Showing posts with label infrastructure. Show all posts
Showing posts with label infrastructure. Show all posts

Monday, May 24, 2021

HELD FOR RANSOM - Colonial Pipeline and U.S. Infrastructure

"The Colonial Pipeline Ransomware Hackers Had a Secret Weapon: Self-Promoting Cybersecurity Firms" by Renee Dudley and Daniel Golden, ProPublica 5/24/2021

This story was co-published with MIT Technology Review.

On Jan 11, antivirus company Bitdefender said it was “happy to announce” a startling breakthrough.  It had found a flaw in the ransomware that a gang known as DarkSide was using to freeze computer networks of dozens of businesses in the U.S. and Europe.  Companies facing demands from DarkSide could download a free tool from Bitdefender and avoid paying millions of dollars in ransom to the hackers.

But Bitdefender wasn’t the first to identify this flaw.  Two other researchers, Fabian Wosar and Michael Gillespie, had noticed it the month before and had begun discreetly looking for victims to help.  By publicizing its tool, Bitdefender alerted DarkSide to the lapse, which involved reusing the same digital keys to lock and unlock multiple victims.  The next day, DarkSide declared that it had repaired the problem, and that “new companies have nothing to hope for.”

“Special thanks to BitDefender for helping fix our issues,” DarkSide said.  “This will make us even better.”

DarkSide soon proved it wasn’t bluffing, unleashing a string of attacks.  This month, it paralyzed the Colonial Pipeline Co., prompting a shutdown of the 5,500 mile pipeline that carries 45% of the fuel used on the East Coast, quickly followed by a rise in gasoline prices, panic buying of gas across the Southeast and closures of thousands of gas stations.  Absent Bitdefender’s announcement, it’s possible that the crisis might have been contained, and that Colonial might have quietly restored its system with Wosar and Gillespie’s decryption tool.

Instead, Colonial paid DarkSide $4.4 million in Bitcoin for a key to unlock its files.  “I will admit that I wasn’t comfortable seeing money go out the door to people like this,” CEO Joseph Blount told The Wall Street Journal.

The missed opportunity was part of a broader pattern of botched or half-hearted responses to the growing menace of ransomware, which during the pandemic has disabled businesses, schools, hospitals and government agencies across the country.  The incident also shows how antivirus companies eager to make a name for themselves sometimes violate one of the cardinal rules of the cat-and-mouse game of cyber-warfare: Don’t let your opponents know what you’ve figured out.  During World War II, when the British secret service learned from decrypted communications that the Gestapo was planning to abduct and murder a valuable double agent, Johnny Jebsen, his handler wasn’t allowed to warn him for fear of cluing in the enemy that its cipher had been cracked.  Today, ransomware hunters like Wosar and Gillespie try to prolong the attackers’ ignorance, even at the cost of contacting fewer victims.  Sooner or later, as payments drop off, the cybercriminals realize that something has gone wrong.

Whether to tout a decryption tool is a “calculated decision,” said Rob McLeod, senior director of the threat response unit for cybersecurity firm eSentire.  From the marketing perspective, “You are singing that song from the rooftops about how you have come up with a security solution that will decrypt a victim’s data.  And then the security researcher angle says, ‘Don’t disclose any information here.  Keep the ransomware bugs that we’ve found that allow us to decode the data secret, so as not to notify the threat actors.’”


Wosar said that publicly releasing tools, as Bitdefender did, has become riskier as ransoms have soared and the gangs have grown wealthier and more technically adept.  In the early days of ransomware, when hackers froze home computers for a few hundred dollars, they often couldn’t determine how their code was broken unless the flaw was specifically pointed out to them.

Today, the creators of ransomware “have access to reverse engineers and penetration testers who are very very capable,” he said.  “That’s how they gain entrance to these oftentimes highly secured networks in the first place.  They download the decryptor, they disassemble it, they reverse engineer it and they figure out exactly why we were able to decrypt their files.  And 24 hours later, the whole thing is fixed.  Bitdefender should have known better.”

It wasn’t the first time that Bitdefender trumpeted a solution that Wosar or Gillespie had beaten it to.  Gillespie had broken the code of a ransomware strain called GoGoogle and was helping victims without any fanfare, when Bitdefender released a decryption tool in May 2020.  Other companies have also announced breakthroughs publicly, Wosar and Gillespie said.

“People are desperate for a news mention, and big security companies don’t care about victims,” Wosar said.

Bogdan Botezatu, director of threat research at Bucharest, Romania-based Bitdefender, said the company wasn’t aware of the earlier success in unlocking files infected by DarkSide.  Regardless, he said, Bitdefender decided to publish its tool “because most victims who fall for ransomware do not have the right connection with ransomware support groups and won’t know where to ask for help unless they can learn about the existence of tools from media reports or with a simple search.”

Bitdefender has provided free technical support to more than a dozen DarkSide victims, and “we believe many others have successfully used the tool without our intervention,” Botezatu said.  Over the years, Bitdefender has helped individuals and businesses avoid paying more than $100 million in ransom, he said.

Bitdefender recognized that DarkSide might correct the flaw, Botezatu said.  “We are well aware that attackers are agile and adapt to our decryptors.”  But DarkSide might have “spotted the issue” anyway.  “We don’t believe in ransomware decryptors made silently available.  Attackers will learn about their existence by impersonating home users or companies in need, while the vast majority of victims will have no idea that they can get their data back for free.”

The attack on Colonial Pipeline, and the ensuing chaos at the gas pumps throughout the Southeast, appears to have spurred the federal government to be more vigilant.  President Joe Biden issued an executive order to improve cybersecurity and create a blueprint for a federal response to cyberattacks.  DarkSide said it was shutting down under U.S. pressure, although ransomware crews have often disbanded to avoid scrutiny and then re-formed under new names, or their members have launched or joined other groups.

“As sophisticated as they are, these guys will pop up again, and they’ll be that much smarter,” said Aaron Tantleff, a Chicago cybersecurity attorney who has consulted with 10 companies attacked by DarkSide.  “They’ll come back with a vengeance.”

