Live data from Hacker News

Collins Aerospace: Sending text messages to the cockpit with test:test

ccc.de

1–10 of 36 posts

Re: Collins Aerospace: Sending text messages to the cockpit with test:test

#2
Well, this is just standard Aerospace grade software. I would be surprised if you could find a single controller in an airplane without some trivial login credentials.

Exposing software like that to the internet is of course a completely insane step.

Re: Collins Aerospace: Sending text messages to the cockpit with test:test

#5

Well, this is just standard Aerospace grade software. I would be surprised if you could find a single controller in an airplane without some trivial login credentials. Exposing software like that to the internet is of course a completely insane step.

> Well, this is just standard Aerospace grade software.

This is a groundside problem, and perhaps it is insane to have it exposed to the open internet but it's not on the aircraft. It needs to be exposed to some network because the intent is that fleet controllers (airlines, or in this case Navy) use it to reach out to their aircraft wherever they may be.

That said, it absolutely fits the quality I've come to expect from IT systems developed by aerospace and defense companies.

Re: Collins Aerospace: Sending text messages to the cockpit with test:test

#6
post #3

Interesting choice of tail number and date... https://www.faa.gov/lessons_learned/transport_airplane/accid...

Looks like the PDF is just to show what the messaging interface looks like, and what they've found as a publicly available screenshot is from the crash report involving that plane.

If they logged in, took a screenshot, and published that (even if lots of things are blurred), there's probably more attack surface for some three-letter-agency to bust down their doors and disappear them...

Re: Collins Aerospace: Sending text messages to the cockpit with test:test

#7
post #4

> RTX did not respond to our vulnerability report I guess they mean you should sell the vulnerability to highest bidder instead of reporting? Weird choice.

Unfortunately, RTX did not respond to our vulnerability report. The account was disabled.

Some sort of acknowledgement of the report certainly would have been good here, but at least they did disable the account. I presume the reported vulnerability no longer exists.

Re: Collins Aerospace: Sending text messages to the cockpit with test:test

#8
post #3

Interesting choice of tail number and date... https://www.faa.gov/lessons_learned/transport_airplane/accid...

I would guess it limits their ability to be accused of anythign to pick a plane, flight, and time that meets at least three criteria:

1) no passengers on board - you can't be accussed of endangering passengers

2) long past - you can't be accused of anything that happened recently

3) the plan literally no longer exists - you can't be accussed of damaging a plane

Re: Collins Aerospace: Sending text messages to the cockpit with test:test

#9

Well, this is just standard Aerospace grade software. I would be surprised if you could find a single controller in an airplane without some trivial login credentials. Exposing software like that to the internet is of course a completely insane step.

> Well, this is just standard Aerospace grade software. This is a groundside problem, and perhaps it is insane to have it exposed to the open internet but it's not on the aircraft. It needs to be exposed to some network because the intent is that fleet controllers (airlines, or in this case Navy) use it to reach out to their aircraft wherever they may be. That said, it absolutely fits the quality I've come to expect…

It meets all requirements! /s

Re: Collins Aerospace: Sending text messages to the cockpit with test:test

#10
post #4

> RTX did not respond to our vulnerability report I guess they mean you should sell the vulnerability to highest bidder instead of reporting? Weird choice.

They will respond after a year or two with a lawsuit and SWAT busting doors.
Post reply on HN