12 ms·
NASA Has Been Hacked
- reversengineer 7y agoYTCracker did it first!
- rasengan 7y agoAnd this is why you need to practice Defense in Depth. DO NOT assume your system is simply hardened and cannot be penetrated. You have to assume the opposite -- assume you will get fcked hard and apply separation among systems such that a wound is just a wound, and not a fatal death.
- chacha2 7y agoWow. Try to opt out of their data tracking, an option they're required to add. "This may take up to a few minutes to process" They make you wait at this long ass loading screen while they "process" your request not to have cookies. Here's the outline for people who don't want to wait minutes to read an article. https://outline.com/TZSBv4 https://outline.com/TZSBv4
- giarc 7y agoI was going to screenshot that page. A small auto play video in bottom left corner, a top bar pop up to get the "latest updates from Forbes", an email sign up for the Forbes Daily Dozen and in the background, blurred out is the article.
- JudgeWapner 7y agoI envision a distributed system that simply renders pages, clicks "agree" or whatever, and uploads just the content to "archive" servers automatically. After a critical mass is reached, then instead of going to the URL, you plug the URL into archive server to see if it already has a copy and render that version. From there, you could go even further and daily download 100mb or so of pre-sanitized internet from the most likely pages you currently visit. Not only would you elide ads, but your page render times would drop to milliseconds and save money on mobile bandwith. This system could be powered by kind volunteers who manually click away the ads and publish their renderings either as images or HTML-1.0 with all shit-ware removed. They could also be paid through micropayments to workers in developing nations. If everyone "tipped" a buck or two per month into a pool that paid work-at-home scavengers to curtail content for us, we would be supporting a real business model while not being harassed and tracked. Alternatively, you could have AI-powered crawlers that are trained to close videos, identify article text and relevant pictures, and ignore ad banners.
- sp332 7y agoIf you have Firefox, Edge, or Safari, you can use Readability Mode to strip just the article text and read it. For something more complex like what you described, check out Brave. It blocks ads from tracking ad networks and either replaces them with non-tracking ads or lets you pay the site author directly.
- jacquesm 7y agoThe one thing that approach would guarantee is that archive servers would end up getting the business end of the stick.
- enriquto 7y agoIf you disable javascript you can read it easily (and much faster, and without ads).
- dvfjsdhgfv 7y agoThis is the best way to browse most of the so-called news sites.
- latexr 7y agoDisable Javascript on the page, and you can read it without a problem.
- enlyth 7y agoIt gets stuck for a minute or two on 100%, then says that some trackers cannot use https and makes you click another link to finish the process. I wonder why these dark patterns are still acceptable on the web. I thought opting-out was supposed to be as easy as opting-in according to the GDPR? The vast majority of sites I see make opting-out a very difficult process, usually hidden behind a tiny grey span of text, while the opt-in is a giant green, frictionless button with immediate effect. Usually there is misleading title like "We value your privacy", and a giant green accept button making you think you're agreeing with that statement. Then a tiny "Other options" in grey somewhere at the bottom which makes you go through sixteen confusing modal dialogs.
- iainmerrick 7y agoI wonder why these dark patterns are still acceptable on the web. I thought opting-out was supposed to be as easy as opting-in according to the GDPR? Yes, that’s the idea, but who’s going to enforce it? The dark patterns trick most people into doing what they want. A small number of technically-savvy users may complain, but we have little leverage.
- Wowfunhappy 7y ago> Yes, that’s the idea, but who’s going to enforce it? In theory, people are supposed to be suing the companies that do this, right?
- LeonM 7y agoI discussed this recently here on HN [0], the fake spinner is a dark-UI to 'punish' you for opting out. If you just accept the popup disappears immediately. [0] https://news.ycombinator.com/item?id=20131381 https://news.ycombinator.com/item?id=20131381
- pdpi 7y agoI don't think that's actually true. Rather, it's an architectural thing — because all these ad systems were designed without consent in mind, accepting is a no-op, whereas refusing consent requires an outbound request to set some sort of "do not track" flag somewhere (presumably as a cookie).
- noja 7y agoWhy do you think it's not true?
