Rendered at 21:54:16 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
userbinator 16 hours ago [-]
one that's routinely within reach of maintenance workers or other airport and airline staff between flights
You already trust them (as well as the pilots) every time with your flight.
Nextgrid 10 hours ago [-]
With the low pay and ever-worsening working conditions, I'd be more worried about oversights/negligence than intentional sabotage (which sometimes happens all the way at manufacturing stage - see the Boeing door incident).
Unfortunately, that is unlikely to get media coverage because the solution would be to respect and pay workers more, a severe crime in a late-stage capitalistic society.
gryfft 8 hours ago [-]
> the solution would be to respect and pay workers more
Not to worry, they're furiously working on an alternative which will ensure no worker must ever be respected or paid ever again!
That trust was what led to this incident where someone just walked into the airplane dressed as a maintainence worker and nobody stopped him.
Also pilot suicide isn't something new and the aviation world has tried to come up with several regulations to ensure it doesn't happen even though we completely trust pilots on a normalative basis.
benjiro29 10 hours ago [-]
> That trust was what led to this incident where someone just walked into the airplane dressed as a maintainence worker and nobody stopped him.
O, it can be even worse, when you realize its a 30 year old problem ...
During the 1998 television show Schalkse Ruiters, presenters Bart De Pauw and Tom Lenaerts dressed in fake pilot uniforms. They bypassed security at Brussels Airport (Zaventem), entered a Boeing cockpit, and left undetected to expose safety flaws
The TV show got cancelled not long after this incident because of pollical backlash.
The show had a reputation of finding security flaws (like being able to transfer money from people bank accounts) and other issues, but the airport one was the end of the show.
People loved the show, as it forced companies, ... make changes to their processes that they normally never did. They even did follow-up episodes to see if the companies actually made changes.
Bit of public shaming to fix security issues... worked great. Until the show was cancelled. The number one rated show of the country ... Yea, there was absolute no correlation between its cancellation and the airport incident. Really ;)
> Also pilot suicide isn't something new and the aviation world has tried to come up with several regulations to ensure it doesn't happen
As AI171 has shown, turning the engines off on rotation does it reliably and there’s nothing that the other pilot or regulations can do to prevent it.
altmanaltman 12 hours ago [-]
I mean yeah that's why we cannot just "trust". And yes, in that case, there was nothing that could be done but its a case of mental illness and we can look into how regulations and airlines handle mental health issues in pilots. There are regulations for this across all airlines, they failed in this case. So yes, at that moment in time, there is nothing you can do if the other pilot freaking turns off the engine as you begin to climb but there is absolutely things you can do to the best of your ability to ensure such a person shouldn't be allowed to fly / be in that situation in the first person.
Nextgrid 10 hours ago [-]
Until such a time where rent/paying for housing is no longer a thing and we have a good social safety net, it will just mean pilots will keep their mental health problems under wraps to avoid losing their jobs and becoming homeless.
I wonder of such regulations are in fact counterproductive if it means people don't seek out help when they can and let the problem escalate instead (since you presumably don't go from healthy to murder-suicidal in one day, and early intervention could resolve the problem).
altmanaltman 4 hours ago [-]
Yes we can argue how effective the regulations are etc and yes there is a validity to the fact that they can fail since they clearly have. What I was talking about is that the concept of regulations exist because we don't just trust the pilots on any inherent basis so we need checks like regulations which try to shift the trust from the individual to the process which is much more comforting to the average passenger.
Air travel is weird in the sense that pilots do have an immense amount of power and the fact that there have been so few pilot suicide cases shows that regulations for that are somewhat working.
Nextgrid 2 hours ago [-]
> which is much more comforting to the average passenger
Indeed I wonder how much of aviation-related security theatre is more for the perception of safety than any measurable safety improvements.
> there have been so few pilot suicide cases
I'm not sure it's conclusively possible to attribute this to regulations without a "control case" of a different profession lacking such regulations and that has a higher rate of murder-suicide-by-vehicle. It could just be that the low rates are because there just aren't that many suicidal people willing to kill innocent bystanders in the process.
To be clear I'm not arguing for less regulations as I'm not qualified and don't have all the facts, but bringing up a counterpoint that the current regulations might cause people to conceal their mental health troubles until they escalate (and the current low - but non-zero - rates of incidents are in spite of the regulations rather than because).
pudgywalsh 15 hours ago [-]
You conveniently left out the part where he walked through a hole in the airport fence.
Airfields are expected to be secure areas. If you can walk through a hole in a fence there's issues.
Remember a guy stole an entire airplane a few years ago (RIP Sky King). Airplanes don't have ignition keys.
kotaKat 11 hours ago [-]
The only subset I've seen with keys are old single-prop Cessnas (makes sense) but every old codger just leaves their keys in the plane anyways.
Sooooooome private jets actually bother to slap a Medeco on the external doors, at least, but that's still the only control keeping you grounded.
markdown 15 hours ago [-]
Is that the legend who managed to do a loop-the-loop?
pudgywalsh 15 hours ago [-]
You know it is.
altmanaltman 12 hours ago [-]
I shared the link to the entire article so not sure how I left that out. And yes, there was a hole in the airport fence but he got so far because people trust these workers but that can be abused. And in that case (sky king), the guy was actually a maintainence worker who stole the plane. So just saying its okay to be vulnerable just because we trust all actors around the vulnerability, especially when its as easy as a freaking hole to abuse that trust is not a strong argument. RIP Sky King.
pudgywalsh 15 hours ago [-]
Are these the same maintenance workers that have access to even more sensitive parts of the airplane like the avionics compartment and its miles of wiring?
