Live data from Hacker News

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

wired.com

81–90 of 277 posts

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#81
post #24

It seems insane that all this code isn't just open source by default. No one's going to be able to rip off airlines by stealing it, you still need to have a company that, you know, sells planes. Keeping it closed seems like a full admission that "there are probably a bunch of bugs in here and we don't want people to see them"

Because by keeping it closed, it is safer. /s Most executives care about profits, security is simply not important. Even if an engineer explains that he needs more time to properly secure something, he will be asked to cut corners. Then, when shit hits the fan the executive will make a "pikachu face" and engineer will get fired for not properly implementing security.

The real reason is that there’s realistically only downsides for the company. The public doesn’t know what “responsible vulnerability management program” means, but they certainly know what “major vulnerability found in Boeing code” means. So doing that will only mean they gain nothing, or take reputation hits.

Open sourcing the codebase doesn’t mean that all it’s vulnerabilities will be discovered, and it’s certainly not the only way for a company to manage them. Out of all the options that are available, it’s really one of the worst ones from the company’s perspective.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#82

I feel like this is the kind of thing that would've been completely ignored by everybody except for a handful of concerned hackers had it not been for the recent media outrage against Boeing (and in my opinion absolutely deserved). I guess the question is how bad is it (from the article it's hard to tell exactly, but it sure doesn't sound great)? And another question is how many of our systems that we rely on, from b…

>I have no idea how that company will ever earn back my trust

Millions of ongoing safe flights? I dunno. I feel like they're getting savaged (which they deserve... to a point... but we will cross that point I am pretty sure, if we haven't already...)

The thousands (tens of thousands?) of safe flights per day don't make the news. Boeing has been a pioneer in the safest form of transportation in existence. Mentour Pilot (an active 737 pilot on YouTube) goes into detail about why he's not concerned about Boeing (any more than he's concerned about Airbus).

I can also share a story from my (late) father who worked at Boeing from 30 years (and was working at Boeing during the MAX crashes). I asked him why Boeing let the 737-MAX debacle happen. These were a dying man's words (paraphrased): "Boeing wanted to ground the plane after the first 737-MAX crash but the FAA refused until after the second crash. Boeing did not have the authority to unilaterally ground the planes."

Take that for what it's worth.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#83
post #26

Earlier quoted context omitted.

Or to driving control! But, engineers keep making this mistake. Hackers were able to take over Jeeps via the entertainment system: https://www.bbc.com/news/technology-33650491 HN discussion: https://news.ycombinator.com/item?id=9942647

Take over as in turn off, not steer, right?

The article says “control” but doesn’t have a lot of specifics.

In any case, for bad dudes that are pursuing you when people aren’t around, being able to shut down your car is just as bad as being able to control it.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#84

I feel like this is the kind of thing that would've been completely ignored by everybody except for a handful of concerned hackers had it not been for the recent media outrage against Boeing (and in my opinion absolutely deserved). I guess the question is how bad is it (from the article it's hard to tell exactly, but it sure doesn't sound great)? And another question is how many of our systems that we rely on, from b…

And another question is how many of our systems that we rely on, from bridges to airplanes to traffic lights, are just actually very insecure

I'd guess virtually all of them.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#85
post #9

Earlier quoted context omitted.

Used to be done with a literal diode.

The funny thing is that LEDs (granted, not all types of diodes) can be used to read data as well as transmit it. Videos of such interfaces can be found on YouTube. So, they are not as one-way as some folks may think. https://youtu.be/aLP-OF4nesY

Well it can not only be a LED that is supposed to be one-way, but the whole circuitry driving it. Likewise for the receptor. With some appropriate review of the physical design, you can have a reasonable expectation that the comm will be limited to one-way, with no way for arbitrary SW to modify the direction.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#86
post #50

Earlier quoted context omitted.

i dont think i know of any airline company that prides themselves on the code they wrote?

I used to work for an airline as a software engineer (different from a company that makes airplanes, but you brought up airlines, so I think it's valid). We definitely attempted to write the best code as we could given the circumstances, but we had issues doing so: * airline margins are razor thin, so salaries are comparatively low, which means * the best employees frequently left for other opportunities, causing * m…

> * airline margins are razor thin, so salaries are comparatively low

Excluding executive pay, of course. Oh and excluding stock buybacks (which increases shareholder value, consequently greatly increasing the value of executive compensation).

https://www1.salary.com/AMERICAN-AIRLINES-GROUP-INC-Executiv...

https://www.sec.gov/Archives/edgar/data/4515/000000620118000...

Razor thin margins which result in $200 million (give or take) in quarterly profits are not exactly sad stories.

In summary, the non-executive employees are paid as little as possible to keep the company operating. And by operating, I mean that the bottom line/shareholder value is all that matters. Safety is really just a bottom line consideration. If an accident or two happens, and an eventual death payout is made, as long as the bottom line is not greatly affected, there will be no change in corporate behavior with respect to paying people properly and not cutting corners.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#87
post #67

Earlier quoted context omitted.

Maybe open-source software is today's standard, but I imagine it wasn't back when those airliners were first designed. Now, imagine they did open-source their code: I imagine those codebases are humongous and it would take months if not years for security issues to be found by the community. How do you make sure that a bad actor doesn't find a flaw before the community does and uses it? So open-sourcing sounds totall…

Bad actors (APT's especially) dont want it open sourced.

Said bad actors probably already have access to the source — or could get it if they wanted it.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#88
post #83

Earlier quoted context omitted.

Take over as in turn off, not steer, right?

The article says “control” but doesn’t have a lot of specifics. In any case, for bad dudes that are pursuing you when people aren’t around, being able to shut down your car is just as bad as being able to control it.

Considering that cars are becoming more drive-by-wire, it's only a matter of time before a hacker will be able to actually steer a car or activate (or prevent activation of!) the brakes.

Re: A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

#89
post #53

Earlier quoted context omitted.

So they would all contribute, which would lower costs?

Personally, I would not want a tech monoculture for passenger jets. A single issue grounding all flights (or worse) wouldn't be good.

OTOH, passenger jets would then all have better tested, higher -quality code.
Post reply on HN