4 ms·
>Once the news broke, some on social media raised the "nightmare scenario" of the virus infecting an airplane’s control software and possibly triggering a ranso
by programbreeding 9y ago
>Once the news broke, some on social media raised the "nightmare scenario" of the virus infecting an airplane’s control software and possibly triggering a ransomware demand while in the air.
>"The plane would have to have been connected to an infected system.," he said. "The chances are pretty minimal."
If they can't confidently say the chances are guaranteed 0% then they need to actually look in to it and not just dismiss the idea.
- ams6110 9y agoWell, aircraft avionics do not run Windows. Thankfully. Though some of the diagnostic and maintenance equipment almost certainly does. So there's probably a path for malware, though likely not mainstream Windows ransomware.
- sneak 9y agoThe question then becomes: why the hell do the aircraft production systems run windows? Is making aircraft in bulk that much less important than flying an individual aircraft? At some point, using systems susceptible to malware to conduct critical business is simply negligence. Windows is not a sane default.
- Klathmon 9y agoAll systems are susceptible malware. Every OS, every architecture, every platform, everything.
- sneak 9y agoSure, in theory. In practice, this is simply not true. Nobody’s burning iOS or Chrome sandbox 0days to try to earn $50k USD ransoms.
- OrganicMSG 9y ago>The question then becomes: why the hell do the aircraft production systems run windows? Boeing use CATIA and Dassault Systèmes dropped non-windows client support for CATIA in 2008.
- ryandrake 9y agoI’ve worked on (non-safety critical) airborne systems that ran Windows Embedded, as freightening as it sounds.
- OrganicMSG 9y agoIf they are non-safety critical, you could use TempleOS and it still doesn't sound all that frightening.
- acct1771 9y agoTempleOS is airtight, so I don't really understand the comment you're trying to make about it.
- taneq 9y ago> freightening So it was on a cargo plane, then?
- bigiain 9y agoAnd there's evidence the "non-safety critical" airborne systems are not nearly as well isolated from the flight control systems as most people assume: https://www.wired.com/2015/05/feds-say-banned-researcher-commandeered-plane/ https://www.wired.com/2015/05/feds-say-banned-researcher-com... "He obtained physical access to the networks through the Seat Electronic Box, or SEB. These are installed two to a row, on each side of the aisle under passenger seats, on certain planes. After removing the cover to the SEB by "wiggling and Squeezing the box," Roberts told agents he attached a Cat6 ethernet cable, with a modified connector, to the box and to his laptop and then used default IDs and passwords to gain access to the inflight entertainment system. Once on that network, he was able to gain access to other systems on the planes." That one might just be a security researcher big-noting himself, but combined with this next one, I do not have a great deal of confidence in Boeing (or any of the airline industry's) software security teams... https://nakedsecurity.sophos.com/2017/11/15/dhs-says-it-remotely-hacked-a-boeing-757-sitting-on-a-runway/ https://nakedsecurity.sophos.com/2017/11/15/dhs-says-it-remo... I wonder what we'd find if Tavis Ormandy were seconded to Boeing for six months? (And can I have a heads-up if that happens? I've got some stock I'd like to short...)