george sarkisian-investigative reporter exposing corruption in government, politics, big business

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

george sarkisian-investigative reporter exposing corruption in government, politics, big business
FAA Chief Daniel K. Elwell murdered 346 people. He will love his Orange Prison Jumpsuit
'I could never live with myself' Parents of Boeing 737 Max victim on why they fight for Daughter
Minneapolis Mayor Jacob Frey and City Council complicit with FAA Great Lakes Mass Murder MacPherson
Minneapolis Mayor Jacob Frey and City Council complicit with FAA Great Lakes Mass Murder MacPherson
Des Plaines Mayor Matthew Bogusz/Council complicit with FAA's Mass Murder MacPherson
Mass Murder MacPherson Mass Murder Drouet Mass Murder Mowery-Schalk think it is a big joke
Des Plaines, Ill. Disgraced Mayor and Aldermen Complicit with City's FAA Mass Murder Suspects
Des Plaines, Ill. Disgraced Mayor and Aldermen Complicit with City's FAA Mass Murder Suspects
FAA Illinois Mass Murder Suspects-Directors Rebecca MacPherson, Christina Drouet, Schalk on loose
FAA Des Plaines Mass Murder Suspects-Directors Rebecca MacPherson, Christina Drouet, Schalk on loose
FAA's Chief Operating Officer, Teri L Bristol, should be at the top of the FBI's most wanted list.
FAA Des Plaines-Mass Murder Suspects: Great Lakes Directors Rebecca MacPherson and Christina Drouet
FAA's 68 Top Level Mgmt. Mass Murder Suspects walking the streets of D.C./Virginia. 346 people dead
FAA Des Plaines/Oak Park Mass Murder Suspects and the streets of Chicagoland. 346 people dead
FAA's Disgraced Rebecca MacPherson's middle finger salute to Bensenville, Wood Dale, DuPage, Ill.
FAA's Disgraced Rebecca MacPherson's middle finger salute to Bensenville, Wood Dale, DuPage, Ill.
A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
New York Congressman Steve Israel calls the FAA the "Federal Arrogance Administration."
Cook County, Ill. Mass Murderers FAA's Rebecca MacPherson/Christina Drouet still on the loose
Why are the FAA's Rebecca MacPherson/Christina Drouet walking free on the streets of Chicagoland?
Boeing Faces At Least 35 Lawsuits Over Its 737 MAX 8 Aircraft Crashes
Boeing reportedly kept the FAA in the dark about big changes it made to the 737 Max's flight-control
In Pics.-Cook County, Ill. Comm Complicit in FAA's Rebecca MacPherson Corruption/Prostitution Scam
New lawsuit alleges conspiracy between Boeing, FAA in Max crashes
Cook County, Ill Commissioners Complicit in FAA Des Plaines/Oak Park Corruption/Prostitution Scam
FAA's Disgraced Rebecca MacPherson's middle finger salute to Bensenville, Wood Dale, DuPage, Ill.
FAA's Disgraced Rebecca B. MacPherson's middle finger salute to Bensenville, Wood Dale, DuPage, Ill.
FAA's Disgraced Christina Drouet's middle finger salute to Bensenville, Wood Dale, DuPage, Ill.
FAA Disgraced Prostitute Rebecca MacPherson and her Des Plaines, Illinois Prostitution ring
FAA (Great Lakes) Rebecca MacPherson and her admiration for Adolph Hitler's management style
City of LA Suing FAA Over Changes to Flight Patterns Over Mid-City, Central LA, June 24, 2019
FAA's Disgraced Christina Kochanski Drouet and the women of Hitler.
FAA's Disgraced Chrisina Kochanski Drouet and the women of Hitler
FAA's Disgraced Rebecca MacPherson and the women of Hitler.
FAA's Disgraced Susan Mowery-Schalk and the women of Hitler
FAA's Rebecca MaPherson is the perfect German female Hitler was trying to create.
Federal ARROGANCE Administration (FAA) mistresses of Hitler, Goebbels, Goering, Speer
Charles Manson family members-FAA's Susan Mowery-Schalk, Rebecca MacPherson, Christina Drouet
Charles Manson family members-FAA's Christina Drouet, Rebecca MacPherson, Susan Mowery-Schalk
Charles Manson family members-FAA's Rebecca MacPherson, Christina Drouet, Susan Mowery-Schalk
691 Northwestern U. grads linked to FAA/Christina Drouet/Rebecca MacPherson prostitution
Disgraced FAA Prostitute Madame-Rebecca MacPherson and her $1000/day Illinois Prostitutes
Christina Drouet is the FAA Great Lakes Face of EVIL and CORRUPTION- Federal ARROGANCE Admin
Disgraced FAA Prostitute Madame-Rebecca MacPherson and her $1000/day Illinois Prostitutes
Disgraced FAA Prostitute Madame-Christina Kochanski Drouet and her $1000/day Illinois Prostitutes
Disgraced FAA Prostitute Madame-Christina Kochanski Drouet-and her Great Lakes House of Prostitution
Disgraced Prostitute Christina Drouet: Top Earning FAA Illinois Prostitute Des Plaines $187,283
Disgraced Martha Drouet is Horse's Ass-Christina Kochanski Drouet is a Horse's Ass-Fed ARROGANCE Adm
Disgraced Prostitute Susan Mowery-Schalk:Top Earning FAA Illinois Prostitute Des Plaines, $192,362
Disgraced Rep. Haley Stevens (D-MI 11th District) Congressional Staff
The difference between Disgraced Rep. Haley Stevens (D-MI 11th District) and a prostitute is..
