Earlier quoted context omitted.
The baggage questions is so stupid, IF you wanted to do some evil with things packed, WHY would you say something that isn't the "right" answer to them?
Because you might not be aware that you're being used. I can't find the reference right now, but that question started being asked after a man put an explosive in his wife's luggage (when she was flying without him, naturally)
United Airlines Stops Researcher Who Tweeted about Airplane Network Security
31–40 of 128 posts
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#32What an overreaction from the EFF. Use a bit of judgement and realize it isn't a smart idea to talk about hacking an airplane full of passengers.
The way we keep airplanes full of passengers from falling out of the sky is that we talk openly about the risks up front, so that the people who created those risks get fired or demoted, and their bosses (or, failing that, regulatory authorities) make sure the risks get fixed. It isn’t a smart idea to short-circuit that process; that’s how we ended up with things like the Ukrainian famine, the Great Leap Forward, Lys…
Sometimes the way we keep airplanes full of passengers from falling out of the sky, is by looking for, and engaging, potential bad actors. The way to determine if someone is a bad actor, is by looking for signals of such intent. And, I think all things equal, this guy probably was throwing off signals that he was a bad actor, even if it's obvious to anyone who knows him, that he's just being a jackass.
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#33Earlier quoted context omitted.
This person was an absolute clown. I think the infosec community needs to grow up. We all hate when legislators use the word 'cyber.' Title 18 is a mess. The new computer crime proposals are worse. Every couple of years we get the occasional story about licensing security professionals. It is because of exactly this type of clownish behavior. There are consequences for the attention seeking type of behavior. This idi…
> Stunt hacking scares the shit out of normal people. Eventually people will demand regulatory intervention. Good. Maybe they'll actually start caring about security instead of obscurity through law.
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#34What an overreaction from the EFF. Use a bit of judgement and realize it isn't a smart idea to talk about hacking an airplane full of passengers.
The way we keep airplanes full of passengers from falling out of the sky is that we talk openly about the risks up front, so that the people who created those risks get fired or demoted, and their bosses (or, failing that, regulatory authorities) make sure the risks get fixed. It isn’t a smart idea to short-circuit that process; that’s how we ended up with things like the Ukrainian famine, the Great Leap Forward, Lys…
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#35We live in shitty knee-jerk reactionary times, but did anyone else see his tweet at the time? At best, it seemed in poor taste. At worst, the outcome seems depressingly predictable. I don't know what I'm trying to contribute here, except that whilst I have no problem with EFF working on this, their article here seems overly shrill and over-reactionary at how shrill and over-reactionary the airline was in their respon…
This person was an absolute clown. I think the infosec community needs to grow up. We all hate when legislators use the word 'cyber.' Title 18 is a mess. The new computer crime proposals are worse. Every couple of years we get the occasional story about licensing security professionals. It is because of exactly this type of clownish behavior. There are consequences for the attention seeking type of behavior. This idi…
Vauge non-specific demands of a loose and fluid group with little to no control over it's members set the group up for inevitable failure.
Without critical thought, it appears to be a reasonable request. Which is why the people who never want to listen to The Cavalry or EFF say it, and why the rest of us propagate the idea. But it's a trap.
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#36What an overreaction from the EFF. Use a bit of judgement and realize it isn't a smart idea to talk about hacking an airplane full of passengers.
The way we keep airplanes full of passengers from falling out of the sky is that we talk openly about the risks up front, so that the people who created those risks get fired or demoted, and their bosses (or, failing that, regulatory authorities) make sure the risks get fixed. It isn’t a smart idea to short-circuit that process; that’s how we ended up with things like the Ukrainian famine, the Great Leap Forward, Lys…
Doing so while on a plane full of people is not a good idea.
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#37Earlier quoted context omitted.
This isn't exactly a new phenomenon - even before 9/11, a careless joke at baggage check-in ("Did you pack your own luggage today, Sir?" - "No, my wife probably put a bomb in there.") would often result in the joke not being recognised or treated as such. Said jokester gets taken to one side, scrutinised by the boys in blue, and eventually told that they "will not be flying today, sir." In the age of Twitter, such hi…
The baggage questions is so stupid, IF you wanted to do some evil with things packed, WHY would you say something that isn't the "right" answer to them?
People are easy to manipulate into carrying a parcel across international borders. Also, isn't it the start of gathering evidence? If you say it's your bag and you had control of it and then they find it full of contraband they can use your comments to tie the bag and contents to you?
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#38Earlier quoted context omitted.
The way we keep airplanes full of passengers from falling out of the sky is that we talk openly about the risks up front, so that the people who created those risks get fired or demoted, and their bosses (or, failing that, regulatory authorities) make sure the risks get fixed. It isn’t a smart idea to short-circuit that process; that’s how we ended up with things like the Ukrainian famine, the Great Leap Forward, Lys…
What would your response be to the person who "joked" that they were pissed off with United Airlines, and would like to remind them that his house was on the approach path to SFO, and the next time United lost his luggage, he would be more than happy to repay them by taking a few potshots at their 747s with his trusty .22? Sometimes the way we keep airplanes full of passengers from falling out of the sky, is by looki…
[0] Foreign Object Damage. In this case, at-speed impacts with grit, ice, and whatever.
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#39Earlier quoted context omitted.
If he was going to harm the aircraft, he wouldn't have announced it in a tweet. If the FBI already had reasonable suspicion he would, they shouldn't have let him get on the plane in the first place. There is no rational reason for their action. This is simply a PR move by United and the FBI. Which leads to the same conclusion: just don't tweet things like this. Not because you're wrong, but because they are assholes.
"If he was going to harm the aircraft, he wouldn't have announced it in a tweet." Many, Many bad actors have a pretty good trail/history of signals that made it clear that they were going to do something stupid. And a lot of them are stopped because authorities stepped in when those signals were reported. Would you want to be the person who was notified that someone was communicating they were considering interfering…
Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security
#40The tweet in question: https://twitter.com/Sidragon1/status/588433855184375808
I clicked on the word "tweeting" in the article twice before realizing it wasn't a hyperlink. I totally assumed it would be. And now I see why EFF didn't link to this. I'm sorry, but that tweet actually is threatening in my eyes. Note that I know __nothing__ about airplane-system-security, but that looks to me like he gained some kind of cmdline and/or admin-tool access and "PASS OXYGEN ON" looks like something that…
https://web.archive.org/web/*/https://twitter.com/Sidragon1/...