NASA hacked because of unauthorized Raspberry Pi connected to its network (2019)
zdnet.com
zdnet.com
Source: good friend was a public defender
Thought exercise only, I ain't cut out for the life of crime.
[1]In fact I was involved on a project where some thieves took a sawzall to the equipment storage conex over the weekend and stole every bit of GPS equipment they could get their hands on. They were pretty quickly tracked down when they tried to offload it though.
I expect that equipment in rental fleets are keyed differently, though.
Go to a caterpillar dealer, and you can ask for a new key by model number. They don't need serial numbers.
You arrived at the facility in a rental car with your keys, clothing, ID (credit cards were ok and could be left in the car), and anything you needed to do the job (laptop, hardware, whatever).
You were told to expect to leave with your clothes, keys, ID, and rental car (obviously the previously mentioned credit cards).
You parked at the gate, were blindfolded, and escorted to the place you did your job, and then the same process out.
NOTHING left the facility beyond those things, even the front gate. (Car was searched and anything in the car might be confiscated).
I honestly think that's a level of security (well maybe without blindfold) that many places will eventually have to adopt.
TY
wait, what? ITAR REGULATION for Mars Missions??
[0] http://www.projectrho.com/public_html/rocket/spacegunexotic....
The New Ocean by William R. Burrows.
Talks about the intentional setup for NASA TO be a 'civilian agency' and not military.
Someone is about to build an entirely COMPLIANT space mission :/
Brace yourselves
That said, I don't see where this is especially valuable to hackers at this point. There are much easier ways to steal nuclear material these days than to target the one on Mars.
Of course that was forseeing malicious placement of something that would be scanning for vulnerabilities, rather than a remote exploit of an unsecured device on a secure network.
Because the costs you think of are but a fraction of the costs that are involved in keeping them accounted for, updated, monitored etc.
I have these discussions with creative individuals far too often :)
Network boundary can never provide strong enough security protection. No matter how small each segment is. Just because a device is in your network doesn't mean you can trust it.
Implement authnz correctly everywhere and make sure the system can verify "if you are who you say you are" is more efficient.
https://www.yahoo.com/news/us-satellite-looks-down-chinas-11...
https://www.techopedia.com/definition/508/ieee-80211x
I believe you’re looking for 802.1X