FAA: No Hacking ADS-B Via Android App

Gemini Sparkle

Key Takeaways:

  • A security consultant, Hugo Teso, claimed he could remotely take control of an aircraft's autopilot by hacking Flight Management System (FMS) software through ADS-B vulnerabilities.
  • The FAA and EASA strongly refuted Teso's claim, stating his specific technique would not work on certified aircraft hardware.
  • They clarified that Teso demonstrated his hack on training software, which lacks the overwriting protections and redundancies present in actual embedded FMS software.
  • Teso, a pilot and security consultant, reportedly aimed to highlight potential vulnerabilities to ensure they are addressed in certified flight systems.
See a mistake? Contact us.

A new claim by a security consultant that he could take control of an aircraft’s autopilot through vulnerabilities in ADS-B has elicited a response from the FAA, which said, in part, “It does not work.” The consultant, Hugo Teso,recentlymadeheadlines for himself and his employer when he demonstrated an Android app of his creation at a security conference in Amsterdam. Teso used his system to remotely hack into Flight Management System (FMS) software and upload data. He claimed that access allowed him to control the aircraft. The FAA has now responded saying it has determined that Teso’s exact technique would not work on certified hardware. EASA agreed, but questions remain.

The FAA has been hounded by concerns that its NextGen air traffic control system includes pathways of communication that are vulnerable to hackers and addressed similar concerns just last year. Responding to the most recent concern, the FAA said “the described technique cannot engage or control the aircraft’s autopilot system using the FMS or prevent a pilot from overriding the autopilot.” EASA noted that Teso’s demonstration hacked training software, as opposed to embedded FMS software. It said that major differences between the two systems meant Teso did not face “the same overwriting protection and redundancies” included in certified flight software. Teso is a certified pilot and works for a company called N.Runs, a security consultancy in Germany. The company has said Teso’s work aims to ensure that vulnerabilities in FMS software are addressed in such a way that they remove the possibility of similar hacking threats. Find Teso’s presentation slides here (PDF).

Sign-up for newsletters & special offers!

Get the latest stories & special offers delivered directly to your inbox

SUBSCRIBE

Please support AVweb.

It looks like you’re using an ad blocker. Ads keep AVweb free and fund our reporting.
Please whitelist AVweb or continue with ads enabled.