Coin-sized device can hack a Boeing 737
Researchers from the University of California San Diego and Oberlin College are set to unveil a hacking method at the upcoming Usenix cybersecurity conference. This technique could potentially take control of a Boeing 737's autopilot, manipulate its navigation, or subtly alter key values in its fuel calculations and takeoff calculations on the plane's screen.
The researchers have developed a device, roughly the size of a coin, that uses Wi-Fi technology and costs less than $100. It can be inserted into a port accessible via a hatch on the plane's exterior, which is typically within reach of maintenance staff or airport personnel during layovers. Once installed, the device can transmit electrical signals through the plane's internal network, sending false commands to critical computer systems that manage the autopilot and display information to the pilot, such as the plane's weight and outside air temperature.
The aim of this demonstration is to highlight how this sort of physical access hacking represents a practical threat in the hands of well-funded adversaries, offering them more control, stealth, and deniability compared to traditional threats like bombing a plane. The researchers emphasize that despite the simplicity of deploying such an attack—taking less than a minute—the Boeing 737 industry has not yet provided a concrete solution to mitigate these vulnerabilities.
While the researchers have shared their findings with Boeing, the company downplayed the risk, stating that their protective measures are sufficient. The researchers suggest that the aviation industry could consider plugging or removing this particular port as a simple yet effective countermeasure.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.