Someone messed with the in-flight Wi-Fi system on a Delta Air Lines flight from Las Vegas following the Black Hat and DEF CON conferences earlier this month, and authorities aren't happy.
In this episode of "What We Missed," Dark Reading's Rob Wright and Alex Culafi discuss some of the recent news events and topics that didn't make it into Dark Reading's publication slate this week. The duo chat about Delta Air Lines flight 591 to Atlanta, which was disrupted when a passenger replaced the plane's Wi-Fi network with their own, dubbed "Delta WiFi Fast," that reportedly led to a phishing page. While it's unclear who was behind the hack (federal authorities are investigating), suspicion was immediately cast on DEF CON 34 attendees by the flight crew.
Also discussed in this episode are the Trump administration's plan to contract private companies for "hacking back" against cybercriminal organizations and the risks posed by that strategy; another airplane hack in which academic researchers demonstrated at the Usenix cybersecurity conference how a tiny hardware implant in the plane's nose cone could compromise a Boeing 737's flight system; and the developers of UBlock Origin, a popular open source ad blocker, who are dropping their ongoing efforts to filter Facebook ads amid an increased volume of scams and malicious links on Meta's platforms.
Related:CISOs Break Their Silence in 'Declassified' Docuseries
What We Missed With Rob Wright & Alex Culafi: Full Transcript
Dark Reading's Rob Wright: Hello, I'm Rob Wright with Dark Reading.
Dark Reading's Alex Culafi: And I'm Alex Culafi with Dark Reading.
DR's Rob Wright: And this is What We Missed. This is a discussion about the stories and topics that we didn't get a chance to cover in the pages, virtual pages, or podcast or videos at Dark Reading. And we're here to discuss some of the more interesting news items and stories that we didn't get a chance to cover. And first up, Alex.
DR's Alex Culafi: Yes.
DR's Rob Wright: Delta Airlines' in-flight hacking incident. Apparently, there was a flight on the way back from Las Vegas — which I'm sure we'll touch on in this discussion, because that is relevant — going to Atlanta. That suddenly, apparently the in-flight Wi-Fi system was disabled or jammed, and a new Wi-Fi system or Wi-Fi network popped up. I believe it was called "Delta WiFi Fast." I probably would have clicked on it, not knowing any better. But yeah, what did you think of this?
DR's Alex Culafi: I think it's crazy. Because there is a history of DEF CON folks, attendees, doing dumb pranks. But doing it on an airline is extremely stupid, especially in the context of the sensitive history the United States has with flights. So, OK, what the person did is they made this fake Wi-Fi network, and then they put what looked to be a Google-esque phishing portal on the back end of that. And the problem with doing that, if it was malicious, which I feel a lot of the headlines are positioning this as potentially a malicious attack, is that it's the stupidest way to possibly do a phishing credential harvesting attack because you're on a flight, which means you're not compromising very many victims. There are security researchers surrounding you, and it's like, you don't want legal attention anywhere worse than a flight. So, what I think happened is someone bought a Pineapple, one of the Wi-Fi Pineapples, which you can just buy at DEF CON. They set up a Wi-Fi portal, they got a credential —
Related:Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
DR's Rob Wright: Sniffer. Yep.
DR's Alex Culafi: Sniffer. A portal, phishing logon from GitHub, probably vibe coded a little bit and stupidly said, "What if we do this?" And now they're probably very anxious that the FBI got involved. What do you think?
DR's Rob Wright: Yeah, and they contacted authorities, which they rightfully should have. And this, I think, generally gives a bad name to the hacking community, the infosec research community, and the events. And I just want to say, as my closing point, to me, this is no different than getting loaded on a plane, like drinking too much and having to be taped to the seat and forcing the flight to call security, call the authorities to meet you at the gate, or worse, divert to Lincoln, Nebraska. That's the worst possible — no disrespect to Lincoln, Nebraska, but the worst possible outcome for something like this, and people should know better. All right. Next topic.
Related:What Boards Need to Know About Tech Risk
DR's Alex Culafi: Yeah. Also in-flight news, kind of the opposite ethical situation. There was recent research from academic researchers. They revealed that there's a coin-sized Wi-Fi-enabled device that they could build for less than a hundred bucks, which they could plug into this maintenance access port on a Boeing 737. I think it's not the key slot, but it's something that's sort of beneath the pilot seat, which could manipulate flight management computers. Sounds scary, but it was done in an academic setting. It was reported to Boeing, and Boeing basically said, 'Yeah, this seems very unlikely that someone would take advantage of it.' My feeling is that Boeing has much bigger fish to fry than this. So I don't know. What do you think?
DR's Rob Wright: So I'm a pessimist. Upon reading this, and it was featured in an article on Wired, we should note. Very good article. Interesting read. I typically don't have a lot of faith in physical security of systems. I think we're very embroiled in cybersecurity, and we kind of miss that somebody could just walk on a tarmac and tinker and just wear an orange pinny, or yellow pinny or whatever, and walk up to a plane. So I don't think it would be that hard to do this.
