upvote
Of course. Doesn’t mean we should leave the root password written down on a post-it next to the hardware. It sounds strange that such a privileged port has no authentication.
reply
Getting security to work reliably in such scenarios can be hard. And your customer really don't want their up to hundred million in cost pieces of equipment sit there doing nothing because maintenance is unable to do something with it.

Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.

reply
> Just as with computers, as the saying goes, if you have physical access to the device then all bets are off

This is far less true than it used to be, though, and it seems reasonable to expect that aircraft become as secure as Macs.

reply
But what if the device contained an explosive?
reply
It is not that simple, atleast in the automotive industry _today_. Atleast here in EU.

Every component is analyzed from a cyber security perspective. Many components needs tampering protection - while others need not. This includes replacing components with malicious ones.

It is not logical at all and a stupid regulation. But it is not as simple as you can do what you want if you have physical access.

reply
Well, the EU, being very much dictated by Germany, who have a large car industry, has a vested interest in making sure that if people want to have a better car they pay for a better one new rather than upgrade with an aftermarket chip.
reply