FAA Network Hacked 110
coondoggie writes "The Federal Aviation Administration has joined the growing list of government agencies that have had their supposedly safe systems hacked. The agency this week notified about 45,000 employees that one of its servers was hacked into and employee personal identity information was stolen.
The FAA was quick to say the server that was accessed was not connected to the operation of the air traffic control system or any other FAA operational system. It did say two of the 48 files on the breached computer server contained personal information about more than 45,000 FAA employees and retirees who were on the FAA's rolls as of the first week of February 2006."
Uhh Ohh! (Score:5, Funny)
Hope they find that CIP device soon!
Re: (Score:1, Funny)
Hope they don't find my CP soon
Re:Uhh Ohh! (Score:4, Funny)
Re:Uhh Ohh! (Score:4, Funny)
Re:Uhh Ohh! (Score:4, Funny)
Re: (Score:2, Insightful)
Re: (Score:2)
Re: (Score:1)
Re: (Score:2)
Right...
Of course in the real FAA (not the one in 24), the ATC computers aren't new enough to support the Internet (at least as of 2-3 years ago). In other words, you can't hack into them because there is essentially nothing to hack!
24? (Score:1, Offtopic)
Re: (Score:2, Funny)
Just make sure he gets a dd for the trip.
Re: (Score:3, Funny)
Re: (Score:3, Informative)
You forgot the links! (Score:1, Flamebait)
Teh Fatal Death Killer Remote Control Module of Deadly Doom [chinawholesalegift.com].
More Erudite 24 Commentary [herald.com]
Oh noes! (Score:3, Funny)
Has the CIP device been recovered yet? Should we call in Jack Bauer?
Re: (Score:3, Interesting)
1. Post a re-iteration of something in the summary
2. Piss people off by getting modded "Informative"
3. ???
4. Profit!!
Re: (Score:1)
In my opinion, Idle and the new metamod system are evidence that they had a good thing going and just had to keep fucking with it, like they couldn't resist.
As if resistance was futile?
Re: (Score:2)
It's intereresting that people feel it necessary to point things out that are actually in the summary:
"The FAA was quick to say the server that was accessed was not connected to the operation of the air traffic control system or any other FAA operational system."
I mean, we'fre not supposed to read TFA, but c'mon, the summary!?
Still, you actually got modded 'informative' for it, so I guess the mods don't read the summary either...so, good call!
Re: (Score:2)
Indeed. But how careful have they been maintaining the office network and are there any known/unknown access points INTO the ATC network that they're not telling us about?
Security is about a way of thinking as well as deploying tech to seal up things. As often as not, someone did something "convenient" for themselves or others and did something that weakened or completely compromised the security somewhere.
Re: (Score:1, Funny)
Yes, but if they delete the memo that says "DON'T CRASH THE PLANES!" then the planes could crash...
Re: (Score:3, Insightful)
I'm sure that will be a great comfort to the people who are subject to identity theft because of this breach.
Re: (Score:3, Informative)
Re: (Score:2)
Re: (Score:3, Insightful)
Re: (Score:1, Insightful)
Re: (Score:2)
You don't own the sky above your land.
Well, not all of it... but some of it [wikipedia.org], you do.
Re: (Score:3, Funny)
Pfft.. they should be pulling new pilots from the pool of Flight Sim junkies. Pick me!!! I have a 5-piece controller setup, including the flight stick, a throttle with 4 separate levers, rudder pedals (and NOT those shitty Mad Katz ones repurposed from some arcade driving game), plus a helmet, an FAA certified Aviation Pilot Headset that I use with Ventrilo. I've got a 17 monitor setup, and an actual working ejection seat! I'm SO READY!!! Just let me disconnect my five-point harrrrr........
Re: (Score:2)
This is why we need to move to the new secure NextGen satellite based ATC that AOPA and the other corporate jet jockeys are fighting against.
No one wants it because it is too expensive and provides little to no value. There are already better solutions available. Which is exactly what AOPA is pushing.
And using your own words to make you look like an even bigger idiot, this article isn't about securing ATC. The article is about the FAA. The FAA does a lot more than ATC.
Made worse, you're completely uninforme
They may have told the current employees... (Score:5, Informative)
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
Interesting to me that you call it a "shit hole" and still spent 25 years employed there.
Was it always a "shit hole" or has it declined over the years?
Here in DC they're running all kinds of negative "campaign" ads regarding the FAA and their treatment of the ATC union.
I imagine both sides are responsible, as usual, but all I'm hearing is the traffic controllers side.
The latest one consists of "The government is running ATC like a Wall Street company. WTH does that even mean?
