Remix.run Logo
elmer2 21 hours ago

This attack is very simple and basically a few button clicks these days.

Script kiddy at best.

xp84 20 hours ago | parent | next [-]

Agreed, and it seems to lack the hacker spirit I'd expect out of someone attending DEFCON. The only intentions I can figure out would be...

1. Just to screw with fellow passengers - dick move, how do you know someone wasn't working on something critically important on that wi-fi?

2. 'Robin Hood'?? If they had a paid wi-fi session and were gonna bridge all the passengers who connected to their rogue AP onto it for free. Extremely farfetched theory though since they could have easily still done this without deauthing the people, who'd already paid anyway.

3. Actual black-hat hacking, hoping to snoop on people's connections for cybercrime reasons.

Can't say I'm bothered at all that these guys had the cops called on them.

hinata08 20 hours ago | parent | prev | next [-]

You would be surprised by the number of professionals who would be at peak tech performance if they could pull it off

IT security is a lot more about the processes, risk, and data management that technical performance these days.

The book to study for CISSP CBK is hardly any technical (The Code Book is more technical than that)

The ISO 27000 series defines an Information security management system that doesn't even need to involve "computer", as it discusses more about data in the organization.

Research these days is also based a lot on how to address security risks on top of safety risks, not just how to hack any system (and I do believe that the obsession of the aviation industry about these studies is why everything was ready so that suspects were met with police)

HDBaseT 21 hours ago | parent | prev | next [-]

Sure, but you probably shouldn't mess with planes, even is mundane or trivial.

For some reason, we treat planes super differently than every other public space or transport.

dlcarrier 16 hours ago | parent | next [-]

At least we limit security theater to airports. Could you imagine if you had to arrive at every bus station and train depot two hours early, so you could wait in line for a security screening that fails 95% of the time?

ronsor 14 hours ago | parent [-]

We should do this for taxi rides and cars.

hinata08 20 hours ago | parent | prev | next [-]

Delta's setup and procedures were able to catch up on that. Good move from their side !

Police was involved

No offense, but I doubt that most other public spaces or transport would have reacted like that.

It's not just because planes fly, but the industry around them has planned for everything.

This Hacker News post could be "Delta is ready"

mckirk 20 hours ago | parent | prev | next [-]

> for some reason

I mean, I can think of one reason. Them being quite far away from the ground most of the time, mainly.

DANmode 18 hours ago | parent | prev [-]

The WiFi isn’t connected to the “plane”,

and if it is, and it historically has been, that’s a different problem also not the hackers’ fault.

netsharc 20 hours ago | parent | prev [-]

The actual hacker creds is earned by not getting caught by a federal investigation.

Although, with Kash Patel's FSB cosplayers, maybe that's playing in easy mode.

And remember, you can't brag about it either, that's how most get caught.