At least until now, private researchers and companies have often been more effective than the government in fighting ransomware.  Last October, Microsoft disrupted the infrastructure of Trickbot, a network of more than 1 million infected computers that disseminated the notorious Ryuk strain of ransomware, by disabling its servers and communications.  That month, ProtonMail, the Swiss-based email service, shut down 20,000 Ryuk-related accounts.

Wosar and Gillespie, who belong to a worldwide volunteer group called the Ransomware Hunting Team, have cracked more than 300 major ransomware strains and variants, saving an estimated 4 million victims from paying billions of dollars.

By contrast, the FBI rarely decrypts ransomware or arrests the attackers, who are typically based in countries like Russia or Iran that lack extradition agreements with the U.S.  DarkSide, for instance, is believed to operate out of Russia.  Far more victims seek help from the Hunting Team, through websites maintained by its members, than from the FBI.

The U.S. Secret Service also investigates ransomware, which falls under its purview of combating financial crimes.  But, especially in election years, it sometimes rotates agents off cyber assignments to carry out its better-known mission of protecting Presidents, Vice Presidents, major party candidates and their families.  European law enforcement, especially the Dutch National Police, has been more successful than the U.S. in arresting attackers and seizing servers.

Similarly, the U.S. government has made only modest headway in pushing private industry, including pipeline companies, to strengthen cybersecurity defenses.  Cybersecurity oversight is divided among an alphabet soup of agencies, hampering coordination.  The Department of Homeland Security conducts “vulnerability assessments” for critical infrastructure, which includes pipelines.

It reviewed Colonial Pipeline in around 2013 as part of a study of places where a cyberattack might cause a catastrophe.  The pipeline was deemed resilient, meaning that it could recover quickly, according to a former DHS official.  The department did not respond to questions about any subsequent reviews.

Five years later, DHS created a pipeline cybersecurity initiative to identify weaknesses in pipeline computer systems and recommend strategies to address them.  Participation is voluntary, and a person familiar with the initiative said that it is more useful for smaller companies with limited in-house IT expertise than for big ones like Colonial.  The National Risk Management Center, which oversees the initiative, also grapples with other thorny issues such as election security.

Ransomware has skyrocketed since 2012, when the advent of Bitcoin made it hard to track or block payments.  The criminals’ tactics have evolved from indiscriminate “spray and pray” campaigns seeking a few hundred dollars apiece to targeting specific businesses, government agencies and nonprofit groups with multimillion-dollar demands.

Attacks on energy businesses in particular have increased during the pandemic — not just in the U.S. but in Canada, Latin America and Europe.  As the companies allowed employees to work from home, they relaxed some security controls, McLeod said.

Since 2019, numerous gangs have ratcheted up pressure with a technique known as “double extortion.”  Upon entering a system, they steal sensitive data before launching ransomware that encodes the files and makes it impossible for hospitals, universities and cities to do their daily work.  If the loss of computer access is not sufficiently intimidating, they threaten to reveal confidential information, often posting samples as leverage.  For instance, when the Washington, D.C., police department didn’t pay the $4 million ransom demanded by a gang called Babuk last month, Babuk published intelligence briefings, names of criminal suspects and witnesses, and personnel files, from medical information to polygraph test results, of officers and job candidates.

DarkSide, which emerged last August, epitomized this new breed.  It chose targets based on a careful financial analysis or information gleaned from corporate emails.  For instance, it attacked one of Tantleff’s clients during a week when the hackers knew the company would be vulnerable because it was transitioning its files to the cloud and didn’t have clean backups.

To infiltrate target networks, the gang used advanced methods such as “zero-day exploits” that immediately take advantage of software vulnerabilities before they can be patched.  Once inside, it moved swiftly, looking not only for sensitive data but also for the victim’s cyber insurance policy, so it could peg its demands to the amount of coverage.  After two to three days of poking around, DarkSide encrypted the files.

“They have a faster attack window,” said Christopher Ballod, associate managing director for cyber risk at Kroll, the business investigations firm, who has advised half a dozen DarkSide victims.  “The longer you dwell in the system, the more likely you are to be caught.”

Typically, DarkSide’s demands were “on the high end of the scale,” $5 million and up, Ballod said.  One scary tactic: If publicly traded companies didn’t pay the ransom, DarkSide threatened to share information stolen from them with short-sellers who would profit if the share price dropped upon publication.

DarkSide’s site on the dark web identified dozens of victims and described the confidential data it claimed to have filched from them.  One was New Orleans law firm Stone Pigman Walther Wittmann.  “A big annoyance is what it was,” attorney Phil Wittmann said, referring to the DarkSide attack in February.  “We paid them nothing,” said Michael Walshe Jr., chair of the firm’s management committee, declining to comment further.

Last November, DarkSide adopted what is known as a “ransomware-as-a-service” model.  Under this model, it partnered with affiliates who launched the attacks.  The affiliates received 75% to 90% of the ransom, with DarkSide keeping the remainder.  As this partnership suggests, the ransomware ecosystem is a distorted mirror of corporate culture, with everything from job interviews to procedures for handling disputes.  After DarkSide shut down, several people who identified themselves as its affiliates complained on a dispute resolution forum that it had stiffed them.  “The target paid, but I did not receive my share,” one wrote.

Together, DarkSide and its affiliates reportedly grossed at least $90 million.  Seven of Tantleff’s clients, including two companies in the energy industry, paid ransoms ranging from $1.25 million to $6 million, reflecting negotiated discounts from initial demands of $7.5 million to $30 million.  His other three clients hit by DarkSide did not pay.  In one of those cases, the hackers demanded $50 million.  Negotiations grew acrimonious, and the two sides couldn’t agree on a price.

DarkSide’s representatives were shrewd bargainers, Tantleff said.  If a victim said it couldn’t afford the ransom because of the pandemic, DarkSide was ready with data showing that the company’s revenue was up, or that COVID-19’s impact was factored into the price.