Re:They may have told the current employees... (Score:4, Interesting)
I think it's supposed to mean that the FAA is being run like a profit-seeking enterprise when its job is to make sure that actual profit-seeking enterprises (i.e. the airlines) have a safe environment to work in (and that they don't pinch so many pennies trying to eke out a profit that safety suffers). The union, in their usual drama-queen fashion, is trying to say that the FAA is being run on a shoestring by people who think it's their job to blow happy smoke up Congress's collective ass rather than tell them the truth.
As for your first question, the place went from high-intensity, challenging, and interesting to flat-out miserable over the course of my career due to gross mismanagement by the government and the greed of controllers. I have never been so excited to start something as I was my ATC career, and never so happy to see something end (well, maybe my first marriage). I stayed for the retirement package.
Re: (Score:2)
Yeah, I've heard that in the past that the job used to be pretty fun but has slowly morphed into "just another government job" over the years.
Kudos to you though, for finding a field where you can actually spend 25 years employed by the same "company" and not get surplussed, fired, or let go. It's really rare these days.
Christ, slashdot, you suck with this 2 minute posting shit. Seriously, LAME. No wonder I haven't posted here in a long time. I'd forgotten how retarded some of this stuff can be.
Re: (Score:1)
Stagnation is a desirable job characteristic? If your attitude is prevalent, it's no wonder the economy is fucked.
Re: (Score:2)
Stagnation is a desirable job characteristic?
Who said that longevity means stagnation? If your attitude is prevalent, we're all screwed.
Re: (Score:1)
Re: (Score:2)
I make a simple statement, in this case "Interesting to me that you call it a "shit hole" and still spent 25 years employed there." and then followed it up with a question: "Was it always a "shit hole" or has it declined over the years?"
But rather than see that, you instantly go for the knee-jerk (surprised you didn't hit your face with your knee) reaction which is to assume something and then go off on it.
Anyway, sorry your work-life has sucked in the past. Hope it doesn't now.
operation of the air traffic control system (Score:3, Interesting)
I'm assuming that the operation of the air traffic control system is not connected to the internet in ANY way at all?
Some questions:
1. Is being offline a guarantee for not being hacked? (How else than through the cable / wifi can you hack into a network)?
2. Is the FAA indeed offline?
Re: (Score:2)
Well someone who really wanted to could physically enter the building and either set up their own wireless access point or use some other setup to allow themselves to acess the network.
Re: (Score:2)
Well... that's then my question:
Does such a network use the same plugs, and systems so that anyone who actually is able to break into the building can also access the network?
Are such important networks using wifi, or normal utp cable networks, so that anyone who can break in can access the network? (I'm ignoring the whole encryption here, just wondering if it's physically possible to even send one byte of data to such a network without having to use a megaton EMP device)?
I mean, breaking into a building is
Re: (Score:2)
If you can gain physical access, network security is essentially meaningless. I would hope FAA air traffic control facilities have more security than a simple key and lock.
Re: (Score:2)
wait so if any point on a network is insecure, everything on the network is unsafe?
And nobody ever developed a protocol to allow two known safe computer to connect over such an unsafe network?
Re: (Score:2)
What I was more refering to was.
1:
You walk in the front door into the guest/public area.
Lean down and plug something into a network port which acts as a wireless repeater.
Of course it would be stupid to have live network ports in the public areas.
2:
Bullshit your way into the office area one way or another.
Do the same.
3:
Bullshit your way into the server room.
At this point you have full physical access and the game is over.
Re: (Score:1, Informative)
A couple of things.
The FAA has been in a broad transition to becoming more secure. This is mainly pointed at the administration network, as ATC and all operations run on an internal network that in no way touches the outside world.
Some things that have happened and are happening on the admin network.
-Wirless intrusion detection (complete, alarms go off if any new wireless devices are detected)
-Network access control (will be completed soon, anything that is not registered will not touch the network)
-Encryp
Re: (Score:1)
Re: (Score:2)
It's good to know they have something like that.
Re: (Score:2, Informative)
Re: (Score:1)
80% of all security incidents are Insider Threat.
I assume most of those numbers are users deleting files, and bringing in virus infected media from home, but still its something to think about.
What protects your data from authorized users already inside your perimeter?
Being off-the-grid reduces drive by attacks from worms, but not dedicated attackers, or insiders.
Re: (Score:1)
Re:operation of the air traffic control system (Score:4, Funny)
Neat Trick (Score:2)
Someone should ask the FAA how they managed to get an entire network (see: article title) onto one server (see: article summary). Was it a server, or a single work station? A server can dispense data, but dispensing data does not make it a server. Servers tend to act as the dispenser for data bearing machines, no?
