The Federal Aviation Administration has said that a researcher’s claims that he could hack an aircraft in-flight using only an Android application and a desktop computer are not possible. The FAA’s dismissal comes after Hugo Teso, a German information technology consultant, presented his findings during the Hack in the Box conference earlier this month.
According to Teso, security issues with the Honeywell NZ-2000 Flight Management System (FMS), allowed him to send signals via his Android device, compromising the FMS within a simulated environment. His research was carried by many news outlets, and sparked some concern.
However, the FAA, in a statement sent to SecurityWeek, says that there is no risk – as the technique doesn’t work against certified flight hardware.
“The FAA is aware that a German information technology consultant has alleged he has detected a security issue with the Honeywell NZ-2000 Flight Management System (FMS) using only a desktop computer,” the statement said.
“The FAA has determined that the hacking technique described during a recent computer security conference does not pose a flight safety concern because it does not work on certified flight hardware. The described technique cannot engage or control the aircraft’s autopilot system using the FMS or prevent a pilot from overriding the autopilot. Therefore, a hacker cannot obtain “full control of an aircraft” as the technology consultant has claimed.”
The dismissals have additional significance as the FAA was given access to the complete process Teso used to exploit the FMS, something that wasn’t publically released. For those interested, a copy of the presentation can be found here.
In addition, further explanations are online here.
In 2012, a similar spoofing attack was discussed at Black Hat, which is covered in detail here.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- US Downs Chinese Balloon Off Carolina Coast
- Microsoft: Iran Unit Behind Charlie Hebdo Hack-and-Leak Op
- Feds Say Cyberattack Caused Suicide Helpline’s Outage
- Big China Spy Balloon Moving East Over US, Pentagon Says
- Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty
- Cyber Insights 2023: Venture Capital
- Atlassian Warns of Critical Jira Service Management Vulnerability
- High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation
