4 ms·
"Bugs on onboard Wi-Fi, entertainment systems or avionics" are not eligible for bounties. It's very strange to see website timing attacks as worth rewarding, b
by bhuga 11y ago
"Bugs on onboard Wi-Fi, entertainment systems or avionics" are not eligible for bounties.
It's very strange to see website timing attacks as worth rewarding, but not avionics. Perhaps they'd rather not incentivize people to attack airplanes in flight?
- akerl_ 11y agoI'm pretty sure that's the reason. While identifying vulnerabilities in the actual airplane is high-value, it's also high-risk. Even the most cautious researcher can easily affect a system being investigated, which is potentially financially costly for a website and potentially fatal for an airplane in the air.
- cortesoft 11y agoYes, I am pretty sure it is a safety thing. That would be very dangerous to encourage people to try to hack a flight in the air.
- shiggerino 11y agoIt would be a good idea to provide access to that sort of equipment on the ground. Bugs that can lead to loss of life should be of much higher priority than bugs that can merely lead to loss of profit on a web site. Though the avionics industry would obviously balk at the proposition, those systems are already spectacularly vulnerable, and they'd hate to lose face.
- danjayh 11y ago"...those systems are already spectacularly vulnerable..." Absolutely untrue, unless you have physical access to them (at which point any system is vulnerable). In truth, the maintenance port on a 787, for example, (which is the only place you could feasibly get the kind of access you'd need to even attempt an exploit) is located in the avionics bay. At the point that an unauthorized party has gained access to the avionics bay, you've got a much bigger problem than software exploits. If you're referring the Chris Roberts' dubious "Planes, Trains, and Automobiles" grrcon talk ... well, I'm sorry, but claiming that you've "made friends <giggle>" with an airplane doesn't seem very substantive to me. Avionics code is some of the most extensively tested code in the world, with 100% statement and decision coverage, 100% requirements test coverage, extensive robustness testing, and somewhere between a handful and hundreds of eyes having reviewed every single line (depending on criticality level). Additionally, design constraints are followed for high criticality software that simply eliminate many types of attacks - no dynamic allocation, mathematically provable static stack analysis, etc. etc. etc. (get yourself a copy of DO-178B and read it if you really want to know all the details). I would bet a significant amount of money that the defect rate per N lines of code in avionics software is probably substantially lower than almost all other commercial software. There's also the fact that on modern aircraft using Ethernet based networks, message routing and authentication are implemented in both hardware and software at multiple layers by independent teams, which greatly reduces the chances of a common fault that allows a successful attack (even if you could gain physical access to the network).
- verelo 11y agoAs much as I agree with the comments below/above about it being a safety issue, I would argue it is possible that a contributing factor is in flight WiFi being so flakey that it would be too expensive to run the program on this asset.
- saryant 11y agoMy guess is wifi and entertainment are excluded because United doesn't build those. Depending on the aircraft they're provided by Panasonic, LiveTV, etc. in the case of LiveTV (United's vendor for DirecTV) it's even seller-financed. United probably isn't interested in paying for someone else's bugs.
- ArkyBeagle 11y agoAccess to the media for futzing with the avionics better be very [expletive deleted]ing hard to get.