What's the matter, wouldn't an article that said "One FAA Computer Hacked - Employee Data Stolen" be sexy enough? Probably not. The title as is misleads people into wondering if the ATC network was
Re: (Score:2)
Someone should ask the FAA how they managed to get an entire network (see: article title) onto one server (see: article summary). Was it a server, or a single work station? A server can dispense data, but dispensing data does not make it a server. Servers tend to act as the dispenser for data bearing machines, no?
What's the matter, wouldn't an article that said "One FAA Computer Hacked - Employee Data Stolen" be sexy enough? Probably not. The title as is misleads people into wondering if the ATC network was implicated.
If you own or administer the equipment in question, you'd have to assume that an attacker getting into the server is the same thing as an attacker getting into the network until proven otherwise. That's for the simple reasons that the attacker has already proven their ability to compromise at least one of your systems and that server can now be used as a platform to attack any other machine with which that server can communicate (i.e. that network). Incidentally, am I the only one who still says "proven"?
Re: (Score:2)
I don't know anything about the FAA or their systems but this is simply common sense. Any administrator who doesn't understand this should not be trusted with such important networks.
You cannot rule out the cost factor. It's for instance not economically feasible to link up all power stations to a separate secure network, so they use the internet.
Facing the Internet is not necessarily insecure. It is possible to make 100% hack proof computers - not counting DOS and physical attacks. Similarly, a secure network can still be compromised so that is not always the best way for securing networked computers.
Re: (Score:2)
I don't know anything about the FAA or their systems but this is simply common sense. Any administrator who doesn't understand this should not be trusted with such important networks.
You cannot rule out the cost factor. It's for instance not economically feasible to link up all power stations to a separate secure network, so they use the internet. Facing the Internet is not necessarily insecure. It is possible to make 100% hack proof computers - not counting DOS and physical attacks. Similarly, a secure network can still be compromised so that is not always the best way for securing networked computers.
That's a rather verbose way of saying that my statements are intentionally general and therefore might not describe every possible specific application. I hope we already knew that.
By the way, you quoted me slightly out of context because you left out the one previous sentence that addressed your concern. This is the full block of text:
Re: (Score:2)
This is about what you would expect because such critical systems should not be Internet-accessible unless there were some incredibly strong overruling need for it that could not be addressed any other way.
(Emphasis mine). In my example there is "another way", even so they use the internet. If you had just said "critical systems should not be Internet-accessible unless it's impractical" I would have understood you better.
Re: (Score:2)
This is about what you would expect because such critical systems should not be Internet-accessible unless there were some incredibly strong overruling need for it that could not be addressed any other way.
(Emphasis mine). In my example there is "another way", even so they use the internet. If you had just said "critical systems should not be Internet-accessible unless it's impractical" I would have understood you better.
That's a funny thing that happens to me from time to time. For a moment it will appear that there is a disagreement or a debate and then I'll find that the other person and I were actually saying (more or less) the same thing, just in different ways or from different perspectives. That most often happens when the other person and I are both knowledgable about the subject. I appreciate you taking the time to clear that up for me :-).
Re: (Score:2)
I think we'll have to agree to disagree on this part. The whole problem is that you'd never be able to actually prove that a computer is 100% secure (no one has found a way to do that), only that it
Re: (Score:2)
For a system, for instance, that just reports power usage over the Internet the complexity is at so a low level that it's possible to validate all possible inputs and outputs. The biggest complexity in this example is actually the TCP/IP protocol.
Ultimately, what you can accomplish is a system that is secure enough that the effort required to break into it far exceeds any value that would be gained by doing so. The rest is damage control.
In theory everything is hack
Whatever (Score:3, Interesting)
We know the air traffic control computers weren't hacked...There hardly are any, which is in itself a problem.
But being sloppy with data is a bad sign in any organization. If you can't keep your secure data secure, then what other important things are you also letting slide?
Having worked at the USDOT.. (Score:4, Interesting)
Of which the FAA is apart of, I can say, with absolute certainty, that like every other major entity, there are literally dozens and dozens of systems that are in no way connected to the ATC, or any other network for that matter. Yes they are networked, but so is every desktop and every camera, that does not mean they are not well isolated and secure from each other.
FAA has well over 10k hosts (desktops, servers, etc etc), its unfortunate, but expected that many of those hosts are probably vulnerable to something. But at the same time, critical systems (ATC for example), are generally isolated from the basic FAA backbone, and on a closed network.
Not found (Score:4, Funny)
Re: (Score:3, Interesting)
Windows cannot find Control Tower. Hit any key to continue.
