<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dreamliner]]></title>
    <link>http://securityratty.com/tag/dreamliner</link>
    <description></description>
    <pubDate>Sun, 06 Jan 2008 13:43:41 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Hacking the Boeing 787]]></title>
      <link>http://securityratty.com/article/7ca828ab0ae2ad8e333d11c067a82c52</link>
      <guid>http://securityratty.com/article/7ca828ab0ae2ad8e333d11c067a82c52</guid>
      <description><![CDATA[The news articles are pretty sensational: The computer network in the Dreamliner's passenger compartment, designed to give passengers in-flight internet access, is connected to the plane's control,...]]></description>
      <content:encoded><![CDATA[<p>The <a href="http://www.wired.com/politics/security/news/2008/01/dreamliner_security">news articles</a> are pretty sensational:</p>

<blockquote>The computer network in the Dreamliner's passenger compartment, designed to give passengers in-flight internet access, is connected to the plane's control, navigation and communication systems, an FAA report reveals.</blockquote>

<p><a href="http://www.theinquirer.net/gb/inquirer/news/2008/01/06/boeing-787-vulnerable-hacking">And</a>:</p>

<blockquote>According to the U.S. Federal Aviation Administration, the new Boeing 787 Dreamliner aeroplane may have a serious security vulnerability in its on-board computer networks that could allow passengers to access the plane's control systems.</blockquote>

<p><a href="http://www.smh.com.au/news/news/dreamliner-hacking-scare/2008/01/07/1199554534790.html">More</a> <a href="http://www.theregister.co.uk/2008/01/07/boeing_dreamliner_hacker_concerns/">press</a>.</p>

<p>If this is true, this is a very serious security vulnerability.  And it's not just terrorists trying to control the airplane, but the more common software flaw that causes some unforeseen interaction with something else and cascades into a bigger problem.  However, the <a href="http://frwebgate6.access.gpo.gov/cgi-bin/waisgate.cgi?WAISdocID=486816490816+0+0+0&WAISaction=retrieve">FAA</a> <a href="http://cryptome.org/faa010208.htm">document</a> in the <i>Federal Register</i> is not as clear as all that.  It does say:</p>

<blockquote>The proposed architecture of the 787 is different from that of existing production (and retrofitted) airplanes. It allows new kinds of passenger connectivity to previously isolated data networks connected to systems that perform functions required for the safe operation of the airplane. Because of this new passenger connectivity, the proposed data network design and integration may result in security vulnerabilities from intentional or unintentional corruption of data and systems critical to the safety and maintenance of the airplane. The existing regulations and guidance material did not anticipate this type of system architecture or electronic access to aircraft systems that provide flight critical functions. Furthermore, 14 CFR regulations and current system safety assessment policy and techniques do not address potential security vulnerabilities that could be caused by unauthorized access to aircraft data buses and servers. Therefore, special conditions are imposed to ensure that security, integrity, and availability of the aircraft systems and data networks are not compromised by certain wired or wireless electronic connections between airplane data buses and networks.</blockquote>

<p>But, honestly, this isn't nearly enough information to work with.  Normally, the aviation industry is really good about this sort of thing, and it doesn't make sense that they'd do something as risky as this.  I'd like more definitive information. </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=UBKEE3D"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=UBKEE3D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3q4ncnD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3q4ncnD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FeSWAHD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FeSWAHD" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 07 Jan 2008 09:38:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/airplane data buses">airplane data buses</category>
      <category domain="http://securityratty.com/tag/on-board computer networks">on-board computer networks</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/control systems">control systems</category>
      <category domain="http://securityratty.com/tag/communication systems">communication systems</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/aircraft data buses">aircraft data buses</category>
      <source url="http://www.schneier.com/blog/archives/2008/01/hacking_the_boe.html">Hacking the Boeing 787</source>
    </item>
    <item>
      <title><![CDATA[Boeing Dreamliner could be vulnerable to hackers]]></title>
      <link>http://securityratty.com/article/b6c937beb0a100419f66fe9097f33123</link>
      <guid>http://securityratty.com/article/b6c937beb0a100419f66fe9097f33123</guid>
      <description><![CDATA[The electronics of Boeing's new 787 Dreamliner jet could be vulnerable to hackers due to the way critical flight systems are linked with those used by passengers, the U.S. Federal Aviation...]]></description>
      <content:encoded><![CDATA[The electronics of Boeing's new 787 Dreamliner jet could be vulnerable to hackers due to the way critical flight systems are linked with those used by passengers, the U.S. Federal Aviation Administration has warned.]]></content:encoded>
      <pubDate>Sun, 06 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal aviation administration">federal aviation administration</category>
      <category domain="http://securityratty.com/tag/critical flight systems">critical flight systems</category>
      <category domain="http://securityratty.com/tag/dreamliner jet">dreamliner jet</category>
      <category domain="http://securityratty.com/tag/hackers due">hackers due</category>
      <category domain="http://securityratty.com/tag/vulnerable">vulnerable</category>
      <category domain="http://securityratty.com/tag/passengers">passengers</category>
      <category domain="http://securityratty.com/tag/electronics">electronics</category>
      <source url="http://www.networkworld.com/news/2008/010708-boeing-dreamliner-could-be-vulnerable.html?fsrc=rss-security">Boeing Dreamliner could be vulnerable to hackers</source>
    </item>
    <item>
      <title><![CDATA[Boeing's New 787 May Be Vulnerable to Hacker Attack]]></title>
      <link>http://securityratty.com/article/23eca575322577abaa4df7c10d338cf4</link>
      <guid>http://securityratty.com/article/23eca575322577abaa4df7c10d338cf4</guid>
      <description><![CDATA[Boeing's new 787 Dreamliner passenger jet may have a serious security vulnerability in its onboard computer networks that could allow passengers to access the plane's control systems,The computer...]]></description>
      <content:encoded><![CDATA[Boeing's new 787 Dreamliner passenger jet may have a serious security vulnerability in its onboard computer networks that could allow passengers to access the plane's control systems,The computer network in the Dreamliner's passenger compartment, designed to give passengers in-flight internet access, is connected to everything the plane controls.]]></content:encoded>
      <pubDate>Sun, 06 Jan 2008 13:43:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dreamliner">dreamliner</category>
      <category domain="http://securityratty.com/tag/dreamliner passenger jet">dreamliner passenger jet</category>
      <category domain="http://securityratty.com/tag/plane">plane</category>
      <category domain="http://securityratty.com/tag/plane controls">plane controls</category>
      <category domain="http://securityratty.com/tag/onboard computer networks">onboard computer networks</category>
      <category domain="http://securityratty.com/tag/passenger compartment">passenger compartment</category>
      <category domain="http://securityratty.com/tag/security vulnerability">security vulnerability</category>
      <category domain="http://securityratty.com/tag/control systems">control systems</category>
      <category domain="http://securityratty.com/tag/computer network">computer network</category>
      <source url="http://digg.com/security/Boeing_s_New_787_May_Be_Vulnerable_to_Hacker_Attack">Boeing's New 787 May Be Vulnerable to Hacker Attack</source>
    </item>
  </channel>
</rss>
