news.mlab.sh
Back to the feed

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

Summary

A Delta Air Lines flight was disrupted after a passenger replaced the in-flight Wi-Fi system with their own, dubbed "Delta WiFi Fast." The incident stemmed from a DEF CON attendee attempting to use a Wi-Fi Pineapple to install a phishing portal. Simultaneously, researchers demonstrated a coin-sized device capable of compromising a Boeing 737's flight systems. The US government is considering contracting private companies to conduct "hack back" operations, a move that experts warn could create significant legal and liability issues. Additionally, Facebook ads have become increasingly difficult to block, forcing the popular ad blocker uBlock Origin to significantly reduce its filtering capabilities. Overall, this highlights a growing trend of sophisticated cyberattacks and the challenges of maintaining security in an increasingly complex digital landscape.

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government’s newest "hack back" strategy. Someone messed with the in-flight Wi-Fi system on a Delta Air Lines flight from Las Vegas following the Black Hat and DEF CON conferences earlier this month, and authorities aren't happy. In this episode of "What We Missed," Dark Reading's Rob Wright and Alex Culafi discuss some of the recent news events and topics that we didn't get a chance to cover. And first up, Alex. Delta Airlines' in-flight hacking incident. Apparently, there was a flight on the way back from Las Vegas — which I'm sure we'll touch on in this discussion, because that is relevant — going to Atlanta. That suddenly, apparently the in-flight Wi-Fi system was disabled or jammed, and a new Wi-Fi system or Wi-Fi network popped up. I believe it was called "Delta WiFi Fast." I probably would have clicked on it, not knowing any better. But yeah, what did you think of this? Dark Reading's Alex Culafi: I think it's crazy. Because there is a history of DEF CON folks, attendees, doing dumb pranks. But doing it on an airline is extremely stupid, especially in the context of the sensitive history the United States has with flights. So, OK, what the person did is they made this fake Wi-Fi network, and then they put what looked to be a Google-esque phishing portal on the back end of that. And the problem with doing that, if it was malicious, which I feel a lot of the headlines are positioning this as potentially a malicious attack, is that it's the stupidest way to possibly do a phishing credential harvesting attack because you're on a flight, which means you're not compromising very many victims. There are security researchers surrounding you, and it's like, you don't want legal attention anywhere worse than a flight. So, what I think happened is someone bought a Pineapple, one of the Wi-Fi Pineapples, which you can just buy at DEF CON. They set up a Wi-Fi portal, they got a credential — Dark Reading's Rob Wright: Sniffer. Yep. Dark Reading's Alex Culafi: A portal, phishing logon from GitHub, probably vibe coded a little bit and stupidly said, "What if we do this?" And now they're probably very anxious that the FBI got involved. What do you think? Dark Reading's Rob Wright: Yeah, and they contacted authorities, which they rightfully should have. And this, I think, generally gives a bad name to the hacking community, the infosec research community, and the events. And I just want to say, as my closing point, to me, this is no different than getting loaded on a plane, like drinking too much and having to be taped to the seat and forcing the flight to call security, call the authorities to meet you at the gate, or worse, divert to Lincoln, Nebraska. That's the worst possible — no disrespect to Lincoln, Nebraska, but the worst possible outcome for something like this, and people should know better. All right. Next topic. Dark Reading's Alex Culafi: Yeah. Also in-flight news, kind of the opposite ethical situation. There was recent research from academic researchers. They revealed that there's a coin-sized Wi-Fi-enabled device that they could build for less than a hundred bucks, which they could plug into this maintenance access port on a Boeing 737. I think it's not the key slot, but it's something that's sort of beneath the pilot seat, which could manipulate flight management computers. Sounds scary, but it was done in an academic setting. It was reported to Boeing, and Boeing basically said, 'Yeah, this seems very unlikely that someone would take advantage of it.' My feeling is that Boeing has much bigger fish to fry than this. So I don't know. What do you think? Dark Reading's Rob Wright: So I'm a pessimist. Upon reading this, and it was featured in an article on Wired, we should note. Very good article. Interesting read. I typically don't have a lot of faith in physical security of systems. I think we're very embroiled in cybersecurity, and we kind of miss that somebody could just walk on a tarmac and tinker and just wear an orange pinny, or yellow pinny or whatever, and walk up to a plane. So I don't think it would be that hard to do this. And the thing that really struck me was if someone was able to do this, if it was someone with ill intent and if they ransomed a flight and said, "Look, I just took control of the control systems, of the in-flight, you know, autopilot systems. I could do a lot of damage with this. Pay me a million dollars or more, a billion dollars." That's going to be an interesting situation, about whether or not you're going to call someone's bluff on that or pay the money. I can't imagine the airlines would call the bluff. But anyway, yeah, that's what I sort of envisioned — a whole new avenue of hacking — and that it kind of scared me. Dark Reading's Alex Culafi: Yeah. I don't want to go out of my way to defend Boeing here because, I mean, I go out of my way to avoid Boeing flights at this point. But I do think their general take is defensible that basically to execute this in a criminal setting, you basically already need to get into the cockpit, which if you have mal intent and could get into a cockpit, like, it's — I don't know, this seems kind of burdensome as a way to do whatever it is. So I get it, but I also think [sarcastically], Gee what a surprise that Boeing is shrugging something off again. Dark Reading's Rob Wright: Right, sure. Dark Reading's Alex Culafi: What else we got? Dark Reading's Rob Wright: We got US government is letting private companies hack back. There was news, and I should note an excellent story from our colleague Eric Geller at Cybersecurity Dive, about the Trump administration issuing a memo to DOJ, DHS saying we want to use or we want to contract private companies to conduct "hack back" operations, a move that experts warn could create significant legal and liability issues. What do you think? Dark Reading's Alex Culafi: A lot of Trump's cybersecurity tactics, strategies, announcements to date have reminded me of anytime you hear RFK [Jr.], which is that he'll say one thing that you kind of agree with and then package it with the most insane thing you've ever heard. And I also feel the same way about Trump's cybersecurity announcements. The thing about this one is, OK, you want to possibly hire overseas espionage activities in the private sector. I think that's reasonable insofar as they want all these organizations to put up million-dollar escrows. I think that's a good idea, and I think it's looking to facilitate a defense contractor ecosystem to possibly do this, which, I'm a pacifist and I don't like this on a personal level, this sort of activity, but I get it as a sensible idea. I don't understand that it's possibly open to pre-established security vendors as well. I think it makes liability a complete nightmare. What do you think? Dark Reading's Rob Wright: Right. Yes. I defer to the experts on this, and there was a session that I caught at Black Hat by Carole House, and she did a session on basically this exact topic. I think it was called, yeah,

Read the full article at Dark Reading