>"The plane would have to have been connected to an infected system.," he said. "The chances are pretty minimal."
If they can't confidently say the chances are guaranteed 0% then they need to actually look in to it and not just dismiss the idea.
>"The plane would have to have been connected to an infected system.," he said. "The chances are pretty minimal."
If they can't confidently say the chances are guaranteed 0% then they need to actually look in to it and not just dismiss the idea.
https://www.wired.com/2015/05/feds-say-banned-researcher-com...
"He obtained physical access to the networks through the Seat Electronic Box, or SEB. These are installed two to a row, on each side of the aisle under passenger seats, on certain planes. After removing the cover to the SEB by "wiggling and Squeezing the box," Roberts told agents he attached a Cat6 ethernet cable, with a modified connector, to the box and to his laptop and then used default IDs and passwords to gain access to the inflight entertainment system. Once on that network, he was able to gain access to other systems on the planes."
That one might just be a security researcher big-noting himself, but combined with this next one, I do not have a great deal of confidence in Boeing (or any of the airline industry's) software security teams...
https://nakedsecurity.sophos.com/2017/11/15/dhs-says-it-remo...
I wonder what we'd find if Tavis Ormandy were seconded to Boeing for six months? (And can I have a heads-up if that happens? I've got some stock I'd like to short...)
So it was on a cargo plane, then?
At some point, using systems susceptible to malware to conduct critical business is simply negligence. Windows is not a sane default.
Boeing use CATIA and Dassault Systèmes dropped non-windows client support for CATIA in 2008.
Every OS, every architecture, every platform, everything.
Nobody’s burning iOS or Chrome sandbox 0days to try to earn $50k USD ransoms.