Live data from Hacker News

Software Vulnerabilities in the Boeing 787

schneier.com

11–20 of 48 posts

Re: Software Vulnerabilities in the Boeing 787

#11
post #4

It seems to me as someone with no experience of designing aircraft control software, avionics or anything to do with planes, that the entertainment system should be on a physically separate network to anything safety critical. Like, different everything: power supplies, switches, cables, control panels, the works. There should be no entryway into the flight control network except from the cockpit.

If Boeing decides to cut costs by using a single network for their entertainment, communications and flight control, who is there gonna be to tell them no? You would assume there is some oversight by independent security researchers who review these planes security, but this assumption seems unsubstantiated.

In reality, how is this separation of critical networks looking like exactly? MAC address filters? Are they air-gapped? I would venture to guess, nobody that isn't bound by an NDA knows.

Re: Software Vulnerabilities in the Boeing 787

#12
post #10

There is IMO exactly one valid way to get data from the flight systems to the entertainment network: use a literal one-way connection. Not “the only supported requests are data retrieval.” Not “the software folks only transmit.” A bona fide physical connection where one side has a transmitter, one side has a receiver, and there is no physical mechanism to send any information whatsoever the other way. These devices a…

Aren't data diodes already a regulatory requirement for any connection between avionics and the IFE?

Re: Software Vulnerabilities in the Boeing 787

#13
post #4

It seems to me as someone with no experience of designing aircraft control software, avionics or anything to do with planes, that the entertainment system should be on a physically separate network to anything safety critical. Like, different everything: power supplies, switches, cables, control panels, the works. There should be no entryway into the flight control network except from the cockpit.

If Boeing decides to cut costs by using a single network for their entertainment, communications and flight control, who is there gonna be to tell them no? You would assume there is some oversight by independent security researchers who review these planes security, but this assumption seems unsubstantiated. In reality, how is this separation of critical networks looking like exactly? MAC address filters? Are they ai…

Boeing actually attempted that on 787,with some VLAN trickery.

FAA caught it and forced them to redesign the setup.

As for actual AFDX networks - they have hardcoded forwarding tables and no MAC learning, and separation between networks tends to use data diodes

Re: Software Vulnerabilities in the Boeing 787

#15
Unlike the security researcher, I do have access to multiple 787s as I am one of many people responsible for maintaining them.

I'm obviously not going to attempt to exploit the firmware on an aircraft for obvious reasons, but the security researcher's notion that you can "pivot" from the in flight entertainment to anything to do with aircraft operation is pure fantasy.

These systems are entirely separate, including the electricity that controls the systems.

This guy is preying on individuals' lack of knowledge about aircraft mechanics in order to promote himself.

Re: Software Vulnerabilities in the Boeing 787

#16
post #10

There is IMO exactly one valid way to get data from the flight systems to the entertainment network: use a literal one-way connection. Not “the only supported requests are data retrieval.” Not “the software folks only transmit.” A bona fide physical connection where one side has a transmitter, one side has a receiver, and there is no physical mechanism to send any information whatsoever the other way. These devices a…

Aren't data diodes already a regulatory requirement for any connection between avionics and the IFE?

No clue, but Boeing’s weasel-worded statement sounds awfully like they’re trying to defend a software-only solution.

Re: Software Vulnerabilities in the Boeing 787

#17

Unlike the security researcher, I do have access to multiple 787s as I am one of many people responsible for maintaining them. I'm obviously not going to attempt to exploit the firmware on an aircraft for obvious reasons, but the security researcher's notion that you can "pivot" from the in flight entertainment to anything to do with aircraft operation is pure fantasy. These systems are entirely separate, including t…

Would you say as someone who deals with these larger planes that at least the 787 current gen is closer to an older style chassis and body for cars? I have always imagined/assumed that 787's are not unique that they would be the same 'chassis' for a cargo plane or a passenger plane, and it really would have to do with how they fitted the plane for purpose?

This is part of the reason why I agree with you, because I don't see why the 787 would be unique by mixing avionics/mechatronics with the passenger systems but I don't know enough to say it with confidence. They would have designed the passenger systems to be independent and replaceable (especially with the knowledge gained from the legacies and upgrades of other planes like the 737).

Is there any public guides for 787 chassis and maintenance that you could point to as being reasonable things to read about this new style plane?

Re: Software Vulnerabilities in the Boeing 787

#18
post #10

There is IMO exactly one valid way to get data from the flight systems to the entertainment network: use a literal one-way connection. Not “the only supported requests are data retrieval.” Not “the software folks only transmit.” A bona fide physical connection where one side has a transmitter, one side has a receiver, and there is no physical mechanism to send any information whatsoever the other way. These devices a…

[deleted]

Re: Software Vulnerabilities in the Boeing 787

#19

Unlike the security researcher, I do have access to multiple 787s as I am one of many people responsible for maintaining them. I'm obviously not going to attempt to exploit the firmware on an aircraft for obvious reasons, but the security researcher's notion that you can "pivot" from the in flight entertainment to anything to do with aircraft operation is pure fantasy. These systems are entirely separate, including t…

That's valuable to know -- thanks -- but nevertheless, demonstrating that if you can get onto the avionics network you can trivially compromise it is still valuable, no? There may be discovered other ways to access the avionics network (besides the IFE) that no one realized, or thought to protect.
Post reply on HN