• userbinator 3 hours ago

one that's routinely within reach of maintenance workers or other airport and airline staff between flights

You already trust them (as well as the pilots) every time with your flight.

• altmanaltman 3 hours ago

https://www.theguardian.com/business/2025/mar/06/avalon-airp...

That trust was what led to this incident where someone just walked into the airplane dressed as a maintainence worker and nobody stopped him.

Also pilot suicide isn't something new and the aviation world has tried to come up with several regulations to ensure it doesn't happen even though we completely trust pilots on a normalative basis.

• 05 2 hours ago

> Also pilot suicide isn't something new and the aviation world has tried to come up with several regulations to ensure it doesn't happen

As AI171 has shown, turning the engines off on rotation does it reliably and there’s nothing that the other pilot or regulations can do to prevent it.

• pudgywalsh 3 hours ago

You conveniently left out the part where he walked through a hole in the airport fence.

Airfields are expected to be secure areas. If you can walk through a hole in a fence there's issues.

Remember a guy stole an entire airplane a few years ago (RIP Sky King). Airplanes don't have ignition keys.

• markdown 3 hours ago

Is that the legend who managed to do a loop-the-loop?

• pudgywalsh 3 hours ago

You know it is.

• pudgywalsh 3 hours ago

Are these the same maintenance workers that have access to even more sensitive parts of the airplane like the avionics compartment and its miles of wiring?

Wait until they find out your mechanic has unfettered access to your car's OBD port when you hand them the keys. They could install a COIN SIZED device on the CAN bus and you'd never know.

Some people do this voluntarily in exchange for a discount on their insurance.

There's literally millions of people driving newfangled EVs where the car manufacturer has full remote access to their vehicle and can upload software however and whenever they like.

I forgot only the nefarious ones wear yellow reflective vests and earmuffs.

• b112 an hour ago

There's literally millions of people driving newfangled EVs where the car manufacturer has full remote access to their vehicle and can upload software however and whenever they like.

This part has been beyond baffling to me. The last thing I want, is to hit the brakes in my car, and suddenly they're less/more sensitive, due to an update the night before, and it really does matter especially on snow/ice. And such updates happen.

I also don't want a perfectly good, 100% working car to suddenly degrade in experience because "Wups! Sorry! Last update broke <whatever>, we'll update within the month to fix!". It's just pure, unbridled dumb.

I recently bought a car, and the dealer tried to sell me an extended warranty. What? It's under a full warranty right now, and yes, my region has very strong warranty and anti-lemon laws. But my point is, they kept saying "there's a lot of complex and expensive electronics in this car, you're going to need an extended warranty".

Um, what? Hello? You just explained that the car breaks down a lot because it's complex? So complex that there are more frequent, highly expensive issues?

How is that a plus?

If a car is "too complex" to roll out the assembly line, without needing updates to modules on a monthly basis for years, it's the opposite of positive. I've had multiple BCM(body control module) updates, updates to every single module in the car. There shouldn't be enough code to cause issues here, it should be simple, simple, simple.

But it's not.

It's complex and difficult to make bug free.

And that makes me oh so very comfortable as I drive down the road.

• glimshe 21 minutes ago

Last time I bought a car the dealer couldn't enable the Internet features because I said my phone was broken. He looked at me puzzled but I said I could but the car some other day if that was a problem...

A dealer will never let a buying customer leave, so 3 years later my car still can't connect to the Internet.

• forestry an hour ago

You also aren’t given a choice. If you decline, “don’t drive it”. Well, I want the car, not the connection. I could probably pull the sim I suppose.

• matherial an hour ago

> This part has been beyond baffling to me. The last thing I want

Most people don't think about it when buying a car, or they have no practical way to evaluate it. So it is one of these things you probably need to fix with legislation, except the legislators love the idea too because sensor-rich, always-online cars give them more tools to police the society.

I don't really know what to do with that, short of going neo-Luddite. People often see the excesses of ad tech as a failure of capitalism, but in a sense, we're seeing a tech-driven failure mode for free, democratic societies. In a world where your online presence is tied to your identity and always under the watchful eye of a large language model, and where you can't move from A to B without leaving a digital trail, it's not gonna be fun if you become a thorn in the government's side.

• _puk an hour ago

But you bought the car

• danw1979 20 minutes ago

I started my career proper as a junior network engineer for a regional British airline (British Midland, since subsumed by BA) in 2001, just before 9/11 continuing for 3 years until mid 2004. Throughout that time, I held an airside pass at LHR that allowed me to get pretty much anywhere I liked, apart from the taxiways and runways of course.

This was pretty standard for most staff - once you’re airside, there were not many restrictions about getting down under the ramp or anywhere around an aircraft on a stand.

Never was this illustrated better than the final homecoming of a BA Concorde in late 2003, when a whole load of staff from different roles across the airport all piled out onto the edge of the apron to wave it home.

A junior IT bod in a high-vis touching something on the outside of an aircraft ? Wouldn’t stand out to anyone watching a CCTV feed. Maybe the other ramp staff would notice, but if you timed it right…

What I’m trying to say is that physical access to aeroplanes even at a place like LHR was pretty much open to anyone who holds an airside pass.

