Coin-sized device can hack a Boeing 737

(wired.com)

45 points | by _tk_ 1 day ago

9 comments

  • userbinator 44 minutes ago
    one that's routinely within reach of maintenance workers or other airport and airline staff between flights

    You already trust them (as well as the pilots) every time with your flight.

    • altmanaltman 25 minutes ago
      https://www.theguardian.com/business/2025/mar/06/avalon-airp...

      That trust was what led to this incident where someone just walked into the airplane dressed as a maintainence worker and nobody stopped him.

      Also pilot suicide isn't something new and the aviation world has tried to come up with several regulations to ensure it doesn't happen even though we completely trust pilots on a normalative basis.

      • pudgywalsh 21 minutes ago
        You conveniently left out the part where he walked through a hole in the airport fence.

        Airfields are expected to be secure areas. If you can walk through a hole in a fence there's issues.

        Remember a guy stole an entire airplane a few years ago (RIP Sky King). Airplanes don't have ignition keys.

        • markdown 9 minutes ago
          Is that the legend who managed to do a loop-the-loop?
    • pudgywalsh 38 minutes ago
      Are these the same maintenance workers that have access to even more sensitive parts of the airplane like the avionics compartment and its miles of wiring?

      Wait until they find out your mechanic has unfettered access to your car's OBD port when you hand them the keys. They could install a COIN SIZED device on the CAN bus and you'd never know.

      Some people do this voluntarily in exchange for a discount on their insurance.

      There's literally millions of people driving newfangled EVs where the car manufacturer has full remote access to their vehicle and can upload software however and whenever they like.

      I forgot only the nefarious ones wear yellow reflective vests and earmuffs.

  • WalterBright 37 minutes ago
    > the company may not in fact implement any such update to their systems for years to come, given how rarely commercial airplanes are redesigned.

    Boeing commercial airplanes are constantly updated. As long as the airplane is in service, Boeing retains a team of engineers that update parts as needed. If FAA review is needed, this will of course take longer.

    BTW, anyone with access to the internals of an airplane could potentially sabotage it. Sadly, all people with access need to undergo a security check.

  • United857 25 minutes ago
    > less than a minute, that hardware implant can be fitted into a port accessible via a hatch on the exterior of the plane

    Just as with computers, as the saying goes, if you have physical access to the device then all bets are off. The tricky part is getting that physical access in the first place...

    • dosshell 13 minutes ago
      It is not that simple, atleast in the automotive industry _today_. Atleast here in EU.

      Every component is analyzed from a cyber security perspective. Many components needs tampering protection - while others need not. This includes replacing components with malicious ones.

      It is not logical at all and a stupid regulation. But it is not as simple as you can do what you want if you have physical access.

  • snapsnail 17 minutes ago
  • haunter 21 minutes ago
    https://archive.md/3fpga

    HN should have a rule like what does some reddit subs do.

    Either outright ban paywalled articles, or if not then either an archived link should be posted alongside, or the whole text of the article should be copy pasted as a comment

    • Symbiote 2 minutes ago
      [delayed]
    • Meetvelde 3 minutes ago
      I think a lot of these links are being shared via the browser extension, but yes I agree they should do something about this.
  • numpad0 21 minutes ago
    ...so they built an equivalent of OBDII reader for planes, and it worked just the same as ones for cars? Interesting but not as scary as the title may suggest.
  • Razengan 18 minutes ago
    ..I feel like I shouldn't bookmark this post, given the invasive "social media checks" in the so-called Free World :')
  • LoganDark 53 minutes ago
    > “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks,” the statement reads.

    So "We don't expect hackers to figure it out"