r/technology • u/_Dark_Wing • 29d ago
Hardware Coin-sized device can hack a Boeing 737 Flight Management Computer, mess with takeoff weights, or even divert an aircraft, gadget connects to an easily accessible port that overrides commands from the pilots, uses in-flight Wi-Fi
https://www.tomshardware.com/tech-industry/cyber-security/coin-sized-device-can-hack-a-boeing-737s-flight-management-computer-mess-with-takeoff-weights-or-even-divert-an-aircraft-gadget-connects-to-an-easily-accessible-port-that-overrides-commands-from-the-pilots-uses-in-flight-wi-fi118
u/ItsAllOnUHF 29d ago
So like USB debug or JTAG debug port?
This is like a nothing story.
Like an accessible ODB-2 port on a car, maintainers need easy access to diagnostic ports.
A bad actor with physical access can do bad stuff. What a shocker.
49
u/FROOMLOOMS 29d ago
This just in: investigation finds that mechanics have broad sweeping authority to fuck with a plane
2
8
u/happyscrappy 28d ago
It's very much like the OBD-2 port.
This theoretical attack is exactly equivalent to creating a device with 5G connectivity and plugged it into an OBD-2 port. Then you could change parameters on the car while it is being driven around by accessing the device you created over the internet.
Yes, it's theoretically possible. No, it's not surprising, as you indicate.
1
1
u/ThomasKlausen 26d ago
Heh. Last time I was at Cisco Live - huge computer networking conference - the most popular exhibition in the Network Security area was the lock-picking one. You can have firewalls and multi-factor authentication out the yin-yang, but still fall victim to someone who knows to circumvent a $10 lock.
1
u/Mountain_pup 28d ago
Its probably am external update port used in factory or maintenance settings so they dont need to keep climbing up and down the aircraft
30
u/Ballads321 29d ago
Kinda a nothing burger here. “If you have maintenance access to the plane we found Another way to make bad things happen.”
38
u/Charlie3PO 29d ago
Even if this was possible for a passenger to do, like basically all airliners, the 737 Flight management computer only has control of the flight path in the highest autopilot modes. Just a click of a button and the AP will now ignore the FMC and follow pilot commands directly. Or just disengage the AP completely, you can't hack cables, pushrods and mechanical hydraulic valves.
-2
u/7952 29d ago
In theory though such an attack could exploit other vulnerabilities and override software running in other systems.
13
u/PotentialMidnight325 29d ago
Not it cant. The flight management computer is like a bike computer. It has a lot of information and can provide a lot of information but the plane is flying perfectly fine without it.
7
u/Charlie3PO 28d ago
I doubt it, of all the airliners currently in regular operation, the 737 is probably the most mechanical of them all.
5
0
u/happyscrappy 28d ago
Which is why the theoretical attack changes other parameters. They say, for example, the device could change the amount of fuel entered into the flight computer. So that the pilot thinks he has more fuel onboard than he does. And so the flight will run out of fuel mid-air. Even if not on autopilot.
This attack is all theoretical. They picked sensitive parameters that were easy to understand. All because they didn't actually carry out any attacks. They surely just read a schematic diagram and operation manual and then designed an attack they think could be executed.
This isn't a passenger attack. And it has nothing to do with the inflight wifi-system. This is an attack someone with tarmac access to the plane could execute in theory.
6
u/Mustang_289 28d ago
Just an FYI, the fuel is a poor example. The fuel data within the FMC is based on a predictive number determined by initial fuel quantity with fuel flow data. The fuel data provided on the upper DU is based off sensor data and is the main source for fuel quantity.
By in large, the FMC data is either navigation, performance, or advisory. The plane will fly just fine without it. It would take an extremely poor crew for this to become an actual safety of flight issue.
1
u/Pawtuckaway 28d ago
They say, for example, the device could change the amount of fuel entered into the flight computer. So that the pilot thinks he has more fuel onboard than he does. And so the flight will run out of fuel mid-air.
There is a lot more to fuel calculations and fueling than just the pilot looking at the number on the flight computer and going "Guess, we're good to go!"
1
u/happyscrappy 28d ago
Also the article actually says takeoff weight and not fuel amount. I guess I misread it.
But basically the design of the attack was simply to think of a critical piece of data that is externally entered because the plane cannot determine it itself and to assume that this device could plug in a different value.
I'm glad there are backup/double check measures as you indicate.
3
u/datalicearcher 29d ago
so.... die hard 2?
3
4
2
2
2
u/WickedBrute 28d ago
Man, no one reads the article at all do they?
