Boeing 787 In Flight Entertainment System Security fun
btr.pm
btr.pm
I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of people who didn't bring a book.
Even if it brought down the server, it's still nothing that the flight attendants can't solve by "turning it off and back on". This kind of fault happens all the time.
More interesting to me is the level of isolation of the network. Could someone exploit my phone through the in-flight WiFi, for example?
They cite inadequate safety standards and an overheating entertainment system.
It's easy to assume that government or the airlines wouldn't allow a faulty system to fly, but just like software it's those extreme edge cases that cause problems. Somehow I doubt hacking the entertainment system is comprehensively covered in the manufacturers safety check. It's probably a remote chance something bad would happen, but we can't say it's 0.
Half the bugs I notice in Chrome, I notice because my laptop fan starts running.
It's more likely for your plane to be hit by a falling unicorn than you being able to burn something up just by the power of `while (1)`.
The origin of Murphy's Law was in a rocket sled project. This guy was strapped onto a rocket sled, fired down a track, and then subjected to strong braking forces. "If anything can go wrong, it will go wrong" didn't just mean "stuff happens". It meant, "you have to either make it impossible for it to go wrong, or you have to find a way that, even if it does go wrong, this guy doesn't die". You can't just ignore the problem as unlikely. It will happen sooner or later.
You don't get to say "lots of things have faulty wiring". Things that can kill you had better not have faulty wiring, or had better be able to survive it if they do.
And read this before dropping your hair dryer in the bathtub: https://iaeimagazine.org/magazine/2010/01/16/the-illusion-of...
So yes, the aircraft is supposed to be robust against any trickery with the entertainment system. And indeed, it's 100% their fault for installing the wiring in a way that would overhead under load.
It's still pretty irresponsible to risk taking down the aircraft like that to check for a vulnerability!
The "rigorous protocol" is one-way hardware diodes. The telemetry simply cannot physically travel the other way.
Now, of course, there can always be mistakes. Certification is supposed to catch that, but of course, that isn't fool proof either.
Is that based on expectation, hope, or knowledge?
https://en.wikipedia.org/wiki/DO-178B#Software_level
https://en.wikipedia.org/wiki/DO-254
By definition, it should have no impact on "safety, aircraft operation, or crew workload".
Mistakes can happen, but this is what is aimed for.
No, and the flaw you're busy exploiting also definitely shouldn't be there.
(Yes, the IFE is probably airgapped. Probably.)
At level E you only have to prove that there's no effects of faults on safety-critical systems, so it's more about the surrounding architecture than the software itself.
Consequently the MD-11 has to land at high speed which makes it prone to catastrophic bounced landing like the 2 Fedex crashes.
Also, it was not produced for very long (compared to other aircrafts from Boeing or Airbus) and the fleet was either retired or converted to freighters quickly by airlines.
This mentality is where a lot of our current security problems come from, from IoT to critical infrastructure to ATMs, etc. Developers can't imagine someone would ever do anything nefarious on their "closed" network, so they don't bother doing more than cursory security. Then the internet shames anyone who tries to demonstrate how bad things really are.
(I work on IFE and avionics)
There is no physical way to write through those.
Tiny nitpick:
In my understanding, ETA denotes a point in time, e.g. 22:50h, that is the estimated time at which you arrive. (Absolute)
If you want to specify a duration in this context, i.e. how much longer until arrival, e.g. 0:53h for another 53 minutes until arrival, you'd speak of the ETE (estimated time enroute). (Relative)
See (in German) e.g. https://de.wikipedia.org/wiki/Estimated_time_of_arrival
tl;dr: use "ete" instead of "eta"
In 2017, you absolutely have a reasonable expectation that network systems are safe to nmap. You might be wrong, but that's a completely reasonable assumption.
However I draw the line when an unauthorized actor accesses a live system to prove a point, rather than going through proper procedures with absolutely no knowledge of the potential outcomes of his or her actions. This isn't white hat by any stretch of the imagination, and is incredibly reckless.
I'd say the absolute worst case scenario is that the IFE crashes and must be restarted. Not a great result but not a plane crash and not a 10h flight without IFE either.
The other almost-catastrophic outcome is apparently that the IFE system would not just crash, but be bricked in a state where it couldn't be restarted. Not impossible, but not likely either.
People switch seats in planes without asking the staff. That's also irresponsible and dangerous, and the worst case scenario is a crash. This is about the same level of risk if you ask me.
