NASA Didn't Even Come Close to Creating a Secure Cloud Network

Image for article titled NASA Didn't Even Come Close to Creating a Secure Cloud Network

Like a lot of organizations, NASA's doing its best to keep up with the times and move its computer systems onto the cloud. Like only a government agency can do, it's failing fantastically at doing so securely.


A review released on Monday by NASA's inspector general had nothing good to say about the space agency's cybersecurity situation. The report found that a large number of cloud initiatives suffered from dangerously poor security, so poor that they would have "severe adverse effects" on NASA if compromised. And out of five contracts reviewed, "none came close" to offering adequate cybersecurity. And on top of that, over 100 of NASA's internal and external websites were found to have no security measures in place whatsoever.

This shouldn't be so surprising. NASA's historically terrible at cybersecurity. Seriously, it seems like the space agency gets hacked every other week. In February of this year, for example, Anonymous hit NASA and leaked a bunch of data. That looks like child's play compared to last year, when NASA admitted to thousands of breaches due to lack of security. Heck, a 15-year-old hacker even broke into NASA back in 1999 and shut down the computers that run the International Space Station for nearly a month. That's just to name a few security breaches.

If you're rooting for NASA's success, the good news is that the government is on this problem. Earlier this year, President Obama issued an executive order for all agencies to beef up their cybersecurity protection as part of his larger cybersecurity initiative. It's too bad about all that NSA spying business, though, because now the very hackers that would be the ones to help improve the cybersecurity on these systems don't want anything to do with the federal government and banned several agencies from attending DEF CON this year. But hey, there's always next year! [NASA via The Verge]

Image via NASA



I personally think the push to the cloud is a little premature. A lot of my clients think that cloud services are what they want in lieu of a new server until they realize how much its going to cost them a month for the same services they have now. Most of the time, the services will equal the cost of the server within 2-3 years.