Wait until they find out your mechanic has unfettered access to your car's OBD port when you hand them the keys. They could install a COIN SIZED device on the CAN bus and you'd never know.
Some people do this voluntarily in exchange for a discount on their insurance.
There's literally millions of people driving newfangled EVs where the car manufacturer has full remote access to their vehicle and can upload software however and whenever they like.
I forgot only the nefarious ones wear yellow reflective vests and earmuffs.
bri3d 6 hours ago [-]
> Wait until they find out your mechanic has unfettered access to your car's OBD port when you hand them the keys
Surprise! “They” did find this out and UN155/156 regulate a bunch of protections against local “attackers,” often to the detriment of right to repair.
b112 14 hours ago [-]
There's literally millions of people driving newfangled EVs where the car manufacturer has full remote access to their vehicle and can upload software however and whenever they like.
This part has been beyond baffling to me. The last thing I want, is to hit the brakes in my car, and suddenly they're less/more sensitive, due to an update the night before, and it really does matter especially on snow/ice. And such updates happen.
I also don't want a perfectly good, 100% working car to suddenly degrade in experience because "Wups! Sorry! Last update broke <whatever>, we'll update within the month to fix!". It's just pure, unbridled dumb.
I recently bought a car, and the dealer tried to sell me an extended warranty. What? It's under a full warranty right now, and yes, my region has very strong warranty and anti-lemon laws. But my point is, they kept saying "there's a lot of complex and expensive electronics in this car, you're going to need an extended warranty".
Um, what? Hello? You just explained that the car breaks down a lot because it's complex? So complex that there are more frequent, highly expensive issues?
How is that a plus?
If a car is "too complex" to roll out the assembly line, without needing updates to modules on a monthly basis for years, it's the opposite of positive. I've had multiple BCM(body control module) updates, updates to every single module in the car. There shouldn't be enough code to cause issues here, it should be simple, simple, simple.
But it's not.
It's complex and difficult to make bug free.
And that makes me oh so very comfortable as I drive down the road.
glimshe 13 hours ago [-]
Last time I bought a car the dealer couldn't enable the Internet features because I said my phone was broken. He looked at me puzzled but I said I could buy the car some other day if that was a problem...
A dealer will never let a buying customer leave, so 3 years later my car still can't connect to the Internet.
twoodfin 9 hours ago [-]
AFAIK, most or all modern cars which depend on OTA updates have their own built-in cellular connectivity, the ongoing cost of which is baked into the sale price and/or optional subscription features.
glimshe 8 hours ago [-]
Because they couldn't do the onboarding process with my phone, the OTA features never worked. Maybe the car still thinks it's sitting on the dealer or something. The free 1 year subscription that everybody gets also never started.
inigyou 12 hours ago [-]
This. The same thing works with some banks.
matherial 13 hours ago [-]
> This part has been beyond baffling to me. The last thing I want
Most people don't think about it when buying a car, or they have no practical way to evaluate it. So it is one of these things you probably need to fix with legislation, except the legislators love the idea too because sensor-rich, always-online cars give them more tools to police the society.
I don't really know what to do with that, short of going neo-Luddite. People often see the excesses of ad tech as a failure of capitalism, but in a sense, we're seeing a tech-driven failure mode for free, democratic societies. In a world where your online presence is tied to your identity and always under the watchful eye of a large language model, and where you can't move from A to B without leaving a digital trail, it's not gonna be fun if you become a thorn in the government's side.
_puk 14 hours ago [-]
But you bought the car
forestry 13 hours ago [-]
You also aren’t given a choice. If you decline, “don’t drive it”. Well, I want the car, not the connection. I could probably pull the sim I suppose.
inigyou 12 hours ago [-]
You really think a car dealer is going to let you just walk away over some trivial thing instead of fixing it for you?
Nextgrid 2 hours ago [-]
Depends how "trivial" is the fix. Are they going to get the workshop to pull out the telematics module?
Otherwise the car is still connected and very likely broadcasting telemetry anyway (and the "account" part is handled entirely on the backend). Refusing to set up or use the app is merely a placebo.
TacticalCoder 10 hours ago [-]
Here's a crazy one: I've got a 38 years old Porsche 911 Carrera since the last century (I bought it in 1999). It used to be my daily. It still runs totally fine: regularly using it to go pick the kid at school.
I've got another car that's 13 years old and has got 126 000 miles / 202 000 km and that is 13 years old. In the 8 years I've had this one, my "green" doctor buddy changed four times his car.
Who's consuming the most? My ecological doctor friend who changes car every two years, my 13 years old daily or my 38 years car? (most cars have long been destroyed after 38 years)
Sure, the 38 old Porsche is a bit of a gas guzzler but the thing still runs strong. One Bosch Motronic electronic board for the fuel injection and that's it: no OTA updates, fully mechanical dashboard (which looks gorgeous btw).
Who's really the consumerist here? Me or my doctor buddy who buys a new EV every two years?
And if instead of an old Porsche I was using an old Toyota with much better mpg, then the equation is even better.
