Go Back  Airline Pilot Central Forums > Pilot Lounge > Safety
Feds: EICAS hacked in-flight >

Feds: EICAS hacked in-flight

Search

Notices
Safety Accidents, suggestions on improving safety, etc

Feds: EICAS hacked in-flight

Thread Tools
 
Search this Thread
 
Old 05-16-2015, 02:08 PM
  #1  
Gets Weekends Off
Thread Starter
 
Joined APC: Oct 2014
Position: Downward-Facing Dog Pose
Posts: 1,537
Default Feds: EICAS hacked in-flight

Highlights...

Chris Roberts, a security researcher with One World Labs, told the FBI during an interview in February that he had hacked the in-flight entertainment system, or IFE, on the airplane and overwrote code on the plane’s Thrust Management Computer while aboard the flight. He was able to issue a climb command and make the plane briefly change course.

He told WIRED that he did access in-flight networks about 15 times during various flights but had not done anything beyond explore the networks and observe data traffic crossing them. According to the FBI affidavit, however, when he mentioned this to agents last February he told them that he had briefly commandeered a plane during one of those flights.

He told the FBI that the period in which he accessed the in-flight networks more than a dozen times occurred between 2011 and 2014.

He obtained physical access to the networks through the Seat Electronic Box, or SEB. These are installed two to a row, on each side of the aisle under passenger seats, on certain planes. After removing the cover to the SEB by “wiggling and Squeezing the box,” Roberts told agents he attached a Cat6 ethernet cable, with a modified connector, to the box and to his laptop and then used default IDs and passwords to gain access to the inflight entertainment system. Once on that network, he was able to gain access to other systems on the planes.
Feds Say That Banned Researcher Commandeered a Plane | WIRED Magazine
SayAlt is offline  
Old 05-16-2015, 06:47 PM
  #2  
Gets Weekends Off
 
Desert Sky's Avatar
 
Joined APC: Feb 2009
Posts: 264
Default

He hacked way more than just EICAS. The Feds say he caused one of the engines to increase thrust and the plane subsequently yawed.
Desert Sky is offline  
Old 05-16-2015, 06:54 PM
  #3  
Line Holder
 
Joined APC: Jan 2013
Posts: 25
Default

"...that's weird..." **autopilot/autothrottle disconnect**
Final Fix is offline  
Old 05-16-2015, 07:01 PM
  #4  
Stuck Mic
 
Firsttimeflyer's Avatar
 
Joined APC: Dec 2013
Posts: 1,059
Default

Wow, seems like a look into securing those boxes in a different location or with specialized screws/locks is in order. On one hand it is good to know the information that could be used to compromise safety, but it seems like this guy was ready to push it to the next level and see what types of things he could do in real life without understanding the potential consequences.
Firsttimeflyer is offline  
Old 05-16-2015, 07:04 PM
  #5  
Organizational Learning 
 
TonyC's Avatar
 
Joined APC: Nov 2005
Position: Directly behind the combiner
Posts: 4,948
Default

And Babe the Blue Ox was in the cargo hold.






.
TonyC is offline  
Old 05-17-2015, 05:45 AM
  #6  
Gets Weekends Off
 
Bilsch's Avatar
 
Joined APC: Jul 2013
Position: FAA ATSI VSRP ERC
Posts: 218
Default

I'm calling BS on this. Just because he told them he did that does not mean it can or did happen.
Bilsch is offline  
Old 05-17-2015, 11:33 AM
  #7  
Prime Minister/Moderator
 
rickair7777's Avatar
 
Joined APC: Jan 2006
Position: Engines Turn Or People Swim
Posts: 40,389
Default

Originally Posted by Bilsch
I'm calling BS on this. Just because he told them he did that does not mean it can or did happen.

They'll probably find out one way or the other...the airplanes computers should have a record of it.

The good news is that this guy is a "white hat" and is probably far more technically skilled than anyone the bad guys could employ. But there's no guarantee that will be the case forever...

IFE and cabin wifi probably needs to be physically separated from all flight ops systems. That's going to cost a few bucks.
rickair7777 is offline  
Old 05-17-2015, 11:39 AM
  #8  
Prime Minister/Moderator
 
rickair7777's Avatar
 
Joined APC: Jan 2006
Position: Engines Turn Or People Swim
Posts: 40,389
Default

Originally Posted by Firsttimeflyer
but it seems like this guy was ready to push it to the next level and see what types of things he could do in real life without understanding the potential consequences.

Yes, very bad idea on his part. He'll gain some street cred in his line of work from this stunt but it may not be worth the cost of defending a federal felony and possible jail time.
rickair7777 is offline  
Old 05-17-2015, 12:47 PM
  #9  
Gets Weekends Off
 
Joined APC: Jul 2013
Posts: 4,784
Default

Originally Posted by RPJ80
He hacked way more than just EICAS. The Feds say he caused one of the engines to increase thrust and the plane subsequently yawed.
^^^^, "Hacking" an "EICAS" or an "ECAM" would mean he got it show porn

Or rather, was able to make the symbol generators display something other than engine/systems data, or any of the reversionary display modes.

Originally Posted by rickair7777
IFE and cabin wifi probably needs to be physically separated from all flight ops systems.
Under the assumption that currently isn't of course.
John Carr is offline  
Old 05-17-2015, 07:54 PM
  #10  
Prime Minister/Moderator
 
rickair7777's Avatar
 
Joined APC: Jan 2006
Position: Engines Turn Or People Swim
Posts: 40,389
Default

Originally Posted by John Carr

Under the assumption that currently isn't of course.
My understanding is that on many newer planes it shares comms channels with critical systems...ie airlines too cheap to install separate SATCOM antennas.
rickair7777 is offline  
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Cubdriver
Hiring News
0
02-05-2013 08:00 AM
CrakPipeOvrheat
Regional
94
02-12-2012 08:14 PM
ebuhoner
Flight Schools and Training
35
10-10-2009 09:02 AM
Longbow64
Part 135
117
07-23-2009 08:46 AM

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Your Privacy Choices