Monday, September 5, 2011

Congressional Hearings: Week of 09-06-11


Congress comes back from their summer recess this week, the Senate on Tuesday and the House on Wednesday. With less than a month until the start of FY 2012 and no spending bills passed, Congress has its work cut out for the month. There are only three hearings currently scheduled dealing with issues of concern to the chemical or cyber security communities; two spending hearings and a replay of a hearing originally scheduled before the break.

DHS Spending Bill


The House passed their version of the DHS spending bill, HR 2017, back in June and the Senate has yet to publish their version of the bill that will be substituted for the House version on the Senate floor. This is one of those silly things that the Founding Fathers inadvertently started when they required that the House initiate any spending bills.

The Homeland Security Subcommittee of Senate Appropriations Committee will be meeting Tuesday to mark up their, as of yet unnumbered, version of the Senate bill. The full Committee will meet the next day to place their mark on the bill as well as two other spending bills. Since the Senate has not produced a DHS spending bill in two years, it is a little difficult to guess how well this abbreviated process will work. Of course, we can expect that the committee staff has been working the bugs out while the Senators were back home.

GPS Interference


The House Science, Space and Technology Committee will be holding the hearing that was originally scheduled for August 3rd dealing with the impacts of the Lightsquared Network on federal science activities.

As I noted in my blog about the original hearing, this will be focusing on federal R&D efforts so it may be a bit of a reach to hope that it might address the ICS timing issues that might be impacted by the GPS interference that has been reported to be associated with the design of this new broadband network. Mr. Anthony Russo, the Director of the National Coordination Office for Space-Based Positioning, Navigation, and Timing, might provide some insight into the effects of the interference on the timing services. If it’s not mentioned in his prepared testimony, I doubt that anyone will ask questions about this issue.

Saturday, September 3, 2011

HR 2838 Introduced – CG Authorization


Yesterday, during the pro forma session of the House, Rep. LoBiondo (R,NJ), introduced HR 2838, the Coast Guard and Maritime Transportation Act of 2011. LoBiondo is the Chair of the Coast Guard & Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee.

This proposed legislation is a significant deviation from the recent history of authorization bills in that it does not introduce a large number of new programs and responsibilities for the covered organization. The bill does include a new policy on sexual harassment/violence {§202} and it does call for an assessment to be made on “the need for additional Coast Guard prevention and response capability in the high latitude regions” {§308}. These and a few other new requirements form a really modest set of mandates for the Coast Guard.

No mention is made of the Maritime Transportation Security Act or any of its components.

GPS Interference


There is an interesting provision that the Federal Communications Commission and Lightspeed may find disconcerting. Section 302 of the bill would make it a Class E Felony to “knowingly and willfully operate[s] a device that interferes with the broadcast or reception of a radio, microwave, or other signal (including a signal from a global positioning system) transmitted, retransmitted, or augmented by the Coast Guard for the purpose of maritime safety”.

Where the appropriations committees have been requiring reports from various agencies on the reports of GPS interference by the proposed new broadband communications system from Lightspeed, Chairman LoBiondo appears to be trying to do something about it. It remains to be seen how liberal (excuse me for mentioning ‘liberal’ and ‘LoBiondo in the same paragraph) he expects the term ‘maritime safety’ to extend. Would it cover, for instance, control systems at portside chemical facilities?

Authorization Bill a Priority


According to the Subcommittee web site, passing a Coast Guard Authorization Bill is a priority for Chairman LoBiondo. We’ll have to watch how quickly it progresses in the next couple of weeks to see how much of a priority it really is. Of course, this bill will have to be reconciled with the desires of Chairman Rockefeller of the Senate Commerce, Science and Transportation Committee.

OMB Approves 2012 Methyl Bromide Exception NPRM


On Thursday the Office of Management and Budget announced that it had approved the EPA’s NPRM for the 2012 exempted uses of methyl bromide. The approval was made ‘consistent with change’ so the EPA’s publication of the NPRM will be delayed slightly as they make (and get internal approval for) changes to the NPRM.

