Live data from Hacker News

Boeing 787 In Flight Entertainment System Security fun

btr.pm

51–60 of 147 posts

Re: Boeing 787 In Flight Entertainment System Security fun

#52

Earlier quoted context omitted.

Do you have source on panasonic IFE hacks? Sounds interesting.

(Its mentioned in the opening paragraph of the article ;) Its been a big thing for a long time and there are lots of articles you can google too.)

Doh! Thank you.

Re: Boeing 787 In Flight Entertainment System Security fun

#53
post #25

Earlier quoted context omitted.

Nothing you do to the IFE is going to take down the plane.

In theory the IFE and avionics are separated by firewalls. Some things like the PA system are often on the IFE side, and hacks for panasonic IFE have included impersonating the pilot announcements and stuff. In practice I wouldn't expect the firewalls to be particularly well tested or complete or configured correctly, and it may be possible for an attacker to DOS the firewall and impact the other systems, and possibl…

Not really familiar with the Boeing architecture, but having worked on similar systems for other commercial aircraft, "firewall" is an understatement for the systems that act as gateways between the aircraft network domains with different criticality levels.

The IFE is in the Passenger Information and Entertainment Services Domain (as defined by the standard ARINC664 Aircraft Data Networks). A basic assumption regarding the connectivity to more sensitive domains is that PIESD is totally insecure and anything can happen.

Finally to people wondering why aircraft designers would physically connect networks with vastly different security requirements: it's for making it possible to share aircraft/ground communication means (satcom...)

Re: Boeing 787 In Flight Entertainment System Security fun

#54
post #42
post #29

Earlier quoted context omitted.

Thank you for this comment. I for one would be pretty pissed if a "hacker" decided to crash my/or my kids entertainment on a long flight. There is definitely a need for this type of work, but doing so in a 50,000 lb brick floating a few miles above the ground isn't an atmosphere I am comfortable with, especially if I am present...

If anything were to happen, it definitely shouldn't affect the avionics, not even remotely, or the plane would not have had a chance of certification. Data to the less secure IFE had better flow through a unidirectional network ("data diode"), and/or use a separate set of sensors. Even if it brought down the server, it's still nothing that the flight attendants can't solve by "turning it off and back on". This kind o…

Accidents happen. Commenter below referenced Swiss Air 111: https://en.m.wikipedia.org/wiki/Swissair_Flight_111

They cite inadequate safety standards and an overheating entertainment system.

It's easy to assume that government or the airlines wouldn't allow a faulty system to fly, but just like software it's those extreme edge cases that cause problems. Somehow I doubt hacking the entertainment system is comprehensively covered in the manufacturers safety check. It's probably a remote chance something bad would happen, but we can't say it's 0.

Re: Boeing 787 In Flight Entertainment System Security fun

#55
post #50
post #6

Earlier quoted context omitted.

It's borderline; if something bad happens (and bad things definitely can happen from portscanning, especially embedded systems), you'll be on the hook for it.

This isn't a publicly accessible system like a webserver. This is an entertainment device on a plane.

It's not your intuition about the IFE hardware that's problematic; it's your intuition about the "publicly accessible system like a webserver".

Re: Boeing 787 In Flight Entertainment System Security fun

#56
post #42
post #29

Earlier quoted context omitted.

Thank you for this comment. I for one would be pretty pissed if a "hacker" decided to crash my/or my kids entertainment on a long flight. There is definitely a need for this type of work, but doing so in a 50,000 lb brick floating a few miles above the ground isn't an atmosphere I am comfortable with, especially if I am present...

If anything were to happen, it definitely shouldn't affect the avionics, not even remotely, or the plane would not have had a chance of certification. Data to the less secure IFE had better flow through a unidirectional network ("data diode"), and/or use a separate set of sensors. Even if it brought down the server, it's still nothing that the flight attendants can't solve by "turning it off and back on". This kind o…

I agree that, in theory, at least the avionics shouldn't be accessible from the IFE. I am sure there is a rigorous protocol for making sure this is properly secured and certification for airworthiness. I think the parent comment was more making the point that we don't need a flight full of people scanning ports for fun and profit, and the consequences of doing so are unknown and could lead to things like no wifi or IFE on the flight you're on and hopefully not worse

Re: Boeing 787 In Flight Entertainment System Security fun

#57
post #40

Earlier quoted context omitted.

Nothing you do to the IFE is going to take down the plane.

So we're supposed to just take your word for it, in the face of contradictory evidence?

You don't have to go any further than the Wikipedia article the previous commenter provided to see that no evidence has been provided for how sending packets to an IFE could take down a plane.

Re: Boeing 787 In Flight Entertainment System Security fun

#58

Earlier quoted context omitted.

I find this hard to believe. I always thought that IFE and avionics are on separate machines and run over different internal networks and wires. But I'm also not a Boeing engineer. Can someone confirm the above post?

You or I would have completely different sets of wires. Sadly, it seems they usually share wires and are separated by firewalls. There's been lots of CCC and defcon talks about hacking in-flight systems. Googling "panasonic ife hack" gets plenty of hits, as does "Chris Roberts" who is a hacker who has made some pretty big claims about actually really hacking planes in flight and other stupid things. And there are art…

I don't know anyone who believes those claims, which have become a kind of shared joke in the software security community.

Re: Boeing 787 In Flight Entertainment System Security fun

#59
post #35
post #25

Earlier quoted context omitted.

Nothing you do to the IFE is going to take down the plane.

229 dead from an overheated entertainment system: https://en.wikipedia.org/wiki/Swissair_Flight_111

faulty wiring in the cockpit after the entertainment system started to overheat. electronic device don't start to do arc wiring with a portscan. Stop spreading bad info.

Even if in any other dimension it can be possible, it's the responsability of who design the system for protect against this.

Re: Boeing 787 In Flight Entertainment System Security fun

#60
Not a pilot, but Regarding flight phrase, actually airplane can detect FLARE easily (Airbus even has a FLARE flight law governing the aircraft during flare).

Typically FLARE would be RA (Radio Altimeter) < 50ft, flaps/slats extended, speedbrake armed, and weight on wheel = 0 or something along this line.

Post reply on HN