There seems to be two threads here bashing heads against each other
1. The specific details of this (admittedly movie-plot-threat) are wonky and not believed by reasonable people in the industry
2. The digital security of most systems when looked at by Internet-hardened veterans is somewhere between vulnerable and laughable, so why should planes be different (ie gas and water control pumps with ethernet ports and factory set default passwords like admin)
2. seems to be most peoples default response - "hey look, another thing thats been connected to the internet, its probably wide open"
That is a good response to have as a) anecdotally it seems to be right 9 times out of 10, and b) its the right side of caution anyway.
The fact that 1. is much harder to do than perhaps shown is indicative that things in the FAA arent as bad as say, sewage treatment industry.
But, even so, all our systems are now connected and so much more vulnerable. And even if this guy cannot down planes with his android phone, he has gotten a hell of a lot closer than anyone not totally paranoid would assume.
I think the correct response would be
This specific setup does not apparently live up to the
media hype. However, all digital security is undergoing a
period of massively increased attack, and we should never
be complacent. He has gotten further than we expected
feasible and will be looking at a program of fixing attack
vectors run under the same rules as air-crash
investigation. Any known bug is investigated, understood
and a comprehensive solution made transparently available
to the industry.
The airline industry is rightly proud of its safety record, and it should see this as an opportunity to become rightly proud of its digital security record too.