Forgot your password?
typodupeerror
Wireless Networking The Internet

DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight (arstechnica.com) 36

An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS.

According to the "ACARS Drama" account, a message was sent by pilots from the plane stated: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A description of the incident posted to Reddit further stated that these passengers created a fake hotspot ("Delta WiFi Fast"), with a phishing landing page "designed to harvest passengers' personal credentials."

This technique, sometimes known as an "evil twin" attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data.
"One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," said a Delta spokesperson. Delta further noted that the flight's safety was "never in question and no aircraft operating systems were affected," and that no emergency was declared.

Ars notes that the "actual onboard Wi-Fi was disabled for 30 minutes."
This discussion has been archived. No new comments can be posted.

DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight

Comments Filter:
  • by 93 Escort Wagon ( 326346 ) on Wednesday August 12, 2026 @03:04PM (#66285922)

    "It's like Blackhat, but for people without jobs"

  • Yeah so what? This is trivial to do. I'm actually surprised anyone noticed.

    • More than that, the seatback display on every Delta flight gives you instructions for how to connect to their real WiFi. If you join some random SSID that doesn't follow the instructions literally in front of your face, you deserve what you bought.

  • They were using Linux!

  • Reroute the plane to Guantanamo!

  • Book a seat on Greyhound. Because you won't be flying anymore.

  • Utter berks that are looking to find themselves with guest accommodations in the US federal prison system. This is one of those places where no one finds it funny and serious people with serious firearms are often found waiting at the exit of the aircraft at the next destination.
    • Serving prison time "at the pleasure of the king or queen" (historically at Her/His Majesty’s pleasure) is a legal term for an indefinite or life sentence where a prisoner has no fixed release date. Instead, their continued detention depends on the ongoing discretion or review of the Crown (or government parole authorities acting in its name)

      In Commonwealth republics, such as Botswana,[7] India,[8] Kenya,[9] Pakistan, Singapore,[10] South Africa,[11] and Sri Lanka, the phrase is "during the president'

      • Uh-huh. And, apart from the fancy language, the difference between that and Life Without Parole [wikipedia.org] is.....?

        "The U.S. is currently housing by far the world's largest and most permanent population of prisoners who are guaranteed to die behind bars. The next closest country was Kenya, with only about 3,700 prisoners serving life without parole as of 2016. At the Louisiana State Penitentiary, for instance, more than 3,000 of the 5,100 prisoners are serving life with a chance of parole, and most of the remaining
    • by DarkOx ( 621550 )

      Right it is a lack of understanding as far as the security model is concerned.

      You are captive in a metal can and the authorities control the exists. It is not even like a bus or train where you might force the operators to top and you could run off into the woods or someone could meet you with a car, even if you hijack the thing by the time you land it, the authorities are there waiting for you.

      There is little room for mischief on an airline because anything you might to try to escape mostly won't work and

      • The authorities control all the exits sure, but unless they plan to search the devices of everyone on the plane, it's difficult to see how they could determine who was behind the mischief

  • Is this news because it happened "on a plane"?
    • No, it's news because it interfered with Delta's P/L for the day. That's what matters for corporate media.
  • by qeveren ( 318805 ) on Wednesday August 12, 2026 @03:42PM (#66285988)
    It broke containment and did the hack. Give us VC funding!
  • Script kids, on a plane.

    What are the chances this was done by a male under the age of 30?

  • This has always been a thing and maybe we need SSL for WiFi. Let's get Let's Encrypt on the case and Apple and Google throwing up big scary "Do you trust this Wifi?" for all non-certified Wifi hotspots and slap on a Certified label.

    • And how exactly will you query the certificate authority before you're on the wifi?
      • Uh, the cert chain exists, you validate the signatures and it is tied to a CA you already trust? You know, like how TLS - SSL was deprecated long enough ago to have a freaking drivers license I think - actually works.
      • WPA Enterprise has this covered. The certificate check occurs during the connection, prior to authentication. Procedurally generated credentials could be printed on to your tickets in advance, designed to work both at airports and during flights.
        • Yeah, but that's a check of the client's cert, not the AP's. There are approaches that do require the AP to have a valid cert, but how do you validate it when all the authentication happens on the other side of the AP? Also, your device has to know beforehand to only connect via EAP-TTLS, and without already having that from the enterprise environment, you're back to connecting to rogues.