DarkSide’s grasp of geopolitics was less advanced than its approach to ransomware.  Around the same time that it adopted the affiliate model, it posted that it was planning to safeguard information stolen from victims by storing it in servers in Iran.  DarkSide apparently didn’t realize that an Iranian connection would complicate its collection of ransoms from victims in the U.S., which has economic sanctions restricting financial transactions with Iran.  Although DarkSide later walked back this statement, saying that it had only considered Iran as a possible location, numerous cyber insurers had concerns about covering payments to the group.  Coveware, a Connecticut firm that negotiates with attackers on behalf of victims, stopped dealing with DarkSide.

Ballod said that, with their insurers unwilling to reimburse the ransom, none of his clients paid DarkSide, despite concerns about exposure of their data.  Even if they had caved in to DarkSide, and received assurances from the hackers in return that the data would be shredded, the information might still leak, he said.

During DarkSide’s changeover to the affiliate model, a flaw was introduced into its ransomware.  The vulnerability caught the attention of members of the Ransomware Hunting Team.  Established in 2016, the invitation-only team consists of about a dozen volunteers in the U.S., Spain, Italy, Germany, Hungary and the U.K.  They work in cybersecurity or related fields.  In their spare time, they collaborate in finding and decrypting new ransomware strains.

Several members, including Wosar, have little formal education but an aptitude for coding.  A high school dropout, Wosar grew up in a working-class family near the German port city of Rostock.  In 1992, at the age of 8, he saw a computer for the first time and was entranced.  By 16, he was developing his own antivirus software and making money from it.  Now 37, he has worked for antivirus firm Emsisoft since its inception almost two decades ago and is its chief technology officer.  He moved to the U.K. from Germany in 2018 and lives near London.

He has been battling ransomware hackers since 2012, when he cracked a strain called ACCDFISA, which stood for “Anti Cyber Crime Department of Federal Internet Security Agency.”  This fictional agency was notifying people that child pornography had infected their computers, and so it was blocking access to their files unless they paid $100 to remove the virus.

The ACCDFISA hacker eventually noticed that the strain had been decrypted and released a revised version.  Many of Wosar’s subsequent triumphs were also fleeting.  He and his teammates tried to keep criminals blissfully unaware for as long as possible that their strain was vulnerable.  They left cryptic messages on forums inviting victims to contact them for assistance or sent direct messages to people who posted that they had been attacked.

In the course of protecting against computer intrusions, analysts at antivirus firms sometimes detected ransomware flaws and built decryption tools, though it wasn’t their main focus.  Sometimes they collided with Wosar.

In 2014, Wosar discovered that a ransomware strain called CryptoDefense copied and pasted from Microsoft Windows some of the code it used to lock and unlock files, not realizing that the same code was preserved in a folder on the victim’s own computer.  It was missing the signal, or “flag,” in their program, usually included by ransomware creators to instruct Windows not to save a copy of the key.

Wosar quickly developed a decryption tool to retrieve the key.  “We faced an interesting conundrum,” Sarah White, another Hunting Team member, wrote on Emsisoft’s blog.  “How to get our tool out to the most victims possible without alerting the malware developer of his mistake?”

Wosar discreetly sought out CryptoDefense victims through support forums, volunteer networks and announcements of where to contact for help.  He avoided describing how the tool worked or the blunder it exploited.  When victims came forward, he supplied the fix, scrubbing the ransomware from at least 350 computers.  CryptoDefense eventually “caught on to us ... but he still did not have access to the decrypter we used and had no idea how we were unlocking his victims’ files,” White wrote.

But then an antivirus company, Symantec, uncovered the same problem and bragged about the discovery on a blog post that “contained enough information to help the CryptoDefense developer find and correct the flaw,” White wrote.  Within 24 hours the attackers began spreading a revised version.  They changed its name to CryptoWall and made $325 million.

Symantec “chose quick publicity over helping CryptoDefense victims recover their files,” White wrote.  “Sometimes there are things that are better left unsaid.”

A spokeswoman for Broadcom, which acquired Symantec’s enterprise security business in 2019, declined to comment, saying that “the team members who worked on the tool are no longer with the company.”

Like Wosar, the 29-year-old Gillespie comes from poverty and never went to college.  When he was growing up in central Illinois, his family struggled so much financially that they sometimes had to move in with friends or relatives.  After high school, he worked full time for 10 years at a computer repair chain called Nerds on Call.  Last year, he became a malware and cybersecurity researcher at Coveware.

Last December, he messaged Wosar for help.  Gillespie had been working with a DarkSide victim who had paid a ransom and received a tool to recover the data.  But DarkSide’s decryptor had a reputation for being slow, and the victim hoped that Gillespie could speed up the process.

Gillespie analyzed the software, which contained a key to release the files.  He wanted to extract the key, but because it was stored in an unusually complex way, he couldn’t.  He turned to Wosar, who was able to isolate it.

The teammates then began testing the key on other files infected by DarkSide.  Gillespie checked files uploaded by victims to the website he operates, ID Ransomware, while Wosar used VirusTotal, an online database of suspected malware.

That night, they shared a discovery.

“I have confirmation DarkSide is re-using their RSA keys,” Gillespie wrote to the Hunting Team on its Slack channel.  A type of cryptography, RSA generates two keys: a public key to encode data and a private key to decipher it.  RSA is used legitimately to safeguard many aspects of e-commerce, such as protecting credit numbers.  But it’s also been co-opted by ransomware hackers.

“I noticed the same as I was able to decrypt newly encrypted files using their decrypter,” Wosar replied less than an hour later, at 2:45 a.m. London time.

Their analysis showed that, before adopting the affiliate model, DarkSide had used a different public and private key for each victim.  Wosar suspected that, during this transition, DarkSide introduced a mistake into its affiliate portal used to generate the ransomware for each target.  Wosar and Gillespie could now use the key that Wosar had extracted to retrieve files from Windows machines seized by DarkSide.  The cryptographic blunder didn’t affect Linux operating systems.

“We were scratching our heads,” Wosar said.  “Could they really have fucked up this badly? DarkSide was one of the more professional ransomware-as-a-service schemes out there.  For them to make such a huge mistake is very, very rare.”

The Hunting Team celebrated quietly, without seeking publicity.  White, who is a computer science student at Royal Holloway, part of the University of London, began looking for DarkSide victims.  She contacted firms that handle digital forensics and incident response.

