Live data from Hacker News

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

wired.com

41–50 of 277 posts

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#41
post #33
post #5

Earlier quoted context omitted.

Connecting entertainment systems to flight control sounds very wrong. Connecting entertainment systems to flight management would be common; it should be one-way communication (entertainment can only read FMS data, not send any), for the purpose of driving the moving map displays for passengers.

The moving map could easily be fed from a separated consumer grade GPS. Same for all other metrics that the median passenger would care about (height, speed over ground), except for the ever-impressive outside temperature.

Outside temperature is pretty impressive indeed. The map also shows projected flight plan and ETA, which would not come purely from GPS.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#43
post #37

> But Boeing counters that it has both "additional protection mechanisms" in the CIS/MS that would prevent its bugs from being exploited from the ODN, and another hardware device between the semi-sensitive IDN—where the CIS/MS is located—and the highly sensitive CDN. That second barrier, the company argues, allows only data to pass from one part of the network to the other, rather than the executable commands that wo…

So you're saying.... rewrite it in Rust?

Or, Ada, no? :)

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#45

Earlier quoted context omitted.

There is more than 1 company that sells planes and writes plane software.

So they would all contribute, which would lower costs?

They'd lose the ability to differentiate themselves (only on this specific criteria, but definitely affects overall competitiveness), thus having to compete more on price, which is great for customers but bad for companies.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#46

From the article: "He was surprised to discover a fully unprotected server on Boeing's network, seemingly full of code designed to run on the company's giant 737 and 787 passenger jets, left publicly accessible and open to anyone who found it. So he downloaded everything he could see." Is that even legal? Will he ever be allowed to cross the US border after admitting this?

I'm surprised that IOActive backed him up on this, seems like it's treading a line that businesses normally are very conservative around. I very much expected him to be unaffiliated with a large organization after reading that.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#49
post #44

I'm slightly astonished that the 3 networks mentioned aren't airgapped. I suppose the entertainment system needs to know where the plane is in order to display the flight map, but that should be provided by a dumb serial link with the RX wire cut.

Heck, just a simple standalone GPS receiver would be perfectly adequate. Doesn't need to be particularly fancy, either, because if it fails nothing bad happens but a non-functional map.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#50

Earlier quoted context omitted.

So they would all contribute, which would lower costs?

They'd lose the ability to differentiate themselves (only on this specific criteria, but definitely affects overall competitiveness), thus having to compete more on price, which is great for customers but bad for companies.

i dont think i know of any airline company that prides themselves on the code they wrote?
Post reply on HN