Is that still white hat? Did they also check to see if the cockpit door is locked?
I wouldn’t guess they would add double sensors for all that information.
Or did you mean well protected, instead of literal air gap?
Fiber optic connections aren't required, anything with separate transmit and receive lines can be turned into a data diode (as long as the protocols used permit it). RS232 null modem cables with the RX lines disconnected are a classic.
The flight critical systems would be isolated from in-flight entertainment system (IFE). The IFE probably has a listen-only tap to flight metric info on an ARINC databus from the flight computer. I did a quick search and looks like 787 uses ARINC 667, a fiber optic interconnect.
> These special conditions are issued for the Boeing Model 787-8 airplane. This airplane will have novel or unusual design features when compared to the state of technology envisioned in the airworthiness standards for transport category airplanes. The architecture of the Boeing Model 787-8 computer systems and networks may allow access to external systems and networks
[1] https://www.federalregister.gov/documents/2007/12/28/E7-2507...
Agree the IFE could crash, but can't see how there is even a remote risk to critical systems, or any risk to the IFE that isn't solved by (yet another) reboot of it.
In the UK for example, the computer misuse act says that using any tool with the intent of accessing a system (without actually doing so, let alone doing so successfully) is an offence.
One of the core apps had a control port that implemented HTTP. Unfortunately, my GET hit a route that didn't exist, and that caused a small memory leak every time.
Nothing too bad happened; the leak was slow, and even though the app stayed up many months at a time, we did notice the leak and figured out what was causing it.
As others have stated elsewhere, I've seen completely 'easy going' TCP connections to embedded devices cause immediate crashes.
Particularly if something goes terribly wrong and you're on the plane.
In practice I wouldn't expect the firewalls to be particularly well tested or complete or configured correctly, and it may be possible for an attacker to DOS the firewall and impact the other systems, and possible for the attacker to penetrate the firewall and so on.
Can someone confirm the above post?
Sadly, it seems they usually share wires and are separated by firewalls.
There's been lots of CCC and defcon talks about hacking in-flight systems. Googling "panasonic ife hack" gets plenty of hits, as does "Chris Roberts" who is a hacker who has made some pretty big claims about actually really hacking planes in flight and other stupid things. And there are articles like this https://www.wired.com/2015/04/hackers-commandeer-new-planes-... that talk about how the systems share wires.
Shared wires? That's fact, right?
The IFE is in the Passenger Information and Entertainment Services Domain (as defined by the standard ARINC664 Aircraft Data Networks). A basic assumption regarding the connectivity to more sensitive domains is that PIESD is totally insecure and anything can happen.
Finally to people wondering why aircraft designers would physically connect networks with vastly different security requirements: it's for making it possible to share aircraft/ground communication means (satcom...)
And it doesn't have to be a dramatic life threatening situation to incur a boatload of financial liability. See this for example: http://nypost.com/2017/08/30/unruly-passenger-ordered-to-pay...
The other reply regarding the overheated IFE is another unlikely, but possible, scenario.
Even if in any other dimension it can be possible, it's the responsability of who design the system for protect against this.
I think if you are not specifically asked to do it, it isn't white hat, and I think (but am not 100% sure) the law is like that. I don't know what hat it is, but white it isn't.
Otherwise, passengers could be so distracted with the electronic entertainment that they might not notice that it got very breezy all of a sudden...
https://github.com/x8BitRain/InFlightEntertainment-Scoot787/...
which then weaves through various functions similar to the above states. So I think your guess is on track!
I took to leaving my phone on top of the seat controls, but even then seemed to have weird gremlins.
I'm not sure who designed that, but it was.. not smart. Poor design, poor implementation.
> There are places where the networks are not touching, and there are places where they are
Boeing's Lori Gunter
https://www.wired.com/2015/04/hackers-commandeer-new-planes-...
Typically FLARE would be RA (Radio Altimeter) < 50ft, flaps/slats extended, speedbrake armed, and weight on wheel = 0 or something along this line.
Why is this blog post being upvoted?
Scanning during flight is not really responsible at all.
Unfortunately nowadays "Arabic" is what worries people, even if that turns out to mathematical notation. [1]
[1] https://www.theguardian.com/us-news/2016/may/07/professor-fl...
Well that's just...awesome..
So many good things with this approach: cost, easy upgrades, no complicated certification or hardening needed.
I have no idea why no other airlines use this method, it seems so much easier to me.