Live data from Hacker News

United Airlines 767 returns to Newark after Bluetooth name sparks alert

simpleflying.com

301–310 of 1001 posts

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#301
post #178

I once consulted on some aviation-related software (not the safety work prominent on my resume), and a company announcement came through, that you must never use a few specific words commonly heard in software development. The two no-no words I recall were "crash" and "bomb". Don't write them in code or documents, don't say them on the phone or videoconf, etc. Those terms have senses that people in aviation take extr…

This reminds me of the story I read of someone trying to take a https://en.wikipedia.org/wiki/Calorimeter#Bomb_calorimeters onto a flight, in the pre-9/11 era. Fortunately he was allowed to after some questioning, but it did raise some eyebrows. I imagine trying to ship one of those would also arouse some attention.

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#302
post #214

Earlier quoted context omitted.

This is trying to sanewash totally insane levels of risk aversion. Do you think terrorists are really going to name their Bluetooth speaker "bomb"? Do you think this behaviour has any meaningful true positives? This is the kind of brainworms thinking that has people throwing our their 150ml liquids out at TSA and taking their shoes off.

1. Are super-organized, highly-capable, fully-sane terrorists the only threat? Or does the threat model include mentally-ill / personality disorder people, who might make mistakes, or taunt those whose job it is to stop them? Or include people of either kind, who create diversions? Or include people who make a statement in an unexpected way? 2. Did the captain, flight control, and everyone else who needed to decide,…

> Are super-organized, highly-capable, fully-sane terrorists the only threat? Or does the threat model include mentally-ill / personality disorder people, who might make mistakes, or taunt those whose job it is to stop them?

I want to think the answer is both. But I cannot think of an example where #2 has actually happened in history resulting in injury or death.

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#304
post #178

I once consulted on some aviation-related software (not the safety work prominent on my resume), and a company announcement came through, that you must never use a few specific words commonly heard in software development. The two no-no words I recall were "crash" and "bomb". Don't write them in code or documents, don't say them on the phone or videoconf, etc. Those terms have senses that people in aviation take extr…

Anecdote: I worked with software for battery EV power-train diagnostics, one of our devs decided to add emojis to success and error messages.

He added a fire emoji to one success message. When testers saw it they were afraid that the customer would think it was a thermal runway problem. Had to do a last-minute revision of the software before shipping the new version.

I was already pretty anti-emoji / personal touch / fun features / easter eggs in professional software. But having to pull a 2-hours overtime to crank out a new release definitely settled me on the side of never again.

edit: To be clear no one actually thought it was a problem, but our QA were very much serious about reducing any potential for confusion when dealing with >1million USD machinery.

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#305
post #178

I once consulted on some aviation-related software (not the safety work prominent on my resume), and a company announcement came through, that you must never use a few specific words commonly heard in software development. The two no-no words I recall were "crash" and "bomb". Don't write them in code or documents, don't say them on the phone or videoconf, etc. Those terms have senses that people in aviation take extr…

Aviation documentation in general is expected to use special, constrained variant of english (Simplified Technical English) where one of the requirements is that every word has preferably only one meaning, and there's a standard dictionary of those meanings that were selected.

Similarly there are various things like Aviation English for actual live comms, though they have less specifity, not to that level.

And yes, this is related to being clear and understandable both when communicating something live (you might have to dictate from a manual over the radio!) but also over native language barriers

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#307
post #178

I once consulted on some aviation-related software (not the safety work prominent on my resume), and a company announcement came through, that you must never use a few specific words commonly heard in software development. The two no-no words I recall were "crash" and "bomb". Don't write them in code or documents, don't say them on the phone or videoconf, etc. Those terms have senses that people in aviation take extr…

This is trying to sanewash totally insane levels of risk aversion. Do you think terrorists are really going to name their Bluetooth speaker "bomb"? Do you think this behaviour has any meaningful true positives? This is the kind of brainworms thinking that has people throwing our their 150ml liquids out at TSA and taking their shoes off.

You word "kind" unzips to three distinct categories:

1. failing hard: Is $trigger_word in the context of an attack, or is it innocuous? Failing hard then assessing the context question later is at least a simple system to design and implement safely. And an adversary can't pentest it. I mean they can, but they'll fail hard every time no matter the context. And that is very expensive for the attacker.

2. failing soft: throw away your too large container of liquid. I'm not sure what this liquid container rule prevents. In any case, an adversary can pentest this as often as they can buy a ticket, and they'll just blend in with all the other grumpy passengers forced to throw out their containers of liquid and continue on through security.

3. don't touch the spaghetti makefile: add a specific rule about removing shoes after the relevant attempt at an attack. Also, let's keep it for decades because no politician wants the liability of having voted to remove a TSA rule in the case of a future attack.

Conflating these all under a single "brainworm" category tells me you are exactly the kind of person who shouldn't be in charge of designing a secure system!

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#308

What a usability nightmare this site is: 3-4 popups before I could even read the title. No thank you. And this is with an adblocker turned on. Don't these sites realize how many users they're losing?

That adblocker does not sound very effective

No popups when using uBlock Origin and/or uMatrix

   scheme=https://
   host=simpleflying.com
   ip=34.233.113.241
   path=/united-airlines-767-returns-newark-bluetooth-name-alert/
   {
   echo url=$scheme$host$path
   echo output=/dev/stdout
   } \
   |curl --resolve $host:443:$ip -K/dev/stdin \
   |sed 's/]*>//;/user-comment/,$d' \
   |grep -o "

.*

" > 1.htm firefox ./1.htm #links -dump 1.htm
The real "nightmare" is the browser that will automatically run all that garbage returned in the response body without any input from the user

It requires an "adblocker" to stop its default behaviour

Alternatively, one needs to disable Javascript, restrict the browser's access to DNS, etc.

When an advertising company releases a "browser" that intentionally allows website operators to cram pages fuil of advertising and tracking is that a coincidence

Is that the only way a browser can be designed

No

How many users realise this

A small number

For example, I'm using a browser that cannot automatically request resources, run Javascript, CSS, etc. where HTTP headers, including cookies, are trivial for the user to create, edit, save and delete. I do not need an "adblocker"

"Don't these sites realise how many users they're losing?"

The number is so small why would they care

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#309

Flight policies have always been very weird. I remember I was not allowed to use a laptop with a CD or DVD attached. Now you have internet on board.

What is even better now phone calls are prohibited, but all these airlines had actual credit card phones installed in every seat just 20-15 years ago and really wanted you to do phone calls for $1 a minute. And some people did, and it was annoying, and it was “fine”. Now that they can’t charge extra suddenly it’s “against regulations”.

Re: United Airlines 767 returns to Newark after Bluetooth name sparks alert

#310

A 16 year boy apparently named his Bluetooth speaker “bomb” and couldn’t turn it off, as it was probably in checked luggage. Woof.

> it was probably in checked luggage Which would violate FAA regulations if it was powered on (as it obviously was): "When portable electronic devices powered by lithium batteries are in checked baggage, they must be completely powered off and protected to prevent unintentional activation or damage." https://www.faa.gov/hazmat/packsafe/portable-electronic-devi...

It might've been off when packed, but all the vibration turned it on at some point.
Post reply on HN