Live data from Hacker News

Airbus hit by series of cyber attacks on suppliers

france24.com

181–190 of 209 posts

Re: Airbus hit by series of cyber attacks on suppliers

#181

Earlier quoted context omitted.

What if the other guy is also innovating? What about what they plan to do next? Let's be honest here. Everyone has an incentive to gain insight into what everyone else is doing. Everyone is spying on everyone else.

So do you think DEC was spying on Intel during the Alpha days? Whatever they could’ve learned wouldn’t be worth the effort.

Everyone tries to get the other guy's secrets.

I don't know a company that doesn't. How far would they go? That depends. Sometimes governments help...

Re: Airbus hit by series of cyber attacks on suppliers

#182

Earlier quoted context omitted.

...what does Chinese gain from these attacks then? International infamy?

This isn't denial of service attack, this is unauthorized access to steal technical data.

I wouldn't call it cyberattack then; rather it should be cyberespionage

Re: Airbus hit by series of cyber attacks on suppliers

#184

Other comments here incorrectly pointing out that Boeing and Airbus don't manufacture in China - they do. And why wouldn't they, it's obviously much cheaper to manufacture there given material and labor costs. Obviously they don't manufacture highly sensitive military aircraft in China, but commercial aircraft, sure why not. What they don't do is the design, testing, and certification in China. This is the real IP -…

Article about Chinese government stealing Airbus property and here we go derailing it towards Boeing.

Re: Airbus hit by series of cyber attacks on suppliers

#185

Other comments here incorrectly pointing out that Boeing and Airbus don't manufacture in China - they do. And why wouldn't they, it's obviously much cheaper to manufacture there given material and labor costs. Obviously they don't manufacture highly sensitive military aircraft in China, but commercial aircraft, sure why not. What they don't do is the design, testing, and certification in China. This is the real IP -…

> The funny thing in all this is that passengers inherently trust the FAA Not anymore.

Anecdata: Not true. Most people aren't even aware of recent events.

My circle of friends is a pretty wide net and only one coworker knows about the Boeing nonsense, and he admitted it was because of Hacker News.

Re: Airbus hit by series of cyber attacks on suppliers

#187
post #50

Earlier quoted context omitted.

Airbus manufactures in China. They have a large factory in Tianjin [1]. China is on course to have its own commercial airliner soon [2] [1] https://www.airbus.com/newsroom/news/en/2018/09/airbus--chin... [2] https://en.wikipedia.org/wiki/Comac_C919

Perhaps, but the article itself says that Comac is having problems certifying its (first) commercial airliner. And part of what was targeted was Airbus data relating to certification. I add (first) because I've read about the C919 elsewhere.

And I did my first job programming some groce frontends for them to use the inhouse-pipeline of a major Airbus subcontractor, which they rebuil(t/d).

The subcontractor did this entirely willingly and I don't blame them, given that Airbus treated them like sh*. Sure they were not the absolute cutting edge business, but they do a solid job and have a strong engineering background (from the times of MBB, DASA & Co. - their IT in the eng department was horrible). And yet when negotiating a contract for a new test (volume of the contract similar to price of the very specialized equipment necessary), Airbus haggled and put taking it inhouse on the table (they could certainly do that, but as the history of german industry shows, this is just an intimidation tactic for mooore profit).

So the management started to sell to COMAC (basically acting as an intermediary for another not as well-connected german supplier, which also likes to sell to China but can't get around export regulations...), which is basically a sell out, but apparently we want it that way given the protection politics give those predatory bit companies around here (never hear anyone calling Airbus for fair treatment of their supply chain)

Re: Airbus hit by series of cyber attacks on suppliers

#188

A question I've always wondered, and relevant here. If this is inter-company (and probably intra-company) communication, why don't these companies manually exchange one-time pads and use them? It's surely not hard for a courier to carry literally terabytes of OTP, and report if it was taken off them at any point. I was thinking of tape or HD, but now you an have the courier carry a terabyte of OTP in a few USB sticks…

Let's say you do that: 1. Send giant HD of OTP bits to other office. 2. Everyone at that office who needs to communicate, so you make those bits accessible on the internal network so various machines can get to it. 3. Now a hacker that accesses the network can get to your OTP bits. At that point, you're no better than using some other security mechanism.

Oh FFS. I was expecting some silly answer involving couriers being intercepted but this is just as bad.

> 3. Now a hacker that accesses the network can get to your OTP bits.

Which is on an internal network so is not exposed (unlike the contents of a VPN which necessarily goes external) so can be more secure. While nothing's unhackable it adds an extra layer to break through.

That the article says "It was very sophisticated and targeted the VPN which connected the company to Airbus" shows the VPN was the weak link, and not the internal networks. So harden the weakest link.

Re: Airbus hit by series of cyber attacks on suppliers

#189

Earlier quoted context omitted.

> The funny thing in all this is that passengers inherently trust the FAA Not anymore.

Anecdata: Not true. Most people aren't even aware of recent events. My circle of friends is a pretty wide net and only one coworker knows about the Boeing nonsense, and he admitted it was because of Hacker News.

Surely people have noticed the thousands of cancelled flights?

Re: Airbus hit by series of cyber attacks on suppliers

#190

Earlier quoted context omitted.

Anecdata: Not true. Most people aren't even aware of recent events. My circle of friends is a pretty wide net and only one coworker knows about the Boeing nonsense, and he admitted it was because of Hacker News.

Surely people have noticed the thousands of cancelled flights?

If you've already missed it in the news, you're certainly only going to notice your own cancelled flight.
Post reply on HN