Your fear of flying is only going to get worse once you hear what these white hat hackers figured out to do with a popular airliner.
As Wired reports, a team of security researchers from the University of California, San Diego and Oberlin College created a device the size of a coin that can take over the autopilot system of a Boeing 737 and change its flight plan, not to mention tampering with key values in its takeoff and fuel calculations.
According to its creators, the device could also change the data on a pilot’s screen so they don’t notice anything’s amiss — or even trick a pilot into making a disastrous decision.
“If you could get 60 seconds with an airplane, what could you do?” Stefan Savage, a UCSL professor who led the project, asked Wired. “Well, it turns out there’s a port that’s externally accessible. You can get to it with no special tools in about 15 seconds. And you can shove in a piece of electronics a little bigger than a quarter that lets you basically tell the autopilot what to do and lie to the pilot about changes to the flight plan.”
The attack relies on plugging the device, which costs less than $100, into a port hidden by a hatch on the exterior of the plane, which the researchers say is easily within reach of maintenance workers and airline staff. Once the device is plugged in, it could connect to the plane’s in-flight Wi-Fi system and allow a hacker to remotely control the aircraft’s systems from terra firma.
As Savage explained to Wired, his team found this vulnerability after spending years cobbling together 737 computer parts to effectively recreate the plane’s nervous system. Inspired by credit card skimming devices that plug into ATMs to steal your information, they realized that an entire aircraft could be broken into by physically plugging a device into its internal “bus” — the system that connects different components of its computer.
And after digging through Boeing wiring diagrams, they found their way in: a port carrying data between the plane’s Flight Manage Computer and the pilot’s display unit, accessible from an unlocked hatch on the plane’s exterior.
It was like finding “the goddamn exhaust port on the Death Star,” Savage told Wired.
The havoc a hacker wreaks using their attack could be catastrophic. They could feed the pilot the wrong information about the air temperature outside or about the weight of its cargo and passengers and cause them to miss the speed they need for takeoff before running out of runway, Wired noted. Or they could suddenly change its navigation and crash it into a mountain.
The attacks could also be far more sneaky.
“It could be something as subtle as, you’re in the Pacific, you see blue everywhere, and this diverts you 3 degrees off course, and now you’re in the middle of nowhere,” Aaron Schulman, another UCSD professor working on the project, told the magazine.
Savage and Schulman shared their findings with Boeing six years ago and have worked closely with the company to explore the vulnerability.
But the researchers say that Boeing hasn’t told them about any fix to the vulnerabilities they found. In fact, they say it’s likely that it any fix may not have been implemented yet, since commercial airplanes are rarely redesigned.
You shouldn’t panic though, they insist.
“All of the authors of this paper routinely travel on Boeing 737 aircraft and expect to continue doing so,” they wrote in their paper.
Beau Woods, a former adviser to the Cybersecurity and Infrastructure Security Agency and the Boeing’s Industry Cyber Technical Council, was alarmed by the findings.
“It is entirely possible to have someone who is on staff go up to an airplane when it’s on the ground, going through maintenance, and put this type of thing in there,” Woods told Wired.
“This is something the aviation industry will want to plan to defend against,” Savage agreed. “I would not sleep on this one.”
More on aviation: Why Aren’t Any AI Companies Watching Their Frontier Models to Make Sure They Don’t Go on Hacking Sprees?