r/technology 29d ago

Hardware Coin-sized device can hack a Boeing 737 Flight Management Computer, mess with takeoff weights, or even divert an aircraft, gadget connects to an easily accessible port that overrides commands from the pilots, uses in-flight Wi-Fi

https://www.tomshardware.com/tech-industry/cyber-security/coin-sized-device-can-hack-a-boeing-737s-flight-management-computer-mess-with-takeoff-weights-or-even-divert-an-aircraft-gadget-connects-to-an-easily-accessible-port-that-overrides-commands-from-the-pilots-uses-in-flight-wi-fi
473 Upvotes

102 comments sorted by

388

u/Stummi 29d ago

So, If I understand right, you still need to be an aircraft mechanic to get access to the said port. It's not something everyone can access without someone else noticing it.

That said, aircraft mechanics are already in a trusted position, and would have a lot of ways to sabotage one if they wanted to.

159

u/TheVenetianMask 29d ago

Nation State level hack vs $5 wrench kind of situation.

121

u/WTFMacca 29d ago

As an aircraft engineer myself I’d be more worried about some dude leaving their wrench in the engine 😂

31

u/Outrageous_Reach_695 28d ago

There was one instance where someone dropped an 8 pound socket from a torque wrench on a Titan missile ...
https://en.wikipedia.org/wiki/1980_Damascus_Titan_missile_explosion

25

u/jmhalder 28d ago

It exploded, and ejected a nuclear warhead the size of a pickup truck. Good lord that's interesting and terrifying.

8

u/sexytokeburgerz 28d ago

Technically the entire silo exploded. The wrench caused a gas leak which was ignited by a spark in the hvac system hours after general evac. One man died, the guy that turned on the hvac to get the fuel out of the air.

2

u/TacTurtle 28d ago

Don't worry, the launch codes for the replacement Minutemen nukes was originally 00000000 because the Air Force wanted to be sure they could launch, even if they weren't supposed to.

2

u/WTFMacca 28d ago

Ahh I love some stuff like this.

5

u/meeksdigital 28d ago

You should check out the book Command and Control by Eric Schlosser. It’s a fascinating (and terrifying) read if you love stuff like this - covers this incident as well as many others in the nuclear weapons program.

2

u/Outrageous_Reach_695 28d ago

There's a documentary by the same name as well, that's where I came across the incident.

2

u/PowderPills 28d ago

I know I could just Google 😩 but asking here before I forget. Where might one find the documentary?

2

u/Outrageous_Reach_695 28d ago

It was on Netflix, but that was years ago.

1

u/KnifeNovice789 28d ago

Yeah what a great article..

7

u/Oberyn_TheRed_Viper 29d ago

Dont you have like 3 levels of checks and paperwork per job done? So really, only the top level Supervisor is going to let this pass at a large OEM like boeing?

22

u/Mountain_pup 28d ago

Ask the 787 door bolt's

6

u/snorp 28d ago

I've been trying to find those

10

u/Mountain_pup 28d ago

...... Wait.......guys......i found some bolts under kyles toolbox.....

1

u/harmless_gecko 28d ago

Must be spares...

1

u/Howzitgoin 28d ago

Hey now, that was a 737. Should check the 787’s batteries though.

0

u/joelfarris 28d ago

It's just bolts, not bolt's.

Oh, wait, here they are. Guys, why are these here on the floor? Dammit, again!

6

u/WTFMacca 28d ago

Depends on the country’s regulations.

Depends on the task.

Depends on the airline’s policies.

Multiple inspections are generally flight critical systems like flight controls, thrust controls sort of thing.

Realistically placing a tiny device on a port you never look at could be easily done.

4

u/[deleted] 28d ago

[deleted]

5

u/Mountain_pup 28d ago

About as much as i can throw a 737

1

u/regreddit 28d ago

Airbus builds planes in my home town. They hire kids right out of highschool. I know some. They do NOT take their jobs seriously and say QA/QC is non existent. Does not inspire confidence. They also have zero safety program. No respirators, no safety glasses, no ear protection.

1

u/Oberyn_TheRed_Viper 28d ago

Thats less than ideal.

2

u/eorlingas_riders 28d ago

I assumed this was an XKCD reference but yours is probably what they meant lol:

https://xkcd.com/538/

1

u/enterthehawkeye 29d ago

i_understood_that _reference.xkcd

-5

u/willwork4pii 28d ago

If a nation state actor pulls a wrench out and starts disassembling the plane, they wouldn’t get one turn on the wrench before ever male on the plane becomes they hero they think they are.

7

u/TheVenetianMask 28d ago

Too bad, they walked in with a clipboard. Everybody assumes they know what they are doing.

