Lookd

Boeing 737 Hackable Due to Coin-Sized Device

· news

“A Coin-Sized Threat: Unmasking the Aviation Industry’s Vulnerability”

Researchers at the University of California San Diego and Oberlin College have demonstrated a coin-sized device capable of hacking into Boeing 737 aircraft electronics, sparking concern about the vulnerability of modern air travel. The device exploits a weakness in the communications between two key flight computers on Boeing 737 aircraft, allowing hackers to secretly change a plane’s flight plan without it appearing on the pilot’s display.

The researchers demonstrated scenarios in which hackers could cause the autopilot to divert the aircraft into another country’s airspace or send it off course. The study suggests that this vulnerability may not be an isolated incident but rather a symptom of a broader cybersecurity risk across the industry. The Boeing 737, with over 8,000 aircraft in service worldwide, accounts for nearly a quarter of Delta’s fleet and nearly 40% of American Airlines’.

The researchers alerted Boeing to their findings as early as 2020, but it is unclear whether the company has taken sufficient action to address the issue. Proposed fixes, such as tightening security around who can access planes on the ground or blocking the vulnerable port altogether, are relatively simple yet seem to have been overlooked by the manufacturer.

Boeing asserts that existing safeguards are enough to reduce any risks, but this may be overly optimistic. While an attentive pilot could recover from most of the attacks demonstrated in the study, it does not alleviate concern that a determined attacker with sufficient planning and expertise can still exploit these vulnerabilities.

The researchers acknowledge that an attack of this type would require significant planning and engineering expertise, but if such a threat can be executed with relative ease, it raises questions about security measures at airports worldwide. Routine access to sensitive areas by maintenance workers and other airport staff highlights the need for more robust security protocols.

This study serves as a wake-up call for the aviation industry, which has long been touted as one of the safest modes of transportation. While air travel remains an incredibly safe way to traverse the globe, this revelation reminds us that complacency can be a luxury we cannot afford. The researchers’ goal in alerting the aviation community to these risks is clear: they hope to prompt action before such threats become deadly.

As manufacturers like Boeing and regulatory bodies move forward, it will be essential for them to take a more proactive approach to addressing cybersecurity concerns. This may involve implementing stricter security protocols, conducting regular vulnerability assessments, or rewriting the rules of aviation cybersecurity from the ground up. The stakes are too high to ignore this warning shot.

Reader Views

  • AD
    Analyst D. Park · policy analyst

    The Boeing 737 vulnerability is a ticking time bomb, and it's alarming that researchers first alerted Boeing in 2020 without seeing tangible action since then. While some proposed fixes seem straightforward, such as blocking the vulnerable port or tightening access controls, one crucial aspect remains underexamined: international cooperation and standardization. Without a unified approach to addressing these risks across manufacturers and national borders, the true extent of this vulnerability may remain obscured, leaving many aircraft flying with an unsettling blind spot in their cybersecurity defenses.

  • RJ
    Reporter J. Avery · staff reporter

    The Boeing 737's vulnerabilities go beyond this coin-sized device. What about the countless other aircraft systems that rely on identical protocols? This isn't just a software fix – it's a systemic problem. Until regulators and manufacturers prioritize end-to-end encryption and secure communication standards across the industry, these types of attacks will remain possible. Meanwhile, pilots will continue to be left in the dark about potential cyber threats, putting lives at risk.

  • EK
    Editor K. Wells · editor

    While Boeing's assertion that existing safeguards are sufficient to mitigate these vulnerabilities may be true in theory, the onus is still on the manufacturer to implement comprehensive and foolproof security measures, rather than relying on the vigilance of pilots who may not always be aware of potential threats. The article highlights a crucial oversight: what about the thousands of planes already flying with this vulnerability, which could potentially remain undetected for years? How will these aircraft be patched and updated in a timely manner to prevent potential disasters?

Related articles

More from Lookd

View as Web Story →