Slashdot Mirror


Romanian Accused of Breaking Into NASA

alphadogg writes "Romanian authorities have arrested a 26-year old hacker who is accused of breaking into multiple NASA servers and causing $500,000 in damages to the U.S. space agency's systems. Robert Butyka, 26, was arrested on Tuesday in Western Romania following an investigation by the Romanian Directorate for Investigating Organized Crime and Terrorism. According to local reports, the hacker used the online moniker of 'Iceman.' He does not have a higher education or an occupation, a DIICOT spokeswoman said."

18 of 169 comments (clear)

  1. ...not to endorse his actions by Anonymous Coward · · Score: 5, Insightful

    ...but why aren't IT admins being held accountable for the lax security on their servers? And no, I don't buy the "if I leave my door unlocked, it's not an invitation to break in", since it's a paid position. If a cop fails to prevent a crime due to neglicence, the city can be sued. Most of these break-ins are due to IT negligence, not hacker genius.

    1. Re:...not to endorse his actions by bberens · · Score: 3, Interesting

      Where do you live that a cop failing to prevent a crime can lead to the city getting sued?

      --
      Check out my lame java blog at www.javachopshop.com
    2. Re:...not to endorse his actions by timeOday · · Score: 3, Insightful

      Most of these break-ins are due to IT negligence, not hacker genius.

      I think negligence would be *very* hard to establish. First, most computer bugs, including vulnerabilities, are very obvious - in retrospect. Finding the needle in the haystack is easy after somebody points it out to you. That's entirely different than integrating hundreds of software components without creating any "obvious" holes.

      Second, how many sysadmins are given all the resources they would like to do their jobs? Security is cost/benefit, like anything else, you devote enough resources to make the pain tolerable, and no more. That means most admins have far more responsibilities than they can cover 100%.

    3. Re:...not to endorse his actions by bws111 · · Score: 3

      How do you know the admin was not held responsible? He could have been fired, demoted, etc.

      If you mean why isn't the admin held responsible by the legal system, what law would allow him to be held responsible? IT admins are not sworn to duty (like police) or licensed (like professional engineers).

      Your example of the city being sued does not work here. The person suing the city would be the person who was harmed by the negligence. Who, other than NASA, would have standing to sue in this case? Who would they sue, themselves?

  2. Damages by AdamJS · · Score: 3, Interesting

    I'm betting the damages are formulated entirely from the cost of them having to do PR (they got hacked by a NEET after all) and 'fix' the security hole (because face it, they'll probably introduce 10 more flaws when fixing one).

    1. Re:Damages by bberens · · Score: 4, Insightful

      You get a few senior level IT people in a room and a single meeting can easily cost $1k. Total time to figure out what happened, track the guy down, etc. could easily cost $500k.

      --
      Check out my lame java blog at www.javachopshop.com
  3. Re:Education by ByOhTek · · Score: 5, Insightful

    How much you make doesn't indicate how much you know.

    I have a friend who is a complete idiot in the functional aspect of doing his job, lacking the background education, but he's good with people and instead delegates most of the functional work to others (basically acting like a manager, though he isn't), and makes a huge salary.

    And I've another friend, who also lacks the background education, but is very competent, and makes a huge salary.

    i.e. Salary does not indicate competence and qualification, sadly this seems to be especially true when you get to managerial and executive level positions, which half the time simply need a warm body to fill a chair and occasionally point in a (hopefully good) direction.

    Likewise, Education (or lack thereof) does not indicate competence or qualification.

    In general there are trends towards better education meaning more competence, and more competence correlating to higher salary, but they are by no means tight or without exception.

    --
    Self proclaimed typo king, and inventor of the bear destroying coffee table (patent not pending).
  4. No education or occupation by roman_mir · · Score: 4, Insightful

    According to local reports, the hacker used the online moniker of "Iceman." He does not have a higher education or an occupation, a DIICOT spokeswoman said.

    No education and no occupation, ha?

    So who is working for NASA then, that this 'no-education and no-occupation' individual is able to break into their systems?

    Butyka is accused of hacking into several NASA servers over a period of time that started on Dec. 12, 2010. The authorities claim that the hacker destroyed protected data and restricted access to it. The charges brought against Butyka include obtaining unauthorized access and causing severe disruptions to a computer system, modifying, damaging and restricting access to data without authorization and possession of hacking programs.

    He possess hacking programs, that means he is a terrorist. What kind of 'severe disruptions' did he cause that cost 500,000 USD?

    Romanian authorities have arrested a 26-year old hacker who is accused of breaking into multiple NASA servers and causing $500,000 in damages to the U.S. space agency's systems.

    - this is a bunch of nonsense.

    He cost an admin a few hours of time and maybe a reinstall and reconfigure. Even at 1000USD / hour no way somebody spent 500 hours on it (that's 20.8 24 hour days) or 12.5 40 hour weeks.

    This is more government nonsense.

    1. Re:No education or occupation by GameboyRMH · · Score: 3, Interesting

      Possession of "hacking programs" is a crime? I think all my computers except my gaming PC have "hacking programs" on them, good thing I don't travel to the states these days.

      --
      "When information is power, privacy is freedom" - Jah-Wren Ryel
    2. Re:No education or occupation by roman_mir · · Score: 4, Funny

      well, he also owns a computer, this is almost a 100% indication that he is a pedophile-terrorist, or a pedo-rist.

