & Equipment Manufacturers Association

I don’t typically review legislation before it is introduced, but I’ll give a brief overview of the cybersecurity provisions of this bill. Title III of the bill is called “Privacy, Hacking Prohibition, and Cyber Security”. Section 301 establishes privacy rules for information collected by privately owned motor vehicles. Section 302 prohibits hacking (access without authorization) “an electronic control unit or critical system of a motor vehicle, or other system containing driving data for such motor vehicle, either wirelessly or through a wired connection”. And §303 establishes the Automotive Cybersecurity Advisory Council that does not include anyone from ICS-CERT (or DHS in general) or security researchers.

Please note that none of the witnesses has any cybersecurity background so it is unlikely that we will hear anything of real substance about cybersecurity at this hearing; other than, of course, please leave our systems alone.

The other cybersecurity related hearing is before the Energy Subcommittee of the House Science, Space and Technology Committee on Wednesday. That hearing will address “Cybersecurity for Power Systems”.

The witness list includes:

• Bennett Gaines, CIO, FirstEnergy Service Company
• Annabelle Lee, Electric Power Research Institute
• Brent Stacey, Idaho National Lab
• Greg Wilshusen, Government Accountability Office

There is a better chance of a technical discussion at this hearing.

Terror Threat

The House Homeland Security Committee will be holding a hearing looking at “Worldwide Threats and Homeland Security Challenges” on Wednesday.

The witness list includes:

• James B. Comey, Director FBI;
• Jeh C. Johnson, Secretary DHS;
• Nicholas J. Rasmussen, Director, National Counterterrorism Center

No actionable intelligence, of course; just an overview of the cruddy state of the world.

On the Floor


There is one bill that is scheduled to come to the floor of the House this week that may be of specific interest to readers of this blog; HR 3350, the Know the CBRN Terrorism Threats to Transportation Act. It will be considered on Tuesday under suspension of the rules. Again, this means limited debate and no floor amendments. It also means that it is likely to pass with bipartisan support. It passed in the Homeland Security Committee on a voice vote without amendments.
 
/* Use this with templates/template-twocol.html */