by Frank Bergman
A team of security researchers in California has developed a tiny device capable of hijacking the autopilot system of a Boeing 737, altering its flight plan, manipulating critical takeoff data, and feeding false information to pilots without them ever being aware that the attack is taking place.
The device, created by researchers from the University of California, San Diego, and Oberlin College, is only slightly larger than a coin and costs less than $100.
Once plugged into an externally accessible port on the aircraft, the device can connect through the plane’s in-flight Wi-Fi system and give a remote attacker access to critical onboard systems.
Tiny Device Can Take Control of Autopilot
Researchers say the port can be reached in seconds without special tools and is accessible to maintenance workers and airline personnel.
“If you could get 60 seconds with an airplane, what could you do?” UCSD professor Stefan Savage, who led the project, told Wired.
“Well, it turns out there’s a port that’s externally accessible.
“You can get to it with no special tools in about 15 seconds.
“And you can shove in a piece of electronics a little bigger than a quarter that lets you basically tell the autopilot what to do and lie to the pilot about changes to the flight plan.”
The researchers developed the attack after spending years rebuilding key elements of a 737’s computer architecture using aircraft components.
Inspired by credit card skimmers used to steal information from ATMs, the team realized that an aircraft could be compromised by physically inserting a device into its internal data bus.
After studying Boeing wiring diagrams, they identified a port carrying information between the Flight Management Computer and the pilot’s display system.
Savage described the discovery as finding “the goddamn exhaust port on the Death Star.”
Hackers Could Feed Pilots False Information
The device does more than alter autopilot commands.