- pdpi 7y agoStarting from Hanlon's razor, you assume incompetence is likelier than malice. Saving the "do not track" preference as a cookie is the most obvious way to distinguish new visitors with no cookie from users who have opted-out, but this means issuing a request to each and every ad network to store a cookie with them. Indeed, a quick look at Chrome's network tab reveals that they are, indeed, making a bazillion requests that is consistent with that explanation.
- Rooster61 7y agoI apply Hanlon's razor to individuals, not collective entities such as a company or agency. The behavior in recent history of such entities I think warrants the exception to the rule.
- pdpi 7y agoIt’s a heuristic that gives you a good starting point, not some sort of law. As it stands, it’s a starting point that’s easy to back with data suggesting it is indeed the case. If you can point me towards evidence that malice is indeed the case here, I’ll willingly change my mind.
- tomp 7y agoWhenever I get a spinner after clicking "Decline", I just reload the page. Often, it works. Presumable, it sets the cookie on the page ("user accepted/rejected the cookies") before setting the cookies on partner pages...
- ddebernardy 7y agoI used to do that too, thinking there was some kind of bug. And then one day I got distracted by my toddler while rejecting and it turned out that yes, a few minutes later, the thing disappeared. So now I'm tempted to assume that if you don't wait then nothing guarantees that the partners got the message that you're not accepting their tracking. The only dark pattern in there, presumably, is that they're notifying partners serially rather than in parallel.
- dessant 7y agoThat's grounds for a GDPR complaint against TRUSTe and Forbes. Opting in or out must not be a condition for accessing content, so a popup that covers the page is problematic. Opting out should also be as simple as opting in, not a maze of options with progress spinners. File a complaint folks.
- magashna 7y agoUnless they geo-block GDPR countries and call it a day
- Krasnol 7y agoI was actually surprised that it went all the way through to 100% and did something. Usually those things break down at some point.
- m_rn 7y agoPIA VPN "mace" seems to be saving me from all the torture.
- cronix 7y agoAt this point I really don't care anymore. It's like reading an article claiming the sky is blue...every damn day. Entire cities are offline and being held hostage. Gov't entities getting hacked, taken over. They don't care about our privacy, so I don't give a shit about their insecure systems. Let them all melt down. Then they might care about us, but only because it affected them in a hardcore way and forced them into action. Can't wait til AI really takes off and they ML it all full of known hacking methods and 0 days and just let it out in the wild. Stuxnet was a baby. Wake the F up.
- deleted 7y ago[deleted]
- m_rn 7y agocronix for president!
- tuanx5 7y agoLink to the actual audit here: https://oig.nasa.gov/docs/IG-19-022.pdf https://oig.nasa.gov/docs/IG-19-022.pdf
- peterwwillis 7y ago> All in all it reads like a security basics 101 list that has been ignored. System administrators lacked security certifications, no role-based security training was in place and JPL, unlike the main NASA security operations center (SOC), didn't even have a round-the-clock incident reporting capability. That is not security 101, that's CYA bullshit that corporations institute once they've been caught with their pants down. "Training" is worth jack. You have to actually implement security practices for them to be worthwhile. Sysadmins are not always the brightest bulbs in the box, but they definitely shouldn't be expected to be doing a security team's job of regularly auditing security policy to make sure it's being enforced.
- gfodor 7y agoI usually roll my eyes at meta comments on HN about ads or tracking on web pages getting in the way, but good lord. This page first slams you with a nearly full page ad with no dismissal, and then after you read a few paragraphs hits you again with a modal sign up dialog.
- pavel_lishin 7y agoThe magic combination of adblockers has spared me from this fate, but not from an annoying video about the top 5 richest rappers, for some reason.