The EPA is going to have a hard time getting this through the regulatory process before January 1st , 2012 if they publish this NPRM with a standard 60-day comment period. This rule went to OMB back in July, so OMB hasn’t helped EPA’s effort much. Though I do have to admit that they are doing much better than they did with the 2010 and 2011 versions of this rule; the 2010 NPRM was published on November 23rd, 2009 and the 2011 NPRM went to the Federal Register on April 28th, 2011. Both of those rules were published after EPA had to give unofficial authority to manufacture and use methyl bromide to meet the fumigation needs for the pre-planting season.

ICS-CERT Publishes BroadWin WebAccess Alert


Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an alert concerning two vulnerabilities that have been publicly reported for Advantech’s BroadWin WebAccess system. While ICS-CERT is not giving credit for the disclosure (they typically don’t for uncoordinated disclosures) SecurityFocus.com is providing a copy of the BugTraq notification from Luigi Auriemma that is almost certainly the ‘public disclosure’ mentioned by ICS-CERT.

The two ActiveX vulnerabilities, according to Luigi, allow for remote exploitation. The two vulnerabilities are:

• A format string vulnerability; and

• A memory corruption vulnerability.

ICS-CERT is coordinating with Advantech to evaluate these reported vulnerabilities.

Friday, September 2, 2011

Implications of FRA PTC Revisions – STB Rate Disputes


A couple of weeks ago I did a posting about the Federal Railroad Administration’s (FRA) notice of proposed rulemaking (NPRM) concerning revisions to the criteria that would be used to determine which rail lines would be required to have expensive positive train control (PTC) equipment installed. Today I would like to take a look at the possible implications such a change would have for shippers of toxic inhalation hazard (TIH or PIH, poisonous inhalation hazard if you prefer) chemicals.

Background


Generally speaking the railroads would prefer to not provide transportation for TIH chemicals. The potential liability issues that could arise from a catastrophic accident that resulted in the wholesale release of a TIH chemical in a populated area are quite possibly corporate killing. Given the fact that they are not currently able to charge a potential liability premium on their TIH rates, one can sympathize with their position.

On the other hand, rail shipment of bulk TIH chemicals is undoubtedly the safest way to transport these materials from producer to consumer. Railroads have an outstanding safety record with hands down the fewest accidents per ton-mile of any transportation mode other than pipelines. Add to that the fact that the robust design of TIH railcars makes a catastrophic release of TIH chemicals unlikely in all but the most violent accidents. That design also makes them relatively hard targets for terrorist attack.

Fortunately for shippers, railroads are not able to deny carriage of TIH chemicals under what is known as their ‘common carrier obligation’. Since most railroads have a near physical monopoly on ownership of the lines over which they travel Congress set out a number of rules that prevented railroads from charging monopolistic rates. One of those rules required them to provide transport to any ‘properly presented shipment’.

The PTC requirements mandated by Congress in Section 104 of the Railroad Safety Improvement Act of 2008 (Public Law 110-432, 122 Stat. 4854) added an additional cost burden on the railroads that transported TIH chemicals. They are being required to add expensive automated control systems on any line that carries TIH chemicals and annually carries 5 million gross tons of freight.

The original PTC rule required that any line that met the TIH transport requirements as of 2008 and any line that added TIH transport and met the gross tons requirement would have to have PTC equipment added to the line. This rule does not change that basic requirement, but it does make it significantly easier to remove a line segment from PTC installation requirements if it no longer carries TIH chemicals as of January 1st, 2016.

Rule of Unintended Consequences


It certainly makes sense to allow the railroads to not equip lines with PTC equipment that do not currently meet the requirements for that installation. Unfortunately, this proposed change, if implemented, would give railroads an even greater financial incentive to deny carriage of TIH chemicals on certain lines.

Since legally railroads cannot not actually deny carriage of properly offered shipments (conforming to government shipping, safety and security regulations and ‘reasonable’ railroad rules) the railroads would have to rely on financial incentives or disincentives to get shippers to not ship TIH commodities on specific rail lines. The easiest way to do that would be to charge excessive shipping rates for those shipments.

The Surface Transportation Board (STB) regulates and moderates the setting of rail shipping rates. They have seen a number of cases in the last couple of years where various railroad have effectively tried to price TIH shipments off of their lines. While a number of these rate disputes are still pending, the STB has generally resisted the more egregious efforts by the railroads to price TIH chemical shipments off of their lines.

