Reply
Thread Tools
Dave999's Avatar
Posts: 7,075 | Thanked: 9,073 times | Joined on Oct 2009 @ Moon! It's not the East or the West side... it's the Dark Side
#3041
on the other hand. Why detain him indefinitely? If he can do it. Others can as well. I hope they fix the issues.

I agree...don't want to see a kid with a laptop and joystick on the plan next time I fly.

here is the FBI warrant:
http://www.wired.com/wp-content/uplo...ch-Warrant.pdf

Time sell your new car too...
http://www.wired.com/2015/04/researc...public-summer/

“[Miller] and I will show you how to hack a car for remote control at [Defcon],” he wrote. “No wires. No mods. Straight off the showroom floor.”
__________________
Do something for the climate today! Anything!

I don't trust poeple without a Nokia n900...

Last edited by Dave999; 2015-05-18 at 19:04.
 
pichlo's Avatar
Posts: 6,453 | Thanked: 20,983 times | Joined on Sep 2012 @ UK
#3042
Exactly! Yeah, shoot the messenger, that has never failed. He told the authorities what he had done, thus highlighting the vulnerability. If he just told them there is a vulnerability without demonstrating it, no one would take him seriously. All FBI will achieve is discourage future hackers from being so open about their actions and ultimately cause more accidents.
 
endsormeans's Avatar
Posts: 3,141 | Thanked: 8,164 times | Joined on Feb 2013 @ From my Gabriola Island hermitage, near the Edge of the World
#3043
Hm...I don't know guys..it is a fine line he's treading...
sure it needs proper attention and it is good he found it...
But...he tried repeatedly to access the onboard systems and was reprimanded repeatedly...this last attempt of his was successful...but it took tampering, the vandalization of another's property and the reckless and willful endangerment of everyone on board.
He could have accomplished the same thing safely demo-ing his technique to the proper authorities in one of the test simulation planes.
If no one wanted to listen to him...
I think it understandable why..
it isn't the 1st time he was caught tampering with a plane..

Hail him as a hero if you wish...
but if he had crashed the plane...
or if he manages to crash one in the future..
or someone in the future does...
Does he think it was worth it to tamper and vandalize property of another and jeopardize every life on board to be vindicated? ...to prove his point?
If it does happen ..expect that on future flights no electronics will be allowed anywhere but in your luggage in the belly of the plane..
or every passenger either restrained or sedated pre-flight to ensure the safety of all on board.
No matter what ..."some" vulnerability will always be found ...
At whatever cost ..passenger and crew safety must be ensured.
__________________
Lurker since 2007, Member since 2013, Certifiable since 1972

Owner of :
1-n770 (in retirement), 3-n800's / 3-n810's (still in daily use), 5-n900's ((3 are flawless, 1 loose usb ( parts), 1 has no telephony (parts))
3-nexus 5's : 1 w/ Floko Pie 9.1 (running beautifully) waiting for Stable Droid 10 rom, 1 w/ ̶Ubuntu Touch, 1 with Maru OS (intend maemo leste when ready)

1/2 - neo900 pre- "purchased" in 2013. N̶o̶w̶ ̶A̶w̶a̶i̶t̶i̶n̶g̶ ̶r̶e̶f̶u̶n̶d̶ ̶p̶r̶o̶c̶e̶s̶s̶ ̶l̶a̶s̶t̶ ̶f̶e̶w̶ ̶y̶e̶a̶r̶s̶ - neo900 start up declared officially dead -
Lost invested funds.


PIMP MY N8X0 (Idiot's Guide and a video walkthrough)http://talk.maemo.org/showthread.php?t=94294
THE LOST GRONMAYER CATALOGShttp://talk.maemo.org/showthread.php...ight=gronmayer
N8X0 VIDEO ENCODING THE EASY WAYhttp://talk.maemo.org/showthread.php...ght=mediacoder
242gb ON N800http://talk.maemo.org/showthread.php?t=90634
THE PAIN-FREE MAEMO DEVELOPMENT LIVE DISTRO-ISO FOR THE NOOB TO THE PROhttp://talk.maemo.org/showthread.php?t=95567
AFFORDABLE MASS PRODUCTION FOR MAEMO PARTShttp://talk.maemo.org/showthread.php?t=93325

Meateo balloons now available @ Dave999's Meateo Emporium

Last edited by endsormeans; 2015-05-18 at 20:21.
 
Posts: 2,076 | Thanked: 3,268 times | Joined on Feb 2011
#3044
or introduce proper air gap for the planes' systems, nah, just add an extra bin next to the liquids above 100ml
 
Dave999's Avatar
Posts: 7,075 | Thanked: 9,073 times | Joined on Oct 2009 @ Moon! It's not the East or the West side... it's the Dark Side
#3045
I don't think he is a hero since he acted as he did several times and if true he should be responsible And face the consequences...and reproduce if he truly want to help, but locked up "forever" for saying something. putting all people with special skills behind bars could be tricky...

Also, Im still not sure I believe it's possible to access air control...but if there are I have no doubt that there are others that can do it as well. And now there is chance to fix it or part of it like moving boxes from so easy access.

What makes a system more secure...hide the faults or highlight and investigate? It's always tricky.
__________________
Do something for the climate today! Anything!

I don't trust poeple without a Nokia n900...

