JPL made it easy to hack the network by connecting a Raspberry Pi without implementing the appropriate security protocols
The logical thing is to think that NASA's security measures are stratospheric. Normally this is the case, since you cannot allow just anyone to sneak into the systems of the US space agency. But NASA's Jet Propulsion Laboratory (JPL) appears to have multiple security vulnerabilities, according to the agency's Office of the Inspector General, one of them for a Raspberry Pi.
Following a security breach in 2018, a comprehensive security check was carried out on the center's network. This security breach was due to that a Raspberry Pi was connected unauthorized and was attacked by hackers. These attackers obtained 500MB of data from one of the main missions and found a gateway that will allow them to delve deep into the JPL network.
NASA security breached by a Raspberry Pi
Through that security breach, the hackers accessed several missions, including NASA's Deep Space Network. This is the network of communication facilities for spacecraft. Because of this, the security systems of some of these sensitive programs, such as the Orion Multi-Purpose Crew Vehicle and the International Space Station, have been disconnected from the agency's network.
In addition, it has been found that security tickets can last a long time without being resolved. Some of these reports took up to 180 days to correct. But it is that the researchers have detected JPL's response and incident management is far from NASA's recommendations.
The OIG will have proposed a battery of solutions to NASA to correct the problems. All the proposals except one have been accepted. The only refusal is to establish a formal threat process to find security flaws before they cause problems. In addition, they must verify if JPL can continue working before the investigation is closed.
Source: engadget
