Someone broadcast a fake Delta Wi-Fi network aboard a flight packed with people returning from DEF CON. The cybersecurity community's response has been about what you'd expect.
It took me a few hours to write anything about the apparent Wi-Fi shenanigans aboard a Delta flight from Las Vegas to Atlanta because I've watched this movie too many times.
Something happens. Social media catches fire. Every repost adds another detail. Someone was spoofing Wi-Fi. No, they were jamming it. No, they were de-authing everyone. They built a phishing portal. Federal agents stormed the plane. The engines were probably next.
Give it a few hours and suddenly someone with a Wi-Fi Pineapple is Hans Gruber.
So I waited.
The other reason I waited is simpler: There are only so many ways to say someone was being stupid.
Full coverage of Hacker Summer Camp:

Messing with Wi-Fi aboard a commercial aircraft — particularly on a flight home from DEF CON, surrounded by cybersecurity professionals — falls into a category of stupid that doesn't require much technical analysis.
Instead, here's some of my favorite reporting and commentary on the incident:
Matt Johansen gets first crack
Matt Johansen of Vulnerable U had one of my favorite reactions, in part because he approached the story with the appropriate mixture of cybersecurity knowledge and disbelief.
His commentary cuts through what is already becoming an unnecessarily complicated discussion about tooling and techniques. Whether somebody was running a Wi-Fi Pineapple, spoofing an SSID, attempting de-authentication or doing something else is obviously relevant to investigators. For the rest of us? The larger lesson is considerably less sophisticated:
Don't screw with the Wi-Fi on an airplane. Especially one filled with hackers flying home from DEF CON.
There. Saved you a SANS course.
Johansen's commentary:

What we actually know
This is where The Register's Brandon Vigliarolo did everyone a favor by separating some of the emerging facts from the social-media telephone game.
The incident involved Delta Flight 591 from Las Vegas to Atlanta. ACARS messages circulating online indicated the crew believed someone aboard had created a suspicious network called "DELTA WIFI FAST." One message initially suggested passengers had "jammed" the aircraft's Wi-Fi.
But Delta subsequently told The Register that nobody hacked Delta's systems or its in-flight Wi-Fi. The airline confirmed that an unauthorized Wi-Fi network was broadcast aboard the aircraft for a short period. The crew turned off the legitimate in-flight Wi-Fi for about 30 minutes while dealing with the situation, which could account for some of the early reports that someone had knocked the network offline. Delta also said aircraft systems were never affected and passenger safety was never in question.
That's a considerably more grounded description than some of what ricocheted around social media Tuesday morning.
The Register nevertheless landed on perhaps the finest headline of the day:
"DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi."
Article from The Register:

The airplane itself was talking
One reason this story exploded was that aviation geeks were watching the aircraft's ACARS traffic.
An archived message attributed to the flight crew warned corporate security about a passenger who had allegedly created a "SCAM WIFI CALLED DELTA WIFI FAST" and said they believed the network was intended to scam other passengers.
A later message blamed passengers returning from a cybersecurity conference in Las Vegas. Again, those messages reflect what the crew believed was happening at the time, not the final forensic findings. That's an important distinction given how quickly "the crew suspects something" became "here's exactly how the hack worked" online.
See the Airframes ACARS archive:

And then the Internet did its thing
The reactions across aviation and cybersecurity social media have been considerably more entertaining than another 800 words from me explaining evil-twin attacks.
That's really the point.
Experienced cybersecurity professionals do not need a lecture about why firing up rogue access points, spoofing networks or deliberately interfering with wireless communications aboard a commercial aircraft is a profoundly bad idea.
We have known this stuff forever.
You also don't get bonus hacker points because you did it while flying home from DEF CON. If anything, choosing an aircraft presumably loaded with security practitioners may qualify as one of history's less promising approaches to avoiding detection.
There are plenty of places to experiment. Labs exist. CTFs exist. DEF CON itself exists.
A commercial airplane carrying a couple hundred people is not your lab.
Congratulations, you became the post-DEF CON story
That's the part that annoys me.
Tens of thousands of people descended on Las Vegas for Hacker Summer Camp. Researchers shared new work. People taught each other. Communities came together. Security professionals spent a week demonstrating what is best about this industry.
And then everybody flies home. One person apparently decides that somewhere around 35,000 feet is the appropriate venue for Wi-Fi stupidity.
And guess what we're talking about now?
Well done.



