NASA Kepler Twitter Account Hacked, Tweets Sexy Butt, io9
“The official Twitter account for NASA’s Kepler, which surveys parts of the Milky Way Galaxy in search for hospitable planets, just got hacked. It’s unclear how or why the account was hacked, but it definitely tweeted a butt and a sketchy link.”
Keith’s note: There is a somewhat NSFW image after the link, so … if you are sitting at a government computer …

Tagged:

Biologist, Explorers Club Fellow, ex-NASA Space Biologist and Payload integrator, Editor of NASAWatch.com and Astrobiology.com, Lapsed climber, Explorer, Synaesthete, Former Challenger Center board member...

5 replies on “Someone Hacked @NASAKepler”

  1. As an unabashed geek I think NASA should reveal the details of how the account was hacked, including the actual vulnerability that was exploited. The best defense is not secrecy but understanding.

    1. I agree, but let’s face it. A Twitter account being hacked is about as far from mission critical as you can get. The problem could as easily be with Twitter as with NASA. So this isn’t going to be something I lose sleep over. The best defense is often information not secrecy. But, sometimes, the best response to a juvenile hack is just to ignore it.

      1. I agree with you on many issues, Michael, but not in this case. The vast majority of hacking incidents on the web involve software vulnerabilities, not the guessing or learning of actual passwords. Web software like Twitter is vulnerable because of the pressure social networks are always under to provide more elaborate services and interactions. A number of vulnerabilities on Twitter have been documanted, e.g.: http://thehackernews.com/20…

        To be fair, NASA IT security really believes that hackers can decrypt any password that isn’t changed every 60 days _and_ has 12 characters of three types. Requiring frequent changes of long passwords does nothing to improve security and is horrible human factors since there is no way to remember such a password. Any password you have to write down is insecure. Password rotation is absurd. If your system is so insecure that the hacker can determine your password he will have access to the system for 59 days. Then when you change your password he can use the same vulnerability to hack it again.

        When questioned on the basis for this policy NASA blames NIST, saying that NIST “requires” frequent password changes a handbook on computer security. This is not accurate. NIST only requires that password rotation be considered as one of a number of security measures in a security plan. As one of the authors of the NIST handbook told me, NIST does not require government agencies to use password rotation or passwords of any arbitrary complexity. In fact lower case letters alone are secure as long as the password is not obvious and the system imposes increasing delays with repeated guesses.

  2. I just though maybe Kepler was just getting better at its imagery… first great gas-giants, then super-earths, and now a couple of large moons colliding. OO *crash!*

Comments are closed.