Live data from Hacker News

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

wired.com

21–30 of 277 posts

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#21

It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"

It's kind of the same reasoning why voting machines are closed source and can only be audited by authorized personnel.

So people can steal elections in peace?

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#22
post #15

I would assume in-flight entertainment is Level E and wasn't ever subjected to verification. And yeah that requires physical separation from higher-level systems. So... surprisingly I think I'm on Boeing's side here?

The subsystem that connects in-flight entertainment to anything on the flight deck (assuming an intended one-way, read-only connection) would probably be Level D. I would guess that that subsystem is in error here.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#23
> But Boeing counters that it has both "additional protection mechanisms" in the CIS/MS that would prevent its bugs from being exploited from the ODN, and another hardware device between the semi-sensitive IDN—where the CIS/MS is located—and the highly sensitive CDN. That second barrier, the company argues, allows only data to pass from one part of the network to the other, rather than the executable commands that would be necessary to affect the plane's critical systems.

Well geez, it's a good thing that there's no class of bugs in which a certain amount of data, maybe more than the receiver was expecting, or terminated in an odd way, overwhelms the receiver in such a way as to cause the data to then be interpreted as commands which are run in place of the receiver's code...

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#24

It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"

Because by keeping it closed, it is safer. /s

Most executives care about profits, security is simply not important. Even if an engineer explains that he needs more time to properly secure something, he will be asked to cut corners. Then, when shit hits the fan the executive will make a "pikachu face" and engineer will get fired for not properly implementing security.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#25
post #14

...an FAA spokesperson wrote in a statement to WIRED that it's "satisfied with the manufacturer’s assessment of the issue." Can't help but read this as: "We don't have a clue and depend on the manufacturer to tell us everything is 5 by 5."

The FAA was satisfied with Boeing's design for the 737MAX. Sorry, but I now have zero trust in the FAA.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#26
post #2

Who thought that having any communication path from the passenger entertainment system to flight control was a good idea?

Or to driving control! But, engineers keep making this mistake. Hackers were able to take over Jeeps via the entertainment system:

https://www.bbc.com/news/technology-33650491

HN discussion: https://news.ycombinator.com/item?id=9942647

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#27

It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"

Maybe open-source software is today's standard, but I imagine it wasn't back when those airliners were first designed.

Now, imagine they did open-source their code: I imagine those codebases are humongous and it would take months if not years for security issues to be found by the community. How do you make sure that a bad actor doesn't find a flaw before the community does and uses it?

So open-sourcing sounds totally unrealistic to me.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#28

If I owned a 787, would I be likely to have the rights to lend it to security researchers to test the exploits, or would it be prohibited through a contract that Boeing requires customers to agree to? Is there a reason that an individual would own a 787 for personal use— eg - is it a plane that people change the interior layout for use as a private jet, or are these planes all tied up in commercial use? If I owned on…

I'd love to see the software licensing agreement that comes w/ an airliner. I can only imagine it contains the same kind of anti-reverse-engineering clauses that accompany virtually all commercial software.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#29

It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"

There is more than 1 company that sells planes and writes plane software.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#30

It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"

It's kind of the same reasoning why voting machines are closed source and can only be audited by authorized personnel.

What is that reasoning?
Post reply on HN