<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>True Insight &#187; airgap</title>
	<atom:link href="http://www.truedigitalsecurity.com/blog/tag/airgap/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.truedigitalsecurity.com/blog</link>
	<description>Information Security in Today&#039;s Digital Culture</description>
	<lastBuildDate>Thu, 02 Feb 2012 15:57:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>This seems like a smart idea&#8230;</title>
		<link>http://www.truedigitalsecurity.com/blog/2008/02/20/this-seems-like-a-smart-idea/</link>
		<comments>http://www.truedigitalsecurity.com/blog/2008/02/20/this-seems-like-a-smart-idea/#comments</comments>
		<pubDate>Wed, 20 Feb 2008 15:40:41 +0000</pubDate>
		<dc:creator>Brett Edgar</dc:creator>
				<category><![CDATA[Give me more Internets!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Terrorism]]></category>
		<category><![CDATA[airgap]]></category>
		<category><![CDATA[airplanes]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://blog.truedigitalsecurity.com/2008/02/20/this-seems-like-a-smart-idea/</guid>
		<description><![CDATA[The new Boeing 787 Dreamliner has been widely reported as a feat of technological engineering. The plane has three separate networks on-board: an administrative network, a flight control/navigation network, and a passenger network. Everything about this plane seems cool from the Ethernet jacks in the armrest of every seat, to the completely computerized flight controls &#8230; <a href="http://www.truedigitalsecurity.com/blog/2008/02/20/this-seems-like-a-smart-idea/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton22" class="tw_button" style=""><a href="http://twitter.com/share?url=http%3A%2F%2Fgoo.gl%2FcNBJr&amp;via=lairofthewalrus&amp;text=This%20seems%20like%20a%20smart%20idea%26%238230%3B&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=http%3A%2F%2Fwww.truedigitalsecurity.com%2Fblog%2F2008%2F02%2F20%2Fthis-seems-like-a-smart-idea%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://www.truedigitalsecurity.com/blog/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;"></a></div><p>The new Boeing 787 Dreamliner has been widely reported as a feat of technological engineering.  The plane has three separate networks on-board: an administrative network, a flight control/navigation network, and a passenger network.  Everything about this plane seems cool from the Ethernet jacks in the armrest of every seat, to the completely computerized flight controls system, to the ability for the plane to automatically adjust humidity settings based on the number of passengers on-board.  There&#8217;s just one problem.  <a href="http://www.foxnews.com/story/0,2933,331088,00.html" title="Is the 787 Dreamliner hackable?">Reports indicate</a>[foxnews.com] that the three networks (administrative, flight, and passenger) are not completely separated.  There is at least the ability for one-way communications from one of the networks to another.  But unless this is a connectionless, no guarantee of delivery, UDP-like fire-the-message-and-hope-it-arrives communications protocol, there are obviously two-way connections, even if control information was designed (in software) to be transmitted in only one direction.</p>
<p>So these networks are not air-gapped, the only foolproof way to prevent one network from talking to another.  To make matters worse, it seems that the administrative network is accessible via Wi-Fi (for maintenance personnel), particularly while the aircraft is sitting at the gate.  So a sufficiently skilled 16-year-old Johnny Q. Hacker could sit comfortably in an airport terminal with his laptop and attempt to hack into a 787&#8242;s administrative network.</p>
<p>I hope they are using WPA2 with AES encryption and rolling keys&#8230;</p>
<div class="wp-about-author-containter-none" style="background-color:#edf0f7;"><div class="wp-about-author-pic"><img alt='Brett Edgar' src='http://www.truedigitalsecurity.com/blog/wp-content/uploads/2012/01/Kayna-Kelley_avatar.jpg' class='avatar avatar-100 photo' height='100' width='100' /></div><div class="wp-about-author-text"><h3><a href='http://www.truedigitalsecurity.com/blog/author/bredgar/' title='Brett Edgar'>Brett Edgar</a></h3><p>Brett is a Founder and the Director of Managed Security Services at TRUE.  He has been working in the system and network forensics field since graduating from the University of Tulsa with a B.S. Computer Science in 2003.  He speaks hexadecimal fluently and is TRUE's resident human Ethernet transceiver.  He holds CISSP, CSSLP, and CNSS 4011-4015 certificates, loves MLB and NCAA Football, and when he gets tired of hexadecimal, he goes home to hang out with his wife and kid.</p><p><a href='lairofthewalrus' title='Brett Edgaron Twitter'>Twitter</a> - <a href='http://www.truedigitalsecurity.com/blog/author/bredgar/' title='More posts by Brett Edgar'>More Posts</a> </p></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.truedigitalsecurity.com/blog/2008/02/20/this-seems-like-a-smart-idea/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

