4 ms·
As a network architect I'm kind of surprised they couldn't answer basic questions such as "can someone sitting in a general user access segment (eg Cafeteria) a
by saber6 7y ago
As a network architect I'm kind of surprised they couldn't answer basic questions such as "can someone sitting in a general user access segment (eg Cafeteria) access critical resource X by default?"
This is a fairly standard infosec method already in use for a long time (defense in depth, enclave-based security architectures, etc).
Not knocking them - JPL are wonderful people. If I had to guess they did not have funding for this prior, got caught (embarrassed) and now are correctly allocating resources to deal with the issue. Good news!
- toomuchtodo 7y agoThe trick is to not let a crisis go to waste, and use it to get the people and dollars you otherwise wouldn’t have been able to justify.
- xenihn 7y agoMy girlfriend's family has a bunch of software engineers who worked on various space programs as employees for the major defense contractors (Boeing, Lockheed Martin, Raytheon), and they had nothing but bad things to say about NASA software engineers, and working with NASA in general. Maybe things have changed in the past 16 years, though. Could also just be typical private vs. public rivalry.
- oso2k 7y agoProfessional rivalries. But IMO, NASA engineers are some of the best and many approach the “scary smart” or renaissance levels of breath & depth of intelligence. Also, on the whole, at least at JPL, our engineers were some of the most ethical in terms of personal accountability and corporate accountability. Fewer ethics violations and higher accuracy in identifying and reporting ethics violations especially as compared to the rest of the industry.
- exdsq 7y agoIs there a general sort of background for a JPL engineer? Do they tend to come in straight after university or do they join later in their careers? It must be fun to work on such critical systems with so little margin for error.
- oso2k 7y agoPhysics, Engineering, Math, Science, CS were obviously prized backgrounds. Over the last 10 years, I think JPL is diversifying but I couldn’t be sure. When I joined as an intern in 2002 out of college, there was a huge push for youth. It used to be that more than 40% of The Lab had 20 years or more experience at The Lab. 33% were due to retire within 10 years. My first mentor there retired after 42 years with The Lab. It was an amazing place to learn and grow in my 20s. Awesome problems to work on and even more amazing people, humans, to work with. You can see what they’re looking for here https://jpl.jobs/ https://jpl.jobs/
- exdsq 7y agoInteresting! It’s up there with X as one of the top companies I’d love to work for but I’m a UK citizen which writes JPL off, unfortunately I can only admire it from the outside!
- WWLink 7y agoQuestion for ya: Are the outsider recruiters of any use? I've been contacted by them before but I get the impression you're better off just applying.
- oso2k 7y agoRecruiters don’t seem to be useful. Apply on your own.
- mturmon 7y agoNASA is a big place, so you can’t make statements at that level of generality. Here’s Arun Viswanathan’s google scholar page: https://scholar.google.com/citations?user=jdotmygAAAAJ&hl=en https://scholar.google.com/citations?user=jdotmygAAAAJ&hl=en
- p_l 7y agoAlso plating their asses in armor. Worst code I ever dealt with was from Lockheed-Martin, worse than scientist's calculation code, as that one tended to work at some point in time.
- joshspankit 7y agoAsking those questions in “as-planned” scenarios are fairly easy, but I think we can all agree that even after a year or two of “tiny tweaks”, reality can be different than what was implemented as planned.
- TimTheTinker 7y agoMy understanding is that this was more about potential attack chains than direct access paths.
- jvanderbot 7y agoI think that was an ad hoc example to illustrate the tech, not an actual use. It actually makes no sense in context; Ive worked from the cafeteria a lot, the coffee is endless and nobody knows where I am.
- icegreentea2 7y agoI think the previous statement that each mission spins up its own infrastructure, and that their data model encompasses a significant mix of systems points to the question not being, "should someone sitting in a cafeteria access critical resource X by default", but rather, "is it actually true that someone sitting in a cafeteria cannot access resource X1 through XN by default". In order words, I think what they're trying to work from is that their existing systems don't present a unified or homogeneous set of interfaces or design or control. What they're trying to solve is how to fit a homogeneous interface onto their existing mess.
- lazulicurio 7y ago> the question [isn't], "should someone sitting in a cafeteria access critical resource X by default", but rather, "is it actually true that someone sitting in a cafeteria cannot access resource X1 through XN by default" I think that this is probably the main purpose of the system. The is-ought problem can become very tricky to manage with a complex network, especially if the team is on the larger size or geographically distributed.
- oso2k 7y agoI last worked at JPL 10 years ago but all mission systems lived on many distinct networks of “dark cable and fiber”. Physical access to mission networks was usually heavily guarded. It would take accessing several doors to just be in a room with a network drop or telco closet. Access in any of cafeterias (there’s more than 1) over WiFi is limited to common systems and the internet. There was no Cat5/6 in the cafeterias. There was also a further limited Guest WiFi network for media, guests and the like with bandwidth limited access to the internet only.
- mturmon 7y agoThis is the kind of event (although technically unrelated to the OP) that caused resources to be allocated as you suggest: https://www.space.com/13423-hackers-government-satellites.html https://www.space.com/13423-hackers-government-satellites.ht... Some of the specific accomplishments in OP (network inventory, network topology) seem related to this intrusion: https://www.drizgroup.com/driz_group_blog/nasas-jet-propulsion-laboratory-jpl-hacked-for-10-months https://www.drizgroup.com/driz_group_blog/nasas-jet-propulsi...
- closeparen 7y agoI've never been in an environment that does security this way so I'm curious about it: if they have the proper credentials and permissions, why would it matter where they're sitting? When someone is granted access to a new resource, do you have to move them to a different network segment? What if there's not already a segment with the right combination of resources? Provision a new one on the fly? Or maybe grant more access than needed at the same time? We just have nginx check if you have the required LDAP group for the URL before forwarding into production. Typically one group per tool. What about temporary access? There are tools at my workplace where manager approval gets you access for 24 hours. As I understand it, there's just a cron job purging people every so often at which point nginx will start bouncing you again. Can you do something similar with VLANs? Is that sane?
- chiph 7y agoWe're talking about space missions that cost a fraction of a billion dollars at the low end, and people have invested decades into just getting approvals and funding. And then perhaps another ten years just to get the spacecraft where it needs to go. These are nation-level assets. You're going to protect them much more heavily & securely than a corporate website. You can't allow a hostile attacker in for even a fraction of a second, so guest access will be strongly vetted, and networks will be protected by physical isolation.