Ashley Bristol is Horse's Ass-Teri Lynn Bristol is a Horse's Ass-Federal ARROGANCE Adm
In Pictures-65 FAA Top Management Characters responsible for killing 346 people in Boeing 737 MAX.
Kirk Shaffer is a Horse's Ass and a Damn Hypocrite-Federal ARROGANCE Administration FAA-Wash D.C.
Susan Mowery-Schalk is a Horse's ASS-Federal ARROGANCE Administration (FAA) Des Plaines, Ill.
Christina Drouet is the FAA Great Lakes Face of EVIL and CORRUPTION- Federal ARROGANCE Admin
Terry Michmerhuizen is a Horse' s Ass (Rhino Division) Western Mich Univ Asso Professor of Aviation
Christina Kochanski Drouet is a Horse's Ass-Federal ARROGANCE Administration FAA-Des Plaines, Ill
Christina Kochanski Drouet is a Horse's Ass-Federal ARROGANCE Administration FAA-Des Plaines, Ill
Terry Michmerhuizen is a Horse' s Ass (Rhino Division) Western Mich Univ Asso Professor of Aviation1
Peter F. Dumont is a Horse's ASS-Air Traffic Controller Association https://www.atca.org/directors
Teri Lynn Bristol is a Horse's Ass-Federal ARROGANCE Administration FAA-Washington D.C.
In Pictures-FAA Female Faces of EVIL and CORRUPTION-Federal Arrogance Administration
Congressional staffer's-Horse's Ass-Hall of Shame for Rep. Haley Stevens (D-MI)
Michael Tash is a Horse's Ass-Congressional staffer for Rep. Haley Stevens (D-MI)
Susan Mowery-Schalk-Pictures-FAA Female Face of EVIL and CORRUPTION-Federal Arrogance Administration
Rebecca MacPherson-Pictures-FAA Female Face of EVIL and CORRUPTION-Federal Arrogance Administration
In Pictures-FAA Romulus, Michigan Faces of EVIL and CORRUPTION
In Pictures-FAA Female Faces of EVIL and CORRUPTION-Federal Arrogance Administration
In Pictures-Michigan's Female Face of EVIL-Stephanie Swann, Asst. Director Fed ARROGANCE Admin (FAA)
In Pics-Wash D.C. Wide Body FAA CEO Teri Bristol-Federal ARROGANCE Admin AND-Culture of Corruption
FAA-Illinois-Sexiest and Most Corrupt--Susan Mowery-Schalk, Keefer, Bonk, Zachas, Felkins
Michigan's Face of EVIL-John Mayfield, Fed ARROGANCE Admin (FAA), ROMULUS Baptist Church
Michigan's Face of EVIL-John Mayfield, Fed ARROGANCE Admin (FAA), ROMULUS Baptist Church
In pictures-Gary Peters-Michigan Most Corrupt Senator-and his Washington D.C. staff
Great Lake's FAA Sexiest and Most Corrupt-Federal ARROGANCE Administration, Director Sue Schalk
Michigan's Most Corrupt-John L. Mayfield-FAA Federal ARROGANCE Administration
Michigan's Sexiest Legislative Director, Sarah Reingold, U.S. House of Representatives
Michigan Corruption Inc.-In Pictures-Legislative Directors-House of Representatives
Michigan Corruption Inc.-In Pictures-U.S. House of Representative's staff in Washington D.C.