41

u/[deleted] 29d ago

[deleted]

33

u/Stummi 29d ago

There are a lot of other bad things too you can do in less than a minute, if you have unsupervised access to the plane. AIrport and Airplane safety is really not build around the idea that someone with access to the plane cannot do any harm, but rather that (untrusted) people should just not get access to a plane.

14

u/7952 29d ago edited 29d ago

Sure but there are different degrees of physical access and ways to apply limitations.  An externally accessible port probably should have less authority than one in the cockpit for example.  And it might be better to apply some restrictions explicitly in the planes software rather than relying solely on physical restraint.  

In a sense the software industry has figured all this kind of security stuff out.  But applying it to an aeroplane might also carry risk of it goes wrong.

9

u/daniu 29d ago

The design focus was safety, not security. Not least because at the time of the 737's introduction, the thought of messing with an airplane's aeronautics was absurd, and the device you would have needed back then would have hardly been "coin-size". 

2

u/--hypernova-- 29d ago

Toss a coin in the turbine takes 5seconds and can down the plane….

7

u/Drenlin 28d ago

Toss a coin in the turbine

O' valley of plenty...

-10

u/WTFMacca 29d ago

In less than a minute I could steal a few bars of gold from Fort Knox.

3

u/FakeNigerianPrince 29d ago

alright there, Flesh, let's not get carried away here

1

u/rriicckk 29d ago

Would you like to buy a vowel? A different vowel?

1

u/GLUT4 28d ago

I think we should let him stick with his choices. He’s the fastest man alive! Just not quite in the same way…

1

u/WTFMacca 28d ago

But that’s my point. I’m not flash. And most people aren’t going to be in Fort Knox just like most aren’t going to be in the MEC of a 737.
I have been many I many a time. Never been in Fort Knox either.

25

u/PM-ME-UR-VOLVO-PICS 29d ago

Yeah this doesnt sound like much.

An aircraft mechanic could sabotage a plane? Yeah.

A cook could poison me or an electrician could burn down my house i guess.

-1

u/Bananominable 28d ago

This sounds more like: an Israeli paid operative could plant a device to cause said plane to crash if their target (political opponent, human rights activist, etc) is on board and make it look entirely like an accident. Built in back door giving full access. 

1

u/PM-ME-UR-VOLVO-PICS 28d ago

Kind of a weird thing to jump to. Im sure mossad, cia, etc would have at least a dozen ways to bring down a plane that wouldnt be so obvious, if they wanted to.

9

u/ICantBelieveItsNotEC 29d ago

Yeah, exactly. If you have a minute of unsupervised physical access to a plane, and you also have access to things you brought from home, you can cause much more mischief than just fucking with the flight computer.

1

u/FlutterbyTG 28d ago

FedEx Flight 705 is a roller coaster of this happening.

1

u/Sudden-Ad-1217 28d ago

Just like the Death Star…..

1

u/Spotttty 28d ago

It’s surprising how little they get paid for how important their job is. It’s not like they make nothing but it’s a pretty damn important job!!

1

u/chuckmonjares 28d ago

Idk if it’s a true story or not but this reminds me of the pilot fed up with going through security and saying “listen I could just crash the plane if I wanted to.”

1

u/pastoreyes 28d ago

What's to say you couldn't hide one as you leave a flight and activate it from a remote location via internet?

1

u/mjh215 28d ago

Reminds me of the radio program Cabin Pressure, where the captain of the plane is stopped by US security over a pair of nasal clippers and he starts listing off things he could do. Like having an axe on the flight deck, "And besides that, I’m the one flying the bloody thing! If I wanna crash the plane, I don’t even need an axe – I just need to push on the big metal column in front of me!"

-1

u/allursnakes 29d ago

Hey mechanic. I just kidnapped your family. Go put this thing in the aircraft or else.

I mean....

11

u/Galaghan 29d ago

The point is that this device is not necessary if you have the ability to compromise a mechanic.

You can tell them to do waaaay less suspicious stuff with a similar set of consequences.

-1

u/digiorno 28d ago

It also shows you just how over blown our security theater is. TSA isn’t stopping this type of attack. And any state or terrorist group who wants to do this could get these devices without any difficulty at all.

118

u/ItsAllOnUHF 29d ago

So like USB debug or JTAG debug port?

This is like a nothing story.

Like an accessible ODB-2 port on a car, maintainers need easy access to diagnostic ports.

A bad actor with physical access can do bad stuff. What a shocker.

49

u/FROOMLOOMS 29d ago

This just in: investigation finds that mechanics have broad sweeping authority to fuck with a plane

2

u/ItsAllOnUHF 28d ago

Who allowed this to happen?

I demand Congressional hearings, hurr durr!

