Fred Avolio's Musings

iChat Status

musings on security and other topics topics archives
July
Sun Mon Tue Wed Thu Fri Sat
    2
   
most recent headlines other links, other blogs  

Wed, 02 Jul 2008
It's not just who you are, it's who your friends are

I've saved this clipping in my "BlogMe" mailbox since February. How to Hack Into a Boeing 787. In a nutshell (in case the article is gone or you don't want to bother) all variants of the jetliner "have three on-board computer networks. One network is for flight safety and navigation, a second is for administrative functions and the third handles passenger entertainment and Internet access." You know the punch-line, right? All three are linked. (Probably, were, as Boeing says the design has been fixed.)

It reminds me of a story.

It takes place in 1992 or so, DARPA was funding a small computer security company to securely connect The White House (really the Executive Office Building) to the Internet. They came to this security company and asked "Do you know anything about 'Internet firewalls?'" People at the company did.

After lots of talking and planning someone with a clue said, "We need to do a network survey."

"Why?"

"We need to see what else is connected to your network."

Now remember, this was 1993, before everyone including your Aunt Tilly was on the Internet.

Long story short, the company did the network survey and found that the White House network was already on the Internet. They were connected via NASA Goddard, which, at the time, was well-known in the local IP community for poor network security. They would have had a firewall in their front door with an unlocked back door.

Back to the jetliner. People tend to make these mistakes. Why, or why in the world are—sorry, were—the networks interconnected? I don't know but experience tells me it was probably to save some copper (or fiber). No matter how smart you are (and the Boeing engineers are smart), always, always, always bring someone else in to look at your plans. And make sure some of those people know something about security and risks.

I heard from someone "in the know," who shall remain nameless.

"How to hack into a 787" was erroneous from the very beginning. It was a scare story launched by someone with no actual knowledge of the systems in question. While there are connections between the sub-networks on the B787, the interactions between the passenger-accessible network and the rest is strictly firewalled and sandboxed. The only data connection between the cabin network and the flight network is a very limited one that allows the cabin crew to talk to the flight crew over the IP-based interphone system. Having actually read the Specification Control Documents (SCDs) which control the design of the system, I can tell you that they were designed with data security issues very much in mind.

Well, certainly good news, but my point remains. These are the times when you don't just bring in application experts, or networking experts, but also security experts.

Comment on this.
[/security/] permanent link

Other Cocktails

As I have previously mentioned, a gin Martini is my drink of choice, up with an olive. I prefer Gordon's, not because it is Bond's gin of choice (and anyway, the Gordon's of the original novels' time was a higher proof), but because I like the taste. I do enjoy other cocktails at times.

Another favorite is a gin Gimlet. A very nice cocktail, made with 2 oz. of gin and 3/4 oz. of Rose's Lime Juice. There are sweeter versions, but this is the ratio I prefer. (In Raymond Chandlers The Long Goodbye,Terry Lenox tells Philip Marlowe A real Gimlet is half gin and half Roses Lime Juice...") Again, very cold, up with a lime quarter.

And when I am in a very quiet, contemplative mood, it's a Vesper. In the novel Casino Royale, Bond ordered thusly:

"Three measures of Gordon's, one of vodka, half a measure of Kina Lillet. Shake it very well until it's ice-cold, then add a large thin slice of lemon peel.

Alas, you can't get Kina Lillet anymore and that's arguably a lot of booze.

I go with the recipe in my signed hardcover copy of Cocktail: The Drinks Bible for the 21st Century by Paul Harrington.

  • 2 oz. Gordon's gin
  • 1 oz vodka (I don't care what kind)
  • 1/2 oz. Lillet blanc
  • a dash of bitters (to simulate the Kina Lillet and to give a light pink glow)

Comment on this.
[/misc/] permanent link