Agreed, and it seems to lack the hacker spirit I'd expect out of someone attending DEFCON. The only intentions I can figure out would be...
1. Just to screw with fellow passengers - dick move, how do you know someone wasn't working on something critically important on that wi-fi?
2. 'Robin Hood'?? If they had a paid wi-fi session and were gonna bridge all the passengers who connected to their rogue AP onto it for free. Extremely farfetched theory though since they could have easily still done this without deauthing the people, who'd already paid anyway.
3. Actual black-hat hacking, hoping to snoop on people's connections for cybercrime reasons.
Can't say I'm bothered at all that these guys had the cops called on them.
You would be surprised by the number of professionals who would be at peak tech performance if they could pull it off
IT security is a lot more about the processes, risk, and data management that technical performance these days.
The book to study for CISSP CBK is hardly any technical (The Code Book is more technical than that)
The ISO 27000 series defines an Information security management system that doesn't even need to involve "computer", as it discusses more about data in the organization.
Research these days is also based a lot on how to address security risks on top of safety risks, not just how to hack any system (and I do believe that the obsession of the aviation industry about these studies is why everything was ready so that suspects were met with police)
At least we limit security theater to airports. Could you imagine if you had to arrive at every bus station and train depot two hours early, so you could wait in line for a security screening that fails 95% of the time?
I have no insider knowledge on how this went, but I guarantee it was a kid or a newbie and that it was either caught by another defcon attendee and they gave the staff a nod.
Even though slamming down the wifi and hamfisting "Delta wifi fast" into peoples face isn't exactly the most surreptitious attack path.
Given that the whole wi-fi systems on planes are all very old unless the planes have Starlink, I wouldn't assume it's even remotely new.
Note: Not that it wouldn't be possible to have even SOTA wi-fi 7 and still use the same old legacy satellite uplink WAN connection, it's just that I can't imagine what airline would consider that "upgrade" worth taking airplanes out of service for to perform, when it wouldn't do jack to increase the speeds people would get.
Even if there's newer equipment, Protected Management Frames (PMF) compatibility with older laptops (for example) would be problematic. This is also the reason why WPA2/WPA3 co-existence mode fails on older equipment that is compatible with "normal" WPA2 (because PMF is mandatory in WPA2/3 coex mode).
Finally, hacker news on Hacker News
but isn't that the other kind of hacker?
life hacks are also hacker news, I guess x)
This attack is very simple and basically a few button clicks these days.
Script kiddy at best.
Agreed, and it seems to lack the hacker spirit I'd expect out of someone attending DEFCON. The only intentions I can figure out would be...
1. Just to screw with fellow passengers - dick move, how do you know someone wasn't working on something critically important on that wi-fi?
2. 'Robin Hood'?? If they had a paid wi-fi session and were gonna bridge all the passengers who connected to their rogue AP onto it for free. Extremely farfetched theory though since they could have easily still done this without deauthing the people, who'd already paid anyway.
3. Actual black-hat hacking, hoping to snoop on people's connections for cybercrime reasons.
Can't say I'm bothered at all that these guys had the cops called on them.
You would be surprised by the number of professionals who would be at peak tech performance if they could pull it off
IT security is a lot more about the processes, risk, and data management that technical performance these days.
The book to study for CISSP CBK is hardly any technical (The Code Book is more technical than that)
The ISO 27000 series defines an Information security management system that doesn't even need to involve "computer", as it discusses more about data in the organization.
Research these days is also based a lot on how to address security risks on top of safety risks, not just how to hack any system (and I do believe that the obsession of the aviation industry about these studies is why everything was ready so that suspects were met with police)
Sure, but you probably shouldn't mess with planes, even is mundane or trivial.
For some reason, we treat planes super differently than every other public space or transport.
At least we limit security theater to airports. Could you imagine if you had to arrive at every bus station and train depot two hours early, so you could wait in line for a security screening that fails 95% of the time?
Delta's setup and procedures were able to catch up on that. Good move from their side !
Police was involved
No offense, but I doubt that most other public spaces or transport would have reacted like that.
It's not just because planes fly, but the industry around them has planned for everything.
This Hacker News post could be "Delta is ready"
> for some reason
I mean, I can think of one reason. Them being quite far away from the ground most of the time, mainly.
The WiFi isn’t connected to the “plane”,
and if it is, and it historically has been, that’s a different problem also not the hackers’ fault.
The actual hacker creds is earned by not getting caught by a federal investigation.
Although, with Kash Patel's FSB cosplayers, maybe that's playing in easy mode.
And remember, you can't brag about it either, that's how most get caught.
I have no insider knowledge on how this went, but I guarantee it was a kid or a newbie and that it was either caught by another defcon attendee and they gave the staff a nod.
Even though slamming down the wifi and hamfisting "Delta wifi fast" into peoples face isn't exactly the most surreptitious attack path.
Is Delta using older Wifi equipment? I was under the impression that the current Wifi standard now prevents deauth attacks.
Given that the whole wi-fi systems on planes are all very old unless the planes have Starlink, I wouldn't assume it's even remotely new.
Note: Not that it wouldn't be possible to have even SOTA wi-fi 7 and still use the same old legacy satellite uplink WAN connection, it's just that I can't imagine what airline would consider that "upgrade" worth taking airplanes out of service for to perform, when it wouldn't do jack to increase the speeds people would get.
Even if there's newer equipment, Protected Management Frames (PMF) compatibility with older laptops (for example) would be problematic. This is also the reason why WPA2/WPA3 co-existence mode fails on older equipment that is compatible with "normal" WPA2 (because PMF is mandatory in WPA2/3 coex mode).
I was not on this flight but another one during this time on Monday (Delta flight out of ATL).
Delta came on the intercom and was directed to reboot WiFi and screens across their fleet. Maybe unrelated but seems coincidental
I preferred when you could just enter any T-Mobile customers number.
Every year some dumbass tries this kind of shenanigan during BH/Defcon and they always make an example out of them.
Just becuase you CAN do something doesn't mean you should. You aren't impressing anyone and you are risking felony charges.