Live data from Hacker News

Boeing 787 In Flight Entertainment System Security fun

btr.pm

81–90 of 147 posts

Re: Boeing 787 In Flight Entertainment System Security fun

#81

I wish people wouldn't do shit like this on live systems like this one. Even the port scan could have had bad consequences (especially since this person did -A). By all means explore the interesting JSON object that was downloaded and yeah I'd worry about installing random stuff on my machine. I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of pe…

Maybe he did it as the plane was coming in to land? When else do you think he might have access to such a system?

Re: Boeing 787 In Flight Entertainment System Security fun

#82

There's a lot of posts mentioning that a scan shouldn't cause any trouble, however there's no way of knowing how the services are configured on the other end, or how they are set up to respond to certain packet types, or how the server will respond to certain data within those packets if said data does not conform to expected lengths etc. A lot of assumptions are made that non-conforming data will be ignored in a clo…

I remember about 20 years ago, you could crash any Windows computer you had the IP address of by sending a particularly crafted package to a certain port. Oh, those were the days.

Re: Boeing 787 In Flight Entertainment System Security fun

#83
post #79

Earlier quoted context omitted.

> definitely shouldn't affect the avionics No, and the flaw you're busy exploiting also definitely shouldn't be there. (Yes, the IFE is probably airgapped. Probably.)

Since when are web servers DO-178 certified?

Wild guess: Roughly about the time they began being used in IFE systems?

Re: Boeing 787 In Flight Entertainment System Security fun

#84
post #56
post #42

Earlier quoted context omitted.

If anything were to happen, it definitely shouldn't affect the avionics, not even remotely, or the plane would not have had a chance of certification. Data to the less secure IFE had better flow through a unidirectional network ("data diode"), and/or use a separate set of sensors. Even if it brought down the server, it's still nothing that the flight attendants can't solve by "turning it off and back on". This kind o…

I agree that, in theory, at least the avionics shouldn't be accessible from the IFE. I am sure there is a rigorous protocol for making sure this is properly secured and certification for airworthiness. I think the parent comment was more making the point that we don't need a flight full of people scanning ports for fun and profit, and the consequences of doing so are unknown and could lead to things like no wifi or I…

This is obscurantism. Port-scanning a networked system, even aggressively, must be considered typical environmental hazards that any network-attached system must be able to weather (preferably with no degradation in service).

Re: Boeing 787 In Flight Entertainment System Security fun

#85
post #2

> I did a port scan on the System Control Unit Is that still white hat? Did they also check to see if the cockpit door is locked?

Is that still white hat?

I think if you are not specifically asked to do it, it isn't white hat, and I think (but am not 100% sure) the law is like that. I don't know what hat it is, but white it isn't.

Re: Boeing 787 In Flight Entertainment System Security fun

#86

Reading through the post it didn't seem like he found any security issues. Their map has javascript variables which isn't a security issue. It doesn't seem like SCU had many open ports. It was running a relatively new version of Linux.

Didn't find anything of interest at all + did a foolish, possibly illegal thing.

Why is this blog post being upvoted?

Re: Boeing 787 In Flight Entertainment System Security fun

#87

Beside a scan is good or bad, how would they go about finding the source? There wont be an IT officr at landing collecting logs/mac address from any wireless card. I've scanned those systems many times and nothing ever happened - i am just pointing out to the issue that catching a real attacker it is hard not just technically but in practice

[deleted]

Re: Boeing 787 In Flight Entertainment System Security fun

#88
post #77
post #54

Earlier quoted context omitted.

Accidents happen. Commenter below referenced Swiss Air 111: https://en.m.wikipedia.org/wiki/Swissair_Flight_111 They cite inadequate safety standards and an overheating entertainment system. It's easy to assume that government or the airlines wouldn't allow a faulty system to fly, but just like software it's those extreme edge cases that cause problems. Somehow I doubt hacking the entertainment system is comprehensiv…

This keeps getting cited on this thread. The IFE didn't simply "overheat". It had faulty wiring . The coffee maker could just as easily have caused that accident.

Lots of things have faulty wiring, but they keep working as long as their power draw is under some limit. Drawing excess power is a common result of software going into an infinite loop, which is a possible outcome of security probes.

Half the bugs I notice in Chrome, I notice because my laptop fan starts running.

Re: Boeing 787 In Flight Entertainment System Security fun

#89

I wish people wouldn't do shit like this on live systems like this one. Even the port scan could have had bad consequences (especially since this person did -A). By all means explore the interesting JSON object that was downloaded and yeah I'd worry about installing random stuff on my machine. I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of pe…

Out of curiosity, when else would you suggest they do this? Other than "not at all", of course, which is not going to happen.

Re: Boeing 787 In Flight Entertainment System Security fun

#90
post #29

I wish people wouldn't do shit like this on live systems like this one. Even the port scan could have had bad consequences (especially since this person did -A). By all means explore the interesting JSON object that was downloaded and yeah I'd worry about installing random stuff on my machine. I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of pe…

Thank you for this comment. I for one would be pretty pissed if a "hacker" decided to crash my/or my kids entertainment on a long flight. There is definitely a need for this type of work, but doing so in a 50,000 lb brick floating a few miles above the ground isn't an atmosphere I am comfortable with, especially if I am present...

500k lb, at the very least :)
Post reply on HN