Skip to content

Comment on Coin-sized device can hack a Boeing 737

Comments

less than a minute, that hardware implant can be fitted into a port accessible via a hatch on the exterior of the plane

Just as with computers, as the saying goes, if you have physical access to the device then all bets are off. The tricky part is getting that physical access in the first place...

Of course. Doesn’t mean we should leave the root password written down on a post-it next to the hardware. It sounds strange that such a privileged port has no authentication.

Getting security to work reliably in such scenarios can be hard. And your customer really don't want their up to hundred million in cost pieces of equipment sit there doing nothing because maintenance is unable to do something with it.

Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.

“Make it the customers problem” always works. These days it feels like LLMs are trained to do the same.

At certain price point customers tend to make it also your problem. And expensive jets are certainly beyond that point. They might sue you. Or simply not buy or lease new ones.

Very true. I was actually thinking that telling the customer to secure the physical location where the insecure port is located is making it the customer’s problem while solving the authentication problem is making it the manufacturer’s problem. I guess you may have read it the other way?

Fair to say that everything has tradeoffs, even expensive hardware.

It is not that simple, atleast in the automotive industry _today_. Atleast here in EU.

Every component is analyzed from a cyber security perspective. Many components needs tampering protection - while others need not. This includes replacing components with malicious ones.

It is not logical at all and a stupid regulation. But it is not as simple as you can do what you want if you have physical access.

I have little faith any of it would stop someone who was a) devoted, b) prepared, and c) had physical access for a reasonable time.

It’s still worth doing because the vast, vast majority of people will fail at a or b without even reaching c.

That’s sort of less so with planes, though. You don’t generally decide to take out a plane without being dedicated at the very least.

Well, the EU, being very much dictated by Germany, who have a large car industry, has a vested interest in making sure that if people want to have a better car they pay for a better one new rather than upgrade with an aftermarket chip.

A better car for most people is not just a chip upgrade. Anyone with a lick of sense has no need for more horsepower than whatever a standard EV has. It's beyond plenty for normal driving. I drive an Opel Corsa E which is a cheap EV and it accelerates more than fast enough. Upgrading would be about better safety equipment, better range, more space, better seats, better sound system and stuff like that. None of that can be done with a chip. It would be a different car, which is what I plan to get in a few years.

Paying for a horsepower upgrade chip is something very few people have any interest in doing. Mostly irresponsible assholes who are a danger to others, maybe a few people who need it to pull trailers or something.

I'm talking about ICE cars :) The sorts of car that Germany does extremely well.

Same point though, almost nobody really needs a horsepower upgrade.

I live in Germany. and i wish i lived in an EU that’s dictated by germany, but that is not the EU I live in.

The above statement sounded way more edgy than intended lol

You should try living in Greece or something, and you'll see what the EU (and the Euro) can wreak on a country.

You can take your car to a tuner shop and they’ll do it. Where do you think those 900 bhp m4s come from.

Just as with computers, as the saying goes, if you have physical access to the device then all bets are off

This is far less true than it used to be, though, and it seems reasonable to expect that aircraft become as secure as Macs.

A huge part of the security of Macs is that the security domain is a single chip. Hard to do with an airplane which is inherently a physically-distributed system.

But what if the device contained an explosive?

Defenders have to think about multiple threats. Explosives are harder to get, conceal from certain types of scans, and are more overtly deliberate. Neither of these is a common threat but that doesn’t mean people don’t harden against low probability/ high damage events.

I mean, if we're going to ignore physical attacks then yeah an airplane can be as safe as a computer I suppose.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.