12 ms·
United Airlines Stops Researcher Who Tweeted about Airplane Network Security
- csirac2 11y agoWe live in shitty knee-jerk reactionary times, but did anyone else see his tweet at the time? At best, it seemed in poor taste. At worst, the outcome seems depressingly predictable. I don't know what I'm trying to contribute here, except that whilst I have no problem with EFF working on this, their article here seems overly shrill and over-reactionary at how shrill and over-reactionary the airline was in their response to what (admittedly, in hindsight) could have easily been interpreted as a threat by an over-zealous corporate drone blind to smily-face emoticons.
- deleted 11y ago[deleted]
- ehmmm 11y agoSeems to be a decent warning to security experts on how are you going to be treated in such situations, and a remainder to act accordingly.
- mentat 11y agoDon't imply you're going to harm an aircraft when you're on it. Also, airlines, don't imply you're going to allow someone to travel when you're not.
- TazeTSchnitzel 11y agoYeah. Don't say: This plane has <security vulnerability> ... shall we play with it and do <bad thing>? It's just asking for trouble. On the other hand, maybe this would go down better: Oh god, this plane has <security vulnerability>. That does not make me feel safe. What if someone did <bad thing>? D:
- DanBC 11y ago(Using four spaces and long lines makes those lines unreadable on mobile.) > Oh god, this plane has <security vulnerability>. That does not make me feel safe. What if someone did <bad thing>? D: No! There are plenty of examples of people who stumbled over a security vulnerability, and who responsibly, confidentially, reported those vulns to the companies, and who then faced scary legal action. I agree that the actions taken against him are far too severe; and that there should be a way for people to talk about security flaws without facing this level of harassment.
- Confusion 11y agoIf he was going to harm the aircraft, he wouldn't have announced it in a tweet. If the FBI already had reasonable suspicion he would, they shouldn't have let him get on the plane in the first place. There is no rational reason for their action. This is simply a PR move by United and the FBI. Which leads to the same conclusion: just don't tweet things like this. Not because you're wrong, but because they are assholes.
- DanBC 11y ago> If he was going to harm the aircraft, he wouldn't have announced it in a tweet. You can't know that. > If the FBI already had reasonable suspicion he would, they shouldn't have let him get on the plane in the first place. They may well have stopped him getting on the plane if he'd made similar tweets beforehand. "I'm going on a plane next month. What should I do with EICAS ;-)" would probably have had the same effect. He shouldn't have had his stuff confiscated, but he has no excuse for not knowing how "they" reacted. Their over reaction is entirely predictable, not just from theory but from their past behaviour.
- ghshephard 11y ago"If he was going to harm the aircraft, he wouldn't have announced it in a tweet." Many, Many bad actors have a pretty good trail/history of signals that made it clear that they were going to do something stupid. And a lot of them are stopped because authorities stepped in when those signals were reported. Would you want to be the person who was notified that someone was communicating they were considering interfering with the proper operation of an aircraft, and ignored them, only to discovery they later on did do damage to the aircraft? I think at the very least, people responsible for flight safety can engage with those making claims they are going to endanger airplanes, and subject them to a strenuous interview to determine what their actual intent is.
- Lorento 11y agoIt's one thing to unobtrusively investigate a suspicious person, but actually interrupting their life just because your heuristics aren't good enough sound like a ding to free speech. If everyone joked about hacking planes, that would no longer be a risk factor.
- droopybuns 11y agoThis person was an absolute clown. I think the infosec community needs to grow up. We all hate when legislators use the word 'cyber.' Title 18 is a mess. The new computer crime proposals are worse. Every couple of years we get the occasional story about licensing security professionals. It is because of exactly this type of clownish behavior. There are consequences for the attention seeking type of behavior. This idiot is catnip for government regulation. It isn't exactly his fault though. Our community has been doing this to garner press attention for the sake of the attention. He is following the pattern that has long been set. Stunt hacking scares the shit out of normal people. Eventually people will demand regulatory intervention.
- tokenizerrr 11y ago> Stunt hacking scares the shit out of normal people. Eventually people will demand regulatory intervention. Good. Maybe they'll actually start caring about security instead of obscurity through law.
- Joeri 11y agoThey don't want to be secure, they want to feel secure. That's why when somebody shows how insecure people are the common reaction is to want to punish that person. They didn't make people less secure, but they made them feel less secure.
- droopybuns 11y agoThis is exactly what I am trying to call attention to. I have tremendous sympathy for the sentiment you are expressing. Unfortunately, the splash damage of flasy exploitation publicity as an incentive for vulns remediation is government regulation of security professionals. The flashy stories have been happening for close to 20 years now. Are vulnerabilities becoming more rare?
