DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight (arstechnica.com) 21
An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS.
According to the "ACARS Drama" account, a message was sent by pilots from the plane stated: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A description of the incident posted to Reddit further stated that these passengers created a fake hotspot ("Delta WiFi Fast"), with a phishing landing page "designed to harvest passengers' personal credentials."
This technique, sometimes known as an "evil twin" attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data. "One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," said a Delta spokesperson. Delta further noted that the flight's safety was "never in question and no aircraft operating systems were affected," and that no emergency was declared.
Ars notes that the "actual onboard Wi-Fi was disabled for 30 minutes."
According to the "ACARS Drama" account, a message was sent by pilots from the plane stated: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A description of the incident posted to Reddit further stated that these passengers created a fake hotspot ("Delta WiFi Fast"), with a phishing landing page "designed to harvest passengers' personal credentials."
This technique, sometimes known as an "evil twin" attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data. "One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," said a Delta spokesperson. Delta further noted that the flight's safety was "never in question and no aircraft operating systems were affected," and that no emergency was declared.
Ars notes that the "actual onboard Wi-Fi was disabled for 30 minutes."
I remember a coworker's description of DEF CON (Score:3)
"It's like Blackhat, but for people without jobs"
So what (Score:2)
Yeah so what? This is trivial to do. I'm actually surprised anyone noticed.
Re: (Score:2)
More than that, the seatback display on every Delta flight gives you instructions for how to connect to their real WiFi. If you join some random SSID that doesn't follow the instructions literally in front of your face, you deserve what you bought.
Terrorist Fuckers! (Score:2)
They were using Linux!
Oh no, not a wifi hotspot! (Score:2)
Reroute the plane to Guantanamo!
Re: Oh no, not a wifi hotspot! (Score:1)
I'm not saying I'm in favor of sending the wayland/systemd/gnome3 crowd to gitmo...but I'm not saying I'm necessarily against it either...
Next year's DEF CON (Score:2)
Book a seat on Greyhound. Because you won't be flying anymore.
Re: (Score:2)
Book a seat on Greyhound. Because you won't be flying anymore.
Because, like Archer, they're on both the No Fly and No Train lists [youtube.com]? :-)
Absolute Berks (Score:2)
At his majesty's pleasuure (Score:3)
Serving prison time "at the pleasure of the king or queen" (historically at Her/His Majesty’s pleasure) is a legal term for an indefinite or life sentence where a prisoner has no fixed release date. Instead, their continued detention depends on the ongoing discretion or review of the Crown (or government parole authorities acting in its name)
In Commonwealth republics, such as Botswana,[7] India,[8] Kenya,[9] Pakistan, Singapore,[10] South Africa,[11] and Sri Lanka, the phrase is "during the president'
Re: (Score:2)
Right it is a lack of understanding as far as the security model is concerned.
You are captive in a metal can and the authorities control the exists. It is not even like a bus or train where you might force the operators to top and you could run off into the woods or someone could meet you with a car, even if you hijack the thing by the time you land it, the authorities are there waiting for you.
There is little room for mischief on an airline because anything you might to try to escape mostly won't work and
This happens all the time, everywhere. (Score:2)
Re: (Score:2)
Just blame your AI model (Score:2)
script kids (Score:2)
Script kids, on a plane.
What are the chances this was done by a male under the age of 30?
SSL for Wifi (Score:2)
This has always been a thing and maybe we need SSL for WiFi. Let's get Let's Encrypt on the case and Apple and Google throwing up big scary "Do you trust this Wifi?" for all non-certified Wifi hotspots and slap on a Certified label.
Re: (Score:2)
Re: SSL for Wifi (Score:1)
Re: (Score:2)
script kiddies (Score:2)
I assumed this was widespread already. It's very similar to the usual procedures to share hotel (and yes, aircraft) wifi across multiple devices while only paying for one connection. It's polite not to be a dick about it and try to steal strangers' credentials though.
Instead of stealing credentials, they could gain some goodwill by resharing the wifi with an SSID like "free_wifi_from_DEFCON." ...though of course nobody sane would trust a name like that. How about "free_wifi_from_48C_buy_me_a_beer"