The Nine-Month Dispute Over an EFB Vulnerability

▶ Watch (2:02)

Gaffney built a secure electronic flight bag (EFB) for a new aircraft. Third-party pentesters found vulnerabilities after day two. He briefed the chief pilot, who explained the safety impacts. Gaffney disclosed to the software supplier. The response: “That’s not a vulnerability, but a feature.” Nine months of discourse with regulators followed. A multi-year action plan was agreed. Then the pandemic hit. Gaffney changed employers and followed up four years later. The supplier stonewalled: “You’re no longer our client. Our code is IP.” Gaffney still holds the vulnerability details and offers to share with operators who need them.

A Regulatory Gap Discovered by Accident

▶ Watch (5:35)

Investigating an unrelated incident, Gaffney found a gap in regulation and its implementation. He had already spent two years studying those regulations. Initial pushback from multiple OEMs was strong. He argued his case successfully. Collaborative work sessions across OEMs and time zones followed, including on-wing tests. The result: a change to Instructions for Continued Airworthiness (ICA) and procedure changes across most airlines worldwide. The regulator was informed throughout. Gaffney contrasts this with the EFB case – a good outcome after a bad start.

When Manufacturers Ignore the Disclosure Process

▶ Watch (8:46)

The Aerospace Village received a talk submission that claimed a vulnerability had been responsibly disclosed. The village contacted the manufacturer, who said it was not complete. The researchers dropped receipts: they had gone through the full disclosure process. The manufacturer had accepted the risk without making a change and failed to negotiate public disclosure timing or a communication plan. In another case, an authentication bypass on a public website went unreported because the aerospace company had no VDP. The researcher used social media to provoke a response. The vulnerability was eventually fixed, but the relationship remains broken.

Dos and Don’ts for Handling Researcher Submissions

▶ Watch (11:52)

Gaffney urged aerospace companies to have an active VDP – more than a web page. Use security.txt files and security@yourdomain.com. Engage every submission; silence makes researchers feel ignored. Communicate regularly, even if there is no update. Avoid legal threats; they scare researchers into hiding. Agree on disclosure timelines and follow the plan. Do not force an NDA on every researcher – many are willing to sign to learn more. Do not belittle concerns, do not threaten reputations, and do not rely on security by obscurity alone.

Researcher Responsibilities and the Business Opportunity Trap

▶ Watch (14:52)

Researchers should first check for a VDP and follow formal channels. The Aviation ISAC can help connect to the right people. Communicate all details, stick to facts, and leave emotion at the door. Understand that fixes in aviation can take years – the 60-day rule does not apply. Accept restrictive agreements if needed. Do not breach NDAs or ignore laws. Gaffney’s final caution: do not use vulnerability disclosure as a business opportunity. When a researcher forwards a meeting invite to marketing and sales, the recipient notices. That destroys trust.

Q&A

What are the latest trends in aviation vulnerability submissions? Connectivity increases the attack surface; aircraft are flying data centers generating gigabytes per flight – security by obscurity will not work. ▶ 16:57

Do companies offer bug bounties? Some use official bug bounty programs; a few airlines offer miles. Gaffney found vulnerabilities by accident in his own company’s stuff but could not claim a reward. ▶ 18:26

Are there aviation-specific CVEs? Yes – the TCAS CD vulnerability publicly disclosed earlier this year is one. Most CVEs affect ground systems or tooling but are not aviation-specific. ▶ 19:23

What is the biggest focus for your airline? Insider threat. ▶ 20:55

Notable Quotes

“that’s not a vulnerability, but a feature” Matt Gaffney · ▶ 3:41

“the code is IP, but the vulnerability isn’t” Matt Gaffney · ▶ 5:16

“our normal users would never do that. It’s not a problem.” Matt Gaffney · ▶ 11:19

“aviate navigate communicate but in VDP it’s communicate communicate communicate” Matt Gaffney · ▶ 12:36

Key Takeaways

  • A VDP is not a web page; it requires active monitoring and engagement.
  • Fixes in aviation take years – researchers must accept extended timelines.
  • Threats and legal escalation drive researchers away, not toward cooperation.
  • Security by obscurity alone fails as aircraft connectivity grows.
  • Researchers should never treat disclosure as a sales opportunity.

About the Speaker(s)

Matt Gaffney (gaffers) is a hacker, veteran, and aviation nerd. He served in the British Army, worked for the UK Foreign and Commonwealth Office and various French companies, and has been working in aviation since 2016. His research covers electronic flight bags, PI aircraft, drones, website vulnerabilities, CVS for Java, and social engineering.