Man’s Claims of Hacking Plane Discredited by Law Enforcement
bloomberg.com
bloomberg.com
Can someone explain this? I've been asking knowledgeable people all day and haven't heard a good explanation of how this could be possible. Is the IFE system really on the same physical network as the flight control system on newer planes?
Edit: the best commentary on this appears to be the comments section on this Schneier blog post from a few weeks back - https://www.schneier.com/blog/archives/2015/04/hacking_airpl...
And here's an interesting puzzle: if these planes are sharing a SATCOM link between their IFE and control systems, is it even possible for it to be non-software-hackable?
I have no direct knowledge here, but I've heard from multiple sources that whereas past aircraft had air gaps between aeronautic and IFE systems, newer aircraft rely on a firewall to block traffic from the IFE side to the aeronautic side.
I find ARINC-429 to be quite elegant/pleasing as an engineer and impressive for the time of its creation.
Either the guy is/was delusional and his 15 min of fame (like mentioned below) blew up in his face, or the systems are vulnerable and it's being downplayed (while hopefully it's being fixed).
At this point though, it's difficult to trust FBI and a corporation that has a lot to loose...
I think Boeing needs to bring in independent researchers and let them loose on some planes on the ground, either proving or disproving this whole debacle...
Note that they didn't actually deny it completely. To me, this says they either don't want to say "it's impossible" for fear of liability, or that they know there are some holes and don't want to talk about it.
Also, comparing what the two companies said is interesting: I prefer Boeing's rather direct "they are isolated" response and find it far more reassuring in comparison to Airbus' wordy and vague statement.
The block diagram shows the flight management system as an output only. The NED gateway seems to be treated as an untrusted device. The flight management system (which can be thought of as turn-by-turn navigation for airplanes) does not directly fly the airplane, but the autopilot, and the human pilot, usually go where it sends them.
The NED does have the ability to update the "electronic flight bag", which contains navigational charts, aircraft manuals, and FAA and company paperwork. Those are updated frequently, so there's now a data distribution system to update them. (They used to be loose-leaf binders with frequent update packages.) But those have no connection to the flight controls.
A bigger concern is that software updates to the aircraft systems pass through the NED. Those can now be transmitted by radio to some aircraft.[3] The new files are stored on a server for updating when the aircraft is parked and the equipment is in a maintenance mode.
So, while taking over the flight controls in flight seems unlikely, some variant on a Stuxnet-type attack might be possible.
[1] http://www.teledynecontrols.com/productsolution/ned/overview... [2] http://www.teledynecontrols.com/productsolution/ned/blockdia... [3] https://web.archive.org/web/20140923154447/http://www.teledy...
Well, that sucks. Messing around with the equipment on a plane like that is really a very bad idea. I don't care how 1337 you are.
Not sure I believe him (or them) (or anyone yet). But it is worth bearing in mind.
Have the media present and have Boeing and Airbus make a plane available and let him do his thing (while it is on the ground and empty).
FBI of course has to agree to give him immunity.
All parties should have nothing to fear if they are truly interested in protecting the public.
I'd be surprised if there's a flight attendant whose duty it is to hit a button at a critical time in flight to make that happen.
Or are they anything more than second-hand hearsay cited by the FBI in a warrant application?
It sounds to me that they trumped up some portion of his interview in the complaint, and are going out of their way to discredit this guy. My fear is that if Mr. Roberts is right, this will have a real chilling effect on other work in the area. If he's just a security troll, it still negatively impacts everyone.
https://www.youtube.com/watch?v=H0F2J_Xh6MA
He doesn't come out and say that he tampered with the controls, but he clearly states that he broke through firewalls and such (Is the unpatched Tomcat instance part of the controls or not?).
This article has a transcript of the stuff he says about the plane:
http://arstechnica.com/security/2015/05/alleged-plane-hacker...
When this whole story first came out, he never said he 'hacked the plane'. He created a simulated network based on public plane documents.
The only thing he did was gain access to the infotainment network through a default username/password.