A Rogue Raspberry Pi Let Hackers Into NASA’s JPL Network

A Rogue Raspberry Pi Let Hackers Into NASA’s JPL Network

NASA’s Jet Propulsion Laboratory (JPL) works with some of the most advanced technology in the world, including Mars rovers and space telescopes. However, it was a relatively simple piece of consumer technology that allowed hackers to break into its network and steal data. According to a report from the US Office of the Inspector General (OIG), someone connected an unauthorized Raspberry Pi to a JPL network, giving hackers a way into the systems.

While inside JPL’s network, the hackers reportedly stole about 500MB of data related to human spaceflight. If they were just some jokers on the internet, that data isn’t terribly useful. If, however, they represented an adversarial nation, the data could be extremely valuable. This would be bad enough, but the OIG review dived deeper and revealed more issues with the way JPL runs its networks.

After ransacking the JPL computers, the attackers found a route deeper into JPL’s network. They were able to access sensitive systems like the Deep Space Network, an array of radio antennas that NASA uses to communicate with distant spacecraft. The security breach was so severe that officials at Johnson Space Center decided to disconnect from the JPL network to protect projects like the Orion Multi-Purpose Crew Vehicle and International Space Station. Johnson remained disconnected from JPL until November 2018, but some connections are still restricted.

JPL is good at visiting other planets, not so much at network security.
JPL is good at visiting other planets, not so much at network security.

The OIG lambasts JPL for the shared nature of its network. A properly segmented network would have kept the attackers from branching out into other systems and threatening flight operations. The system JPL uses to track network hardware is apparently woefully incomplete and poorly maintained. Network administrators even admitted they don’t regularly check the list of new devices.

NASA and JPL have pledged to address the issues cited in the report, and the OIG will circle back to make sure that happens. We can’t take chances with major endeavors like the Artemis Program coming up.

Continue reading

Intel Launches AMD Radeon-Powered CPUs
Intel Launches AMD Radeon-Powered CPUs

Intel's new Radeon+Kaby Lake hybrid CPUs are headed for store shelves. Here's how the SKUs break down and what you need to know.

NASA’s OSIRIS-REx Asteroid Sample Is Leaking into Space
NASA’s OSIRIS-REx Asteroid Sample Is Leaking into Space

NASA reports the probe grabbed so much regolith from the asteroid that it's leaking out of the collector. The team is now working to determine how best to keep the precious cargo from escaping.

Chromebooks Gain Market Share as Education Goes Online
Chromebooks Gain Market Share as Education Goes Online

Chromebook sales have exploded in the pandemic, with sales up 90 percent and future growth expected. This poses some challenges to companies like Microsoft.

Intel’s Raja Koduri to Present at Samsung Foundry’s Upcoming Conference
Intel’s Raja Koduri to Present at Samsung Foundry’s Upcoming Conference

Intel's Raja Koduri will speak at a Samsung foundry event this week — and that's not something that would happen if Intel didn't have something to say.