- forgottenpass 11y agoI think the infosec community needs to grow up. Vauge non-specific demands of a loose and fluid group with little to no control over it's members set the group up for inevitable failure. Without critical thought, it appears to be a reasonable request. Which is why the people who never want to listen to The Cavalry or EFF say it, and why the rest of us propagate the idea. But it's a trap.
- jamesbrownuhh 11y agoThis isn't exactly a new phenomenon - even before 9/11, a careless joke at baggage check-in ("Did you pack your own luggage today, Sir?" - "No, my wife probably put a bomb in there.") would often result in the joke not being recognised or treated as such. Said jokester gets taken to one side, scrutinised by the boys in blue, and eventually told that they "will not be flying today, sir." In the age of Twitter, such hijinks are amplified further due to their world-readable nature. The problem with innocent, uncomfortable-but-well-intentioned jokes is that you have to consider how it will play with someone whose job it is to flag up and respond to any and all threats, no matter how credible. Fundamentally it's your joke versus a member of staff who is not in a position to deviate from the procedure and brush it aside. Plus, who'd want to be the guy who gets their face on the news after an incident because they ignored a threat and thought it was a joke? They won't, and often CAN'T, take that risk - they are simply not in a position where they are allowed to do so. As you say, we live in shitty knee-jerk reactionary tines, but whatever the rights and wrongs, in this kind of situation it's prudent to moderate one's comedy appropriately.
- tomp 11y ago> whose job it is to flag up and respond to any and all threats, no matter how credible. That's exactly the problem, right there. Such jobs should not exist, because non-credible/joking threats are not threats, they are just jokes.
- jamesbrownuhh 11y agoAbsolutely, but a credible security researcher, on a plane, talking about its configuration and asking "shall we start playing with EICAS messages?" is not a joke that can be disambiguated in real time. That is achieved through men with badges, confiscation of property, the disruption of travel, and the kind of inconvenience being written about here.
- jhildings 11y agoThe baggage questions is so stupid, IF you wanted to do some evil with things packed, WHY would you say something that isn't the "right" answer to them?
- Confusion 11y agoIt seems reasonable to allow someone to joke about their own research when it becomes applicable in their real life.
- getsat 11y agoIn that case, it was potentially VERY applicable to the other people's lives who also were on the plane in question.
- Confusion 11y agoPeople make harmless jokes that are applicable to your life at a daily basis, you're just not party to them. Thinking a joke is dangerous just because you observe it is a base rate fallacy.
- ghshephard 11y agoBut, at the same time, thinking that "a joke" is safe when observed, is also not necessarily true. Good judgement needs to be taken into account. I recall having to "reapply" for my temporary job in the computing center every semester (because, of course, it was "temporary") - and one of my fellow students, after having done this for a couple years, and having a bit of ego, basically just scrawled on his application form, "Hire me again or I will murder all of you." You see, if you knew him, it was actually really, really funny. We were all a close group, and everyone on the team thought it was hilarious. The HR organization that unbeknownst to this student, screened all applications, and had no idea who he was, took a decidedly different perspective on his application. The proper response was to alert security, and thankfully his hiring managers - who then de-escalated the situation. The problem with the airline situation - their is no easy "oracle" who can confirm that this person is most decidedly not a threat.
- rhino369 11y agoPeople in general are very afraid of flying despite the fact it is reasonably safe. Making a joke about fucking with an airplane is in poor taste considering many people are on edge. It'd be like making a rape joke when you pass a woman on a dark street.
- patcon 11y ago> their article here seems overly shrill and over-reactionary I totally disagree and am confused how that could be your reading
- SixSigma 11y agoOp doesn't understand what "reactionary" means.
- appleflaxen 11y agoYes, it's a stupid tweet. But essentially saying "I could bring this plane down with my laptop hackery" is a statement about security, not about intent. The guy has bad judgment, but he's not saying anything that should trigger any action against him (they should investigate the basis for his claim, not him as an individual).
- ssully 11y agoIf he were to announce to the passengers on the plane, "I could bring this plane down with my laptop hackery", people would be terrified and want him off the plane. They don't give a shit about intent, they just know the guy is talking about being able to bring down the plane they are on.
- ocdtrekkie 11y agoThe issue is that he was hacking the plane. Intent is irrelevant. The reality is he could inadvertently damage an aircraft system while playing around. A responsible security researcher would not put 200 people at risk to do his testing.
