A Rogue Raspberry Pi Let Hackers Into NASA’s JPL Network

A Rogue Raspberry Pi Let Hackers Into NASA’s JPL Network

NASA’s Jet Propulsion Laboratory (JPL) works with some of the most advanced technology in the world, including Mars rovers and space telescopes. However, it was a relatively simple piece of consumer technology that allowed hackers to break into its network and steal data. According to a report from the US Office of the Inspector General (OIG), someone connected an unauthorized Raspberry Pi to a JPL network, giving hackers a way into the systems.

While inside JPL’s network, the hackers reportedly stole about 500MB of data related to human spaceflight. If they were just some jokers on the internet, that data isn’t terribly useful. If, however, they represented an adversarial nation, the data could be extremely valuable. This would be bad enough, but the OIG review dived deeper and revealed more issues with the way JPL runs its networks.

After ransacking the JPL computers, the attackers found a route deeper into JPL’s network. They were able to access sensitive systems like the Deep Space Network, an array of radio antennas that NASA uses to communicate with distant spacecraft. The security breach was so severe that officials at Johnson Space Center decided to disconnect from the JPL network to protect projects like the Orion Multi-Purpose Crew Vehicle and International Space Station. Johnson remained disconnected from JPL until November 2018, but some connections are still restricted.

JPL is good at visiting other planets, not so much at network security.
JPL is good at visiting other planets, not so much at network security.

The OIG lambasts JPL for the shared nature of its network. A properly segmented network would have kept the attackers from branching out into other systems and threatening flight operations. The system JPL uses to track network hardware is apparently woefully incomplete and poorly maintained. Network administrators even admitted they don’t regularly check the list of new devices.

NASA and JPL have pledged to address the issues cited in the report, and the OIG will circle back to make sure that happens. We can’t take chances with major endeavors like the Artemis Program coming up.

Continue reading

Someone Hacked Ray Tracing Into the SNES
Someone Hacked Ray Tracing Into the SNES

Surely, a game console from the 90s couldn't support ray tracing, right? Wrong. Game developer and engineer Ben Carter hacked ray tracing into the Super NES with a little help from an FPGA dev board.

New ‘Morpheus’ CPU Design Defeats Hundreds of Hackers in DARPA Tests
New ‘Morpheus’ CPU Design Defeats Hundreds of Hackers in DARPA Tests

A new CPU design has won accolades for defeating the hacking efforts of nearly 600 experts during a DARPA challenge. Its approach could help us close side-channel vulnerabilities in the future.

Knee-Deep in the LED: Hackers Get Doom Running on Ikea Smart Bulb
Knee-Deep in the LED: Hackers Get Doom Running on Ikea Smart Bulb

The devices capable of running Doom keep growing. Today's demonstration? Smart bulbs.

Switch Hacker Agrees to Pay Nintendo an Additional $10 million
Switch Hacker Agrees to Pay Nintendo an Additional $10 million

After spending the last few years making and selling Switch modding kits, Bowser has agreed to pay Nintendo $10 million in damages to settle a civil lawsuit. This is in addition to the restitution he was ordered to pay following his criminal conviction.