I'm not against switching to an EV but I don't want any of this OTA updates and 24/7 connected bullshit: give me an EV that doesn't phone home and I may listen.
Things however don't seem to be heading that way so I think I'll be driving used cars for a very long time.
speedstyle 3 hours ago [-]
Every 20k miles in the Porsche emits as much as producing a typical EV. Maybe 50k miles in an old hybrid. And it's not just emissions, significant resources and labour go into finding, extracting, refining, transporting fuel, compared to burning half as much in a CCGT, let alone renewables.
Obviously it would be even better to keep one EV longer (hard to say how much better, they do displace ICE vehicles in the used market) but they're almost certainly consuming less than you.
margalabargala 9 hours ago [-]
People like your doctor friend are where the used cars you buy come from. I imagine when he gets a new one he sells the old one.
Certainly he creates some demand for new cars and you make a good point about reducing consumption.
27183 9 hours ago [-]
I have a 1999 Benz E300, a 1995 Toyota FZJ80, and a 1998 Dodge Ram 2500. The Benz is by far the most complex, with full CAN network, drive-by-wire, and Bosch EDC fuel injection (no mechanical governor on the injection pump). The Toyota has a 4.5L EFI engine and an electronically controlled automatic transmission. The Dodge has a mechanically governed P7100 injection pump and a manual transmission.
As of right now, my bets on which cars will be running 30 more years from now are:
Dodge: yes
Toyota: maybe
Benz: no
I have a concept of a plan to combine the "maybe" and "no" vehicles into a single Frankenstein's monster which will undoubtedly be a "yes". It involves eliminating all the electronic controls.
I don't see how these proprietary, point-in-time hardware/software systems can possibly be maintainable long term. In 20 years there will only be 50yo ECUs available to replace my current ones.
Contrast that with any 1970s era vehicles you can buy today. So long as the rust isn't too bad, you can 100% definitely restore it mechanically.
toast0 8 hours ago [-]
> I don't see how these proprietary, point-in-time hardware/software systems can possibly be maintainable long term. In 20 years there will only be 50yo ECUs available to replace my current ones.
There are a handful of aftermarket ECUs to do fuel injection and electronic ignition. Initial configuration is a bit of a bear and I dunno if you'll be able to find a shop to do it, but if your model runs out of working pulls, it's an option. My 1981 van has a Bosch electronic fuel injection system and if it fails (which seems rare), most people can find a replacement module from a van that was crashed or rusted out; some people put carbuerators on it; a couple people put a microsquirt. The air flow meter might be a bigger issue, they have mechanical wear and I haven't seen anything about refurbishing them (but maybe I missed it)
27183 8 hours ago [-]
Yes and for diesels there are options too, but fewer and as far as I'm aware none are open source or open hardware. If I'm going to bet on the longevity and maintainability of a computer control system all 3 of these things need to be open software and open hardware or highly standardized in a very stable way:
1. Controllers. Absolutely must be open software and hardware, no compromises.
2. Actuators. If not open hardware, they must be documented sufficiently to facilitate adapting a suitable replacement in the future.
3. Sensors. Same constraints as actuators.
Unfortunately even mega/microsquirt systems don't quite get us there yet.
[edit] One example that informs my hardline stance here is reading ECU codes. On the Toyota's ECU there's an open interface for reading fault codes documented in the factory shop manual. You jump a couple pins on a connector in the engine compartment with a test light and read the number of flashes. The Benz, by contrast, is completely proprietary and "secret". It does have an OBD2 port, but almost none of the modules are accessible. To read and clear codes you need to use a round 38pin connector and software that knows how to speak their protocols. There are aftermarket systems which are somewhat unreliable but function almost "good enough". The most reliable option for an end user is to buy a counterfeit Star Diagnostics System multiplexer and a sketchy pirated version of Mercedes-Benz's diagnostics software and run it on an air gapped laptop. Or you can purchase the official Star Diagnostics System for like $20k.
So even routine maintenance is borderline impossible, let alone replacing components. Without the proprietary software, variant coding is impossible for example.
United857 15 hours ago [-]
> less than a minute, that hardware implant can be fitted into a port accessible via a hatch on the exterior of the plane
Just as with computers, as the saying goes, if you have physical access to the device then all bets are off. The tricky part is getting that physical access in the first place...
jurgenburgen 15 hours ago [-]
Of course. Doesn’t mean we should leave the root password written down on a post-it next to the hardware. It sounds strange that such a privileged port has no authentication.
Ekaros 12 hours ago [-]
Getting security to work reliably in such scenarios can be hard. And your customer really don't want their up to hundred million in cost pieces of equipment sit there doing nothing because maintenance is unable to do something with it.
Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.
jurgenburgen 9 hours ago [-]
“Make it the customers problem” always works. These days it feels like LLMs are trained to do the same.
Ekaros 8 hours ago [-]
At certain price point customers tend to make it also your problem. And expensive jets are certainly beyond that point. They might sue you. Or simply not buy or lease new ones.
dosshell 15 hours ago [-]
It is not that simple, atleast in the automotive industry _today_. Atleast here in EU.
Every component is analyzed from a cyber security perspective. Many components needs tampering protection - while others need not. This includes replacing components with malicious ones.
It is not logical at all and a stupid regulation. But it is not as simple as you can do what you want if you have physical access.
everforward 8 hours ago [-]
I have little faith any of it would stop someone who was a) devoted, b) prepared, and c) had physical access for a reasonable time.