“We told them, ‘Hey listen, if you have any DarkSide victims, tell them to reach out to us, we can help them.  We can recover their files and they don’t have to pay a huge ransom,’” Wosar said.

The DarkSide hackers mostly took the Christmas season off.  Gillespie and Wosar expected that, when the attacks resumed in the new year, their discovery would help dozens of victims.  But then Bitdefender published its post, under the headline “Darkside Ransomware Decryption Tool.”

In a messaging channel with the ransomware response community, someone asked why Bitdefender would tip off the hackers.  “Publicity,” White responded.  “Looks good.  I can guarantee they’ll fix it much faster now though.”

She was right.  The next day, DarkSide acknowledged the error that Wosar and Gillespie had found before Bitdefender.  “Due to the problem with key generation, some companies have the same keys,” the hackers wrote, adding that up to 40% of keys were affected.

DarkSide mocked Bitdefender for releasing the decryptor at “the wrong time…., as the activity of us and our partners during the New Year holidays is the lowest.”

Adding to the team’s frustrations, Wosar discovered that the Bitdefender tool had its own drawbacks.  Using the company’s decryptor, he tried to unlock samples infected by DarkSide and found that they were damaged in the process.  “They actually implemented the decryption wrong,” Wosar said.  “That means if victims did use the Bitdefender tool, there’s a good chance that they damaged the data.”

Asked about Wosar’s criticism, Botezatu said that data recovery is difficult, and that Bitdefender has “taken all precautions to make sure that we’re not compromising user data” including exhaustive testing and “code that evaluates whether the resulting decrypted file is valid.”

Even without Bitdefender, DarkSide might have soon realized its mistake anyway, Wosar and Gillespie said.  For example, as they sifted through compromised networks, the hackers might have come across emails in which victims helped by the Hunting Team discussed the flaw.

“They might figure it out that way — that is always a possibility,” Wosar said.  “But it’s especially painful if a vulnerability is being burned through something stupid like this.”

The incident led the Hunting Team to coin a term for the premature exposure of a weakness in a ransomware strain.  “Internally, we often joke, ‘Yeah, they are probably going to pull a Bitdefender,’” Wosar said.



Monday, March 15, 2021

MISSISSIPPI - The Drinking Water Crisis

"Water crisis in Jackson, Mississippi highlights ‘dire state’ of city’s infrastructurePBS NewsHour 3/9/2021

Excerpt

SUMMARY:  Much of Mississippi's largest city is beginning its fourth week without safe drinking water coming out of faucets.  Jackson residents, about 80 percent of whom are Black, remain under a system-wide order to boil water, and some don't have any running water at all.  Since a mid-February storm, the city has had about 80 water main breaks.  Jackson Mayor Chokwe Antar Lumumba joins John Yang to discuss.



Monday, May 27, 2019

TRUMP - Impeach or Not

"Why Rep. Raskin says he’s changed his mind on impeaching Trump" PBS NewsHour 5/21/2019

Excerpt

SUMMARY:  The showdown over the balance of power between the executive and legislative branches continued to play out Tuesday on Capitol Hill, as Congress again sought answers from the White House, and the Trump administration declined to provide them.  Lisa Desjardins reports, and Judy Woodruff talks to Rep. Jamie Raskin (D-Md.) a member of the House Judiciary Committee, about moving toward impeachment.




"Trump defiance could push more Democrats into ‘impeachment camp,’ Connolly says" PBS NewsHour 5/22/2019

Excerpt

SUMMARY:  House Democrats are divided on the question of whether to begin impeachment proceedings against President Donald Trump.  Rep. Gerry Connolly (D-Va.) says that while he thinks “we have seen a massive cover-up on so many fronts” by the President -- echoing House Speaker Nancy Pelosi -- he doesn’t believe Democrats need an impeachment inquiry to move forward.  Connolly joins Judy Woodruff.




A bully threatens again.

"Trump refuses to work with Democrats amid simmering impeachment debate" PBS NewsHour 5/22/2019

Excerpt

SUMMARY:  House Speaker Nancy Pelosi did not call for impeachment proceedings against President Donald Trump on Wednesday, as some members of her party are increasingly urging.  But her firm message for the President was met with a vow by Trump not to work with Democrats on infrastructure or anything else until investigations into him have ceased.  Lisa Desjardins joins Judy Woodruff for more.
Inherent contempt of Congress

Monday, May 20, 2019

CALIFORNIA - Wildfire Fallout

"This wildfire season, aging power infrastructure may leave parts of California dark" PBS NewsHour 5/17/2019

Excerpt

SUMMARY:  California wildfires have been brutal recently.  The worst in a century was last November’s Camp Fire, which killed 85 people and largely destroyed the town of Paradise.  State investigators have confirmed a Pacific Gas & Electric transmission line caused the blaze.  Amna Nawaz talks to The Wall Street Journal’s Russell Gold about how it started and whether PG&E has taken steps to prevent recurrence.

SOUTH AFRICA - Running Dry

"How failing infrastructure and climate change leave many South Africans without water" PBS NewsHour 5/16/2019

Excerpt

SUMMARY:  It's been 25 years since South Africa dismantled apartheid, and while political progress has occurred, the young democracy continues to face hurdles.  In recent years, extreme drought pushed the country to the brink of disaster, and although rainfall finally mitigated the situation, persistent water shortages are now a part of daily life.  Special correspondent Fred de Sam Lazaro reports.

Monday, April 23, 2018

PUERTO RICO - 2018 Hurricane Season

"Hurricane season is coming and Puerto Rico still has a big power problem" PBS NewsHour 4/19/2018

Excerpt

SUMMARY:  Seven months after Hurricane Maria devastated Puerto Rico and its power grid, the entire island lost power on Wednesday -- the biggest outage since September.  As crews keep working to restore power to the full island, residents are raising questions once again about the adequacy of those efforts.  Amna Nawaz gets an update from special correspondent Monica Villamizar.

Amna Nawaz (NewsHour):  So, you have been reporting on this painfully slow pace of recovery ever since Hurricane Maria hit.

But this doesn’t seem to be related to Maria anymore.  Everyone’s wondering, how does this keep happening?