- SamuelAdams 7y agoI highly recommend reading the actual audit[1]. There's a lot of good details in there, similar to the Senate report on the Equifax breach a few days ago. There were several problems: the inventory tracking issue was particularly enlightening: >system administrators did not consistently update the inventory system when they added devices to the network. Specifically, we found that 8 of 11 system administrators responsible for managing the 13 systems in our sample maintain a separate inventory spreadsheet of their systems from which they periodically update the information manually in the ITSDB. One system administrator told us he does not regularly enter new devices into the ITSDB as required because the database’s updating function sometimes does not work and he later forgets to enter the asset information. Other good notes Lack of training: > NIST requires that organizations provide security-related technical training specifically tailored for their assigned duties... As of April 2019, JPL did not have a role-based training program, provide additional IT security training for system administrators, nor fund their IT security certifications. Refusing to let Department of Homeland Security (DHS) complete a thorough post-intrusion assessment: >However, according to NASA SOC personnel, JPL was concerned with inadvertent access to its corporate network and feared disruption of mission operations. In addition, JPL was unfamiliar with DHS’s standard engagement procedures. Collectively, resolution of these issues resulted in DHS being unable to perform scans of the entire network until 4 months after the incident was detected. [1]: https://oig.nasa.gov/docs/IG-19-022.pdf https://oig.nasa.gov/docs/IG-19-022.pdf
- Markovweaklink 7y agoThank you Samuel Adams
- hcnews 7y agoThis is expected. Any manual work will have errors and lots of them. If you want a system to be robust, you have to engineer it in a way it stops working if one of the prerequisites aren't satisfied. It's costly but there's no way around it afaict. In this case, you wouldn't allow a device to access any information on the network without a proper certificate. The public systems need to learn from private companies in this regard.
- 7y ago
- tetha 7y agoReading the audit, this kind of confirms my base question when building infrastructure: If people don't do the right thing the business needs, why is it too hard to do? Can't we reduce the pain to do the right thing so doing the lazy / wrong thing is harder? People not doing thing tends to be an indication of boundaries and responsibilities being drawn in bad ways. Something like the log reviews are a classical thing. Training a sysadmin to know all the new hot attacks and patterns they cause in a log is hard, because that world moves fast. It'd be much more effective to task the admin with a well-defined, easily monitored task: <Ship logs to splunk. Make sure logs are always shipped to splunk>. Might need some definition about format and which logs, but all logs go to splunk. And then it's the security guys job to look for malicious patterns in those logs, probably automatically. Ideally with something simple, like elastic-alert, logstash, you name it, from my own stack. Similar, why do people have to manually enter systems into the host database? It depends on how far you want to automate that, but firewall all systems to access the central registry only, and widen the firewall after an authorized registration of the system. That way, the admins just have to rack systems with a usb stick with some credentials, and it goes or it doesn't. If basic things are so hard people don't do them, something is structurally wrong.
- txcwpalpha 7y ago> but firewall all systems to access the central registry only, and widen the firewall after an authorized registration of the system. That way, the admins just have to rack systems with a usb stick with some credentials, and it goes or it doesn't. Someone first has to build this system, and after accounting for all of the red tape and approvals and training and new audits required and tallying up the total man-hours required to implement, your solution that is supposed to be "less hard" might actually be much harder than the previous system. It's pretty easy to come up with a multitude of ideas to fix issues like this, but it's another thing entirely to actually implement them, especially in a big government org like NASA. Obviously their current/previous system isn't working and they need to fix it, but I think you would be surprised at how difficult it is to do something even as simple as the system you've conceptualized. Just to give a small anecdote: I've built asset management systems, and in one case at a major F500 company, one that used USB sticks for something similar to what you're describing. Just getting the approval to purchase the USB sticks and establish a process for properly handling the USB sticks once credentials were put on them was something that, by itself, took months.
- rdruxn 7y agoWow what a horrible website - the entire article was nearly completely covered with popover ads
- Krasnol 7y agohttps://addons.mozilla.org/en-US/firefox/addon/ublock-origin/ https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... Works also on mobile (Android)
- olliej 7y agoIT security people need to stop thinking in terms of disallowing “unauthorized” devices on physical (wired and WiFi) and recognize start designing for human nature. Assume that the physical networks are compromised, and have all privileged resources only accept connections over VPN. Is it perfect? No, but it makes further compromise harder. The assumption of no trust also means acknowledging that you need gate incoming connections.
- txcwpalpha 7y ago> IT security people need to stop thinking in terms of disallowing “unauthorized” devices on physical (wired and WiFi) and recognize start designing for human nature. I can assure you that many, many security people (I would say all security people, but I have no doubt that there's some laggards working under the radar somewhere) already think like this. This is all part of a multi-layer security strategy, and having encrypted communication on top of a secured physical network is pretty standard and is what a lot of orgs strive for. Unfortunately, it really isn't feasible and it's not because of any decisions by the security people, because... > have all privileged resources only accept connections over VPN This sounds great until you remember that half of your organization runs on legacy software that doesn't play nice with forcing VPNs and your technical architect has informed you that they aren't planned to upgrade to newer software until 2030. This is especially so in government orgs (like NASA).