I would expect that if this rule goes into effect there will be even more such disputes brought before the STB. In fact I would expect a whole slew of them to appear in late 2014 and 2015 as the deadline approached. This would be due to the wording of . This would be due to the proposed wording of §236.1005(b)(4)(ii)(C):

“The cessation or expected cessation [emphasis added] of PIH traffic over the involved track segment prior to January 1, 2016”

With no standard for what constitutes ‘expected cessation’ a railroad could argue that they expect that the STB would rule in their favor in a rate dispute and that would result in the shipper no longer using their service over a particular line segment. A good example of the type of complaint where this argument might be legitimately used would be the current dispute between Canexus Chemicals Canada and the BNSF railroad (STB Docket: FD 35524).

Even if the railroad had to subsequently add that segment back to the PTC covered list, it might be able to avoid the installation cost for a number of years as it wouldn’t be covered under the initial installation plan. Additionally, it would be better able to justify to the STB using the cost of the PTC system for that added line segment as part of the cost equation for setting ‘reasonable’ rates for transporting the TIH chemical over that line. That would allow the railroad to recoup at least a portion of their PTC costs from a single shipper.

More Unintended Consequences to Come


I’ll look at some further implications of this rule in future blogs. 

Thursday, September 1, 2011

PHMSA Publishes Post-Hurricane Pipeline Advisory


The Pipeline and Hazardous Material Safety Administration (PHMSA) published an Advisory Bulletin in today’s Federal Register (76 FR 54531-54532) regarding possible damage to pipeline facilities caused by the passage of a hurricane. Since this advisory is primarily targeted at off-shore pipelines it is particularly timely considering the developing tropical storm in the Gulf of Mexico.

There is nothing really new in the recommendations other than two recommendations that deal with identifying and contacting marine vessel operators to remind them of the dangers of potentially exposed pipeline. The first deals with those that “engage in shallow-water commercial fishing, shrimping, and other marine vessel operations”. The second deals with those in deeper water that are “deploying fishing nets or anchors and conducting dredging operations”.

The last paragraph of the advisory is the most interesting. It states:

“PHMSA would appreciate receiving information [emphasis added] about any damage to pipeline facilities caused by hurricanes. The Federal pipeline safety regulations require that operators report certain incidents and accidents to PHMSA by specific methods. Damage not reported by these methods may be reported to John Hess, Director for Emergency Support and Security, 202-366-4595 or by e-mail at PHMSA.OPA90@dot.gov.”

It’s nice to see a Federal agency politely asking for information that the public is not required to provide. It would, however, be nice to know what type of information that PHMSA is expecting to be covered by this statement and why it isn’t addressed in existing regulations. I would like to think that any ‘damage’ to an undersea pipeline would be required to be reported to PHMSA and/or the Coast Guard. Perhaps some Gulf Coast legislator might want to ask PHMSA about this?

I haven’t heard of any off-shore pipelines being affected by Hurricane Irene so maybe PHMSA is being proactive in publishing this Bulletin as opposed to the reactive Bulletin issued for under-river pipelines affected by flooding. If so, they are to be commended.


DHS ICS-CERT Updates Sunway Force Control Alert


Last week the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published a limited information alert about an overwrite vulnerability in the structured exception handler for the Sunway Force Control SCADA system. Yesterday they published an updated version of that alert that provides more information on the vulnerability. Probably the most important item of information is that the alert is based upon the public availability of exploit code for the vulnerability.

Interestingly ICS-CERT now thinks that the exploit is “likely targeting a previously disclosed and patched vulnerability”. There are patches and mitigation measures available for that vulnerability, so this alert recommends that they be implemented (should have already been implemented?) as a preliminary response to this exploit. More information, including perhaps a confirmation of this being the same vulnerability, will follow.

I briefly wrote about the earlier advisory back in June and noted that the newsworthy aspect of that advisory was that the vulnerability had been reported by Dillon Beresford of Siemens vulnerability notoriety. ICS-CERT is careful to note in this advisory that it is someone else (currently unidentified) that published the exploit code, not Dillon.
 
/* Use this with templates/template-twocol.html */