Hacker told FBI he made plane fly sideways after cracking entertainment system
aptn.ca
aptn.ca
Having said that, I once worked with a guy who used to work for Boeing. Given the work he produced while we worked together, nothing would surprise me.
I hope this just turns out to be a vocal series of lies, but I also hope it's fully investigated.
http://scifi.stackexchange.com/questions/54734/making-sense-...
What's better for raising consciousness about a potentially fatal flaw that by making people think that lives were at risk when they weren't?
more examples: ~ https://youtu.be/YiPOyee_V0E inflight movement and shipbourne TO/L ~ https://youtu.be/4Sf6LQ50V2c
Page 14 (pdf page 15) of the investigation report describes evidence of seat electronics box tampering at the location where Chris Roberts sat when he tweeted about hacking the plane. It may be a coincidence (a lot of wear-and-tear on old aircraft could be described as "evidence of tampering" if you wanted to look at it that way), but the FBI doesn't seem to think so.
The extravagant claims were maliciously taken out of context by the agent in order to secure whatever he wanted from a judge, trump up charges, and making it sound as if there was some dire urgency to expedite due process and rational thought.
I don't actually know anything about this case, but have seen this happen with virtually every warrant document or indictment related to computer "crime". They're an adversarial exercise in sales to further the author's agenda, not an impartial document aimed at ensuring justice.
Now his lawyer is telling him to STFU, but he's being mischaracterized in the court of public opinion.
- If he was just lying, this must be one of the stupidest publicity stunts I've seen, and planes are still as resistant to hacking as they've always been.
- If he was telling the truth, there could be some serious effects and perhaps it was his way of imparting momentum to finally fix the vulnerabilities that he claims have been around for years; if that were the case, whatever happens to him, his "sacrifice" could even be considered heroic.
I'd really like to believe it's the former, but something about the latter still feels plausible.
Roberts is the founder of One World Labs
Incidentally, not to be confused with http://en.wikipedia.org/wiki/Oneworld
The In-Flight Entertainment network is regular Ethernet, and Flight Management System is a different format (ARINC 664/AFDX) which provides deterministic real-time connectivity.
There is a device called a Network Extension Device (NED) which is a one-way gateway between the FMS and the IFE for showing the progress of the flight to passengers.
The NED for the IFE doesn't physically have the wires for two-way connectivity to the aircraft FMS network.
I once had a customer that provided energy pricing data from their network via a leased line to be put onto their website. In their case the isolation they required was provided by not running any network stack over that link - they sent a mostly raw (error correction but that was it) stream of data point to point rather than network packets, and the connection was entirely one-way - if we were to try to send anything back, nothing was listening.
Making it physically impossible for something to listen is reasonably straight forward if you control the hardware, and you can easily additionally electrically isolate the networks.
One circuit emits light, the other circuit listens to the pattern.
But the article mentions this:
""" After news broke about a report from the Government Accountability Office revealing that passenger Wi-Fi networks on some Boeing and Airbus planes could allow an attacker to gain access to avionics systems and commandeer a flight, """
Anyone could find that report? I see mention about the report on other news sites, but not the report itself.
EDIT: I think I found the report:
It looks to me like Wired literally made the whole thing up and a bunch of other sites took it as gospel.
I mean, I've released bugs to production before, but they have never put my life at risk...
If true, he also risked the lives of everyone else on that plane. That's not ballsy, it's selfish and dangerous. If proven true, what he needs is a "timeout" at one of our country's many penal institutions.
There's no excuse for risking the lives of passengers and crew.
In an empty plane you're piloting alone, or a simulation, sure, but there's clearly a non-zero chance that the navigation hijacking could disrupt the plane enough to force an emergency landing or even cause it to crash. Even if you think you know what you're doing, there could be lots of unintended side effects from forcing the plane to make certain maneuvers.
If his statements are true, then it would be far better him doing it and potentially endangering people, causing manufacturers to fix their planes very quickly, than a terrorist doing it and actually causing some serious damage.
One day, a malicious person could be the one that pulls the lever and kills hundreds of people. The company has been putting lives at risk for years - but only after receiving bad press regarding the insecure lever have they decided to invest in its security.
The end.
Looking at flight information, seeing nearby aircrafts, etc are not dangerous and they provide "proof of concept." Heck he could even turn on and off the navigation lights as proof that he can "control the aircraft" without directly endangering anyone.
I am sceptical like other people here that he actually altered the engine output from the entertainment system network. If he did then that would both be a gross lapse in basic aircraft security and he actually deserves some level of legal recourse for endangering other passenger's life, as well as thanks for exposing the vulnerability.
I liken it to hacking into a car and causing the acceleration pedal to stick on momentarily when you change radio stations. It would definitely alert people to the problem, but how many lives have been endangered to alert people? In particular if he made a mistake and instead of having it stick for 1 sec he did 10 sec? Is it right to put other people's lives in the hands of his experiments? They didn't sign up to be his guinea pigs.
This is the sort of testing that should be done on planes without passengers.
Thankfully, being evil is a fairly uncommon situation. But, as in the case of this hacker, being stupid apparently isn't.
You don't execute the thing that can hurt people to demonstrate that people can be hurt if that thing is executed.
Presuming (big presumption by the way) that he actually did break through the avionics firewall of an actual plane, and attempt to send commands to the flight-control system - then he deserves pretty much all the pain he's going to experience for the next 10-15 years.
But, on the flip side, if it turns out that he wasn't actually ever hacking with the flight systems of operating planes, then I wish him the best, and I hope he's able to convince people that all of this was hypothetical, a misunderstanding, and the only testing he's done has been with research systems, or test environments made available by various plane manufacturers.
We're now essentially arguing about which situation puts the passenger's lives at stake the most. Which is the most dangerous situation?
If we absolutely have to use an analogy we should make the train and the plane situations equal. In the case of the plane no one was hurt. Nobody even knew what had happened - not even the pilots. This might be analogous to a train "hacker" placing a washing machine on the tracks...and then removing the washing machine while the train is still at a safe distance.
There we go - the train "hacker" has shown that a washing machine can be placed on the tracks successfully and now the train companies can start to think of a solution. Maybe breaks. Or horns. Or those big cute scoops ;)
I think if you wanted to send the hacker to rot in jail (and keep your conscience) you'd have to prove that the hacker was very reckless and had no experience with avionics systems. Something tells me he knew how to run these systems though - at least enough to hack into them.
They were the kind of shoes that lit up when he put his feet down, and the guy had clearly not seen them before - he looked at the other screeners with this terrified look on his face. Thankfully one of them reassured him that it was safe quickly enough.
Never mind that I regularly forget water bottles and/or electronics in my carry on that they either never spot or can't be bothered to do anything about.
Several people have suggested that Roberts' goal is to raise awareness about airplane safety, so perhaps he actually wanted the article published like this even if inaccurate, though it still reflects poorly on the author.
But maybe they asked him point blank if he had ever pwned a real plane in flight. And he didn't didn't want to risk lying to an FBI agent. Tough call.
The real secret the security services are trying to hide is their complete ineffectiveness, total waste of money and hijacking for political and public manipulation.
I really don't believe any of this piddling feargeddon media manipulation nonsense - spies are jerks.
Reprinting propaganda does not count as journalism or news.