It’s still worth doing because the vast, vast majority of people will fail at a or b without even reaching c.
That’s sort of less so with planes, though. You don’t generally decide to take out a plane without being dedicated at the very least.
philipallstar 13 hours ago [-]
Well, the EU, being very much dictated by Germany, who have a large car industry, has a vested interest in making sure that if people want to have a better car they pay for a better one new rather than upgrade with an aftermarket chip.
i_am_a_peasant 12 hours ago [-]
I live in Germany. and i wish i lived in an EU that’s dictated by germany, but that is not the EU I live in.
The above statement sounded way more edgy than intended lol
throw1234567891 10 hours ago [-]
You can take your car to a tuner shop and they’ll do it. Where do you think those 900 bhp m4s come from.
sfn42 11 hours ago [-]
A better car for most people is not just a chip upgrade. Anyone with a lick of sense has no need for more horsepower than whatever a standard EV has. It's beyond plenty for normal driving. I drive an Opel Corsa E which is a cheap EV and it accelerates more than fast enough. Upgrading would be about better safety equipment, better range, more space, better seats, better sound system and stuff like that. None of that can be done with a chip. It would be a different car, which is what I plan to get in a few years.
Paying for a horsepower upgrade chip is something very few people have any interest in doing. Mostly irresponsible assholes who are a danger to others, maybe a few people who need it to pull trailers or something.
acdha 13 hours ago [-]
> Just as with computers, as the saying goes, if you have physical access to the device then all bets are off
This is far less true than it used to be, though, and it seems reasonable to expect that aircraft become as secure as Macs.
Nextgrid 11 hours ago [-]
A huge part of the security of Macs is that the security domain is a single chip. Hard to do with an airplane which is inherently a physically-distributed system.
amelius 12 hours ago [-]
But what if the device contained an explosive?
acdha 11 hours ago [-]
Defenders have to think about multiple threats. Explosives are harder to get, conceal from certain types of scans, and are more overtly deliberate. Neither of these is a common threat but that doesn’t mean people don’t harden against low probability/ high damage events.
amelius 10 hours ago [-]
I mean, if we're going to ignore physical attacks then yeah an airplane can be as safe as a computer I suppose.
ctippett 7 hours ago [-]
The connector shown in the article is apparently the 24-pin connector known as the Open Maintenance Connector (OMC). It's located in the electronics and equipment bay under the nose of the Boeing 737 NG and 737 Max.
I say "apparently" as I had Gemini identify the port from the image.
The OMC provides direct access to key avionics data networks, including the ARINC 429 buses that link the pilot's Flight Management Computer (FMC) to the Multi-Function Control and Display Unit (MCDU).
stefansavage 2 hours ago [-]
It’s not actually called the OMC. That was a generic name used in the paper in lieu of naming the precise connector.
kmoser 8 hours ago [-]
> In their paper, the researchers outline a range of fixes for the vulnerability they've uncovered, starting with removing the connector in the vulnerable port altogether, or plugging it with epoxy.
If you can safely disable the port completely, that implies the port is not needed to begin with. Is that really true? What's the purpose for it?
padjo 7 hours ago [-]
Probably diagnostics and debugging.
danw1979 13 hours ago [-]
I started my career proper as a junior network engineer for a regional British airline (British Midland, since subsumed by BA) in 2001, just before 9/11 continuing for 3 years until mid 2004. Throughout that time, I held an airside pass at LHR that allowed me to get pretty much anywhere I liked, apart from the taxiways and runways of course.
This was pretty standard for most staff - once you’re airside, there were not many restrictions about getting down under the ramp or anywhere around an aircraft on a stand.
Never was this illustrated better than the final homecoming of a BA Concorde in late 2003, when a whole load of staff from different roles across the airport all piled out onto the edge of the apron to wave it home.
A junior IT bod in a high-vis touching something on the outside of an aircraft ? Wouldn’t stand out to anyone watching a CCTV feed. Maybe the other ramp staff would notice, but if you timed it right…
What I’m trying to say is that physical access to aeroplanes even at a place like LHR was pretty much open to anyone who holds an airside pass.
TheOtherHobbes 12 hours ago [-]
You'd have to build many more barriers and gates to stop that, which would be awkward for baggage systems, fuelling, and general maintenance.
The question is more - how hard is it to get airside without a pass?
I once went in through the main arrivals exit doors at Heathrow. I'd forgotten something so I went in, got it, came out again.
It was a stupid thing to do, but I wasn't arrested, stopped, or anythinged.
This was before 9/11 so I doubt you could do it today. But even so.
kotaKat 11 hours ago [-]
> The question is more - how hard is it to get airside without a pass?
Depends. Did you fly in with a random unlocked Cessna from a remote field?
Really funny when you see a random rural airport with an unattended gate with a sign on it telling you the code is "SQUAWK VFR" and you just look at the crusty keypad and slap 1200 in like everyone else before you did on the rubbed-off 1, 2, and 0 keys.
jen729w 12 hours ago [-]
Tangential story. I used to work for one of Australia's 'Big 4' banks. One night I was working in one of the 2 'tier 1' DCs. The place was chock-full of ancient kit. Old mainframes. Tape drives. Nothing in a locked cabinet: this was a room from the 1960s, still active in 2007. I remember it being very beige.
