Live data from Hacker News

Airbus hit by series of cyber attacks on suppliers

france24.com

161–170 of 209 posts

Re: Airbus hit by series of cyber attacks on suppliers

#161
post #145

Earlier quoted context omitted.

Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?

I'm pretty sure ISO 9001 companies are audited every 4 years at their own expense. Basically an auditor comes and quizzes you on your own processes. You must show that you have processes which meet ISO criteria, and that you religiously follow those processes. Basically you have a lot of freedom to develop your business, just be sure you adhere to whatever you put into writing.

Back in the day of Total Quality Management and ISO9002 the software company I worked for decided to get itself certified. Problem was, nobody had a clue how to quickly describe the business of creating software as a set of processes, let alone apply them in measurable ways under the beady gaze of an auditor. So with evil inspiration it was decreed that the software division had no processes at all. The customers could rest assured that the Accounts and Marketing departments were fully ISO9002 compliant - as for the actual product they were buying? spun out of desperate sweat and divine revelations so far as they could tell.

But this didn't entirely get the software division off the hook. We still had to be able to show an auditor that we knew our processes were excluded. So there was a special folder containing just one functional page besides the meta-bumf to support it, and it read (in effect) "THE ACTIVITIES OF THE SOFTWARE DEPT ARE EXCLUDED FROM ISO9002 PROCESSES". And we were all trained to be able to produce it upon demand.

We passed the audit. Our letterhead paper gained the magical ISO9002 seal of approval. The administrator who had championed the long and expensive business sprung from its success to a much larger company. In her absence the process documentation for the rest of the company quietly withered and when the follow-up audit came due we quietly neglected to apply for it. The letterhead paper was reprinted with a snazzier logo and no seal of approval. We got back to work, quietly apprehending the next big thing.

Re: Airbus hit by series of cyber attacks on suppliers

#162
Without wanting to dive into the politics cesspool, In general I'd favour sharing IPR on RAND terms, rather than locking it up as special secret sauce. I think if Comac is struggling to learn how to make safe aircraft, then helping them is "build a better world" more than fighting them at the firewall.

Re: Airbus hit by series of cyber attacks on suppliers

#163
post #155
post #14

Earlier quoted context omitted.

It took my vouch to un-dead your comment, useful because I couldn't reply to it otherwise. I'm morbidly fascinated as to how the top two comments on this submission were marked dead in the first place, but considering it took a vouch to automatically bring it back to life, there's a hint of a Flag brigade on this thread. To answer your comment: because the title of the submission "Airbus Suppliers Hit in State-Sponso…

Please don't post insinuations of astroturfing or similar manipulation ("Flag brigade") without evidence. If you're concerned about abuse, please follow the site guidelines and email hn@ycombinator.com so we can look into it. https://news.ycombinator.com/newsguidelines.html

Hm, I didn't bucket flag-brigading into the astroturfing bucket (specifically because they're quite different - one suppresses speech whereas the other purports to be grassroots speech). Your point is well taken, but going forward dang, there's value in adding the "or similar manipulation" qualifier to the current iteration of guidelines:

> Please don't make insinuations about astroturfing. It degrades discussion and is usually mistaken. If you're worried, email us and we'll look at the data.

Hopefully this comment is viewed as both the acknowledgement as well as the constructive feedback it's intended to be.

Re: Airbus hit by series of cyber attacks on suppliers

#164
post #152

Earlier quoted context omitted.

HN / Reddit votes are very easy to manipulate with State-backed funding. Best to ignore the "consensus" on online boards and make one's own decision based on available evidence.

Please don't post insinuations about astroturfing without evidence. It poisons the well, and the overwhelming majority of such comments are based on imagination only. https://news.ycombinator.com/newsguidelines.html https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

[deleted]

Re: Airbus hit by series of cyber attacks on suppliers

#165

A question I've always wondered, and relevant here. If this is inter-company (and probably intra-company) communication, why don't these companies manually exchange one-time pads and use them? It's surely not hard for a courier to carry literally terabytes of OTP, and report if it was taken off them at any point. I was thinking of tape or HD, but now you an have the courier carry a terabyte of OTP in a few USB sticks…

Let's say you do that:

1. Send giant HD of OTP bits to other office.

2. Everyone at that office who needs to communicate, so you make those bits accessible on the internal network so various machines can get to it.

3. Now a hacker that accesses the network can get to your OTP bits.

At that point, you're no better than using some other security mechanism.

Re: Airbus hit by series of cyber attacks on suppliers

#166
post #152

Earlier quoted context omitted.

HN / Reddit votes are very easy to manipulate with State-backed funding. Best to ignore the "consensus" on online boards and make one's own decision based on available evidence.

Please don't post insinuations about astroturfing without evidence. It poisons the well, and the overwhelming majority of such comments are based on imagination only. https://news.ycombinator.com/newsguidelines.html https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

Honest guestion: I understand that unfounded allegations of astroturfing are not helpful. But does HN have systems in place to avoid malicious manipulation like this?

Re: Airbus hit by series of cyber attacks on suppliers

#167
post #145

> "Globally recognized standards, such as ISO 27001, 27701 and 9001, can definitely ensure a baseline of security, privacy and quality assurance amid suppliers. One should, however, bear in mind that they are no silver bullet and some additional monitoring of suppliers handling critical business data is a requisite.” This is misleading. ISO standards dictate that a company should have certain processes in place. Like…

Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?

ISO27001 (the main security one) has annual reviews which are more lightweight. After two years, the three-year cycle restarts.

Re: Airbus hit by series of cyber attacks on suppliers

#168

Other comments here incorrectly pointing out that Boeing and Airbus don't manufacture in China - they do. And why wouldn't they, it's obviously much cheaper to manufacture there given material and labor costs. Obviously they don't manufacture highly sensitive military aircraft in China, but commercial aircraft, sure why not. What they don't do is the design, testing, and certification in China. This is the real IP -…

This video from Wendover Productions discusses specifically that they setup "finishing" centers in China for the planes they are selling into China: https://www.youtube.com/watch?v=XjbYloKJX7c

Re: Airbus hit by series of cyber attacks on suppliers

#169

Earlier quoted context omitted.

I'm pretty sure ISO 9001 companies are audited every 4 years at their own expense. Basically an auditor comes and quizzes you on your own processes. You must show that you have processes which meet ISO criteria, and that you religiously follow those processes. Basically you have a lot of freedom to develop your business, just be sure you adhere to whatever you put into writing.

Back in the day of Total Quality Management and ISO9002 the software company I worked for decided to get itself certified. Problem was, nobody had a clue how to quickly describe the business of creating software as a set of processes, let alone apply them in measurable ways under the beady gaze of an auditor. So with evil inspiration it was decreed that the software division had no processes at all. The customers cou…

That is a great story!

I've seen companies pack trunks of cars with unclaimed scrap. Buy a 55' trailer with cash, fill it with stuff, then claim it belongs to the neighbors. Load material onto 30' racks and send the forklift operators home.

It's almost better that your company committed to ISO to kinda get organized and then let it slide afterwards. I'd almost say it's worth it in a medium sized company every 10 years just to stay accountable and organized.

Re: Airbus hit by series of cyber attacks on suppliers

#170
post #50

Earlier quoted context omitted.

Perhaps, but the article itself says that Comac is having problems certifying its (first) commercial airliner. And part of what was targeted was Airbus data relating to certification. I add (first) because I've read about the C919 elsewhere.

Boeing is having problems with its new planes... Designing and building airliners from scratch is not easy but China will get there because it's of strategic importance, and then the current duopoly will be broken.

But Boeing's problem isn't an innovation problem. Boeing's problem is ceding engineering decisions to marketing wanks and MBA bros.
Post reply on HN