It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"
It's kind of the same reasoning why voting machines are closed source and can only be audited by authorized personnel.
A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
21–30 of 277 posts
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#22I would assume in-flight entertainment is Level E and wasn't ever subjected to verification. And yeah that requires physical separation from higher-level systems. So... surprisingly I think I'm on Boeing's side here?
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#23Well geez, it's a good thing that there's no class of bugs in which a certain amount of data, maybe more than the receiver was expecting, or terminated in an odd way, overwhelms the receiver in such a way as to cause the data to then be interpreted as commands which are run in place of the receiver's code...
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#24It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"
Most executives care about profits, security is simply not important. Even if an engineer explains that he needs more time to properly secure something, he will be asked to cut corners. Then, when shit hits the fan the executive will make a "pikachu face" and engineer will get fired for not properly implementing security.
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#25...an FAA spokesperson wrote in a statement to WIRED that it's "satisfied with the manufacturer’s assessment of the issue." Can't help but read this as: "We don't have a clue and depend on the manufacturer to tell us everything is 5 by 5."
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#26Who thought that having any communication path from the passenger entertainment system to flight control was a good idea?
https://www.bbc.com/news/technology-33650491
HN discussion: https://news.ycombinator.com/item?id=9942647
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#27It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"
Now, imagine they did open-source their code: I imagine those codebases are humongous and it would take months if not years for security issues to be found by the community. How do you make sure that a bad actor doesn't find a flaw before the community does and uses it?
So open-sourcing sounds totally unrealistic to me.
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#28If I owned a 787, would I be likely to have the rights to lend it to security researchers to test the exploits, or would it be prohibited through a contract that Boeing requires customers to agree to? Is there a reason that an individual would own a 787 for personal use— eg - is it a plane that people change the interior layout for use as a private jet, or are these planes all tied up in commercial use? If I owned on…
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#29It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"
Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
#30It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"
It's kind of the same reasoning why voting machines are closed source and can only be audited by authorized personnel.