Software Vulnerabilities in the Boeing 787
schneier.com
schneier.com
These devices are often called “data diodes”. They are cheap. They cannot be hacked from the output side — at best a severely malfunctioning destination could send so much power the wrong way on the fiber or so much voltage the wrong way on the wire that the data diode fails. This would be surprising to say the least.
For example for the Airbus A350;:
> The applicable airworthiness regulations do not contain adequate or appropriate safety standards for this design feature. These proposed special conditions contain the additional safety standards that the Administrator considers necessary to establish a level of safety equivalent to that established by the existing airworthiness standards.
[1] https://www.federalregister.gov/documents/2013/12/17/2013-29...
I'm obviously not going to attempt to exploit the firmware on an aircraft for obvious reasons, but the security researcher's notion that you can "pivot" from the in flight entertainment to anything to do with aircraft operation is pure fantasy.
These systems are entirely separate, including the electricity that controls the systems.
This guy is preying on individuals' lack of knowledge about aircraft mechanics in order to promote himself.
This is part of the reason why I agree with you, because I don't see why the 787 would be unique by mixing avionics/mechatronics with the passenger systems but I don't know enough to say it with confidence. They would have designed the passenger systems to be independent and replaceable (especially with the knowledge gained from the legacies and upgrades of other planes like the 737).
Is there any public guides for 787 chassis and maintenance that you could point to as being reasonable things to read about this new style plane?
I was hoping that the person I commented to could point us at some fun manuals to describe how these configurations worked at a technical level.
Doing things, however, that increased the weight or changed aerodynamics of the airplane were a very big deal, causing a ripple effect that would be very expensive.
Freighter versions were commonplace, with the obvious omission of windows (weight savings) and interior fluff.
Doing a stretch, or a re-wing or re-engine is an enormous thing.
There are _always_ bugs in software. Your assertion that it's pure fantasy to pivot from the flight entertainment system goes against there near infinite space of sidechannel attacks and demonstrated attacks on even airgapped systems; it's almost a law of physics that you are wrong.
The "self promotion" angle was brought up last time this was discussed: https://news.ycombinator.com/item?id=20657965 and it's an obviously pointless rebuttal.
Boeing: Please post the code. Lets read it. It's already out there: https://ioactive.com/arm-ida-and-cross-check-reversing-the-7...
This is not what Boeing said to the FAA 12 years ago when they asked to certify their network architecture
> The proposed architecture of the 787 is different from that of existing production (and retrofitted) airplanes. It allows connection to and access from external sources (the public Internet) and airline operator networks to the previously isolated Aircraft Control Domain and Airline Information Services Domain. The Aircraft Control Domain and the Airline Information Services Domain perform functions required for the safe operation of the airplane.
[1] http://rgl.faa.gov/Regulatory_and_Guidance_Library%5CrgSC.ns...
I believe this contradicts the "systems are entirely separate" statement from the parent comment.
https://i.blackhat.com/USA-19/Wednesday/us-19-Santamarta-Arm...
page 52.
So, you're saying there's no shared components at all... boards, data lines/switches, power lines/switches... between entertainment and critical systems? They run separate, highly-filtered power wires with separate boards with separate data lines for the two? No shared components at all?
You burn one lb (unit) of fuel for every three lbs (units) of fuel you carry.
Me: FAA licensed dispatcher
(Also, you'll see a 1:1 rule would imply adding fuel does not increase range, which is absurd.)
HW separation was enforced by FAA back when 787 was in prototype stage.
> The proposed architecture of the 787 allows connection to and access from external sources (the public Internet) and airline operator networks to the previously isolated Aircraft Control Domain and Airline Information Services Domain.
> Capability is proposed for providing electronic transmission of field-loadable software applications and databases to the aircraft. These would subsequently be loaded into systems within the Aircraft Control Domain and Airline Information Services Domain.
[1] http://rgl.faa.gov/Regulatory_and_Guidance_Library%5CrgSC.ns...
I can't find the "work-in-progress" reports for type certification regarding the network, but the special conditions involve:
> The applicant shall ensure system security protection for > the Aircraft Control Domain and Airline Information > Domain from access by unauthorized sources external to > the airplane, including those possibly caused by > maintenance activity. The applicant shall ensure that > security threats are identified and assessed, and that > risk mitigation strategies are implemented to protect the > airplane from all adverse impacts on safety, > functionality, and continued airworthiness.
In reality, how is this separation of critical networks looking like exactly? MAC address filters? Are they air-gapped? I would venture to guess, nobody that isn't bound by an NDA knows.
FAA caught it and forced them to redesign the setup.
As for actual AFDX networks - they have hardcoded forwarding tables and no MAC learning, and separation between networks tends to use data diodes
Assuming planes don't use something like CAN-bus but regular TCP protocol, this can't really be true right? Perhaps they talk about which services are allowed to connect (listen for incoming connections).
Electronic Flight Bag being part of maintenance network is not something good, though.
The 787 Dreamliner is a nightmare. Bad code produced by offshore teams. International teams totally violating safety procedures.