It's very strange to see website timing attacks as worth rewarding, but not avionics. Perhaps they'd rather not incentivize people to attack airplanes in flight?
It's very strange to see website timing attacks as worth rewarding, but not avionics. Perhaps they'd rather not incentivize people to attack airplanes in flight?
United probably isn't interested in paying for someone else's bugs.
Though the avionics industry would obviously balk at the proposition, those systems are already spectacularly vulnerable, and they'd hate to lose face.
Absolutely untrue, unless you have physical access to them (at which point any system is vulnerable). In truth, the maintenance port on a 787, for example, (which is the only place you could feasibly get the kind of access you'd need to even attempt an exploit) is located in the avionics bay. At the point that an unauthorized party has gained access to the avionics bay, you've got a much bigger problem than software exploits.
If you're referring the Chris Roberts' dubious "Planes, Trains, and Automobiles" grrcon talk ... well, I'm sorry, but claiming that you've "made friends <giggle>" with an airplane doesn't seem very substantive to me.
Avionics code is some of the most extensively tested code in the world, with 100% statement and decision coverage, 100% requirements test coverage, extensive robustness testing, and somewhere between a handful and hundreds of eyes having reviewed every single line (depending on criticality level). Additionally, design constraints are followed for high criticality software that simply eliminate many types of attacks - no dynamic allocation, mathematically provable static stack analysis, etc. etc. etc. (get yourself a copy of DO-178B and read it if you really want to know all the details). I would bet a significant amount of money that the defect rate per N lines of code in avionics software is probably substantially lower than almost all other commercial software. There's also the fact that on modern aircraft using Ethernet based networks, message routing and authentication are implemented in both hardware and software at multiple layers by independent teams, which greatly reduces the chances of a common fault that allows a successful attack (even if you could gain physical access to the network).