Last edited by Dave999; 2015-05-18 at 21:15.
 
endsormeans's Avatar
Posts: 3,141 | Thanked: 8,164 times | Joined on Feb 2013 @ From my Gabriola Island hermitage, near the Edge of the World
#3046
Agreed.....
__________________
Lurker since 2007, Member since 2013, Certifiable since 1972

Owner of :
1-n770 (in retirement), 3-n800's / 3-n810's (still in daily use), 5-n900's ((3 are flawless, 1 loose usb ( parts), 1 has no telephony (parts))
3-nexus 5's : 1 w/ Floko Pie 9.1 (running beautifully) waiting for Stable Droid 10 rom, 1 w/ ̶Ubuntu Touch, 1 with Maru OS (intend maemo leste when ready)

1/2 - neo900 pre- "purchased" in 2013. N̶o̶w̶ ̶A̶w̶a̶i̶t̶i̶n̶g̶ ̶r̶e̶f̶u̶n̶d̶ ̶p̶r̶o̶c̶e̶s̶s̶ ̶l̶a̶s̶t̶ ̶f̶e̶w̶ ̶y̶e̶a̶r̶s̶ - neo900 start up declared officially dead -
Lost invested funds.


PIMP MY N8X0 (Idiot's Guide and a video walkthrough)http://talk.maemo.org/showthread.php?t=94294
THE LOST GRONMAYER CATALOGShttp://talk.maemo.org/showthread.php...ight=gronmayer
N8X0 VIDEO ENCODING THE EASY WAYhttp://talk.maemo.org/showthread.php...ght=mediacoder
242gb ON N800http://talk.maemo.org/showthread.php?t=90634
THE PAIN-FREE MAEMO DEVELOPMENT LIVE DISTRO-ISO FOR THE NOOB TO THE PROhttp://talk.maemo.org/showthread.php?t=95567
AFFORDABLE MASS PRODUCTION FOR MAEMO PARTShttp://talk.maemo.org/showthread.php?t=93325

Meateo balloons now available @ Dave999's Meateo Emporium
 
pichlo's Avatar
Posts: 6,453 | Thanked: 20,983 times | Joined on Sep 2012 @ UK
#3047
The article did not say what exactly happened., so I will reserve judgement.

It reminds me of a case some 15 years ago. A guy received a URL from a utility company to get access to his data. The URL was in the form, http://www.utilitycompany.com/somelo.../accountnumber. Our guy was lazy and typed the URL in the browser without the last bit and - what should happen but get a page with a list of all the accounts, allowing hi. to go in and see anyone else's data: not just consumption but also full name and address and bank details.

This guy went ahead and notified said utility company, prompti.g them to close this gaping security hole. So what did they do? Accuse him of hacking and pressed charges against him. Eventually they were forced to silently drop the charges and it was only then that our guy went public.

Whenever I read a story like this, my judgement may be influenced with this story. For all we know, this story may have been very similar. Or not.
 
Posts: 2,076 | Thanked: 3,268 times | Joined on Feb 2011
#3048
Originally Posted by pichlo View Post
The article did not say what exactly happened., so I will reserve judgement.

It reminds me of a case some 15 years ago. A guy received a URL from a utility company to get access to his data. The URL was in the form, http://www.utilitycompany.com/somelo.../accountnumber. Our guy was lazy and typed the URL in the browser without the last bit and - what should happen but get a page with a list of all the accounts, allowing hi. to go in and see anyone else's data: not just consumption but also full name and address and bank details.

This guy went ahead and notified said utility company, prompti.g them to close this gaping security hole. So what did they do? Accuse him of hacking and pressed charges against him. Eventually they were forced to silently drop the charges and it was only then that our guy went public.

Whenever I read a story like this, my judgement may be influenced with this story. For all we know, this story may have been very similar. Or not.
Similar happened with one bank's URL, get the last part of URL++ and you could see other people's full details of transactions with account numbers/names etc (not sure if they accused the guy who reported it, but yeah, security)
 
wicket's Avatar
Posts: 634 | Thanked: 3,266 times | Joined on May 2010 @ Colombia
#3049
Originally Posted by endsormeans View Post
No matter what ..."some" vulnerability will always be found ...
That really depends on the architecture of the plane's computer network. This vulnerability could have been avoided by isolating the in-flight entertainment system from the flight control system. In my opinion, the person(s) who thought it would be a good idea to put both systems together is/are way more guilty than the guy who exploited this glaring flaw.

As pichlo mentioned, the article is lacking details so it's not clear how much knowledge or experience this guy has with planes. This means that there is the possibility that he knew exactly what he was doing and therefore never put the safety of anyone at risk. He appears to be collaborating with the F.B.I and he hasn't yet been charged with any crime. This is unusal. His discovery may well prevent future terrorist attacks.
__________________
DebiaN900 - Native Debian on the N900. Deprecated in favour of Maemo Leste.

Maemo Leste for N950 and N9 (currently broken).
Devuan for N950 and N9.

Mobile devices with mainline Linux support - Help needed with documentation.

"Those who do not understand Unix are condemned to reinvent it, poorly." - Henry Spencer
 
Kangal's Avatar
Posts: 1,789 | Thanked: 1,699 times | Joined on Mar 2010
#3050
I'm sure we aren't getting the full picture.
The FBI probably wants to send him to Guantanamo and take his rectum.
However they haven't done that.
So either the FBI doesn't have a case, or they're trying to build one.
Or they are scared of a possible backlash to this by the public (yeah right), or by others/terrorists taking advantage of this flaw.
They probably want to avoid another Snowden incident.
__________________
Originally Posted by mscion View Post
I vote that Kangal replace Elop!
The Following 5 Users Say Thank You to mscion For This Useful Post

I'm flattered
 
Reply

Tags
countdown, dooms_day, specc is the, troll ericsson

Thread Tools

 
Forum Jump


All times are GMT. The time now is 20:33.