Live data from Hacker News

Airbus hit by series of cyber attacks on suppliers

france24.com

141–150 of 209 posts

Re: Airbus hit by series of cyber attacks on suppliers

#141

Interesting how Boeing and Airbus don't manufacture in China, and coincidentally China hasn't been able to produce any viable competitor to those products. Goes to show that without easy access to product blueprints/IP at the factories, China is very slow to actually innovate on their own. Hence why I feel the "China will outpace everyone in tech and take over the world" is super overblown. Even their university cult…

Airbus manufactures in China. They have a large factory in Tianjin [1]. China is on course to have its own commercial airliner soon [2] [1] https://www.airbus.com/newsroom/news/en/2018/09/airbus--chin... [2] https://en.wikipedia.org/wiki/Comac_C919

Also AFAIK: (1) There is a mandatory pilot Airbus training facility in Zhongshan, I believe for China Southern. (2) There is a Rolls Royce engine repair facility in Zhuhai. (3) Cirrus was bought by China and are establishing production in Zhuhai.

... and that's just airline related tech stuff I have passively become aware of within 50km of my office in the last 12 months.

Re: Airbus hit by series of cyber attacks on suppliers

#142
post #89

The way I figure, if a sophisticated attack is so sophisticated that it can only be state-sponsored, then it is sophisticated enough to appear to be sponsored by another country.

Your problem here is ability and motive. What other countries are capable of executing this attack and would want to steal this information? As far as I know Comac is the only company that is attempting to build planes that rival Boeing and Airbus for commercial flight so you have your motive. The Chinese have a history of corporate espionage (lookup Huawei and Nortel) and given that Comac is a state owned company you can clearly understand why they would try to steal information.

If you're trying to frame someone, there has to be a plausible explanation for why you would do it.

Re: Airbus hit by series of cyber attacks on suppliers

#143
post #127

Original report: https://www.france24.com/en/20190926-airbus-hit-by-series-of... Link to the actual source, please. This is a rehash (abhorrent blog spam) of a proper news report.

Thanks! Url changed from https://www.infosecurity-magazine.com/news/airbus-suppliers-....

Re: Airbus hit by series of cyber attacks on suppliers

#144
> "Globally recognized standards, such as ISO 27001, 27701 and 9001, can definitely ensure a baseline of security, privacy and quality assurance amid suppliers. One should, however, bear in mind that they are no silver bullet and some additional monitoring of suppliers handling critical business data is a requisite.”

This is misleading.

ISO standards dictate that a company should have certain processes in place. Like quality assurance, customer satisfaction, continuous improvement, ect. They do not specify individual processes or procedures to the company. They just lay out which structures should exist in an ISO compliant company. It is up to the company to develop processes and procedures that fulfill those structures.

The specific standards that are a "silver bullet" (as the author puts it) are NIST 800-171 "DFARS", ITAR, AS9100, NADCAP, and other smaller (yet equally significant) manufacturer-specific specifications that get flowed down the supply-chain on an as-needed basis.

So there is no ambiguity. If a supplier does business with a diverse enough client base in aerospace they will almost certainly have overlapping systems in place to protect against these things. Without pretty much all of the specifications I listed above, a supplier would not legally limited in what they are allowed to possess and produce.

Re: Airbus hit by series of cyber attacks on suppliers

#145

> "Globally recognized standards, such as ISO 27001, 27701 and 9001, can definitely ensure a baseline of security, privacy and quality assurance amid suppliers. One should, however, bear in mind that they are no silver bullet and some additional monitoring of suppliers handling critical business data is a requisite.” This is misleading. ISO standards dictate that a company should have certain processes in place. Like…

Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?

Re: Airbus hit by series of cyber attacks on suppliers

#146

I used to complain so bitterly that the computers I had for AI research work, despite being a flavor of Linux, had no access to any sort of networking, making the installation of basic packages a pain. It turns out the safest way, barring spies who willingly steal, is provide no entry/exit points for data. For smaller organizations or small divisions that's feasible, but super hard to maintain at larger divisions.

That's one way to get security... not a very practical one though.

Re: Airbus hit by series of cyber attacks on suppliers

#147
post #57

Earlier quoted context omitted.

I don't think China has to invade Europe, they're quite happy buying real estate, businesses and going on vacation there. Governments like Italy and others are happy to bow in front of the Chinese government in exchange for money. A military invasion would ruin the whole thing. The same holds for Russia, but to a lesser degree, because they're not as rich as China. An actual problem in Western European societies is m…

Immigration is not a problem, even in Europe. At current rates, it would take several generations for immigrants to make up half of the population. But at that point, the immigrants' children and grand-children will have assimilated. Just like how immigrants to the USA lost their native language and customs, so too will this generation. Today, the only thing remaining from the influx of Italians, Irish, and Germans,…

[deleted]

Re: Airbus hit by series of cyber attacks on suppliers

#148
post #145

> "Globally recognized standards, such as ISO 27001, 27701 and 9001, can definitely ensure a baseline of security, privacy and quality assurance amid suppliers. One should, however, bear in mind that they are no silver bullet and some additional monitoring of suppliers handling critical business data is a requisite.” This is misleading. ISO standards dictate that a company should have certain processes in place. Like…

Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?

I'm pretty sure ISO 9001 companies are audited every 4 years at their own expense.

Basically an auditor comes and quizzes you on your own processes. You must show that you have processes which meet ISO criteria, and that you religiously follow those processes.

Basically you have a lot of freedom to develop your business, just be sure you adhere to whatever you put into writing.

Re: Airbus hit by series of cyber attacks on suppliers

#149

Interesting how Boeing and Airbus don't manufacture in China, and coincidentally China hasn't been able to produce any viable competitor to those products. Goes to show that without easy access to product blueprints/IP at the factories, China is very slow to actually innovate on their own. Hence why I feel the "China will outpace everyone in tech and take over the world" is super overblown. Even their university cult…

Please don't take HN threads into nationalistic flamewar. Those discussions are all the same, i.e. predictable, i.e. lacking in curiosity and therefore off topic here.

https://news.ycombinator.com/newsguidelines.html

Re: Airbus hit by series of cyber attacks on suppliers

#150

Interesting how Boeing and Airbus don't manufacture in China, and coincidentally China hasn't been able to produce any viable competitor to those products. Goes to show that without easy access to product blueprints/IP at the factories, China is very slow to actually innovate on their own. Hence why I feel the "China will outpace everyone in tech and take over the world" is super overblown. Even their university cult…

Wow, these are some seriously racist comments.

That comment was bad for taking the thread into nationalistic flamewar, but this comment is also bad for taking the thread further into flamewar.

Please don't do that. The site guidelines specifically ask you not to:

https://news.ycombinator.com/newsguidelines.html

Post reply on HN