How easy is it to hack an airplane?

  • By Andrea Peterson The Washington Post
  • Tuesday, April 21, 2015 1:22pm
  • Business

Chris Roberts knows a lot about hacking planes, but not because he’s trying to make them fall out of the sky. His job as a security researcher is to prevent those types of breaches from happening – whether’s it’s on a plane or in a major retailer’s computer system.

But a tweet joking about “playing” with a plane’s on-board communications systems made while Roberts was on a United Airlines flight last week landed him in hot water. The FBI questioned him for several hours after he landed, and confiscated his laptop and hard drives. Over the weekend, he was blocked from boarding another United flight while on the way to speak at a security conference.

Roberts was able to book a last-minute flight on another airline. But his research raises a bigger question: How hackable are the planes that millions of worldwide travelers rely on? The answer, it turns out, is up for debate.

Planes are increasingly designed to give passengers more access to technology, mostly through in-flight WiFi. But connectivity may have a dark side. Last week, the Government Accountability Office released a report saying that security researchers have warned that this trend leaves planes less secure by providing a “direct link” between an aircraft and the outside world that could be leveraged by hackers.

Keeping flight-related and entertainment systems separate can be one way to limit an attacker’s access, but not all planes are designed with that in mind. In 2008, the Federal Aviation Administration expressed concern that the Boeing 787 Dreamliner combined some of that digital infrastructure – saying that the design “may result in security vulnerabilities.”

Modern planes use digital defenses called firewalls to protect critical technology used during flight against intrusions from someone who has gained access to other parts of the aircraft such as in-flight entertainment systems, the report said. Some cybersecurity experts worry that isn’t enough, arguing that “because firewalls are software components, they could be hacked like any other software and circumvented,” according to the report. (Some critics of the report say it may have overstated the risks.)

Boeing and competitor Airbus have defended the security of their systems. “Multiple security measures and flight deck operating procedures help ensure safe and secure airplane operations,” Boeing said in a statement to CNN in response to the GAO report.

But over the years, many researchers have warned about potential problems – including Roberts, the founder of One World Labs, who has given several talks about airplane cybersecurity.

Brad “RenderMan” Haines, a researcher who has investigated potential vulnerabilities in aircraft tracking systems, said limited access to the technology can make comprehensive audits difficult. “A lot of our research we can only take so far because we don’t want to cause problems – but all of the evidence seems to point to there being issues that remain unresolved,” he said.

In an interview with CNN after being detained by the FBI, Roberts said he tested theories about how much visibility into avionic systems he had from the passenger cabin – pulling out his laptop and connecting it to a box underneath his seat 15 to 20 times on flights – and was able to view sensitive data. That interview, combined with the tweet, seems to have set off alarm bells at United.

“Given Mr. Roberts’s claims regarding manipulating aircraft systems, we’ve decided it’s in the best interest of our customers and crew members that he not be allowed to fly United,” United spokesman Rahsaan Johnson told The Washington Post. “However, we are confident our flight control systems could not be accessed through techniques he described.”

The Electronic Frontier Foundation, which represents Roberts, called United’s decision “both disappointing and confusing.”

“Security researchers are allies, not opponents, and their work makes us all more safe, not less,” EFF staff attorney Nate Cardozo said. “We fear that United’s actions here will cause a real chilling effect, and that researchers will be less likely to help United improve their security in the future based on its over reaction to Mr. Roberts’s statements.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

People walk along a newly constructed bridge at the Big Four Ice Caves hike along the Mountain Loop Highway in Snohomish County, Washington on Wednesday, July 19, 2023. (Annie Barker / The Herald)
Check out the best tourist attractions in Snohomish County

Here’s a taste of what to do and see in Snohomish County, from shopping to sky diving.

People walk out of the Columbia Clearance Store at Seattle Premium Outlets on Thursday, April 25, 2024 in Quil Ceda Village, Washington. (Olivia Vanni / The Herald)
Head to Tulalip for retail recreation at Seattle Premium Outlets

The outlet mall has over 130 shops. You might even bring home a furry friend.

Brandon Baker, deputy director for the Port of Edmonds, shows off the port's new logo. Credit: Port of Edmonds
A new logo sets sail for the Port of Edmonds

Port officials say after 30 years it was time for a new look

Travis Furlanic shows the fluorescent properties of sulfur tuft mushrooms during a Whidbey Wild Mushroom Tour at Tilth Farmers Market on Saturday, April 27, 2024 in Langley, Washington. (Annie Barker / The Herald)
On Whidbey Island, local fungi forager offers educational mushroom tours

Every spring and fall, Travis Furlanic guides groups through county parks. His priority, he said, is education.

Penny Clark, owner of Travel Time of Everett Inc., at her home office on Tuesday, April 23, 2024 in Arlington, Washington. (Olivia Vanni / The Herald)
In a changing industry, travel agents ‘so busy’ navigating modern travel

While online travel tools are everywhere, travel advisers still prove useful — and popular, says Penny Clark, of Travel Time in Arlington.

ZeroAvia founder and CEO Val Mifthakof, left, shows Gov. Jay Inslee a hydrogen-powered motor during an event at ZeroAvia’s new Everett facility on Wednesday, April 24, 2024, near Paine Field in Everett, Washington. (Ryan Berry / The Herald)
ZeroAvia’s new Everett center ‘a huge step in decarbonizing’ aviation

The British-American company, which is developing hydrogen-electric powered aircraft, expects one day to employ hundreds at the site.

Allan and Frances Peterson, a woodworker and artist respectively, stand in the door of the old horse stable they turned into Milkwood on Sunday, March 31, 2024, in Index, Washington. (Ryan Berry / The Herald)
Old horse stall in Index is mini art gallery in the boonies

Frances and Allan Peterson showcase their art. And where else you can buy a souvenir Index pillow or dish towel?

Everett
Red Robin to pay $600K for harassment at Everett location

A consent decree approved Friday settles sexual harassment and retaliation claims by four victims against the restaurant chain.

magniX employees and staff have moved into the company's new 40,000 square foot office on Seaway Boulevard on Monday, Jan. 18, 2020 in Everett, Washington. magniX consolidated all of its Australia and Redmond operations under one roof to be home to the global headquarters, engineering, manufacturing and testing of its electric propulsion systems.  (Andy Bronson / The Herald)
Harbour Air plans to buy 50 electric motors from Everett company magniX

One of the largest seaplane airlines in the world plans to retrofit its fleet with the Everett-built electric propulsion system.

Simreet Dhaliwal speaks after winning during the 2024 Snohomish County Emerging Leaders Awards Presentation on Wednesday, April 17, 2024, in Everett, Washington. (Ryan Berry / The Herald)
Simreet Dhaliwal wins The Herald’s 2024 Emerging Leaders Award

Dhaliwal, an economic development and tourism specialist, was one of 12 finalists for the award celebrating young leaders in Snohomish County.

Lynnwood
New Jersey company acquires Lynnwood Land Rover dealership

Land Rover Seattle, now Land Rover Lynnwood, has been purchased by Holman, a 100-year-old company.

Szabella Psaztor is an Emerging Leader. (Olivia Vanni / The Herald)
Szabella Pasztor: Change begins at a grassroots level

As development director at Farmer Frog, Pasztor supports social justice, equity and community empowerment.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.