Monica Villamizar, special correspondent:  Yes, absolutely.  That’s a great question.

Many people — Puerto Ricans right now are being out to sort of be patient and understand, at least by PREPA the power utility company — that keep on asking everybody, be patient and understand that generating electricity and distributing it to everybody is very difficult, and our infrastructure was absolutely decimated by Maria.

But if you stop think, Puerto Ricans are saying, how can we be patient after not having electricity for months on end?  Many people still today do not have power.

Amna Nawaz:  Right.

Monica Villamizar:  And how can it be so complicated?

The truth of the matter is, in all fairness, it is complicated.  And the grades is — was very poorly [badly] damaged, but it was also in very bad conditions.

They have a massive transmission problem right now, which means it’s really fragile and unstable.  So, if you will, you knock down a power — like you say, how can that throw the whole island into darkness?  That’s not normal, normally what happens in other countries.

In Puerto Rico, it’s happening because the system that was put in place and the power grid is so obsolete, that this is the situation they have.

Amna Nawaz:  So, it was a bad problem decimated and made worse by this Category 5 storm seven months ago.

So, who owns the problem?  Who actually has responsibility to try to fix it now?

Monica Villamizar:  That’s a great question.  And that’s sort of what we have been seeing, a political blame-game.

So, the power utility company blames FEMA.  FEMA blames the Corps of Engineers.  Puerto Ricans blame the Trump administration.  Everybody is going to blame everybody.  But in the end, the island is bankrupt.  There is no money.

And to fix this enormous problem is going to take billions and billions of dollars that the island does not have.  So they’re facing a very serious situation, which is fixing a massive problem, fixing it soon, because, remember, hurricane season is going to start again.

Amna Nawaz:  Right.

Monica Villamizar:  And in the meantime, all these local authorities and politicians throwing blame around.

In the end, everybody is to blame in a way.  But what they have to do and what a lot of people are telling me now is that they want to look to local authorities and pass that to sort of try to own the situation, as you say, and make something better for the island, really, try to construct the future themselves.

Amna Nawaz:  And what about people on the ground?  What are they telling you now?  How do they feel after all this time and where they still are today?

Monica Villamizar:  Well, so, most people at the beginning, when we first reported in Puerto Rico, and the generalized feeling was, we are American citizens and we are being treated as secondhand citizens by the company administrations effectively, because the response to our hurricane wasn’t the same as we saw in Florida or Texas, for instance.

And there was no sense of urgency.  But we were here dying and hungry and being affected.

It’s sort of slightly shifted now, and I think they’re looking to their local authorities, to Governor Rossello, to Mayor Carmen Yulin, et cetera, like, what are you going to do to fix our problems?

Because, you know what, in the end, they say they don’t have education because of all this debt restructuring and the consolidations of schools, et cetera.  They don’t have education, they don’t have power, and they don’t have health.

So when a government is not providing that, it’s somewhat failing in its role.  And that’s when people are really going to start asking more of their local authorities and local leaders, because they really need solutions to urgent problems.

And the situation they’re facing right now is, we stay here and make things better, or we have to leave to the mainland.

Monday, February 19, 2018

BALTIMORE - Failing Schools & Corrupt Cops

"Freezing classrooms spark heated debate over Baltimore’s school infrastructure" PBS NewsHour 2/13/2018

Excerpt

SUMMARY:  Baltimore City Public Schools faced outrage from parents after images emerged of students wearing coats in a freezing classroom.  More than a third of schools reported a lack of heat this winter during a cold snap, and that’s just one of the many problems plaguing the school system’s crumbling infrastructure, underscoring a larger debate about long-term funding and investment.  John Yang reports.




"How corrupt Baltimore cops used the badge to steal" PBS NewsHour 2/13/2018

Excerpt

SUMMARY:  Two Baltimore city police officers were convicted in federal court on Monday on charges including racketeering and robbery, as part of a brazen corruption scandal.  Baltimore’s Gun Trace Task Force were tasked with getting illegal guns off the street, but used their authority to target people for theft.  John Yang talks to Jayne Miller of WBAL-TV about the debate on how the city police force needs to change.

TRUMP AGENDA - The Non-Infrastructure Plan

"Here’s what Trump’s spending proposal would fund and cut" PBS NewsHour 2/12/2018

In actually, the so-called infrastructure spending is actually a privatizing plan (aka big profit to private industry).

Excerpt

SUMMARY:  President Trump unveiled his long-awaited infrastructure plan to fix roads, bridges, and airports on Monday; as well as his $4.4 trillion outline of spending priorities.  But the plan was overshadowed by internal struggles at the White House, and questions of how top staff handled domestic violence allegations against two aides.  Yamiche Alcindor joins Judy Woodruff for more.




"LA mayor: Infrastructure fuels prosperity, and federal government needs to do its part" PBS NewsHour 2/12/2018

Excerpt

SUMMARY:  President Trump's $1 trillion infrastructure blueprint relies on states and local governments, as well as private sector investment, to provide much of the needed funding.  Los Angeles Mayor Eric Garcetti says that his city is doing its part already, and that the federal government needs to step up.  Garcetti joins Judy Woodruff to discuss that, as well as protecting “Dreamers.”

Monday, January 29, 2018

PUERTO RICO - Power, Why So Long

"Here’s why restoring power in Puerto Rico is taking so long" PBS NewsHour 1/25/2018

Answer, Puerto Rico is not the 'state next door' but its entire infrastructure was wiped out.

Excerpt

SUMMARY:  Four months after Hurricane Maria, about 450,000 of 1.5 million electricity customers in Puerto Rico still have no service.  Blackouts regularly occur for hours at a time, even in San Juan.  Special correspondent Monica Villamizar reports on the emergency efforts to restore power, and how some have taken matters into their own hands as outdated technology, and suspected corruption, stand in the way.

Wednesday, January 10, 2018

Monday, March 13, 2017

AMERICA - Our Crumbling Infrastructure

"America's infrastructure receives poor assessment" PBS NewsHour 3/11/2017

Excerpt

SUMMARY:  The nation's infrastructure received an overall grade of D-plus in a report card published this week by the American Civil Society of Engineers, the same poor grade it issued in 2013.  With 16 categories graded, bridges, roads and dams were among those that received a low score.  The group's managing director, Casey Dinges, joined Hari Sreenivasan from Washington to explain why.