      This is what government is for - making sure that the right people are always punished for their transgressions. That's why Jon Corzine is in charge normally, of some government and/or economic function somehow and disgusting people like Ron Paul are blacked out by the media because they challenge the status-quo.

      Also USA is sending troops to Australia. You know, in case pro-Chinese Kangaroos join Al-Qaeda.

    3. Re:No education or occupation by timeOday · · Score: 3, Insightful

      So who is working for NASA then, that this 'no-education and no-occupation' individual is able to break into their systems?

      So anybody who can smash a car window and steal a stereo is smarter than the guys who design cars? That is not a logical conclusion.

    4. Re:No education or occupation by Sarten-X · · Score: 5, Informative

      I take it you've never actually worked on a high-security system. Here's what I remember of the procedure at the last high-security place I worked:

      In the event that a machine (including a gateway) is compromised, any machine it can access is considered threatened, and must be thoroughly checked. No, NAT does not help, because once someone has control over the bridge, they can send data to any machine they want, even those without an external IP address. If any router, switch, or machine shows any slightly-suspicious activity (even as benign as an unscheduled database login), that machine gets an even more thorough examination to find out whether the activity was actually related to the hack, and what resources the hacker may have gained access to. If there's any indication that the hacker had shell access or retrieved data, the machine is considered compromised. If the machine stored any sensitive data, that data is reviewed to see if it could allow access to other systems (such as challenge questions & answers for resetting passwords). This investigation, which often involves the use of outside consultants (because there may have been inside help) continues throughout the whole network until the full extent of the breach is known. Being a government agency, the breach will likely involve a several-hundred-page report covering every detail. Somebody has to write that.

      The cost is already in the hundreds of thousands of dollars, and only then can the repairs start. It's often not as simple as just restoring a backup, either. Sure, the operating system can usually be done quickly (including fixes for the responsible security holes), but if there's any indication of data being touched (which, in this case, there was), that has to be addressed, too. Backups are usually old. In an ideal world we'd be making hourly backups stored offsite in an everything-proof vault, but that's never really the case. If an admin's lucky, he has a backup that's less than a week old - or it was when the breach occurred. Somehow (best described as "magically"), the admin has to figure out what changes were intentional (like experiment results, or customer orders, or whatever) and what was the result of the breach, then piece together the data to get something reasonably complete and up-to-date. Finally, after days, weeks, or months of reconstruction (most vital systems first, of course), the system is declared clean. Until then, projects get postponed, and other employees are being paid to play solitaire until their real work can continue.

      Then there's the "let's not do this again" phase, where employees change passwords, get lectured on security practices, sit through seminars on how to properly encrypt data, and so forth, all of which costs even more money. There's probably still an ongoing investigation as to whether anyone inside the organization helped the hacker, likely being run by consultants.

      Then there's the damages caused by any delays, which may involve contractual obligations. That's more money.

      It's not as simple as just re-imaging and assuming that everything's fine. Sure, that works on workstations, but it's unlikely that a workstation was all that was damaged. Once a server gets touched, the costs rise dramatically.

      --
      You do not have a moral or legal right to do absolutely anything you want.
  5. Re:Education by trum4n · · Score: 4, Funny

    Being smart and poor ain't something to brag about. I'd know.

  6. Re:How much? by moogied · · Score: 3, Insightful

    Its not just a restore. There was an investigation, then an audit process for the proposed change, then you have the CAB meetings, the testing in dev, then in stage, then finally the push to production environment. Then you have possible hardware changes(depending on mode of access), and additionally you need to sanitize the environment to be 100% sure nothing was left behind. Thats easily a few hundred man hours . 500k may be a tad high(depending on a lot of things), but its not unreasonable.

    --
    So basically, -1 troll/offtopic is really slashdots way of saying "I hate that you thought of something before me."
  7. Re:Bill Gates by Anonymous Coward · · Score: 3, Informative

    Woz was the phone phreak, true. Jobs was the one who wanted to commercialize the device to do the phreaking. Woz was one guy making free calls. Jobs wanted to make money off of selling "free call devices" to others.

  8. Not in DC by srussia · · Score: 5, Informative

    If a cop fails to prevent a crime due to neglicence, the city can be sued.

    http://en.wikipedia.org/wiki/Warren_v._District_of_Columbia

    --
    Set your phasers on "funky"!
  9. Re:Education by 0-until-pink · · Score: 5, Insightful

    This reminds me of the Kurt Vonnegut bit in Slaughterhouse Five about Americans attitude towards esteem and money.

    "America is the wealthiest nation on Earth, but its people are mainly poor, and poor Americans are urged to hate themselves. To quote the American humorist Kin Hubbard, “It ain’t no disgrace to be poor, but it might as well be.” It is in fact a crime for an American to be poor, even though America is a nation of poor. Every other nation has folk traditions of men who were poor but extremely wise and virtuous, and therefore more estimable than anyone with power and gold. No such tales are told by the American poor. They mock themselves and glorify their betters. The meanest eating or drinking establishment, owned by a man who is himself poor, is very likely to have a sign on its wall asking this cruel question: “if you’re so smart, why ain’t you rich?” There will also be an American flag no larger than a child’s hand – glued to a lollipop stick and flying from the cash register."

  10. The real story here... by DeltaVelocity · · Score: 3, Insightful

    ...is not that a Romanian hacker got into NASA systems and caused an alleged $500k in damages/remediation expenses. The real story is that the Romanian authorities actually DID something about it.