• jen729w 13 minutes ago

Tangential story. I used to work for one of Australia's 'Big 4' banks. One night I was working in one of the 2 'tier 1' DCs. The place was chock-full of ancient kit. Old mainframes. Tape drives. Nothing in a locked cabinet: this was a room from the 1960s, still active in 2007. I remember it being very beige.

It occurred to me that the catastrophe I could have caused simply by ripping out as many cables as I could see would have been … if not a mini-recession, certainly the sort of thing that moved markets.

Yeah yeah, redundancy and backups. I knew the infrastructure. It wouldn't have worked, not for weeks anyway.

To be in said room, I had undergone a cursory police check.

• United857 3 hours ago

> less than a minute, that hardware implant can be fitted into a port accessible via a hatch on the exterior of the plane

Just as with computers, as the saying goes, if you have physical access to the device then all bets are off. The tricky part is getting that physical access in the first place...

• jurgenburgen 2 hours ago

Of course. Doesn’t mean we should leave the root password written down on a post-it next to the hardware. It sounds strange that such a privileged port has no authentication.

• Ekaros 5 minutes ago

Getting security to work reliably in such scenarios can be hard. And your customer really don't want their up to hundred million in cost pieces of equipment sit there doing nothing because maintenance is unable to do something with it.

Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.

• acdha an hour ago

> Just as with computers, as the saying goes, if you have physical access to the device then all bets are off

This is far less true than it used to be, though, and it seems reasonable to expect that aircraft become as secure as Macs.

• amelius 5 minutes ago

But what if the device contained an explosive?

• dosshell 3 hours ago

It is not that simple, atleast in the automotive industry _today_. Atleast here in EU.

Every component is analyzed from a cyber security perspective. Many components needs tampering protection - while others need not. This includes replacing components with malicious ones.

It is not logical at all and a stupid regulation. But it is not as simple as you can do what you want if you have physical access.

• philipallstar 30 minutes ago

Well, the EU, being very much dictated by Germany, who have a large car industry, has a vested interest in making sure that if people want to have a better car they pay for a better one new rather than upgrade with an aftermarket chip.

• WalterBright 3 hours ago

> the company may not in fact implement any such update to their systems for years to come, given how rarely commercial airplanes are redesigned.

Boeing commercial airplanes are constantly updated. As long as the airplane is in service, Boeing retains a team of engineers that update parts as needed. If FAA review is needed, this will of course take longer.

BTW, anyone with access to the internals of an airplane could potentially sabotage it. Sadly, all people with access need to undergo a security check.

• ThrowawayTestr 3 hours ago

Sadly?

• lukan 2 hours ago

Irony/point of view from an attacker.

• snapsnail 3 hours ago
• haunter 3 hours ago

https://archive.md/3fpga

HN should have a rule like what does some reddit subs do.

Either outright ban paywalled articles, or if not then either an archived link should be posted alongside, or the whole text of the article should be copy pasted as a comment

• Symbiote 3 hours ago

Who do you expect to pay for journalism?

• muragekibicho 2 hours ago

It's all so bizarre. They don't want to pay but expect in-depth articles.

It's akin somewhat to the open-source crowd demanding features (and security updates) all without donating to the project.

• haunter an hour ago

> They don't want to pay but expect in-depth articles.

You are putting words in my mouth I've never said. I don't "expect in-depth articles", HN would be perfectly fine without paywalled content.

• graemep an hour ago

Paying for individual publications you like is fine.

Paying for all the publications that get articles on the HN front page would be very expensive. Only a minority of people reading HN would have subscribed to any one publication. The result is that paywalled articles can only be properly discussed by a minority people. It also encourages discussion of the headline instead of the article.

• tgv 2 hours ago

Jeff Bezos, probably. The internet really is the death of quality journalism, and democracy slowly dies with it.

• thaumasiotes an hour ago

> The internet really is the death of quality journalism

At every level of quality, there is more journalism than there was before.

• acdha an hour ago

There used to be journalists in every town or city working for local newspapers back when ad revenue stayed local. Don’t confuse the success of a handful of top journals with the health of the field.

> In 1990 we had one daily news(paper) journalist for every 4,490 Americans. Now (or 2019 to be exact), we have one such reporter per 14,250.

https://www.reportforamerica.org/2021/06/28/the-journalist-p...

• randomNumber7 2 hours ago

Slowly?

• aziaziazi an hour ago

Google, serving adds to the article reader? Adds are annoying, but we’re free to leave if we don’t like how a website is managed.

I personally loves the way HN pages are served as they are loading very fast even on not-high end devices, and volunteers contributes to the content (comments).

Paywall are annoying and there’s always someone that post an archive link to circumvent it but I’m not sure about the ethic of a rule requiring to do so.

• Meetvelde 3 hours ago

I think a lot of these links are being shared via the browser extension, but yes I agree they should do something about this.

• numpad0 3 hours ago

...so they built an equivalent of OBDII reader for planes, and it worked just the same as ones for cars? Interesting but not as scary as the title may suggest.

• Razengan 3 hours ago

..I feel like I shouldn't bookmark this post, given the invasive "social media checks" in the so-called Free World :')

• LoganDark 3 hours ago

> “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks,” the statement reads.

So "We don't expect hackers to figure it out"

• x______________ 3 hours ago

>So "We don't expect hackers to figure it out"

People