And the thing that really struck me was if someone was able to do this, if it was someone with ill intent and if they ransomed a flight and said, "Look, I just took control of the control systems, of the in-flight, you know, autopilot systems. I could do a lot of damage with this. Pay me a million dollars or more, a billion dollars." That's going to be an interesting situation, about whether or not you're going to call someone's bluff on that or pay the money. I can't imagine the airlines would call the bluff. But anyway, yeah, that's what I sort of envisioned — a whole new avenue of hacking — and that it kind of scared me.
DR's Alex Culafi: Yeah. I don't want to go to bat for Boeing here because, I mean, I go out of my way to avoid Boeing flights at this point. But I do think their general take is defensible that basically to execute this in a criminal setting, you basically already need to get into the cockpit, which if you have mal intent and could get into a cockpit, like, it's — I don't know, this seems kind of burdensome as a way to do whatever it is. So I get it, but I also think [sarcastically], Gee what a surprise that Boeing is shrugging something off again.
DR's Rob Wright: Right, sure.
DR's Alex Culafi: What else we got?
DR's Rob Wright: We got US government is letting private companies hack back. There was news, and I should note an excellent story from our colleague Eric Geller at Cybersecurity Dive, about the Trump administration issuing a memo to DOJ, DHS saying we want to use or we want to contract private companies to hack back against cybercriminals, disrupt them, et cetera, et cetera. This seems like not a great idea, Alex. What do you think?
DR's Alex Culafi: A lot of Trump's cybersecurity tactics, strategies, announcements to date have reminded me of anytime you hear RFK [Jr.] speak, which is that he'll say one thing that you kind of agree with and then package it with the most insane thing you've ever heard. And I also feel the same way about Trump's cybersecurity announcements. The thing about this one is, OK, you want to possibly hire overseas espionage activities in the private sector. I think it's reasonable insofar as they want all these organizations to put up million-dollar escrows. I think that's a good idea, and I think it's looking to facilitate a defense contractor ecosystem to possibly do this, which, I'm a pacifist and I don't like this on a personal level, this sort of activity, but I get it as a sensible idea. I don't understand that it's possibly open to pre-established security vendors as well. I think it makes liability a complete nightmare. What do you think?
DR's Rob Wright: Right. Yes. I defer to the experts on this, and there was a great session that I caught at Black Hat by Carole House, and she did a session on basically this exact topic. I think it was called, yeah, "Cyberspace Pirates," outsourcing cyber war. She is the senior fellow at the Atlantic Council and CEO of Penumbra Strategies, and she was just basically saying, if companies are going to do this, there's a lot of risk and liability to them. I mean, just because the government here authorizes you to do it, if you go and you hack some cloud infrastructure in another country to get the bad guys, that's not good. That's not good for you. You could be held liable. There could be legal issues coming your way. So I guess if I was going to do this, if I ran a company and I was going to do this, I would want a lot of money for that. So that's my feeling. All right. Lastly, Alex, what do we got?
DR's Alex Culafi: Last one, we got the news that uBlock Origin, one of the better-respected, I would say, free ad blockers that exists in this larger ecosystem of ad blockers. They've announced that Facebook ads have basically become so hard to block, for multiple reasons. I think it's that they're heavily obfuscated even on Facebook's own platforms. They change how they're presented to the user constantly. I mean, Facebook's motivated to make it this crazy because it's their whole business model. But basically, Facebook ads have gotten so hard to block that uBlock Origin has stopped filtering them. Or at least they're going to keep doing the basic level of protection that they can do, but it's become so resource-intensive to stay ahead of Facebook ads that this volunteer project, or at least it's open source, of like two or three people — I'm pretty sure, it's a very small organization — that they just can't keep up. And to me, this is a story of big companies winning attrition wars. But I'm — what do you think?
DR's Rob Wright: Yes. I feel the same way. And I think the bigger picture to me is that I think the malvertising, ad fraud, click fraud, just the whole sort of degradation of the ecosystem in favor of cybercriminals is getting worse and worse. And this is, I think, it's easy to kind of look over things like this, but I think this is pretty important. There's a story not too long ago, a Reuters investigation, where the headline is, I'll just summarize, Meta is earning a fortune on fraudulent ads. And there's another research report from Gen [Digital] that basically says that nearly one in three Meta ads found to point to a scam, phishing, or malware. Like, that's incredible. And so if you're getting rid of — not getting rid of, but if you're losing a weapon to mitigate these threats and to improve security, your personal security, and you can't use that anymore, I just think it may be time to look at Facebook as more trouble than it's worth. Because, yeah, the scams and the malware and the malicious links are ubiquitous on that platform. And that doesn't seem that they want to do anything about it. So …
DR's Alex Culafi: Yep. Little late to call Facebook a little more trouble than it's worth. I still use Facebook to keep up with my local town's community. I think I might be the youngest remaining Facebook user. But it is a browsing nightmare. I know that the content people at Facebook probably work very hard to keep a lot of very bad things off that platform.
DR's Rob Wright: Yep. I was just about to say that sounds very old, but that's OK.
DR's Alex Culafi: But boy, do they let a lot of things through as well. It's a lot of it is the worst. It is one of the worst legitimate places on the Internet to browse.
DR's Rob Wright: Unfortunately. Yeah. Well, that will do it for this episode of What We Missed, Alex. Thank you.
DR's Alex Culafi: Thanks, Rob.