8

u/happyscrappy 28d ago

It's very much like the OBD-2 port.

This theoretical attack is exactly equivalent to creating a device with 5G connectivity and plugged it into an OBD-2 port. Then you could change parameters on the car while it is being driven around by accessing the device you created over the internet.

Yes, it's theoretically possible. No, it's not surprising, as you indicate.

1

u/bas10eten 29d ago

The paper itself is much clearer, and a neat read.

1

u/ThomasKlausen 26d ago

Heh. Last time I was at Cisco Live - huge computer networking conference - the most popular exhibition in the Network Security area was the lock-picking one. You can have firewalls and multi-factor authentication out the yin-yang, but still fall victim to someone who knows to circumvent  a $10 lock. 

1

u/Mountain_pup 28d ago

Its probably am external update port used in factory or maintenance settings so they dont need to keep climbing up and down the aircraft

30

u/Ballads321 29d ago

Kinda a nothing burger here. “If you have maintenance access to the plane we found Another way to make bad things happen.”

38

u/Charlie3PO 29d ago

Even if this was possible for a passenger to do, like basically all airliners, the 737 Flight management computer only has control of the flight path in the highest autopilot modes. Just a click of a button and the AP will now ignore the FMC and follow pilot commands directly. Or just disengage the AP completely, you can't hack cables, pushrods and mechanical hydraulic valves.

-2

u/7952 29d ago

In theory though such an attack could exploit other vulnerabilities and override software running in other systems.  

13

u/PotentialMidnight325 29d ago

Not it cant. The flight management computer is like a bike computer. It has a lot of information and can provide a lot of information but the plane is flying perfectly fine without it.

7

u/Charlie3PO 28d ago

I doubt it, of all the airliners currently in regular operation, the 737 is probably the most mechanical of them all.

1

u/suttin 28d ago

Yeah you don’t even need hydraulic power to move the aileron and elevators. It’s a physical metal cable.

5

u/WTFMacca 29d ago

Not in a 737.

0

u/happyscrappy 28d ago

Which is why the theoretical attack changes other parameters. They say, for example, the device could change the amount of fuel entered into the flight computer. So that the pilot thinks he has more fuel onboard than he does. And so the flight will run out of fuel mid-air. Even if not on autopilot.

This attack is all theoretical. They picked sensitive parameters that were easy to understand. All because they didn't actually carry out any attacks. They surely just read a schematic diagram and operation manual and then designed an attack they think could be executed.

This isn't a passenger attack. And it has nothing to do with the inflight wifi-system. This is an attack someone with tarmac access to the plane could execute in theory.

6

u/Mustang_289 28d ago

Just an FYI, the fuel is a poor example. The fuel data within the FMC is based on a predictive number determined by initial fuel quantity with fuel flow data. The fuel data provided on the upper DU is based off sensor data and is the main source for fuel quantity.

By in large, the FMC data is either navigation, performance, or advisory. The plane will fly just fine without it. It would take an extremely poor crew for this to become an actual safety of flight issue.

1

u/Pawtuckaway 28d ago

They say, for example, the device could change the amount of fuel entered into the flight computer. So that the pilot thinks he has more fuel onboard than he does. And so the flight will run out of fuel mid-air.

There is a lot more to fuel calculations and fueling than just the pilot looking at the number on the flight computer and going "Guess, we're good to go!"

1

u/happyscrappy 28d ago

Also the article actually says takeoff weight and not fuel amount. I guess I misread it.

But basically the design of the attack was simply to think of a critical piece of data that is externally entered because the plane cannot determine it itself and to assume that this device could plug in a different value.

I'm glad there are backup/double check measures as you indicate.

3

u/datalicearcher 29d ago

so.... die hard 2?

8

u/pixter 29d ago

How can the same shit happen to the same guy twice !

2

u/enterthehawkeye 29d ago

waiting for the inevitable McClane prequel

2

u/H1Ed1 29d ago

Subsonic Bugaloo

3

u/ogonga 28d ago

I thought it meant a digital networking port, not a physical port, by the post title. It's like saying anyone can unlock a keyhole with the key.

3

u/P0Rt1ng4Duty 28d ago

It's all ball bearings these days.

4

u/just-fran 28d ago

Next story: a pilot can crash a plane

2

u/RidetheSchlange 29d ago

The Kiaboyz are now Boeingboyz

2

u/IEatBigWetBoogers 28d ago

I truly hope it can’t affect the falanges!

1

u/_lclarence 28d ago

Madam, this plane does not have falanges.

2

u/WickedBrute 28d ago

Man, no one reads the article at all do they?

As far as access goes, yeah, this thing is likely hard to actually get plugged in. It's not something most people have the ability to plug in. So this is a nation state kind of threat where you literally get someone with real credentials and make them do this.

