Live data from Hacker News

Airbus hit by series of cyber attacks on suppliers

france24.com

171–180 of 209 posts

Re: Airbus hit by series of cyber attacks on suppliers

#171
post #142
post #89

The way I figure, if a sophisticated attack is so sophisticated that it can only be state-sponsored, then it is sophisticated enough to appear to be sponsored by another country.

Your problem here is ability and motive. What other countries are capable of executing this attack and would want to steal this information? As far as I know Comac is the only company that is attempting to build planes that rival Boeing and Airbus for commercial flight so you have your motive. The Chinese have a history of corporate espionage (lookup Huawei and Nortel) and given that Comac is a state owned company yo…

>Comac is the only company that is attempting to build planes that rival Boeing and Airbus

Boeing also competes with Airbus, as in actively competes in real dollar terms compared to Comac which is more or less aspirational. Given their current situation they have as much incentive to hack Airbus, plus they've been accused recently:

Airbus to sue NSA, German spies accused of swiping tech secrets

>European aerospace giant Airbus is promising legal action over claims its top blueprints were stolen by German spies and given to America's intelligence agencies.

https://www.theregister.co.uk/2015/04/30/airbus_us_german_in...

My view is that both Boeing and Comac is actively stealing from airbus because why wouldn't they?

Re: Airbus hit by series of cyber attacks on suppliers

#172
post #145

Earlier quoted context omitted.

Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?

I'm pretty sure ISO 9001 companies are audited every 4 years at their own expense. Basically an auditor comes and quizzes you on your own processes. You must show that you have processes which meet ISO criteria, and that you religiously follow those processes. Basically you have a lot of freedom to develop your business, just be sure you adhere to whatever you put into writing.

> I'm pretty sure ISO 9001 companies are audited every 4 years at their own expense

Eh, kind of? I currently work for one and they haven't been audited in over a decade. The history goes: once upon a time, they were seeking certification because $potential_buyer asked about it. They failed the first audit quite miserably, and the next. By the third time, they squeezed by and were certified. The auditors came back 2 times in the next 2 years to make sure they were still compliant, and by the third year the auditors just asked if their processes had changed (without bothering to scrutinize everything again). They had not, and the auditors have not reached out ever since. The company is still certified. I think in theory they've "checked" since then but no one at the company can recall them actually showing up/auditing.

Re: Airbus hit by series of cyber attacks on suppliers

#173
post #154

So, it used to be that saying anything remotely skeptical about Bitcoin was the way to get downvoted on HN. Nowadays, it seems that saying anything negative about China is how. Although, in the field of aeronautics, it is not like China is the only "state sponsor" to engage in espionage, or that this is anything new for any of the major powers.

It's not remotely close to true that negative comments about China are "the way to get downvoted on HN". On the contrary, HN's demographic, while quite international, is almost all Western, and for better or worse it follows geopolitical trends and the leads set by government and media. When we have to ask commenters not to take HN threads into nationalistic flamewar, it's usually because of generic nationalistic rhe…

I appreciate HN doing their best to keep discussion in a productive zone and out of flamewar territory. I enjoy HN a lot, which is very different from most sites that allow comments.

However, comparing my parent comment here to the average for most comments I make, or comparing it to comments related to Russia, France, Germany, or any other major nation-state, I have to say that the empirical evidence does not support your statement. :)

But, again, I appreciate HN discussions and the efforts to keep it a productive discussion.

Re: Airbus hit by series of cyber attacks on suppliers

#174

I used to complain so bitterly that the computers I had for AI research work, despite being a flavor of Linux, had no access to any sort of networking, making the installation of basic packages a pain. It turns out the safest way, barring spies who willingly steal, is provide no entry/exit points for data. For smaller organizations or small divisions that's feasible, but super hard to maintain at larger divisions.