- pla3rhat3r 11y agoThis is the world we live in. Question, detain, and let the courts handle the interpretation of the law. Whether it's the NSA, FBI, CIA, it matters very little to them. After 9/11 we as a country wrote them a blank check. And while this guy shouldn't have taken to twitter to say planes can be hacked pretty easily, it's not shocking to see what happened after he did.
- ocdtrekkie 11y agoI absolutely think the EFF is making poor use of their funds defending someone who was doing penetration testing on live planes with people aboard. If the security is as bad as he claims, the risk his testing might inadvertently put people in danger could be pretty high. And he was a repeat offender, as by his own admission he'd hacked planes 15-20 times so far in a live environment. That's incredibly dangerous, and it takes an incredible amount of ego and an incredible lack of consideration to fail to realize that he could be putting people at risk himself.
- narsil 11y agoThe tweet in question: https://twitter.com/Sidragon1/status/588433855184375808 https://twitter.com/Sidragon1/status/588433855184375808
- briandear 11y agoCould someone be so kind as to translate this tweet so that those of us that aren't security experts can understand what was said? Or perhaps point me in the direction of some recommended, intro-level reading? I feel distinctly ignorant at the moment!
- ButchDriveshaft 11y agoI'm relatively uninformed in this area, but I assume it was a proposal for an exploitation path. "Box-IFE-ICE-SATCOM" would most likely be a plan meaning exploiting and escalating privileges from the actual passenger's client interface or in-seat screen(box), escalating to the in flight entertainment system (IFE), to the inter-communications system (ICE), and finally to the Satellite Communications system (SATCOM). Not sure how realistic it is, because I know really nothing about info-sec with regard to aircraft, but it's no different than planning something like web app/service vulnerability -> database -> backend systems.
- UnoriginalGuy 11y ago> Find myself on a 737/800, lets see Box-IFE-ICE-SATCOM, ? Shall we start playing with EICAS messages? "PASS OXYGEN ON" Anyone ? :) 737/800: is the type of aircraft and specific model (Boeing 737, stretched version (800)). Box-IFE-ICE-SATCOM: Is a theoretical (or actual?) exploitation path. Box: I'm assuming is in-flight WiFi IFE: Is the in-flight entertainment system ICE: Is also part of the IFE, but I'm guessing he specifically referenced that due to the "I" (in ICE) namely, the information that gets fed into the IFE from the flight systems (speed, altitude, and position) SATCOM: The uplink used by in-flight WiFi but also the IFE to provide "latest news." If can be used to deliver information to the airline about the aircraft so they can keep track of if its on schedule and such. EICAS messages: Used on aircraft's secure network for flight crew alerts and diagnostic information. Some of these may be relayed onto the insecure network and forwarded to the airline (similar to ACARS, but over SATCOM). PASS OXYGEN ON: The implication is he wants to cause the oxygen masks to drop down into the passenger cabin (although in reality sending this wouldn't do that, it would just set off a warning on the flight deck letting the pilots know that the oxygen masks dropped, even if they physically hadn't). If he could send EICAS messages to the aircraft's secure network, that would be a legitimate safety concern. However if he just witnessed EICAS messages from the insecure network, that isn't really a concern except maybe he could send misleading ones to the airline and give them a metaphorical heart attack.
- 616c 11y agoSo for aspiring infosec people, can someone explain how he can crack the encryption of EICAS? Different commenters on different site articles claim that the 737 never had EICAS, or maybe they mean that the Oxygen Mask On light is of course not connected to the internal avionics network. Are there people who know this stuff better and have pointers? I would love to know more.
- appleflaxen 11y agoYou probably just put yourself on the no-fly list.
- neurotech1 11y agoEICAS is the Airbus terminology. The 737NG engine instrument display is somewhat similar, except non-engine warnings are on other displays. Some warnings go on the Primary Flight Display. The 737NG also has a warning panel with lightbulbs.
- itg 11y agoWhat an overreaction from the EFF. Use a bit of judgement and realize it isn't a smart idea to talk about hacking an airplane full of passengers.
- cm2187 11y agoParticularly for a "security researcher". If he is, he should know better.
- kragen 11y agoThe way we keep airplanes full of passengers from falling out of the sky is that we talk openly about the risks up front, so that the people who created those risks get fired or demoted, and their bosses (or, failing that, regulatory authorities) make sure the risks get fixed. It isn’t a smart idea to short-circuit that process; that’s how we ended up with things like the Ukrainian famine, the Great Leap Forward, Lysenkoism, and presumably Windows Vista. Use a bit of judgement; we’re trying to have a civilization here, Nero.