- olliej 7y agoThen you need to either mandate updating, or isolate those machines.
- txcwpalpha 7y ago> mandate updating hahahahahahahahaahaha > isolate those machines that's exactly what is done, but you just said that security people need to stop thinking in those terms, so...?
- olliej 7y ago
- madengr 7y agoUnfortunately this will just make it more difficult to get real work done, as security is tightened further. Maybe they just ought to physically isolate their networks. Working at a large engineering organization, I have given up and now do all engineering work on a stand alone computer, with dongle licensed software. I feel bad about the piles of CDR I burn through to transfer files, but it’s the only solution to getting work done.
- hluska 7y agoFor further context, here’s another report on NASA’s security in 2012. https://oig.nasa.gov/congressional/FINAL_written_statement_for_%20IT_%20hearing_February_26_edit_v2.pdf https://oig.nasa.gov/congressional/FINAL_written_statement_f... Sadly, it doesn’t seem like things have changed.
- 0xffff2 7y agoNote that the report in the OP is a report on JPL, not NASA. JPL is a federally funded research institution that does most of its work for NASA, but it is run by Caltech, not NASA directly. Having seen the process from the inside, I can attest that NASA's security posture has changed enormously over the last 5 years. If anything, we've swung the pendulum so far in the direction of security that measures are being put in place that interfere with our work for little to no real security benefit.
- tamalesfan 7y agoWaiting for the inevitable "it was contractors" cop out. I'm surprised it wasn't in this Forbes story as these events happened over a year ago; they've had plenty of time to work up the usual narrative about negligent contractors. And so the the cycle continues. Now we'll have hearings; "it was Republican budget cuts; we need a more funding."
- module0000 7y agoHopefully, this doesn't cause fear mongering around raspberry pi devices. It's not a stretch to imagine a bureaucrat reading articles like this, seeing "a raspberry pi was plugged in", and forming a negative opinion of the device and people that use them.
- neuralzen 7y agoUnfortunately there already is. When I interviewed for a job in Antarctica we had discussed methods of saving on bandwidth usage and I suggested the use of a PiHole to strip out ads to save precious KB and was told that the Raspberry Pi was frowned upon due to previous issues, and it would likely never happen. :(
- SolarNet 7y agoThen just use a server that does the same thing. If the issue is the buzzword then work around the buzzword.
- ryandrake 7y agoGood news then: you don’t need an actual Raspberry Pi or to run “pihole” software in order to filter ads via DNS. Just a beige Linux box running dnsmasq is enough!
- AnIdiotOnTheNet 7y agoI mean, it's just a DNS server right? There are probably watches that could run it.
- oh_sigh 7y agoNot: it is NASA, not NASA. I've only ever seen the BBC call it Nasa because of their typographic rules.
- countbackula 7y ago> it is NASA, not NASA It's LeviOHsa, not LeviosAH
- roscoe2020 7y agoThe amount of ads on that Forbes page is absurd
- rawoke083600 7y agoFinally ! Now send me the.megadownload-link for Bigfoot and e.t photos
- thereare5lights 7y agoDon't forget, CBP likely already compromised their security before. https://www.theatlantic.com/technology/archive/2017/02/a-nasa-engineer-is-required-to-unlock-his-phone-at-the-border/516489/ https://www.theatlantic.com/technology/archive/2017/02/a-nas...
- eggy 7y agoI remember back in the late 80s telnetting out of the NYU Bobst library on their VAX 11(?) system to some pretty interesting systems. The Johnson Space Center in Houston (running VAX 11/785s was one I particularly remember. Of course, back then things were not battened down as much as they are now; the spirit was an open network. A sysadmin would interrupt your session with quesitons like "Who is this? You are unauthorized to access this system, etc."
- Theodores 7y agoI used to love roving around VAX networks. In the UK the ones for science (and defence research) were all setup the same. They didn't design the login scripts for pests like me. So I was able to go round the different boxes looking for interesting datasets. I only wanted super hi resolution satellite imagery, convinced there was some sub-metre resolution stuff out there. All was going well until I put my own backdoors in to speed up my remote logins. Accidentally I denied access to everyone but me to a MOD computer. I had to admit to that one! Luckily my boss handled it and was practically pleased with his student hire. But yes, I can actually claim to have hacked military computers. I doubt my boss has forgotten that day, the day when the men from the ministry arrived. Happy times, VAX computers were cool and hacking them with genuine VT DEC terminals on those fairly open networks was living the lifestyle.
