Nasa to encrypt data after its latest laptop loss


Recommended Posts

US space agency Nasa has ordered that the data on all its laptops must be encrypted, after losing another one of its portable computers.

Until the process is complete, it has forbidden staff from removing Nasa-issued laptops containing sensitive information from its facilities.

The order follows the loss of a device containing "sensitive personally identifiable information".

There have been several similar incidents over recent years.

Nasa said the latest incident had occurred on 31 October, when a laptop and documents were stolen from a locked vehicle of one of its employees at Nasa headquarters in Washington DC.

The machine was password protected, but the agency acknowledged that the information might still be accessible to hackers since it was not encrypted.

Encryption would have scrambled the data, requiring a complicated code to make it understandable again.

As a result, Nasa has warned its workers to watch out for bogus messages.

"All employees should be aware of any phone calls, emails, and other communications from individuals claiming to be from Nasa or other official sources that ask for personal information or verification of it," an agency-wide email published by news site Spaceref stated.

"Because of the amount of information that must be reviewed and validated electronically and manually, it may take up to 60 days for all individuals impacted by this breach to be identified and contacted."

Encryption order

As a result of the security breach, Nasa's chief information officer, Linda Cureton, has said that with immediate effect laptops containing information about the following topics could only leave its buildings if the relevant data was encrypted:

* The international sale or transport of weapons, nuclear equipment or other materials that fall under the US's export administration regulations

* Information about Nasa's human resources

* Other "sensitive but unclassified" data

She said that she wanted the maximum possible number of laptops to be encrypted by Wednesday and a target of all laptops a month later. In addition employees have been banned from storing sensitive data on mobile phones, tablets and other portable devices.

The Nasa Watch blog, which comments on affairs at the agency, had previously criticised it for a series of other data losses.

It noted that the organisation had been warned in 2009 that it was not taking enough steps to sufficiently protect information and had reported the loss or theft of 48 of its mobile computing devices between April 2009 and April 2011.

This is not the first time Nasa has promised action to address the problem.

In March, Nasa administrator Charles Bolden told the House Appropriations Committee Subcommittee on Commerce that that he was going to sign a directive ordering all portable devices to use encryption, after acknowledging the agency was "woefully deficient" when compared to other government departments.

http://www.bbc.co.uk/news/technology-20343745

It amazes me how many of the US organizations/companies don't encrypt there data (create FDE), heck I only have family pictures and work files that anybody would care less to see, I keep my laptop encrypted even though, so if someone steals, or I lose the laptop somehow my things stay mine (as they are backed up). Its just simple encryption, not a chemistry formula, why would any big organization/company not do it in the first place?

wow... we've had a company policy that we MUST use truecrypt with AES at minimum as a boot level encryption on all laptops for many years now and all encryption passwords are at least 15 characters long, and picked by IT staff not the individuals to ensure they are compliant with encryption standards here...

wow... we've had a company policy that we MUST use truecrypt with AES at minimum as a boot level encryption on all laptops for many years now and all encryption passwords are at least 15 characters long, and picked by IT staff not the individuals to ensure they are compliant with encryption standards here...

Finally, someone who uses TrueCrypt, maybe you can tell me how to use it, because the instructions on the web site suck. And, I'm getting a laptop again soon.

Finally, someone who uses TrueCrypt, maybe you can tell me how to use it, because the instructions on the web site suck. And, I'm getting a laptop again soon.

Lots of people here use TrueCrypt (including myself). If you can't figure it out on your own, create a new thread and we'll help you out.

I encrypt my laptop. If my laptop were ever stolen, I know my data is secure... unless they keep the laptop powered on and bypass the login screen through the FireWire port... Nothing is secure these days, especially my f-ing Android phone. :/

Many devices are easily broken into with user-friendly forensics software such as this.

If it was so 'simple', how come I still can't figure out how to use it!

Install it

Start the program up, go to system menu, select encrypt system partition, follow the wizard, that's all the harder it is... and all the wizard does is make sure you have MBR partition tables (GTP is not supported) select the drive, pick a password, make a recovery CD and then it encrypts it... when done restart and it will ask for the password on the next boot..... that's all the harder it is

Encryption costs money. Did anyone think about what happens when you underfund an entire department like Nasa is? Mistakes happen.