It occurred to me that the catastrophe I could have caused simply by ripping out as many cables as I could see would have been … if not a mini-recession, certainly the sort of thing that moved markets.
Yeah yeah, redundancy and backups. I knew the infrastructure. It wouldn't have worked, not for weeks anyway.
To be in said room, I had undergone a cursory police check.
elias_t 12 hours ago [-]
It’s crazy how much trust there was prior 9/11. I’m wondering if it’s the same nowadays if you get to a certain position or if everything is perfectly compartmentalised
> the company may not in fact implement any such update to their systems for years to come, given how rarely commercial airplanes are redesigned.
Boeing commercial airplanes are constantly updated. As long as the airplane is in service, Boeing retains a team of engineers that update parts as needed. If FAA review is needed, this will of course take longer.
BTW, anyone with access to the internals of an airplane could potentially sabotage it. Sadly, all people with access need to undergo a security check.
Why coin sized, you can fit a gps tracker in a grain of rice-size pellet, why not a phone card.
alexthedigger 11 hours ago [-]
Still too big, I’d like it to fit on the tip of a needle.
numpad0 15 hours ago [-]
...so they built an equivalent of OBDII reader for planes, and it worked just the same as ones for cars? Interesting but not as scary as the title may suggest.
HN should have a rule like what does some reddit subs do.
Either outright ban paywalled articles, or if not then either an archived link should be posted alongside, or the whole text of the article should be copy pasted as a comment
Symbiote 15 hours ago [-]
Who do you expect to pay for journalism?
boesboes 11 hours ago [-]
No one should be paying for this journalism. Calling wired journalism is a stretch, it’s more a blogspam ad farm site
muragekibicho 14 hours ago [-]
It's all so bizarre. They don't want to pay but expect in-depth articles.
It's akin somewhat to the open-source crowd demanding features (and security updates) all without donating to the project.
inigyou 12 hours ago [-]
No, we just expect them not to be posted on link aggregators like HN. Because they are useless links for 99% of readers.
Did you know that video game piracy enhances video game sales? That's because if someone pirates a game and likes it, they might buy it, recommend it to friends, or buy the next one.
haunter 14 hours ago [-]
> They don't want to pay but expect in-depth articles.
You are putting words in my mouth I've never said. I don't "expect in-depth articles", HN would be perfectly fine without paywalled content.
tgv 15 hours ago [-]
Jeff Bezos, probably. The internet really is the death of quality journalism, and democracy slowly dies with it.
randomNumber7 14 hours ago [-]
Slowly?
inigyou 12 hours ago [-]
We're still in the denial phase.
thaumasiotes 14 hours ago [-]
> The internet really is the death of quality journalism
At every level of quality, there is more journalism than there was before.
acdha 13 hours ago [-]
There used to be journalists in every town or city working for local newspapers back when ad revenue stayed local. Don’t confuse the success of a handful of top journals with the health of the field.
> In 1990 we had one daily news(paper) journalist for every 4,490 Americans. Now (or 2019 to be exact), we have one such reporter per 14,250.
> Don’t confuse the success of a handful of top journals with the health of the field.
You appear to be confusing the health of a certain class of employment with the health of the product people in that class used to produce.
tgv 11 hours ago [-]
That's false. I have a 20-odd year old newspaper in a drawer, and it contains so much more news about the world than today's paper. Even national politics is only covered when it's click-bait worthy. Economy? Just a little bit. Foreign politics? Perhaps in a neighboring country when there's an election or something; otherwise, forget it. But its science, art and human interest sections are still comparable. Those don't feed democracy, though.
thaumasiotes 3 hours ago [-]
> That's false. I have a 20-odd year old newspaper in a drawer, and it contains so much more news about the world than today's paper.
Do you think that journalism can't exist outside of a newspaper?
aziaziazi 13 hours ago [-]
Google, serving adds to the article reader? Adds are annoying, but we’re free to leave if we don’t like how a website is managed.
I personally loves the way HN pages are served as they are loading very fast even on not-high end devices, and volunteers contributes to the content (comments).
Paywall are annoying and there’s always someone that post an archive link to circumvent it but I’m not sure about the ethic of a rule requiring to do so.
Symbiote 9 hours ago [-]
The other front-page item on HN is Firefox's continued support for Ublock Origin.
HN readers are also free to pass on an article they can't read. Sometimes I do this when a US website has a complete block on Europe.
graemep 13 hours ago [-]
Paying for individual publications you like is fine.
Paying for all the publications that get articles on the HN front page would be very expensive. Only a minority of people reading HN would have subscribed to any one publication. The result is that paywalled articles can only be properly discussed by a minority people. It also encourages discussion of the headline instead of the article.
acdha 11 hours ago [-]
That still seems better than saying that we have a right to use other people’s work on our terms. People used to subscribe to multiple magazines and that paid for a lot of journalists.
Meetvelde 15 hours ago [-]
I think a lot of these links are being shared via the browser extension, but yes I agree they should do something about this.
croemer 11 hours ago [-]
From the HN FAQs:
Are paywalls ok?
It's ok to post stories from sites with paywalls that have workarounds.
In comments, it's ok to ask how to read an article and to help other users do so. But please don't post complaints about paywalls. Those are off topic. More here.
