Live data from Hacker News

United Airlines Stops Researcher Who Tweeted about Airplane Network Security

eff.org

51–60 of 128 posts

Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security

#51
post #2

We live in shitty knee-jerk reactionary times, but did anyone else see his tweet at the time? At best, it seemed in poor taste. At worst, the outcome seems depressingly predictable. I don't know what I'm trying to contribute here, except that whilst I have no problem with EFF working on this, their article here seems overly shrill and over-reactionary at how shrill and over-reactionary the airline was in their respon…

This person was an absolute clown. I think the infosec community needs to grow up. We all hate when legislators use the word 'cyber.' Title 18 is a mess. The new computer crime proposals are worse. Every couple of years we get the occasional story about licensing security professionals. It is because of exactly this type of clownish behavior. There are consequences for the attention seeking type of behavior. This idi…

Every response to this I've seen from "the infosec community" (my connection to that community tends sharply towards vulnerability researchers, since that's my background) has been critical of this guy. I can't think of anyone I've seen cheerleading him. I've even seen rare glimmers of people criticizing EFF for trying to make a cause celebre of him.

But you're taking things too far by casting aspersions on all of "stunt hacking".

The problem with this idiotic tweet is that, if there is a vulnerability in the electronics of an airplane, this is exactly the thing you'd expect to see before some moron accidentally forced an emergency landing by tinkering with it. Vulnerability researchers disrupt and disable systems all the time without trying to.

The same is not true of people using logic analyzers on car CANbus systems (the archetypical example of stunt hacking).

The real criticism I've seen of stunt hacking is that (a) we don't learn all that much from it and (b) it's not particularly difficult ("look at this debugger debugging", as a friend of mine summarizes most stunt hacking talks).

Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security

#54
post #2

We live in shitty knee-jerk reactionary times, but did anyone else see his tweet at the time? At best, it seemed in poor taste. At worst, the outcome seems depressingly predictable. I don't know what I'm trying to contribute here, except that whilst I have no problem with EFF working on this, their article here seems overly shrill and over-reactionary at how shrill and over-reactionary the airline was in their respon…

> their article here seems overly shrill and over-reactionary

I totally disagree and am confused how that could be your reading

Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security

#55
Really dumb.

Really dumb of this security consultant to have bragged about tampering with airplane control systems in the middle of a flight.

Really dumb of EFF to make a cause célèbre of him.

EFF's analysis of this situation seems to revolve around the consultant's intent. He's a security researcher, ego not a real threat, and undeserving of scrutiny.

I'd have thought that EFF would be better acquainted with pentesters by now. Anyone who spends a lot of time with pentesters knows that when it comes to disrupting or disabling critical systems, intent doesn't have much to do with the outcome of a pentest. We break shit all the time without trying. We break shit even when we're trying not to. Smart clients who have spent the last decade working with pentesters often have e-l-a-b-o-r-a-t-e rules of engagement designed to avoid prod disruption. We still break shit in prod, even when we follow the letter of the rules.

So this goofy tweet the consultant sends: is it what you'd expect right before a terrorist crashes a plane? Of course not. But is it exactly what you'd expect right before some idiot trips a bug that does something to force an emergency landing? It absolutely is.

Is it outside the realm of possibility that some control system somehow bridged to airplane wireless would have a problem that would allow a passenger to deploy the oxygen masks? It is not. Would that design flaw be idiotic? Yes it would. Does the idiocy of that design flaw mean it's unlikely to be there? No it does not. Virtually every system you interact with in the world has idiotic design flaws. Wait, that's not a question. "Does virtually every system..." YES. YES THEY DO.

So imagine that, just like in pretty much every pentest ever, this consultant is merely poking around trying to see what functionality is exposed to him through this design flaw. No intention to make anything happen at all. Now imagine he purely by accident does manage to, I don't know, deploy oxygen masks. No harm done (stipulate nobody on the flight has a severe heart condition). Plane integrity undamaged. Plane fully capable of continuing along its itinerary. Nonetheless, what's the likely outcome here? Unplanned emergency landing.

There probably is no such vulnerability. But then you have to ask yourself: who in United's flight operations chain of command is qualified to assess whether there is? Really, who in the entire flight safety chain of command, from flight captain through FAA to DOJ, is? There aren't that many people in the world who know how EICAS messages work. All they have to work with is the hypothetical. "Unexpected behavior found in in-flight wireless. Tinkering in process!" That's a threat!

I think the thing that frustrates me most about this story is the fact that it's probably not possible to launch anything more than nuisance attacks from the vantage point of a passenger. And yet because of our (admirable and effective) attitude with regard to flight safety, those nuisance attacks are all economically devastating. In other words, this kind of "research" is unhelpful.