HARI SREENIVASAN, NEWSHOUR WEEKEND ANCHOR:  The nation's infrastructure received an overall grade of “D- plus” in a report card published this week by the American Society of Civil Engineers, the same grade the group issued in 2013.  Among the 16 categories graded:  bridges received a “C-plus”; roads, dams and airports, a “D”; while mass transit came in with a “D-minus.”

The group's senior managing director, Casey Dinges, joins me now from Washington to explain these very low grades.

Mr. Dinges, these are not grades that we would want to see on any child's report card.  Yet, I guess we tolerate them at such crucial things as the roads and bridges we drive on and the water that we drink.

CASEY DINGES, SENIOR MANAGING DIRECTOR, AMERICAN SOCIETY OF CIVIL ENGINEERS:  I think the way the issue may play out is that the degradation is maybe so imperceptible to the public users, the traveling public you know, the water main break, even though it happens every 2 1/2 minutes in the United States, people my say, “Well, it's just not happening in my neighborhood, so I'm not thinking about it.”  Traffic congestion is a huge issue in major metropolitan areas.  Pavement issues you'll find in regions all across the country affect people, but maybe not enough to make it a top-of-mind issue.

So, at this point, we are somewhat encouraged to see presidential leadership being exerted on the infrastructure issue.  But funding is the key thing.  That would be the heavy lift for the Congress.

Monday, December 05, 2016

REPAIRING AMERICA - Our Crumbling Infrastructure

"Is crumbling infrastructure inhibiting American productivity?" PBS NewsHour 12/1/2016

Excerpt

SUMMARY:  In recent decades, American productivity growth has slowed.  Yale University's Jacob Hacker has a possible explanation:  the country's outdated and deteriorating infrastructure.  Hacker, co-author of “American Amnesia,” argues the U.S. has forgotten the role government plays in engineering prosperity, and that public investment got us where we are today.  Economics correspondent Paul Solman reports.

ANNOUNCER:  Attention, please, this is the last call.

PAUL SOLMAN (NewsHour):  Mid-morning at New York's Penn Station.  Throngs rush to the 10:00 a.m.  Acela to Washington, D.C. ridership is up and these highish-speed trains are at or near capacity as business travelers chug up and down the Northeast Corridor.

WOMAN:  Amtrak conductor 2153 to the heading.  All stations are cleared.

PAUL SOLMAN:  But they're hurrying up in an America of slowed-down productivity, the amount of output per hour of work rising at just 1.3 percent a year since 2007, compared to more than double that rate from 1947 to 1973.

One cause, America's crumbling infrastructure, like our passenger rail system, some of which dates to the Civil War, causing delays that hamstring the economy.

Wick Moorman worked his way to the top of the Norfolk Southern Freight Railroad, before retiring last year, returning to work recently, at a dollar a year, to steer and revive Amtrak.  Riding the Acela back to New York, he insisted it's not just our railroads that need work.

WICK MOORMAN, CEO, Amtrak:  When you look at the state of our highway system today, which we all get out and drive on every day, in terms of congestion, in terms of the surface conditions, in terms of the fact that we're seeing that more and more bridges have to be closed to rehabilitate, it has to be an economic drag, right?  Highway congestion alone costs this country an enormous amount of productivity.

PAUL SOLMAN:  So, why aren't we investing in infrastructure of the kind that made America great in the '40s, '50s, '60s, government investments that hiked our economy to unheard-of heights of productivity?

So asks Yale's Jacob Hacker.  His answer?

JACOB HACKER, Co-Author, American Amnesia:  We have forgotten the incredibly important role that government plays in our prosperity.

PAUL SOLMAN:  And thus the term “American Amnesia,” Hacker's new book, subtitled “How the War on Government Led Us to Forget What Made America Prosper,” because, in the 19th and 20th centuries, prosper, we did.

JACOB HACKER:  We went from being from a relatively poor, relatively under-educated and relatively unhealthy society, to being the richest, the most well-educated and the healthiest society that the world had ever seen.

After World War II, we see the blossoming of this really active investing state that's investing on both non-defense and defense technology and really sowing the seeds for the productivity revolution that occurs during this period.

PAUL SOLMAN:  Government outlays of land for railroads, say, subsidies for airports and waterways that helped make the country one market, speed goods and labor from coast to coast.  Think of Republican President Eisenhower's interstate highway system.

JACOB HACKER:  The estimates are that it accounted for something like a third of productivity growth in the U.S. economy in the late 1950s, and around a quarter in the 1960s.

PAUL SOLMAN:  And what's true of hard infrastructure is true of what were once America's greatest soft productivity advantages:  health and education.

JACOB HACKER:  If you look at older Americans in the United States, they're the most educated older citizens in the world.  But if you look at younger Americans, we have fallen to the high teens in terms of college completion rates.

So, in a new economy that's based much more on knowledge and technology, we're not investing adequately or correctly to get kids through college the way other countries are.

Monday, December 28, 2015

OVER THE RIVER AND THROUGH THE WOODS - Highway Bill 2015

"Will the highway bill lead to funding problems down the road?" PBS NewsHour 12/25/2015

Excerpt

SUMMARY:  The scope of the $300 billion highway bill recently passed by Congress will touch roads and bridges in every state and most counties for a half decade.  Since 2009, there has been no long-term or stable federal funding to address needed transportation fixes.  But critics question where that funding for the new bill is coming from.  Political director Lisa Desjardins reports.

GWEN IFILL (NewsHour):  That trip over the river and through the woods might go a little more smoothly in future years, thanks to the big highway bill that became law this month.  It is the largest deal of its kind in a decade.

And, as political director Lisa Desjardins reports, it’s attracting both cheers and concern.

LISA DESJARDINS (NewsHour):  The scope of this highway bill is vast, over $300 billion that will touch roads and bridges in every state and most counties for half-a-decade, a dramatic law that hits very familiar places to Americans.