Eleg007 10 hours ago [-]
Reader mode gave me full access
kotaKat 12 hours ago [-]
“researchers aren't revealing which port they targeted on the 737, nor are they releasing some details of how their hacking device is able to spoof commands to the plane's computers”
Bro. You put “429 interceptor” on the PCB. You’re just fucking on the ARINC 429 bus.
There's already a dongle on the market hooked in some 737s that gives you WiFi access to the 429 and 717 busses through the same port...
EDIT (again): Oh come on, the paper says they went into the Open Maintenance Connector through the E&E bay through the nose gear. C'moooon.
Double-triple edit: Also - ARINC 429 is kinda fun. You can do things like take old glass cockpit hardware and work it into your flight simulator by just feeding the cockpit hardware simulated 429 messages over the wire from your flight sim.
ARINC 429 is the most widely used data bus standard for aviation. Electrical and data format characteristics are defined for a two-wire serial bus with one transmitter and up to 20 receivers. The bus is capable of operating at a speed of 100 kbit/s. - https://en.wikipedia.org/wiki/ARINC_429
15 hours ago [-]
Razengan 15 hours ago [-]
..I feel like I shouldn't bookmark this post, given the invasive "social media checks" in the so-called Free World :')
fragmede 12 hours ago [-]
[dead]
LoganDark 16 hours ago [-]
> “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks,” the statement reads.
You already trust them (as well as the pilots) every time with your flight.
Unfortunately, that is unlikely to get media coverage because the solution would be to respect and pay workers more, a severe crime in a late-stage capitalistic society.
Not to worry, they're furiously working on an alternative which will ensure no worker must ever be respected or paid ever again!
That trust was what led to this incident where someone just walked into the airplane dressed as a maintainence worker and nobody stopped him.
Also pilot suicide isn't something new and the aviation world has tried to come up with several regulations to ensure it doesn't happen even though we completely trust pilots on a normalative basis.
O, it can be even worse, when you realize its a 30 year old problem ...
During the 1998 television show Schalkse Ruiters, presenters Bart De Pauw and Tom Lenaerts dressed in fake pilot uniforms. They bypassed security at Brussels Airport (Zaventem), entered a Boeing cockpit, and left undetected to expose safety flaws
The TV show got cancelled not long after this incident because of pollical backlash.
The show had a reputation of finding security flaws (like being able to transfer money from people bank accounts) and other issues, but the airport one was the end of the show.
People loved the show, as it forced companies, ... make changes to their processes that they normally never did. They even did follow-up episodes to see if the companies actually made changes.
Bit of public shaming to fix security issues... worked great. Until the show was cancelled. The number one rated show of the country ... Yea, there was absolute no correlation between its cancellation and the airport incident. Really ;)
I'm sorry, what now? Did an LLM tell you that?
https://en.wikipedia.org/wiki/Schalkse_Ruiters#History
As AI171 has shown, turning the engines off on rotation does it reliably and there’s nothing that the other pilot or regulations can do to prevent it.
I wonder of such regulations are in fact counterproductive if it means people don't seek out help when they can and let the problem escalate instead (since you presumably don't go from healthy to murder-suicidal in one day, and early intervention could resolve the problem).
Air travel is weird in the sense that pilots do have an immense amount of power and the fact that there have been so few pilot suicide cases shows that regulations for that are somewhat working.
Indeed I wonder how much of aviation-related security theatre is more for the perception of safety than any measurable safety improvements.
> there have been so few pilot suicide cases
I'm not sure it's conclusively possible to attribute this to regulations without a "control case" of a different profession lacking such regulations and that has a higher rate of murder-suicide-by-vehicle. It could just be that the low rates are because there just aren't that many suicidal people willing to kill innocent bystanders in the process.
To be clear I'm not arguing for less regulations as I'm not qualified and don't have all the facts, but bringing up a counterpoint that the current regulations might cause people to conceal their mental health troubles until they escalate (and the current low - but non-zero - rates of incidents are in spite of the regulations rather than because).
Airfields are expected to be secure areas. If you can walk through a hole in a fence there's issues.
Remember a guy stole an entire airplane a few years ago (RIP Sky King). Airplanes don't have ignition keys.
Sooooooome private jets actually bother to slap a Medeco on the external doors, at least, but that's still the only control keeping you grounded.
Wait until they find out your mechanic has unfettered access to your car's OBD port when you hand them the keys. They could install a COIN SIZED device on the CAN bus and you'd never know.
Some people do this voluntarily in exchange for a discount on their insurance.
There's literally millions of people driving newfangled EVs where the car manufacturer has full remote access to their vehicle and can upload software however and whenever they like.
I forgot only the nefarious ones wear yellow reflective vests and earmuffs.
Surprise! “They” did find this out and UN155/156 regulate a bunch of protections against local “attackers,” often to the detriment of right to repair.
This part has been beyond baffling to me. The last thing I want, is to hit the brakes in my car, and suddenly they're less/more sensitive, due to an update the night before, and it really does matter especially on snow/ice. And such updates happen.
I also don't want a perfectly good, 100% working car to suddenly degrade in experience because "Wups! Sorry! Last update broke <whatever>, we'll update within the month to fix!". It's just pure, unbridled dumb.
I recently bought a car, and the dealer tried to sell me an extended warranty. What? It's under a full warranty right now, and yes, my region has very strong warranty and anti-lemon laws. But my point is, they kept saying "there's a lot of complex and expensive electronics in this car, you're going to need an extended warranty".