- killjoywashere 7y agoI have two DEC VT510 terminals in my lab, serving mission critical functions, right now.
- eggy 7y agoWow, that's wild. Never upgraded that system I guess. I hope mission critical is not something that could effect things outside the scope of your workplace. Although, security through obscurity or age here, might actually work ;)
- eggy 7y agoYes, the early days were more innocent, and really fringe. I didn't connect with other hackers until years later, and then attended the monthly 2600 Wednesday meeting or two (Citicorp bldg.?) in the late 80s/early 90s. A great moment when an analogue red box device could be made digital by simply changing out a crystal in a pocket digital speed dialer by RadioShack (RIP). Nowadays you can find the recipes galore, and have no need to bang keys on your to discover hacks and tricks. It's probably why I have given it up. As they say, "those were the days, my friend."
- johnrbent 7y agoRaspberry Pi is all over HN today
- rochester6666 7y agoCAUDIT is a potential mitigation tool that is extensible for data breaches. Ref: https://github.com/pmcao/caudit https://github.com/pmcao/caudit
- rurban 7y agoThe JPL has been hacked, not just the NASA. The JPL does much more interesting stuff than just NASA, like engines for military and also secret SW programs for the NSA (we know that from Larry Wall who was sysadmin there). And they are just administered by Caltech staff. Whow. Random hackers are only interested in confirmation of aliens, but NSA or DOD stuff is very, very interesting to the Chinese who hacked these systems last.
- sirbranedamuj 7y agoI was hoping there would be more info about how exactly the RPi was compromised, and the steps that were taken from there.
- jlmorton 7y agoHere's food for thought: while a proper firewall and network segmentation is a well-established best practice, I'm not sure this is a winning battle. There are probably a few dozen organizations out there that are properly implementing strong information security practices, and my hats go off to them. But they are the few, and I have never worked for one. Despite best laid plans and policies, every place I have worked has always had some improperly secured services somewhere on their network. And every place that I've worked has had segmented networks that people end up relying on. And the people working for these organizations are often aware of the improperly secured resources, but they're only in the DMZ, and there are many other things to worry about, so it lives on. Especially now that we live in an IPv6 world, why not just run everything publicly. Push security all the way down to the applications themselves, and rely on the software development lifecycle process to catch security issues. Every service has to be secure. And they can get an awful lot of help in this from things like a service mesh architecture, where you're getting mutual TLS from something like Envoy, and the applications won't accept a network connection unless they're specifically authorized. We need to stop relying on firewalls and network segmentation entirely, and just run everything on the public Internet, and make sure every service is secured. I will say, when a zero day comes out in whatever proxy you're using to secure your services, you are in for a world of hurt. But there are zero days in firewalls too.
- 0xffff2 7y agoI work at a non-JPL NASA center. My workstation and internal server resources are already locked down to a barely tolerable extreme. I can't imagine what kind of restrictions would be added if we went forward with something resembling the above proposal. I don't want to go into much detail about our internal network architecture, but suffice to say it's extremely difficult to run any kind of service whatsoever even internally. It has literally taken me years to get approval to expose a fairly simple REST API to the public internet, and I'm not even there yet.
- majewsky 7y ago> Especially now that we live in an IPv6 world, why not just run everything publicly. Push security all the way down to the applications themselves, and rely on the software development lifecycle process to catch security issues. Yeah, wouldn't it be nice if software just didn't have any bugs? You got the correlation backwards: Software isn't garbage because we can rely on the band-aids. The band-aids were invented because all software is garbage.
- temptemptemp111 7y agoHackers, please upload the moon landing telemetry data :P
- Just147 7y agoDo you need hackers for hire? Do you need to keep an eye on your spouse by gaining access to their emails? As a parent do you want to know what your kids do on a daily basis on all social networks in others to make sure they're not getting into trouble? Whatever it is, Ranging from Bank Jobs, Flipping cash, Criminal records, removal of mugshots ,DMV, Taxes, crypto currency fraud investigation Name it, they can get the job done .contact at www.assuredhacks.com .. its that easy . try them out today .