5 ms·
Bruce Schneier has said several times that reinforced doors are one of the very few improvements when it comes to airplane security[1]. I think the deeper quest
by probably_wrong 12y ago
Bruce Schneier has said several times that reinforced doors are one of the very few improvements when it comes to airplane security[1]. I think the deeper question would be, if your pilot is compromised, can you really do anything?
If the pilot of the EgyptAir Flight 990[2] could not keep his co-pilot from crashing the plane, what could a mob of random passengers realistically do? It seems to me like the DRM problem - you can't protect the pilot and keep them from hijacking the plane at the same time.
At least the doors will prevent any of the other random 150 passengers from taking the plane. That does seem to me like an improvement.
[1] https://www.schneier.com/essays/archives/2005/12/airline_security_a_w.html https://www.schneier.com/essays/archives/2005/12/airline_sec...
[2] https://en.wikipedia.org/wiki/EgyptAir_Flight_990 https://en.wikipedia.org/wiki/EgyptAir_Flight_990
- frevd 12y agoYou can, using some biometric safeties on the controls.
- toyg 12y agoHow would biometrics protect from an authorized party controlling the plane he is supposed to control?
- frevd 12y agoOverriding the override ;]. But yeah, it's kind of a race-condition. Not sure, how about some majority vote, enough members on the crew there to vote?
- s_kilk 12y agoAren't many biometric controls trivial to defeat though? For instance, to replicate someones fingerprints all you need is a high res photo of their hand from a distance.
- frevd 12y agoYeah, iris scan isn't safe either if attackers can get the authorized person in their control. Maybe using two random people from the crew would be best, hard to find out for an attacker and still safe against "forgetting" the secret code.
- ptaipale 12y agoOr, a less high-tech solution: use the knife of your airline meal set to cut away the finger. Then the airline will move on in the arms race by responding with a fingerprint reader that wants to have a pulse in the finger, and then it doesn't work when the user is in distress and has an extremely high pulse. And then there is an accident and we the armchair security experts come up with more bright ideas.
- ben1040 12y ago>Or, a less high-tech solution: use the knife of your airline meal set to cut away the finger. Last time I had an airline meal, even in first class, the knife "blade" was hard rubber mounted on a blunt metal handle. It could barely cut the food cleanly, never mind someone's finger.
- ptaipale 12y agoYes, I was being sarcastic. You do, however, occasionally get real cutlery, even in economy class, with some airlines.
- ptaipale 12y agoThat's not foolproof either. There's always a compromise to make: if you have more automation to prevent pilot from being suicidal or making mistakes, you also have more automation that prevents a pilot - or anyone - taking over when the computer control goes wrong. Let's accept it: we may make things gradually better, but there is no silver bullet that would solve all these problems.
- frevd 12y agoFine. You authorize the whole crew, not by fingerprint and not by code, but by voice recognition and secret code words per person. Then you allow the override to be overridden by a majority (recursively). Sounds way better than making the door break when a majority of people kicks at them. It is faster than remembering and entering codes, and cannot be overridden by one sick authorized person. An attacker would have to control the whole crew to make them do what he wants, to a level where they actually speak the secret words. In an event where the crew anticipates a crash, giving in on pressure would be the worst option to take. To prevent attackers from muting all but the required majority of crew members, sensors all over the plane must be able to record any emergency code words spoken in the event of an attack, which will enact certain security measures (depending on the code word could lock or unlock the possibility to enter the cockpit, notify air security etc). This system should of course not be able to be deactivated. And if you really wanted to make things sure, you could install majority-authorization buttons on every seat setup to be pressed by a percentage of boarded people within a period of mere seconds, which would allow the people on the plane to make a decision. For an attacker it is not possible to make all those people press the button, since he would not know who is not complying. Of course you can also have some remote mechanism of unlocking, although the security implications of remote authorization and transmission of commands would be complicated to get right and open too many attack vectors.
- ptaipale 12y agoI guess you are making fun of someone, but that is a good demonstration why too complex procedures are not a good idea. Any procedure that aircraft crew is supposed to handle also needs to be something that is trained, memorized, and practiced regularly. Certain simplicity is ideal.
- deleted 12y ago[deleted]
- krschultz 12y agoI think it's the same thing as intelligence (in the national security sense). You can do lots of things to prevent outsiders from getting in, but if the insiders want to circumvent the protections, they can. Someone has to have "root" access, when you can't trust that person, you are done. About the only thing I could think of is some way for people to report a problem like this and air traffic controllers on the ground having a way to take over control of the plane from people inside the plane. But that too could have problems (what if the air traffic controller on the ground is the murderous one, and now he is crashing planes that the pilot can't control). I think it's a near impossible problem to fully solve. The closest thing I can think of is positive train control (PTC) which sets safe boundaries and overrides the operator if the train exceeds those boundaries. In this case maybe the plane simply can not be flown into the airspace around the Alps no matter how much the pilot wants to.
- erglkjahlkh 12y agoBeen there done that. The entourage I was in (30 people going to enjoy the woods) was once stopped in airport for carrying knives. Hell yeah we did, everyone did, the longest one was 40 cm long and all were carried visibly. We just told the guards to sod off as we had our own private transport plane we were waiting for. Who on earth would hijack their own plane? Especially as there were 30 armed people on board? That's the safest way to travel!
- timoth 12y agoRather than ATC taking over the plane, which seems like a non-trivial exercise, it might be a lot easier to allow them to override the door 'lock' mode in the cockpit (which ignores the keypad code for door entry) so that in this case the pilot/others outside could have asked ATC for it and got in. This means that there isn't someone outside the cockpit on the plane who has 'root' access (so nobody can be threatened for it). Even then, there are considerations like not allowing the cockpit to kill all com links / power so that people outside the cockpit are still able to communicate with the ground to get the root pwd, and as mentioned elsewhere the person inside the cockpit could change their strategy to make recovery of control difficult or impossible even in this case (EDIT: e.g. throwing the plane about). Also, you'd probably want >1 ATC person to authorise to reduce the chance of the door being unlocked by someone at ATC in cahoots with hijackers.