Um, what? Hello? You just explained that the car breaks down a lot because it's complex? So complex that there are more frequent, highly expensive issues?
How is that a plus?
If a car is "too complex" to roll out the assembly line, without needing updates to modules on a monthly basis for years, it's the opposite of positive. I've had multiple BCM(body control module) updates, updates to every single module in the car. There shouldn't be enough code to cause issues here, it should be simple, simple, simple.
But it's not.
It's complex and difficult to make bug free.
And that makes me oh so very comfortable as I drive down the road.
A dealer will never let a buying customer leave, so 3 years later my car still can't connect to the Internet.
Most people don't think about it when buying a car, or they have no practical way to evaluate it. So it is one of these things you probably need to fix with legislation, except the legislators love the idea too because sensor-rich, always-online cars give them more tools to police the society.
I don't really know what to do with that, short of going neo-Luddite. People often see the excesses of ad tech as a failure of capitalism, but in a sense, we're seeing a tech-driven failure mode for free, democratic societies. In a world where your online presence is tied to your identity and always under the watchful eye of a large language model, and where you can't move from A to B without leaving a digital trail, it's not gonna be fun if you become a thorn in the government's side.
Otherwise the car is still connected and very likely broadcasting telemetry anyway (and the "account" part is handled entirely on the backend). Refusing to set up or use the app is merely a placebo.
I've got another car that's 13 years old and has got 126 000 miles / 202 000 km and that is 13 years old. In the 8 years I've had this one, my "green" doctor buddy changed four times his car.
Who's consuming the most? My ecological doctor friend who changes car every two years, my 13 years old daily or my 38 years car? (most cars have long been destroyed after 38 years)
Sure, the 38 old Porsche is a bit of a gas guzzler but the thing still runs strong. One Bosch Motronic electronic board for the fuel injection and that's it: no OTA updates, fully mechanical dashboard (which looks gorgeous btw).
Who's really the consumerist here? Me or my doctor buddy who buys a new EV every two years?
And if instead of an old Porsche I was using an old Toyota with much better mpg, then the equation is even better.
I'm not against switching to an EV but I don't want any of this OTA updates and 24/7 connected bullshit: give me an EV that doesn't phone home and I may listen.
Things however don't seem to be heading that way so I think I'll be driving used cars for a very long time.
Obviously it would be even better to keep one EV longer (hard to say how much better, they do displace ICE vehicles in the used market) but they're almost certainly consuming less than you.
Certainly he creates some demand for new cars and you make a good point about reducing consumption.
As of right now, my bets on which cars will be running 30 more years from now are:
Dodge: yes
Toyota: maybe
Benz: no
I have a concept of a plan to combine the "maybe" and "no" vehicles into a single Frankenstein's monster which will undoubtedly be a "yes". It involves eliminating all the electronic controls.
I don't see how these proprietary, point-in-time hardware/software systems can possibly be maintainable long term. In 20 years there will only be 50yo ECUs available to replace my current ones.
Contrast that with any 1970s era vehicles you can buy today. So long as the rust isn't too bad, you can 100% definitely restore it mechanically.
There are a handful of aftermarket ECUs to do fuel injection and electronic ignition. Initial configuration is a bit of a bear and I dunno if you'll be able to find a shop to do it, but if your model runs out of working pulls, it's an option. My 1981 van has a Bosch electronic fuel injection system and if it fails (which seems rare), most people can find a replacement module from a van that was crashed or rusted out; some people put carbuerators on it; a couple people put a microsquirt. The air flow meter might be a bigger issue, they have mechanical wear and I haven't seen anything about refurbishing them (but maybe I missed it)
1. Controllers. Absolutely must be open software and hardware, no compromises.
2. Actuators. If not open hardware, they must be documented sufficiently to facilitate adapting a suitable replacement in the future.
3. Sensors. Same constraints as actuators.
Unfortunately even mega/microsquirt systems don't quite get us there yet.
[edit] One example that informs my hardline stance here is reading ECU codes. On the Toyota's ECU there's an open interface for reading fault codes documented in the factory shop manual. You jump a couple pins on a connector in the engine compartment with a test light and read the number of flashes. The Benz, by contrast, is completely proprietary and "secret". It does have an OBD2 port, but almost none of the modules are accessible. To read and clear codes you need to use a round 38pin connector and software that knows how to speak their protocols. There are aftermarket systems which are somewhat unreliable but function almost "good enough". The most reliable option for an end user is to buy a counterfeit Star Diagnostics System multiplexer and a sketchy pirated version of Mercedes-Benz's diagnostics software and run it on an air gapped laptop. Or you can purchase the official Star Diagnostics System for like $20k.
So even routine maintenance is borderline impossible, let alone replacing components. Without the proprietary software, variant coding is impossible for example.
Just as with computers, as the saying goes, if you have physical access to the device then all bets are off. The tricky part is getting that physical access in the first place...
Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.
Every component is analyzed from a cyber security perspective. Many components needs tampering protection - while others need not. This includes replacing components with malicious ones.
It is not logical at all and a stupid regulation. But it is not as simple as you can do what you want if you have physical access.
It’s still worth doing because the vast, vast majority of people will fail at a or b without even reaching c.
That’s sort of less so with planes, though. You don’t generally decide to take out a plane without being dedicated at the very least.