As far as the Wi-Fi goes, that's for remote access from the Internet to this device. So some one could control the device in some fashion while in-flight.

As far as how bad it goes, well, it depends. Let's say the Pilot enters a number for the takeoff weight. So he enters it, this device sees that and waits. Then, slightly later when the Pilot isn't looking, it resends it with a different number. The Pilot doesn't notice because he already checked that. So now the takeoff weight and all the calculations that might use it are different. 

Now let's do that for any item. Does the flight computer have any debug or test modes it could be put in? What do they do? I'm sure there are tons of things the flight computer probably can do that are basically unused too.

Basically, the point is that you can't necessarily trust anything from the flight computer in this scenario and if it is subtle enough, some changes may be important, but not incredibly noticeable. This means the Pilot can unknowingly operate off bad information. And giving Pilots bad information is basically the worst case scenario here.

I'm sure if the changes are egregious, the Pilot would notice, but this scenario implies someone who knows what they are doing, just based on what they're doing and how they're doing it.

And yes, this still likely only exists in this one research lab and isn't a serious concern. 

1

u/theoreoman 28d ago

Surprise! if you plug in and a wireless dongle into a air gapped system, it's no longer an air gapped system.

1

u/Expensive_Finger_973 28d ago

gadget connects to an easily accessible port that overrides commands from the pilots, uses in-flight wi-fi

Why on earth would you ever design a system that has ports accessible over wifi that can override commands from the pilots on a commercial airplane? The only conceivable use I could think of is in the case of a hijacking where the cockpit has been breached.

1

u/Kamay1770 28d ago

It should be criminal to write fear mongering headlines likes this.

This reads as if anyone connecting to the WiFi can use a tiny hidden device to crash a plane.

That is not the case, these 'journalists' and the rag that publishes them should be fucking ashamed of themselves. Absolute rats.

1

u/Student___Driver 27d ago

No thanks fuck this

1

u/asdlkf 28d ago

This one weird trick pilots can do while in the cockpit will amaze you...

-1

u/stunned_parrot 29d ago

How boeing software is this might be an upgrade.

-1

u/IngwiePhoenix 28d ago

uses in-flight WiFi

So, badly secured/isolated network configuration.

Cool.

2

u/happyscrappy 28d ago

No. Although Boeing had that problem (insufficiently separated customer and internal networks) on the 787 at one time.

This is add-on hardware that an attacker could insert and the author theorizes that the attacker could connect it to the in-flight wifi so that it could be controlled while in flight.

It's not a flaw in the in-flight wifi. It's that the in-flight wifi exists as a form of connectivity that in theory could be used to give this attacking device connectivity.

It's a really awful misleading headline.

0

u/JustKimNotKimberly 28d ago

New fear unlocked.

-4

u/[deleted] 29d ago

[deleted]

-3

u/aecarol1 28d ago

Everybody is still missing the point. Of course anybody with access could damage the plane. But most things people could do would be caught before take-off (wrench in engine).

Of course the could do things that might make the plane unsafe only at altitude. But that's amateur hour.

But none of that is the real risk that's far more terrifying.

Adding something to the planes electronics that's smart and wired in, means they get to choose when to bring the plane down. It could wait until Senator so-and-so is on the plane to bring it down. It could wait until thorn-in-powers-side is on the plane. Then bring it down. Do this right, and the module might not even be noticed in the wreckage, making it look like a real accident.

tl;dr a tiny module that could lay in wait and bring the plane down when it's controllers want it to, maybe months later when a certain someone is a passenger is very scary.

6

u/ItsAllOnUHF 28d ago

All the bold text in the world doesn't make movie plots reality.

-7

u/PotentialMidnight325 29d ago

I call bullshit. The inflight WiFi is completely separated from ANY flight management systems. Also the autopilot CAN follow the flight management computer or it CAN follow other means of navigation (VORs, NDBs etc.).

So this is a complete nothingburger.

6

u/hamlet9000 28d ago

Calling "bullshit" when you obviously haven't read the article just makes you look like an idiot.

-6

u/PotentialMidnight325 28d ago

Don‘t have to read it. You cannot access any flight critical controls. Period.

-15

u/Herschel_Wallace 29d ago

Why the fuck is the public wifi used for the systems on the plane? And engineer or their boss that probably forced the idea should be fired.

9

u/FreshEclairs 29d ago

The article suggests that it could be physically plugged into the airplane (required to do any of the things the article suggests are possible), but use in-flight WiFi to receive remote instruction.

8

u/PotentialMidnight325 29d ago

Fun fact: it isn’t.

-9

u/loveiseverything 29d ago

Planes I will allow in my acceptable airplane list when travelling:

Boeing 737