HANS RIEMER, Montgomery County Councilman, Maryland:  Behind me is one of the most congested intersections in the state of Maryland.  And we have had the designs completed for this upgrade of this intersection for maybe 10 years.  It’s shovel-ready.

LISA DESJARDINS:  Meet Hans Riemer, a man who thinks about transportation a lot.  He has to, as a councilman for traffic-heavy Montgomery County, Maryland, north of Washington, D.C.

Riemer showed us this intersection that is a major bottleneck each morning.  The county has had a fix ready for years, but it has been in limbo waiting for stable federal funding to help, because — listen to this fact — since 2009, Congress has limped through 34 short-term highway bills, and no stable funding to back big projects like this, until now.

HANS RIEMER:  If the concern is, well, the federal government is not going to be there on the other end, don’t — then there is a lot of pressure not to spend the money locally.  And that is, you know, a — that is just a downward spiral really for everybody.  So the fact that bill is done at least for a temporary funding fix is a great step forward.

SEN. MITCH MCCONNELL, Majority Leader:  It would be the longest-term bill to pass Congress in almost two decades.

LISA DESJARDINS:  Senate Majority Leader Mitch McConnell pushed the highway bill as a priority, and the mega-deal was put together by usual adversaries, Democrat Barbara Boxer of California and Republican Jim Inhofe of Oklahoma.  They hashed out a final agreement with House members and the new speaker.

REP. PAUL RYAN, Speaker of the House:  We’re going to have a highway bill, which will help families and workers by rebuilding our infrastructure and giving a boost to our economy.

Can you believe it?!  A Republican Speaker of the House that believes in (conservative explicative deleted) compromise.

Monday, August 03, 2015

U.S. INFRASTRUCTURE - Road Patch

IMHO:  States and cities are paying for NOT having a year-by-year infrastructure maintenance schedule that was adhered to.  Repair was always put off to pay for other priorities, and now such repairs are much more expensive.

"States struggle with needed transportation fixes after years of cutbacks" PBS NewsHour 7/30/2015

Excerpt

SUMMARY:  Potholes, vulnerable bridges, a lack of sidewalks -- following years of cutbacks in federal transportation funding, states are feeling the pinch.  In Oregon, the NewsHour’s Cat Wise explores pressing infrastructure funding needs, like alternative forms of transportation, traffic reduction measures and preparing for a massive earthquake that many predict will hit in the state within 50 years.

JUDY WOODRUFF (NewsHour):  As we reported earlier, after much debate, Congress today passed a short-term extension of the Highway Trust Fund.  But years of cutbacks in federal and local transportation funding are being felt in communities around the country.

The NewsHour’s Cat Wise takes a look at some of the key transportation issues facing Portland, Oregon, and the surrounding region.

CAT WISE (NewsHour):  Early one morning this week, as thousands of commuters drove overhead, Oregon bridge inspector Joel Boothe hoisted himself 100 feet up in the air and got to work.

Boothe was doing a routine inspection of one of the state’s busiest bridges, the Marquam Bridge built in 1966.  It carries about 90,000 vehicles a day on Interstate 5 over the Willamette River near downtown Portland.  Unlike some of the other bridges in Portland, it’s in fairly good shape, but it’s still got some issues.

JOEL BOOTHE, Bridge Inspector:  So, question, on both sides of the location of those general hanging locations, we have had problems.

CAT WISE:  Issues that are being closely monitored by the state’s chief bridge engineer, Bruce Johnson.

BRUCE JOHNSON, State Bridge Engineer, Oregon Department of Transportation:  They found some pack rust, so we have got some corrosion going on.  We’re losing some section in our steel.  The other issue, this bridge has had a lot of fatigue cracking.

And, of course, we have mitigated the cracks by doing repairs, but we’re concerned about the performance of our repairs and how the cracking is going.

CAT WISE:  Johnson says that maintaining bridge safety is a huge task for the state.

Monday, November 17, 2014

NUCLEAR INFASTRUCTURE - Dealing With Decay

"How should the U.S. deal with decaying nuclear arms infrastructure?" PBS NewsHour 11/14/2014

Excerpt

HARI SREENIVASAN (NewsHour):  Earlier today, the nation’s top defense official said there are systematic problems in the management of America’s nuclear weapons stockpile, adding that without billions of dollars for improvements, the safety and security of the force could be undermined.

Chief foreign affairs correspondent Margaret Warner reports.

CHUCK HAGEL, Secretary of Defense:  Our nuclear enterprise is foundational to America’s national security and the resources and attention we commit to the nuclear force must reflect that.

MARGARET WARNER (NewsHour):  Defense Secretary Chuck Hagel announced the shake-up after two reviews that began in February.  They found the country’s aging nuclear infrastructure, including facilities, silos and its nuclear submarine fleet, has decayed markedly and will cost billions of dollars to fix.

CHUCK HAGEL:  The internal and external reviews I ordered show that a consistent lack of investment and support for our nuclear forces over far too many years has left us with too little margin to cope with mounting stresses.

MARGARET WARNER:  Among other things, the findings revealed equipment problems, including the fact that crews maintaining the nation’s 450 intercontinental ballistic missiles shared a single specialized wrench that’s been shipped from base to base, and blast doors atop 60-year-old silos that no longer seal.

These lapses were attributed to a culture of micromanagement and bureaucracy that left top-level officials unaware of problems and personnel shortages and poor career advancement opportunities in the infrastructure force.

A series of embarrassing incidents led to the reviews.  In 2007, six nuclear warheads, still attached to missiles, were flown across the country, in a violation of safety rules.  In 2013, the Air Force decertified 17 launch officers in North Dakota for poor performance.  And this year, a cheating scandal involving nuclear launch officers erupted at Malmstrom Air Force Base in Montana.  The head of the nuclear wing there resigned last March, and nine other officers were removed.

In the meantime, the Navy had its own exam cheating scandal involving reactor training instructors.

Today, Hagel said the Pentagon took its eye off the ball in recent years, and has to act quickly.

Thursday, January 09, 2014

U.S. INFRASTRUCTURE - Bipartisan Push to Revitalize

It is important to note that this type of spending CREATES jobs and promotes transportation infrastructure.