- gcr 11y agoNero?
- ghshephard 11y agoWhat would your response be to the person who "joked" that they were pissed off with United Airlines, and would like to remind them that his house was on the approach path to SFO, and the next time United lost his luggage, he would be more than happy to repay them by taking a few potshots at their 747s with his trusty .22? Sometimes the way we keep airplanes full of passengers from falling out of the sky, is by looking for, and engaging, potential bad actors. The way to determine if someone is a bad actor, is by looking for signals of such intent. And, I think all things equal, this guy probably was throwing off signals that he was a bad actor, even if it's obvious to anyone who knows him, that he's just being a jackass.
- simoncion 11y agoMe? I would laugh at him. Everyday FOD [0] will do far more damage than an impact with a .22. [0] Foreign Object Damage. In this case, at-speed impacts with grit, ice, and whatever.
- velox_io 11y ago'Corporate types' have a lack of humour at the best of times, but that isn't what is going on here. It's the 1 in 100, 1 in 1,000,000 chance that the tweet wasn't a joke, but a real threat. They can't take the risk that they knew about it, and didn't take it seriously and 100's died.
- makeitsuckless 11y agoI have a problem with the often used phrase "legitimate researchers", because it suggests that certain freedoms should only apply to certain people. "legitimate researcher" is not a specific job, researching is an activity any citizen can and should be free to conduct within the confines of the law, and all of that is "legitimate". The whole "legitimate researcher" creates a huge loophole through which the powers that be can create some kind of registered researcher status, with the obvious consequences for everyone else.
- dendory 11y agoI don't think they mean legitimate as professional or industry recognized, but more as a way to distinguish from an actual bad guy hacking for criminal intents and then claiming he is a researcher and should have carte blanche.
- sneak 11y agoResearching with criminal intent is also legitimate research provided no laws are broken.
- loup-vaillant 11y agoIn France there is a crime labelled "association de malfaiteurs" (criminal's gathering). Fantasizing about a crime is allowed. But actually laying out plans, watching the neighbourhood, or performing concrete steps towards the crime with the intent of actually performing it… well, that is forbidden. Makes sense to me. Mere thoughts should never be forbidden, but acting on a criminal intent, even if the acts, taken independently, wouldn't be forbidden, is something else entirely. First, actions can be punished. Second, actions are actual evidence for the intent.
- sneak 11y agoWhat you are describing is thoughtcrime. Criminal intent is not illegal. Only actions.
- notduncansmith 11y agoAs someone who's flying United today, this is a bit disconcerting. Note to self: don't crack jokes.
- throwaway232 11y agosuch is life in the land of the free!
- mml 11y agoMilos Kundera has an entire book "The Joke", about this very thing. I often think about it when contemplating saying something ill-advised.
- liffingford 11y agoAre you one of those guys who does super stupid stuff then tries to defend yourself by saying 'bro! it was just a joke!'
- rdlecler1 11y agoKnock knock. Who's there? The Gesapto The Gestapo Who? It is we who will be asking the questions!
- tptacek 11y agoReally dumb. Really dumb of this security consultant to have bragged about tampering with airplane control systems in the middle of a flight. Really dumb of EFF to make a cause célèbre of him. EFF's analysis of this situation seems to revolve around the consultant's intent. He's a security researcher, ego not a real threat, and undeserving of scrutiny. I'd have thought that EFF would be better acquainted with pentesters by now. Anyone who spends a lot of time with pentesters knows that when it comes to disrupting or disabling critical systems, intent doesn't have much to do with the outcome of a pentest. We break shit all the time without trying. We break shit even when we're trying not to. Smart clients who have spent the last decade working with pentesters often have e-l-a-b-o-r-a-t-e rules of engagement designed to avoid prod disruption. We still break shit in prod, even when we follow the letter of the rules. So this goofy tweet the consultant sends: is it what you'd expect right before a terrorist crashes a plane? Of course not. But is it exactly what you'd expect right before some idiot trips a bug that does something to force an emergency landing? It absolutely is. Is it outside the realm of possibility that some control system somehow bridged to airplane wireless would have a problem that would allow a passenger to deploy the oxygen masks? It is not. Would that design flaw be idiotic? Yes it would. Does the idiocy of that design flaw mean it's unlikely to be there? No it does not. Virtually every system you interact with in the world has idiotic design flaws. Wait, that's not a question. "Does virtually every system..." YES. YES THEY DO. So imagine that, just like in pretty much every pentest ever, this consultant is merely poking around trying to see what functionality is exposed to him through this design flaw. No