08 Dec 2010
Nasa has been hit by embarrassing revelations that it sold end-of-life PCs that contained top secret data on the Space Shuttle programme.
An internal investigation (PDF) at the US space agency found "significant weaknesses in the sanitisation and disposition processes" at the Kennedy and Johnson Space Centres and Ames and Langley Research Centres, which resulted in 10 computers being released with Nasa information still on the hard drives.
Nasa policy dictates that all machines which have ever stored Nasa information must be "sanitised" before being "reassigned, transferred or discarded".
In other words, they must be scrubbed of data so that it is "impossible or nearly impossible to recover the data previously stored there", the report stated.
However, the investigation found that managers at some sites were not notified when computers failed sanitisation verification testing. On some occasions no verification testing was performed at all, and unapproved sanitisation software was used in some cases.
"In addition, we found computers at the Kennedy disposal facility that were being prepared for sale on which Nasa internet protocol information was prominently displayed," the report said.
"Internet protocol information could provide a hacker with the details needed to target specific Nasa network assets, and exploit weaknesses resulting in the compromise of sensitive information."
Investigators seized a further four computers being prepared for sale that had failed sanitisation verification testing and contained sensitive data.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Working within the central Service Desk Team of a well...
GIS Applications Engineer - circa £35k Excellent opportunity...
Senior C++ Developer x 2 - Senior C++ Software Engineer...
We are actively searching for Information security specialists...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Why dont they....
Why don't they just remove Hard Drives and destroy them. Selling a PC without a HD is not hard as a HD can be purchased cheaply these days. No excuse at all for selling PCs with HDs that has had secret data on them, and they are after Assenge! Why... they are pratically giving away secrets
Posted by: Trev 09 Dec 2010