But I expect that the Money-Worshiping Republicans will insist it be paid for by cuts to programs that help ordinary citizens, no matter how good it would be for our nation.  It a part of their psyche that nothing is worth spending money if it's too expensive in their eyes (aka does not benefit their rich paymasters).

"LaHood, Rendell make bipartisan push to revitalize America's infrastructure" PBS Newshour 1/8/2014

Excerpt

JUDY WOODRUFF (Newshour):  Finally tonight, a conversation about rebuilding the country's roads, bridges and other critical components, as seen through the lens of American competitiveness.

Infrastructure investment rarely captures national attention, until there's a tragic failure or accident, such as the 160-foot chunk of Washington State's Skagit River Bridge that suddenly gave way in May, the deadly 2007 collapse of the 1-35 bridge spanning the Mississippi River between Minneapolis and Saint Paul, and the historic failure of New Orleans' levee system during 2005's Hurricane Katrina.

But some experts say the problems are exacerbated by a lack of investment that can leave the nation's transportation, communications, and energy networks outdated and unreliable.

Still, there's been more investment in the years since the recession began, the most prominent being President Obama's 2009 stimulus bill.  The American Recovery and Reinvestment Act, as it was called, allocated $150 billion to a wide array of public works projects.  While the stimulus fund has expired now, the president has continued to press Congress for more spending.


Build America's Future link

Thursday, July 04, 2013

SAN DIEGO - My Hometown Reflects U.S. Infrastructure Problem

This is what happens when you DO NOT have budgets with a yearly built-in upkeep for infrastructure.  The problems just keep accumulating until the cost for fixing problems is much bigger than if you had cyclic yearly upkeep.  It's better and cheaper to fix problems in small bites.

Note that this reflects one of the problems that killed the U.S. steel industry, not upgrading machines on a regular bases.  Hence they grew older and more expensive to repair, and did not keep up with more modern steel factories in competing nations.

"Victory for San Diego Sidewalks" by Liam Dillon, Voice of San Diego 6/11/2013

Sidewalks had a good day on Monday.

For the first time, San Diego will evaluate its 5,000 miles of sidewalks after City Council members voted to include a $1 million assessment in next year’s budget.  The evaluation will uniformly identify broken and missing sidewalks, rank the blocks needing the most help and put a price tag on fixing them and building new ones.

And it gets better.  The council also committed to changing the city’s illogical policies that make homeowners responsible for repairing broken sidewalks but the city legally liable for trip-and-fall lawsuits.

“Ultimately we want to revamp the policy in such a fashion that it works,” said Councilman Mark Kersey, who heads the city’s infrastructure committee.

Kersey said he expects the city’s transportation department to bring his committee a formal plan for the assessment in the fall.  At the same time, the committee will begin revamping sidewalk polices.

These efforts should lead to what everyone wants:  A plan to fix the city’s decaying sidewalks so they don’t look like this one in City Heights anymore.

Photo courtesy of The Stumblr
A busted sidewalk in City Heights


Getting money for the sidewalk evaluation wasn’t a slam dunk.  Mayor Bob Filner, who supported the concept of the evaluation, didn’t include it in his initial or revised budgets.  His staffers had concerns about a spate of new trip-and-fall lawsuits should the city identify bad sidewalks but not fix them.  Councilwoman Sherri Lightner recently said she opposed the evaluation because she feared the city would use it as an excuse to send unsuspecting residents a bill to fix the sidewalk outside their house.

But at Monday’s meeting, Lightner made the motion to include the evaluation, along with boosting library hours and other changes, in the budget.  She said she wanted to support the majority of her colleagues who had asked for it.

Numerous neighborhood interest groups and disabled advocates had pushed for the study as well.  I’ve beat the drum for changes to sidewalk policies since January, including through our Stumblr broken sidewalks photo blog.   At the council hearing, Kersey said the sidewalk evaluation “captured the attention of the public.”

The legal concerns are real, he said, but the city has to deal with its sidewalks.

“We can’t just bury our heads in the sand and hope that it goes away,” Kersey said.

A couple notes about our continuing sidewalk coverage.  With the sidewalk assessment funded, we’re going to scale back our publishing on The Stumblr.  So far, we’ve been posting new photos every work day and have almost 130 of them.  We’re going to keep the blog rolling, but now we’re only going to put up photos as they come in.

And make sure to put those photos to good use.  We’re sponsoring an art contest inspired by The Stumblr for the best art project using Stumblr photos or actual sidewalks.  The contest deadline is July 8 and we’ll be unveiling the winner at an event soon after.

Make sure to send in your ideas!

Wednesday, May 29, 2013

AMERICA - Health of U.S. Infrastructure

"What Bridge Collapse in Wash. State Says About Health of U.S. Infrastructure" PBS Newshour 5/28/2013

Excerpt

SUMMARY:  The collapse of a bridge on Washington state's Interstate-5 has refocused the nation's attention on the state of its ailing transportation infrastructure.  Gwen Ifill discusses the deficiencies and potential solutions with Casey Dinges of the American Society of Civil Engineers and infrastructure analyst Dan McNichol.

Friday, January 04, 2013

AMERICA - Our Aging Water Systems

"A Journey to America's Smelly Depths to Confront Our Aging Water Systems" PBS Newshour 1/3/2013

Excerpt

SUMMARY: As clean water regulations become tougher and sewer systems and water treatment plants become outdated, cities are struggling to stay compliant and safe. Science correspondent Miles O'Brien goes underground to discover the many ways America's sewer systems could be revamped to conserve water and save money.


COMMENT: In the video 'deferring' repairs is mentioned. This is an ongoing problem not only in water systems but in our nation's infrastructure as a whole. We (citizens and government) keep putting upkeep of infrastructure 'till mañana, the usual excuse is money. Problem, repair is going to cost MORE in the future, more than if we had plans to *constantly* update infrastructure over several years (be pro-active) rather than wait until something breaks.

Note that this attitude of wait 'till mañana is what killed our U.S. steel industry and almost killed our auto industry, not replacing aging manufacturing equipment on a regular bases.