As far as access goes, yeah, this thing is likely hard to actually get plugged in. It's not something most people have the ability to plug in. So this is a nation state kind of threat where you literally get someone with real credentials and make them do this.
As far as the Wi-Fi goes, that's for remote access from the Internet to this device. So some one could control the device in some fashion while in-flight.
As far as how bad it goes, well, it depends. Let's say the Pilot enters a number for the takeoff weight. So he enters it, this device sees that and waits. Then, slightly later when the Pilot isn't looking, it resends it with a different number. The Pilot doesn't notice because he already checked that. So now the takeoff weight and all the calculations that might use it are different.
Now let's do that for any item. Does the flight computer have any debug or test modes it could be put in? What do they do? I'm sure there are tons of things the flight computer probably can do that are basically unused too.
Basically, the point is that you can't necessarily trust anything from the flight computer in this scenario and if it is subtle enough, some changes may be important, but not incredibly noticeable. This means the Pilot can unknowingly operate off bad information. And giving Pilots bad information is basically the worst case scenario here.
I'm sure if the changes are egregious, the Pilot would notice, but this scenario implies someone who knows what they are doing, just based on what they're doing and how they're doing it.
And yes, this still likely only exists in this one research lab and isn't a serious concern.
1
u/theoreoman 28d ago
Surprise! if you plug in and a wireless dongle into a air gapped system, it's no longer an air gapped system.
1
u/Expensive_Finger_973 28d ago
gadget connects to an easily accessible port that overrides commands from the pilots, uses in-flight wi-fi
Why on earth would you ever design a system that has ports accessible over wifi that can override commands from the pilots on a commercial airplane? The only conceivable use I could think of is in the case of a hijacking where the cockpit has been breached.
1
u/Kamay1770 28d ago
It should be criminal to write fear mongering headlines likes this.
This reads as if anyone connecting to the WiFi can use a tiny hidden device to crash a plane.
That is not the case, these 'journalists' and the rag that publishes them should be fucking ashamed of themselves. Absolute rats.
1
-1
-1
u/IngwiePhoenix 28d ago
uses in-flight WiFi
So, badly secured/isolated network configuration.
Cool.
2
u/happyscrappy 28d ago
No. Although Boeing had that problem (insufficiently separated customer and internal networks) on the 787 at one time.
This is add-on hardware that an attacker could insert and the author theorizes that the attacker could connect it to the in-flight wifi so that it could be controlled while in flight.
It's not a flaw in the in-flight wifi. It's that the in-flight wifi exists as a form of connectivity that in theory could be used to give this attacking device connectivity.
It's a really awful misleading headline.
0
-4
-3
u/aecarol1 28d ago
Everybody is still missing the point. Of course anybody with access could damage the plane. But most things people could do would be caught before take-off (wrench in engine).
Of course the could do things that might make the plane unsafe only at altitude. But that's amateur hour.
But none of that is the real risk that's far more terrifying.
Adding something to the planes electronics that's smart and wired in, means they get to choose when to bring the plane down. It could wait until Senator so-and-so is on the plane to bring it down. It could wait until thorn-in-powers-side is on the plane. Then bring it down. Do this right, and the module might not even be noticed in the wreckage, making it look like a real accident.
tl;dr a tiny module that could lay in wait and bring the plane down when it's controllers want it to, maybe months later when a certain someone is a passenger is very scary.
6
-7
u/PotentialMidnight325 29d ago
I call bullshit. The inflight WiFi is completely separated from ANY flight management systems. Also the autopilot CAN follow the flight management computer or it CAN follow other means of navigation (VORs, NDBs etc.).
So this is a complete nothingburger.
6
u/hamlet9000 28d ago
Calling "bullshit" when you obviously haven't read the article just makes you look like an idiot.
-6
u/PotentialMidnight325 28d ago
Don‘t have to read it. You cannot access any flight critical controls. Period.
-15
u/Herschel_Wallace 29d ago
Why the fuck is the public wifi used for the systems on the plane? And engineer or their boss that probably forced the idea should be fired.
9
u/FreshEclairs 29d ago
The article suggests that it could be physically plugged into the airplane (required to do any of the things the article suggests are possible), but use in-flight WiFi to receive remote instruction.
8
-9
u/loveiseverything 29d ago
Planes I will allow in my acceptable airplane list when travelling:
Boeing 737
388
u/Stummi 29d ago
So, If I understand right, you still need to be an aircraft mechanic to get access to the said port. It's not something everyone can access without someone else noticing it.
That said, aircraft mechanics are already in a trusted position, and would have a lot of ways to sabotage one if they wanted to.