Really? didn't cost us a cent outside normal IT time cost to encrypt 100+ laptops... just pull one when you have time encrypt the drive put it back in service.... keep going until its done... we didn't have to "budget" for it... truecrypt is free, each laptop took a whole 3 minutes of our time of actual worker time not it sitting there clearing free space until its done time

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I like Tidal, but it still does not control devices from the mobile/app and still no surround support. And yeah re: above comment I still get a lot of network errors and I am on a 4/4 Gbit Fiber connection.
    • Aren`t "security features" and "AI model that can see your screen" a tad diametric!
    • Samsung, Amazon extend 990 PRO 2TB NVMe SSD deal beyond Prime Day 2026 by Sayan Sen Recently, we had Amazon's Prime Day 2026 sales wherein there were several great deals including on SSDs. One of those discounted components was the Samsung 990 PRO SSD as the 2TB variant of it was selling for $370, a very good price after a long time. Although that deal was supposed to expire today, Amazon has now extended that sale further (purchase link under the specs table down below). The 990 PRO is a PCIe Gen4 NVMe SSD and still one of the fastest drives available today for under $400. Speaking of fast, sequential reads and writes are rated at 7450 MB/s and 6900 MB/s, respectively. The random throughputs for reads and writes are 1400K IOPS and 1550K IOPS, respectively. The 990 PRO is based on Samsung's 7th Gen V-NAND flash, and it too is TLC. It packs 2 gigs of LPDDR4 DRAM cache, which helps the random performance. The endurance rating for this is 1200 TBW (terabytes written), which should be sufficient for most users. The Samsung 990 PRO is compatible with the PlayStation 5, but if you are going to use the 990 PRO on a PC, check out the Samsung Magician app that lets you track your drive's health, update its firmware, customize various settings, and more. The technical specs of the Samsung 990 PRO 2TB are given in the table below: Specification Value Form Factor M.2 2280 Interface PCIe Gen 4.0 x4, NVMe 2.0 NAND Flash Samsung V-NAND TLC Controller Samsung In-house Controller Cache Memory Samsung 2GB Low Power DDR4 SDRAM Sequential Read Speed Up to 7,450 MB/s Sequential Write Speed Up to 6,900 MB/s Random Read (4KB, QD32) Up to 1,400,000 IOPS Random Write (4KB, QD32) Up to 1,550,000 IOPS Random Read (4KB, QD1) Up to 22,000 IOPS Random Write (4KB, QD1) Up to 80,000 IOPS Operating Temperature 0°C to 70°C Reliability (MTBF) 1.5 Million Hours Endurance 1,200 TBW (Total Bytes Written) Get it at the link below: Samsung 990 PRO SSD 2TB NVMe SSD (MZ-V9P2T0B/AM): $369.99 (Sold and Shipped by Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases
    • Glad im on the right boat. Tidal has lots of issues in terms of app and music mix, its worst than spot but its honest. Spot algo is very tendentious and they pess less to artists, so im comfortable with the tidal errors, for now.
    • Tidal won't monetize AI slop music, company says by David Uzondu Image via Tidal Tidal has announced an AI policy aimed at protecting artists and their crafts, as AI music generation tools continue to improve both in speed and quality. According to the music streaming platform, AI-generated music will be accepted, but these tracks will be held to a "higher standard" of content integrity. Next month, the company plans to auto-identify and tag these uploads. Listeners will spot a special icon next to content that algorithms flag as 100% AI-generated starting mid-July, and the platform hopes to expand this tag to partially generated songs as detection tech improves. Any AI music that exploits an artist's voice or likeness will be taken down, and Tidal will immediately block tracks associated with fraudulent activity, which includes artificial streaming and deceptive content that interferes with real creators. And finally, music that's 100% AI-generated will not be monetized. Tidal said there is "ongoing debate" about whether certain licensed synthetic models deserve payouts, so it's possible that this part will change in the future. Streaming platforms are absolutely getting flooded with AI-generated music because of how easy it is to pump out endless tracks every minute. To give you an idea of how "bad" it is, Deezer alone reported that synthetic uploads now make up about 44% of its daily intake, which translates to roughly 75,000 automated tracks hitting its servers every single day. Interestingly, Deezer found most people cannot tell the difference between human and machine creations, with an Ipsos study revealing that 97% of listeners failed to spot the AI-generated tracks. Spotify's CEO recently pushed back against listeners who call AI music "slop," urging people to stop using the term and instead embrace the creative potential of AI music. The Swedish platform partnered with Universal Music Group to test "legal and controlled" generative AI tools that let subscribers remix songs with AI.
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      539
    2. 2
      +Edouard
      269
    3. 3
      PsYcHoKiLLa
      153
    4. 4
      Steven P.
      98
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!