A Rogue Raspberry Pi Let Hackers Into NASA’s JPL Network

A Rogue Raspberry Pi Let Hackers Into NASA’s JPL Network

NASA’s Jet Propulsion Laboratory (JPL) works with some of the most advanced technology in the world, including Mars rovers and space telescopes. However, it was a relatively simple piece of consumer technology that allowed hackers to break into its network and steal data. According to a report from the US Office of the Inspector General (OIG), someone connected an unauthorized Raspberry Pi to a JPL network, giving hackers a way into the systems.

While inside JPL’s network, the hackers reportedly stole about 500MB of data related to human spaceflight. If they were just some jokers on the internet, that data isn’t terribly useful. If, however, they represented an adversarial nation, the data could be extremely valuable. This would be bad enough, but the OIG review dived deeper and revealed more issues with the way JPL runs its networks.

After ransacking the JPL computers, the attackers found a route deeper into JPL’s network. They were able to access sensitive systems like the Deep Space Network, an array of radio antennas that NASA uses to communicate with distant spacecraft. The security breach was so severe that officials at Johnson Space Center decided to disconnect from the JPL network to protect projects like the Orion Multi-Purpose Crew Vehicle and International Space Station. Johnson remained disconnected from JPL until November 2018, but some connections are still restricted.

JPL is good at visiting other planets, not so much at network security.
JPL is good at visiting other planets, not so much at network security.

The OIG lambasts JPL for the shared nature of its network. A properly segmented network would have kept the attackers from branching out into other systems and threatening flight operations. The system JPL uses to track network hardware is apparently woefully incomplete and poorly maintained. Network administrators even admitted they don’t regularly check the list of new devices.

NASA and JPL have pledged to address the issues cited in the report, and the OIG will circle back to make sure that happens. We can’t take chances with major endeavors like the Artemis Program coming up.

Continue reading

Researchers Are Studying Mice in VR With a Tiny, Raspberry Pi-Powered Headset
Researchers Are Studying Mice in VR With a Tiny, Raspberry Pi-Powered Headset

The headset works with a spherical treadmill to translate a mouse's real-life movements into the virtual world.

Don’t Expect a Raspberry Pi 5 in 2023, Says CEO
Don’t Expect a Raspberry Pi 5 in 2023, Says CEO

Upton says the firm's updated single-board computer won't be available until at least 2024.

Raspberry Pi 3 Model B+ Is More Powerful, Still Just $35
Raspberry Pi 3 Model B+ Is More Powerful, Still Just $35

This model includes several useful improvements over the old Model B, but it keeps the same $35 price point.

Everything We Know About the Raspberry Pi 4
Everything We Know About the Raspberry Pi 4

When will we see a Raspberry Pi 4? Here's everything we know so far.