Having seen what a competent Red team can do that is not much of a barrier if information its valuable enough

Re: Airbus hit by series of cyber attacks on suppliers

#175

Earlier quoted context omitted.

I'm pretty sure ISO 9001 companies are audited every 4 years at their own expense. Basically an auditor comes and quizzes you on your own processes. You must show that you have processes which meet ISO criteria, and that you religiously follow those processes. Basically you have a lot of freedom to develop your business, just be sure you adhere to whatever you put into writing.

Back in the day of Total Quality Management and ISO9002 the software company I worked for decided to get itself certified. Problem was, nobody had a clue how to quickly describe the business of creating software as a set of processes, let alone apply them in measurable ways under the beady gaze of an auditor. So with evil inspiration it was decreed that the software division had no processes at all. The customers cou…

It was all worth it for the line on her resume.

Re: Airbus hit by series of cyber attacks on suppliers

#176
post #142

Earlier quoted context omitted.

Your problem here is ability and motive. What other countries are capable of executing this attack and would want to steal this information? As far as I know Comac is the only company that is attempting to build planes that rival Boeing and Airbus for commercial flight so you have your motive. The Chinese have a history of corporate espionage (lookup Huawei and Nortel) and given that Comac is a state owned company yo…

>Comac is the only company that is attempting to build planes that rival Boeing and Airbus Boeing also competes with Airbus, as in actively competes in real dollar terms compared to Comac which is more or less aspirational. Given their current situation they have as much incentive to hack Airbus, plus they've been accused recently: Airbus to sue NSA, German spies accused of swiping tech secrets >European aerospace gi…

Yes, US/NSA/Boeing must at least be under suspicion in these circumstances.

As the Comac C919 approaches certification and full production, airlines, especially Chinese ones, will delay orders, to wait and see, or actively prefer the C919 over the 737 series. Even if the C919 is delayed with the usual teething troubles, many customers will decide to wait, or buy Airbus if they have to.

At this point, Boeing is the weakest of the three competitors in the mid-size market, and must be desperate to do anything to survive.

Re: Airbus hit by series of cyber attacks on suppliers

#177

Earlier quoted context omitted.

What if the other guy is also innovating? What about what they plan to do next? Let's be honest here. Everyone has an incentive to gain insight into what everyone else is doing. Everyone is spying on everyone else.

So do you think DEC was spying on Intel during the Alpha days? Whatever they could’ve learned wouldn’t be worth the effort.

I would hope that Ken Olson was more honest than that, although I guess you never know.

Re: Airbus hit by series of cyber attacks on suppliers

#178
post #142
post #89

The way I figure, if a sophisticated attack is so sophisticated that it can only be state-sponsored, then it is sophisticated enough to appear to be sponsored by another country.

Your problem here is ability and motive. What other countries are capable of executing this attack and would want to steal this information? As far as I know Comac is the only company that is attempting to build planes that rival Boeing and Airbus for commercial flight so you have your motive. The Chinese have a history of corporate espionage (lookup Huawei and Nortel) and given that Comac is a state owned company yo…

The US also has a long history of state-sponsored industrial espionage. https://en.wikipedia.org/wiki/ECHELON

Re: Airbus hit by series of cyber attacks on suppliers

#179
post #145

Earlier quoted context omitted.

Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?

Almost every certification is a recurring income generator for the certificating parties. Some are annual, others bi-annual or even longer periods between certifications but none that I am aware of are 'forever'.

That makes sense. My goal in life is to never work for a company where that type of thing would be considered seriously.

Re: Airbus hit by series of cyber attacks on suppliers

#180

Other comments here incorrectly pointing out that Boeing and Airbus don't manufacture in China - they do. And why wouldn't they, it's obviously much cheaper to manufacture there given material and labor costs. Obviously they don't manufacture highly sensitive military aircraft in China, but commercial aircraft, sure why not. What they don't do is the design, testing, and certification in China. This is the real IP -…

[deleted]
Post reply on HN