Skip to content

When the Target is Also the Threat

In my last post, I took that LastPass attack as inspiration to write about how security tools can not only be less secure than advertised but can actually become threats in and of themselves. LastPass password vaults were supposed to keep all user’s passwords safe in one place – instead, the vaults allowed hackers to steal all those passwords at once. The defense caused the damage, as much or more than the attackers did.

I began thinking about this concept again today as flights across America were canceled due to an outage in a Federal Aviation Administration (FAA) computer system. The obscure but essential system, called Notice to Air Missions (NOTAM), provides pilots with information about potential flight hazards such as icy runways, high-elevation construction, or migrating birds. NOTAM went down, pilots couldn’t get this data, and thousands of flights had to be grounded as a result. It would have been a huge risk to fly otherwise.

The situation is only a few hours old at this point, so the cause of the outage hasn’t been reported. Officials have said it wasn’t a cyber attack – but whether they could know that for certain already is questionable, as is whether officials would admit to an attack being the true cause of the outage. Officials have the means and motive to obfuscate the cause, especially if a foreign government was somehow behind the outage. But even if the outage was not the result of an attack, as reported, it does not bode well, either for the FAA, the airline industry, or for any of us, frankly.

Watching a Trend Emerge

The airline industry is known for sudden, large-scale problems. It’s almost a cliché. But recent events still feel remarkable. Today’s FAA outage comes shortly after a technical glitch forced Southwest Airlines to cancel hundreds of flights at the peak of the holiday travel season.

That glitch happened in their staffing system. When a major winter storm hit the East Coast, forcing many Southwest staffers to call out, the airline had to scramble to redirect resources and reroute flights. Unfortunately, the staffing system couldn’t keep up with making changes on that scale and collapsed under the pressure, leaving Southwest without a way to send staff where they were sorely needed.

In the wake of the staffing system going down, blame has been pointed at aging technology that couldn’t keep up with the speed, scale, or sophistication of today’s computing requirements. We don’t know the cause of the NOTAM outage, but FAA insiders have suggested that decades-old technology may be responsible. There hasn’t been a similar flight stoppage since 9/11, so the NOTAM technology has a history of reliability. If it wasn’t a cyber attack that brought it down, the next most logical conclusion is that the system itself is starting to show its age.

That can only mean one thing: what happened today will start to happen more often. We can already see the trend in progress. Unfortunately, I think we will start to see it progress even further, accelerating and extending to other industries because the problem of expired technology controlling key systems is hardly reserved for the airline industry only.

System at Risk of Collapse

Look deep enough into just about any system, structure, or supply chain and you will find a piece of legacy technology controlling a critical process. They have persisted longer than anyone anticipated. And at this point, they are so deeply entrenched that some (or maybe even most) seem impossible to root out and replace.

It has been well documented that legacy systems are harder to make secure and keep secure, consuming more security resources while still creating more security risk. Less discussed, however, is that no amount of security can prop up a system that is approaching or past the brink of collapse. And when that point arrives, the damage is as bad (or worse) as any attack. Just look at what’s happened to airlines in recent weeks – massive damage to revenues and reputations all because old software started to act its age.

I think we will start to see similar collapses happen more often, more disruptively, and more unexpectedly in the near future. In so many areas, we have not so much replaced the old with the new as balanced the latter on top of the former. And now the foundation is crumbling.

As with my piece on the LastPass attack, my point is not to be defeatist about the future of technology. Rather, I want to take a more expansive view of cybersecurity – one focused less exclusively on defense and more on risk and resilience. How we get there is a massive question (leave your thoughts in the comments). But if there’s any silver lining to today’s airline apocalypse, it’s that maybe it pushes us one step closer to making change.

#cybersecurity #airline #FAA #Mainframe #Legacy

About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Topia
TOPIA is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.