          Enterprise. It assumes your device is already joined to an environment that handles authentication and configuration

          • Yeah, but that's a check of the client's cert, not the AP's.

            The AP is irrelevant in all of this. Certificate validation occurs between the EAP server and supplicant. When the server is done it furnishes encryption keys to the AP for it to use.

            There are approaches that do require the AP to have a valid cert, but how do you validate it when all the authentication happens on the other side of the AP?

            The supplicant uses its trust anchor to validate the cert the same way any web browser would. The real problem is having a valid cert is completely meaningless because its identity is tied to nothing not even the SSID of whatever you are connecting to.

            • Well, the AP is relevant here since that's what we were talking about authenticating. Or rather, how they aren't authenticated so it is possible to connect to a rogue. And no, I agree, certs don't help there. WPA Enterprise is not appropriate for guest/hotspot wifi. I was pointing out some reasons why. Like the last thing you said, that's a good one too.
        • WPA Enterprise has this covered. The certificate check occurs during the connection, prior to authentication. Procedurally generated credentials could be printed on to your tickets in advance, designed to work both at airports and during flights.

          This solves nothing because anyone (including Defcon attendees) can obtain a valid certificate. What what is needed are secure authentication algorithms rather than endless parades of absurd band-aids that only make the lack of secure authentication even worse.

          Using existing infrastructure and code one could do this quite easily using a PAKE rather than certificates for mutual authentication within EAP-TLS.

    • by jsonn ( 792303 )
      You are aware that WPA-Enterprise authentication is thing? Eduroam for example is using federated RADIUS authentication for researcher on 5 continents.
      • You are aware that WPA-Enterprise authentication is thing? Eduroam for example is using federated RADIUS authentication for researcher on 5 continents.

        This technology is an unusable insecure clusterfuck. Unlike normal secure sites linked to DNS names cert identities are pointless indicators of nothing. For it to be secure you have to constrain both certificate identity and issuer which in the real world will only ever happen if your supplicant is provisioned by an administrator. Without it WPA-Enterprise is completely insecure. Most supplicants will gladly connect without proper verification and not so much as issue a warning while doing so.

        • by jsonn ( 792303 )
          If your site is not run by complete morons, you get a list of settings to put in and it is secure. If you can't follow simple instructions, too bad.
    • How about no.

      Making it a requirement for a wifi network to have a valid SSL certificate is a horrible can of worms you don't want to open.
      It starts with the millions of devices that will never get a firmware update (think light bulbs, and the APs themselves), and ends with APs that are purposefully not on the Internet (or their management interface isn't -> no cert renewal).

      certified wifi... With a chain of trust managed by profit seeking CAs. Govts would love this: associate a certificate to a person, a

  • I assumed this was widespread already. It's very similar to the usual procedures to share hotel (and yes, aircraft) wifi across multiple devices while only paying for one connection. It's polite not to be a dick about it and try to steal strangers' credentials though.

    Instead of stealing credentials, they could gain some goodwill by resharing the wifi with an SSID like "free_wifi_from_DEFCON." ...though of course nobody sane would trust a name like that. How about "free_wifi_from_48C_buy_me_a_beer"

  • by Uldis Segliņš ( 4468089 ) on Wednesday August 12, 2026 @09:12PM (#66286510)
    It is trivially simple to ddos a wifi network. And even simpler to create one, even with phone. And you can even connect your work laptop to your private phone wifi! Magic, isn't it!? I know! If such activities are considered defconworthy, we have some serious problems incoming - which electrode went into which orifice and should they be changed.
  • They should have named the hotspot "FBI Surveillance Van". Surely nobody would object to that?

"Just the facts, Ma'am" -- Joe Friday

Working...