intention to make anything happen at all. Now imagine he purely by accident does manage to, I don't know, deploy oxygen masks. No harm done (stipulate nobody on the flight has a severe heart condition). Plane integrity undamaged. Plane fully capable of continuing along its itinerary. Nonetheless, what's the likely outcome here? Unplanned emergency landing. There probably is no such vulnerability. But then you have to ask yourself: who in United's flight operations chain of command is qualified to assess whether there is? Really, who in the entire flight safety chain of command, from flight captain through FAA to DOJ, is? There aren't that many people in the world who know how EICAS messages work. All they have to work with is the hypothetical. "Unexpected behavior found in in-flight wireless. Tinkering in process!" That's a threat! I think the thing that frustrates me most about this story is the fact that it's probably not possible to launch anything more than nuisance attacks from the vantage point of a passenger. And yet because of our (admirable and effective) attitude with regard to flight safety, those nuisance attacks are all economically devastating. In other words, this kind of "research" is unhelpful. Where EFF made me flip out this time: Nevertheless, United’s refusal to allow Roberts to fly is both disappointing and confusing. As a member of the security research community, his job is to identify vulnerabilities in networks so that they can be fixed. Wat. United's decision here is extremely easy to understand: they do not want to offer service to someone who was willing to disrupt a flight to make a point. Meanwhile: the "security research community" does not deputize its members, make them swear an oath, and given them a little tin badge. No part of this guy's "job" gave him the right to tamper with the computer systems on an aircraft. If EFF thinks that's what it means to be a vulnerability researcher, they are broken. They cannot advocate effectively for legitimate research while promoting the idea of special rights for people who call themselves security researchers.
- h4x3r 11y agoThe War against security researchers "hackers" has began, and I think the reason is because in "information war" the hackers are a threat. http://blog.erratasec.com/2015/01/obams-war-on-hackers.html http://blog.erratasec.com/2015/01/obams-war-on-hackers.html Note: They keep saying "HACKERS" and not criminals!
- billpollock 11y agoUnited Airlines is THE worst. http://www.nytimes.com/2013/01/29/business/passenger-vs-airline-policy-stand-offs-in-the-air.html http://www.nytimes.com/2013/01/29/business/passenger-vs-airl... In my case they almost apologized for having had Federal Air Marshals detain me.
- liffingford 11y agoI don't get what happened. The airline put up a sign saying don't go past this curtain. You went past the curtain. You were surprised when they told you off? The people in business class (or whatever it was in front of you) have paid more to be less crowded. Therefore the airline puts up a curtain and asks you not to cross it. That seems super reasonable to me. You don't like the curtain and sign. A reasonable response might be to fly a different airline or pay to get in that section next time. Deliberately ignoring the sign, going out of your way to tell them that you're going to do that, and then filming the poor guy when he stops you, that seems pretty far off into psycho land to be honest. In fact, I'm glad that they went out of their way to protect the people in the seats in front of you from being unnecessarily bothered by people like you hiking past. Am I missing part of the story?
- getsat 11y agoWhy do you think your selfish and egotistical (and apparently unlawful) actions should have no consequences? >Mr. Pollock conceded that he told the flight attendant he planned to ignore the sign, which other travelers had questioned in online travel forums. Do you also drive around on public roads without a licence stating the "Right to Travel" like people also talk about online?
- yeukhon 11y agoI second the motion that this is dumb. But weakness of airplane security is not unknown. Numerous presentations had been done at BlackHat and DefCon over the last few years, and people generally received good responses. But does anyone know if these presenters ever contacted the airline authority before they went on stage?
- tripzilch 11y agoReminds me of this 2012 story about two British tourists being barred from their flights for tweeting they were going to "destroy America" (slang for "having a blast"): http://www.bbc.com/news/technology-16810312 http://www.bbc.com/news/technology-16810312 I wonder how they connect the tweets to the persons? Do they actually actively search Twitter for keywords, and when they hit they dig into it until they have found a name, which they check against their passengers lists? There's probably some shortcuts they can use, but it still seems weird to me.
- rdtsc 11y agoI would guess they go off passenger list first, then expand from there. Find Facebook, twitter, other social accounts. Then scour for keywords. "So I saw you threatened to 'Bomb that test' when you were in college in 2001, Mrs/Mr tripzilch, please step over here and follow this officer to the enhanced interrogation area".
- deleted 11y ago[deleted]