The above statement sounded way more edgy than intended lol
Paying for a horsepower upgrade chip is something very few people have any interest in doing. Mostly irresponsible assholes who are a danger to others, maybe a few people who need it to pull trailers or something.
This is far less true than it used to be, though, and it seems reasonable to expect that aircraft become as secure as Macs.
I say "apparently" as I had Gemini identify the port from the image.
The OMC provides direct access to key avionics data networks, including the ARINC 429 buses that link the pilot's Flight Management Computer (FMC) to the Multi-Function Control and Display Unit (MCDU).
If you can safely disable the port completely, that implies the port is not needed to begin with. Is that really true? What's the purpose for it?
This was pretty standard for most staff - once you’re airside, there were not many restrictions about getting down under the ramp or anywhere around an aircraft on a stand.
Never was this illustrated better than the final homecoming of a BA Concorde in late 2003, when a whole load of staff from different roles across the airport all piled out onto the edge of the apron to wave it home.
A junior IT bod in a high-vis touching something on the outside of an aircraft ? Wouldn’t stand out to anyone watching a CCTV feed. Maybe the other ramp staff would notice, but if you timed it right…
What I’m trying to say is that physical access to aeroplanes even at a place like LHR was pretty much open to anyone who holds an airside pass.
The question is more - how hard is it to get airside without a pass?
I once went in through the main arrivals exit doors at Heathrow. I'd forgotten something so I went in, got it, came out again.
It was a stupid thing to do, but I wasn't arrested, stopped, or anythinged.
This was before 9/11 so I doubt you could do it today. But even so.
Depends. Did you fly in with a random unlocked Cessna from a remote field?
Really funny when you see a random rural airport with an unattended gate with a sign on it telling you the code is "SQUAWK VFR" and you just look at the crusty keypad and slap 1200 in like everyone else before you did on the rubbed-off 1, 2, and 0 keys.
It occurred to me that the catastrophe I could have caused simply by ripping out as many cables as I could see would have been … if not a mini-recession, certainly the sort of thing that moved markets.
Yeah yeah, redundancy and backups. I knew the infrastructure. It wouldn't have worked, not for weeks anyway.
To be in said room, I had undergone a cursory police check.
Boeing commercial airplanes are constantly updated. As long as the airplane is in service, Boeing retains a team of engineers that update parts as needed. If FAA review is needed, this will of course take longer.
BTW, anyone with access to the internals of an airplane could potentially sabotage it. Sadly, all people with access need to undergo a security check.
HN should have a rule like what does some reddit subs do.
Either outright ban paywalled articles, or if not then either an archived link should be posted alongside, or the whole text of the article should be copy pasted as a comment
It's akin somewhat to the open-source crowd demanding features (and security updates) all without donating to the project.
Did you know that video game piracy enhances video game sales? That's because if someone pirates a game and likes it, they might buy it, recommend it to friends, or buy the next one.
You are putting words in my mouth I've never said. I don't "expect in-depth articles", HN would be perfectly fine without paywalled content.
At every level of quality, there is more journalism than there was before.
> In 1990 we had one daily news(paper) journalist for every 4,490 Americans. Now (or 2019 to be exact), we have one such reporter per 14,250.
https://www.reportforamerica.org/2021/06/28/the-journalist-p...
You appear to be confusing the health of a certain class of employment with the health of the product people in that class used to produce.
Do you think that journalism can't exist outside of a newspaper?
I personally loves the way HN pages are served as they are loading very fast even on not-high end devices, and volunteers contributes to the content (comments).
Paywall are annoying and there’s always someone that post an archive link to circumvent it but I’m not sure about the ethic of a rule requiring to do so.
HN readers are also free to pass on an article they can't read. Sometimes I do this when a US website has a complete block on Europe.
Paying for all the publications that get articles on the HN front page would be very expensive. Only a minority of people reading HN would have subscribed to any one publication. The result is that paywalled articles can only be properly discussed by a minority people. It also encourages discussion of the headline instead of the article.
Are paywalls ok?
It's ok to post stories from sites with paywalls that have workarounds.
In comments, it's ok to ask how to read an article and to help other users do so. But please don't post complaints about paywalls. Those are off topic. More here.
Bro. You put “429 interceptor” on the PCB. You’re just fucking on the ARINC 429 bus.
Also, this exists as a commercial product (in some ways): https://www.astronics.com/wireless-electronic-flight-bags-we...
There's already a dongle on the market hooked in some 737s that gives you WiFi access to the 429 and 717 busses through the same port...
EDIT (again): Oh come on, the paper says they went into the Open Maintenance Connector through the E&E bay through the nose gear. C'moooon.
Double-triple edit: Also - ARINC 429 is kinda fun. You can do things like take old glass cockpit hardware and work it into your flight simulator by just feeding the cockpit hardware simulated 429 messages over the wire from your flight sim.
Here's some 737 instruments being driven from FSX: https://www.youtube.com/watch?v=RtTJiU-vArs
ARINC defines a series of standards for Avionics Systems and Communications - https://en.wikipedia.org/wiki/ARINC
ARINC 429 is the most widely used data bus standard for aviation. Electrical and data format characteristics are defined for a two-wire serial bus with one transmitter and up to 20 receivers. The bus is capable of operating at a speed of 100 kbit/s. - https://en.wikipedia.org/wiki/ARINC_429
So "We don't expect hackers to figure it out"
People