TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

A Rogue Raspberry Pi Let Hackers Into JPL Network

97 pointsby workerthreadalmost 6 years ago

7 comments

jasciialmost 6 years ago
The actual OIG report: <a href="https:&#x2F;&#x2F;oig.nasa.gov&#x2F;docs&#x2F;IG-19-022.pdf" rel="nofollow">https:&#x2F;&#x2F;oig.nasa.gov&#x2F;docs&#x2F;IG-19-022.pdf</a> I only did the briefest of scans, but the recommendations seem pretty basic best practices stuff.<p>In my experience, research labs tend to be creative spaces with a focus on collaboration and information security is not foremost on peoples mind. I guess that will have to change.
评论 #20246907 未加载
评论 #20246763 未加载
kryogen1calmost 6 years ago
&gt;5,406 unresolved SPLs—about 86 percent of which were rated high or critical &gt;JPL did not effectively address a known software vulnerability, first identified in 2017, with a critical score of 10. This software flaw can be used by cyberattackers to remotely execute malicious code &gt;one of the projects has a waiver of JPL IT security requirements to change passwords every 90 days. Instead, the project relies on a designated application and team accounts to share password files, group files, host tables, and other files over the network<p>There seems to be a fair amount of filler in the report (review access logs, out of date inventory, etc) but these points seem pretty damning.
评论 #20247028 未加载
Canadaunialmost 6 years ago
The article mentions that the hackers stole 500MB? The number seems small given the scale of storage in modern computers but I guess 500MB could account for a large number of documents that contain confidential info.
评论 #20247284 未加载
DataJunkiealmost 6 years ago
I am surprised this doesn&#x27;t happen more often.
kevin_b_eralmost 6 years ago
It would be nice to know what this specific &quot;Raspberry Pi&quot; vulnerability is, considering the software stack is almost entirely Debian.
评论 #20246185 未加载
评论 #20245578 未加载
评论 #20246362 未加载
评论 #20245528 未加载
Mbaqangaalmost 6 years ago
The articles says if the hackers were some jokers on the internet then the data isn’t terribly useful, but if it was an adversarial nation then it is very useful. Why? Can’t the jokers sell it to other nations?
noir-yorkalmost 6 years ago
The report doesn&#x27;t mention how the intrusion was discovered. Someone just noticed the RPi one day? 500mb traffic to a Chinese IP?