Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

NASA Breaches Leak ISS Control Code

A laptop computer--one of 48 devices that went missing from the space agency between 2009 and 2011--contained algorithms to command the space station.

Top 10 Open Government Websites
Top 10 Open Government Websites
(click image for larger view and for slideshow)
A laptop computer stolen from NASA in March 2011 contained algorithms used to command and control the International Space Station (ISS), one of a number of breaches that raise new concerns about the agency's ability to protect sensitive data, an agency watchdog official told Congress.

NASA reported the loss or theft of 48 computing devices between April 2009 and April 2011, resulting in the unauthorized release of private data, including ISS control codes, NASA Inspector General Paul Martin said in his written testimony submitted to the House Committee on Science, Space, and Technology.

Martin testified before the committee about NASA's IT security, which apparently is lacking when it comes to protecting data. Although NASA also has leaked sensitive data through lost hardware and other ways over the last several years, the agency continues to lag behind others in encrypting its data, he said.

In addition to the ISS codes, the laptops that went missing also contained personally identifiable information, third-party intellectual property, social security numbers, and sensitive data on NASA's Constellation and Orion programs, according to Martin.

[ See our complete RSA 2012 Security Conference coverage, live from San Francisco. ]

What's more, the agency has no way to accurately gauge the amount of data that could be released when laptops are lost or stolen because it does not review backup files to determine what was stored on them. Instead, it relies on employees to report on the lost data, according to Martin's testimony.

Laptop theft or loss is not the only threat to NASA data. The agency is increasingly the target of specialized attacks called "advanced persistent threats" (APTs) that are "particularly well-resourced and committed to steal or modify information from computer systems and networks without detection," said Martin in his testimony.

The APT hacker groups are highly organized and well-funded and may lurk inside NASA's network even after the agency has fixed the vulnerability, he added.

In fiscal year 2011, NASA reported 47 APT attacks, 13 of which compromised agency computers. Moreover, Martin reported that credentials for more than 150 NASA employees were stolen during those attacks.

The problem may lie because NASA historically has been slow to adopt full-disk encryption on notebook and other mobile computing devices, even as its counterparts in other agencies are doing so. The Office of Management and Budget reported that government-wide encryption for these devices is at 54%, but as of Feb. 1, 2012, only 1% of NASA devices were encrypted, according to Martin.

"Until NASA fully implements an agency-wide data encryption solution, sensitive data on its mobile computing and portable data storage devices will remain at high risk for loss or theft," he said.

InformationWeek and InformationWeek Government are conducting a survey on IT security and cybersecurity in U.S. federal government agencies. Upon completion of our survey, you will be eligible to enter a drawing to receive an Apple 16-GB iPad 2. Take our Federal Government Cybersecurity Survey now. Survey ends March 9.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Fill
50%
50%
Fill,
User Rank: Apprentice
3/1/2012 | 7:30:21 PM
re: NASA Breaches Leak ISS Control Code
It is surprising that NASA, of all agencies, doesn't use encryption more. Encryption is built into some OSs these days and otherwise is pretty simple to use with third party apps (free and commercial).
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/28/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
10 iOS Security Tips to Lock Down Your iPhone
Kelly Sheridan, Staff Editor, Dark Reading,  5/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11949
PUBLISHED: 2020-05-28
testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.
CVE-2020-11950
PUBLISHED: 2020-05-28
VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.
CVE-2020-13645
PUBLISHED: 2020-05-28
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verificat...
CVE-2020-13643
PUBLISHED: 2020-05-28
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be e...
CVE-2020-13644
PUBLISHED: 2020-05-28
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accord...