Where EFF made me flip out this time: Nevertheless, United’s refusal to allow Roberts to fly is both disappointing and confusing. As a member of the security research community, his job is to identify vulnerabilities in networks so that they can be fixed. Wat. United's decision here is extremely easy to understand: they do not want to offer service to someone who was willing to disrupt a flight to make a point. Meanwhile: the "security research community" does not deputize its members, make them swear an oath, and given them a little tin badge. No part of this guy's "job" gave him the right to tamper with the computer systems on an aircraft. If EFF thinks that's what it means to be a vulnerability researcher, they are broken. They cannot advocate effectively for legitimate research while promoting the idea of special rights for people who call themselves security researchers.

Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security

#57
post #3

The tweet in question: https://twitter.com/Sidragon1/status/588433855184375808

Could someone be so kind as to translate this tweet so that those of us that aren't security experts can understand what was said? Or perhaps point me in the direction of some recommended, intro-level reading? I feel distinctly ignorant at the moment!

> Find myself on a 737/800, lets see Box-IFE-ICE-SATCOM, ? Shall we start playing with EICAS messages? "PASS OXYGEN ON" Anyone ? :)

737/800: is the type of aircraft and specific model (Boeing 737, stretched version (800)).

Box-IFE-ICE-SATCOM: Is a theoretical (or actual?) exploitation path.

Box: I'm assuming is in-flight WiFi

IFE: Is the in-flight entertainment system

ICE: Is also part of the IFE, but I'm guessing he specifically referenced that due to the "I" (in ICE) namely, the information that gets fed into the IFE from the flight systems (speed, altitude, and position)

SATCOM: The uplink used by in-flight WiFi but also the IFE to provide "latest news." If can be used to deliver information to the airline about the aircraft so they can keep track of if its on schedule and such.

EICAS messages: Used on aircraft's secure network for flight crew alerts and diagnostic information. Some of these may be relayed onto the insecure network and forwarded to the airline (similar to ACARS, but over SATCOM).

PASS OXYGEN ON: The implication is he wants to cause the oxygen masks to drop down into the passenger cabin (although in reality sending this wouldn't do that, it would just set off a warning on the flight deck letting the pilots know that the oxygen masks dropped, even if they physically hadn't).

If he could send EICAS messages to the aircraft's secure network, that would be a legitimate safety concern. However if he just witnessed EICAS messages from the insecure network, that isn't really a concern except maybe he could send misleading ones to the airline and give them a metaphorical heart attack.

Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security

#58
post #55

Really dumb. Really dumb of this security consultant to have bragged about tampering with airplane control systems in the middle of a flight. Really dumb of EFF to make a cause célèbre of him. EFF's analysis of this situation seems to revolve around the consultant's intent. He's a security researcher, ego not a real threat, and undeserving of scrutiny. I'd have thought that EFF would be better acquainted with pentest…

[deleted]

Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security

#59
post #25
post #21

What an overreaction from the EFF. Use a bit of judgement and realize it isn't a smart idea to talk about hacking an airplane full of passengers.

The way we keep airplanes full of passengers from falling out of the sky is that we talk openly about the risks up front, so that the people who created those risks get fired or demoted, and their bosses (or, failing that, regulatory authorities) make sure the risks get fixed. It isn’t a smart idea to short-circuit that process; that’s how we ended up with things like the Ukrainian famine, the Great Leap Forward, Lys…

"I am on a plane messing with what I believe to be control systems" is a threatening message, even if it isn't intended to be. Moreover: every computer system in the world is vulnerable. The process of finding those flaws is disruptive. It can't be the case that knowing in the abstract about those flaws is a predicate to allowing people to disrupt systems to find specific instances of them.

Re: United Airlines Stops Researcher Who Tweeted about Airplane Network Security

#60
post #47
post #43

Earlier quoted context omitted.

I don't think they mean legitimate as professional or industry recognized, but more as a way to distinguish from an actual bad guy hacking for criminal intents and then claiming he is a researcher and should have carte blanche.

Researching with criminal intent is also legitimate research provided no laws are broken.

In France there is a crime labelled "association de malfaiteurs" (criminal's gathering). Fantasizing about a crime is allowed. But actually laying out plans, watching the neighbourhood, or performing concrete steps towards the crime with the intent of actually performing it… well, that is forbidden.

Makes sense to me. Mere thoughts should never be forbidden, but acting on a criminal intent, even if the acts, taken independently, wouldn't be forbidden, is something else entirely. First, actions can be punished. Second, actions are actual evidence for the intent.

Post reply on HN