"Where's the 'any' key?" [bauer-power.net]
Am I the only one who remembers the "ANY" stickers that were usually placed on the ENTER key and were specifically designed for (l)users who kept asking that question? When I first saw them, someone had to explain to me that yes it's a serious product, it's not a joke item or a gag gift. I think I looked at the world a bit differently after that.
If I ever marvel at how even otherwise intelligent people sometimes shut down all common sense and ability to reason when they are
Re: (Score:2)
Re: (Score:2)
Well, you have to remember that computers also have buttons people have never seen before - especially on a keyboard. Think keys like "Ctrl", "Alt", "PrtSc", "SysRq", "NumLk", "ScrLk" and the like. It's entirely possible believe that "ANY" refers to some computer-y term rather than literally, any (and in most cases, any key won't work - keys like Shift, Ctrl, Alt, the locks, other modifiers (Windows, Menu, AltGr, Compose, blah blah blah) probably won't make the message go away). A slightly better wording might be "Press a key co continue". The literalists will probably type "a", the pedants will try the modifiers and complain, and the rest of us will hit space or something.
I don't think you're appreciating how deep the lack of common sense really is.
If what you're saying were the crux of the problem, then such a user might have this problem one time. It wouldn't take very long to exhaustively perform a visual search of the keyboard and conclude that there is no key labelled "ANY". At that point, this theory that the prompt refers to a specific key has been falsified and it's time to abandon it. Isn't that simple? The only possible remaining explanation is that "any" is
Re: (Score:1)
You're equating hard-won esoteric knowledge with common sense. Common sense as a concept is bankrupt - it doesn't exist in isolation, it is simply learned behavior which is not in any way universal. Dragging the term out derisively is a merely a rhetorical crutch.
Re: (Score:2)
You're equating hard-won esoteric knowledge with common sense. Common sense as a concept is bankrupt - it doesn't exist in isolation, it is simply learned behavior which is not in any way universal. Dragging the term out derisively is a merely a rhetorical crutch.
A basic process of elimination, which is the only specific instance of common sense that I mentioned, is "hard-won esoteric knowledge"? I just can't go along with that.
I'm not really deriding anyone. I'm expecting better of them. There's a difference and it's a huge one. Derisive would amount to believing that they can't handle basic problem-solving because they are inferior to me; even when it appears to be humorous, derision always has this type of negative comparison as a core component. Instead,
Re: (Score:1)
Re: (Score:2)
If what you're saying were the crux of the problem, then such a user might have this problem one time. It wouldn't take very long to exhaustively perform a visual search of the keyboard and conclude that there is no key labelled "ANY". At that point, this theory that the prompt refers to a specific key has been falsified and it's time to abandon it. Isn't that simple?
If users' general experience with computers was that software and hardware were universally compatible and all computers had the same interface design, then it would be that simple. But what of the user who is told to use the right mouse button when he's on a Mac? Or to use the Windows key when his keyboard predates that invention? Or to use the number pad on a laptop?
Users have, sadly, been trained to jump to the conclusion that, when the hardware or software doesn't perform according to their initial e
Re: (Score:2)
Re: (Score:2)
Hacked? Or Cracked? (Score:1, Flamebait)
If the readership and editors of /. can't seem to correctly grasp the difference between 'hacked' and 'cracked', how do we expect the mainstream press to ever come even close to getting it?
Re:Hacked? Or Cracked? (Score:4, Insightful)
Oh get off your 133tist high-horse.
You know, or should know at any rate, that language changes over time. The correct definition of a word is the one that people actually understand. Like it or not, when people say "hacked" in this context, people understand that it means "illicitly and illegally accessing a computer system". I understand that, everyone else understands that, and therefore -- like it or not -- it is now the definition of the word.
When are YOU ever going to get that the definition has evolved and changed? YOU are the one clinging to a deprecated and archaic definition of the word that only a very small percentage of the population knows, and an even smaller percentage actually cares about.
P.S. Same goes for "piracy".
Re: (Score:2)
Re: (Score:2)
tag MICROSOFT WINDOWS (Score:2)
Thanks Bill - enjoy your retirement.
Re: (Score:2)
Opps. There goes the doorbell.
The Feds use the doorbell? I thought they used a needle and a gunnysack?
Here's the e-mail the FAA sent out to Employees (Score:5, Informative)
Congres made us safe :) (Score:2, Interesting)
FFA hacked? (Score:2)
Vote for Pedro!
Coincidence? (Score:1)
This is on the same day Microsoft announced you could take control of an Exchange server by sending an email to it? [slashdot.org]
My first thought (Score:1)