Michigan Corruption Inc.-In Pictures-Sen. Debbie Stabenow and her Washington D.C. staff
Michigan Corruption Inc.-In Pictures-Sen. Gary Peters and his Washington D.C. staff
Michigan Corruption Inc.-Laura Marsh (Lackey), Sen. Gary Peters, AG Dana Nessel, John Mayfield (FAA)
Michigan Corruption Inc.-Courtney Evans, Lackey for Michigan Senator Gary Peters
Michigan Corruption Inc.-Laura Marsh, Lackey for Michigan Senator Gary Peters
Michigan Corruption Inc.-Laura Marsh (Lackey), Sen. Gary Peters, AG Dana Nessel, John Mayfield (FAA)
Michigan AG Dana Nessel looks the other way to the Corruption at John Mayfield's FAA
Michigan AG Dana Nessel turns a blind eye to the Corruption at John Mayfield's FAA
James W. Tegtmeier (FAA) condones CORRUPTION at Federal ARROGANCE Administration-1987 Luther College
Michigan AG Dana Nessel sits on her Keister while Corruption is King at John Mayfield's FAA
Robert Notigan (GSA) condones CORRUPTION at Federal ARROGANCE Administration (FAA)
Michigan's MOST CORRUPT Federal Employee-John Mayfield's Federal ARROGANCE Administration (FAA)
Illinois' MOST CORRUPT-John Mayfield's Fed ARROGANCE Admin (FAA), ROMULUS Community Baptist
Ohio's MOST CORRUPT-John Mayfield's Fed ARROGANCE Admin (FAA), ROMULUS Community Baptist
Michigan's most CORRUPT-John Mayfield's Fed ARROGANCE Admin (FAA), ROMULUS Community Baptist
John Mayfield's Fed ARROGANCE Admin (FAA), ROMULUS Community Baptist Church -The evolution of EVIL
John Mayfield's Fed ARROGANCE Admin (FAA), ROMULUS Community Baptist Church -The evolution of EVIL
Stephanie Swann's Fed ARROGANCE Admin (FAA), ROMULUS Community Baptist Church -The evolution of EVIL
ROMULUS Community Baptist Church, John Mayfield (Fed Arrogance Administration)-The evolution of EVIL
ROMULUS Community Baptist Church, John Mayfield (Fed Arrogance Administration)-The evolution of EVIL
DEVIOUS Dan Elwell (Federal ARROGANCE Administration) is the MOST CORRUPT MAN in Washington D.C.
ROMULUS-Corruption Capital, John Mayfield-Corruption Captain-Fed ARROGANCE-Romulus Baptist Church
Cleveland settles airport whistleblowers First Amendment-retaliation lawsuit Wednesday, Oct 10, 2018
Retaliation threats by City of Cleveland and Cleveland Hopkins, related to Case No. #EWB15580
ROMULUS-Corruption Capital, John Mayfield-Corruption Captain-Federal ARROGANCE Administration (FAA)
There are 1,000 employees at the FAA nationwide making $187,000 or more/year. Here are the top 100
Devious FAA Director Dan Elwell-Federal ARROGANCE Administration and his Culture of Corruption
ROMULUS' John Mayfield-AUTOCRATIC Director-Federal ARROGANCE Administration (FAA)
ROMULUS' John Mayfield-Detroit Director-Federal ARROGANCE Administration (FAA)
The failure of FAA chief Daniel Elwell--Trump names new FAA boss with Boeing grounding as backdrop
ROMULUS, Michigan-Home to Corruption In Michigan-Federal ARROGANCE Administration (FAA)
WAYNE, Michigan-Neighbor to Corruption In Romulus, Mich.-Federal ARROGANCE Administration (FAA)
Oberlin, Ohio-Home to Corruption In Ohio-Federal ARROGANCE Administration (FAA) Part 1
Oberlin, Ohio-Home to Corruption In Ohio-Federal ARROGANCE Administration (FAA) Part 2
Devious FAA Director Dan Elwell-Federal Arrogance Administration and his Culture of Corruption
Beefy FAA CEO Teri Bristol-Federal Arrogance Administration and her Culture of Corruption
Des Plaines, Illinois-Home to Corruption In Illinois-Federal Arrogance Administration (FAA) Part 3
Des Plaines, Illinois-Home to Corruption In Illinois-Federal Arrogance Administration (FAA) Part 2
Des Plaines, Illinois-Home to Corruption In Illinois-Federal Arrogance Administration (FAA) Part 1
Des Plaines, Ill. and the Corrupt Office of the Federal Arrogance Administration (FAA)
FAA CEO Teri Bristol-Federal Arrogance Administration Declines to Regulate Seat Size
FAA Chief of Staff Tina Amereihn-Federal Arrogance Administration and her Culture of Corruption
FAA Director Daniel K. Elwell-Federal Arrogance Administration and his Culture of Corruption
Des Plaines, Ill.-FAA James Tegtmeier-Fed Arrogance Adm (FAA) and his quest to quash Public Opinion
Illinois AG Kwame Raoul Vs. Director Daniel K. Elwell-FAA Federal Arrogance Administration
Ohio AG Dave Yost Vs. Director Daniel K. Elwell-FAA Federal Arrogance Administration
Michigan AG Dana Nessel Vs. Director Daniel K. Elwell-FAA Federal Arrogance Administration
Photo-Des Plaines, Illinois-FAA Federal Arrogance Association Wedding of the year
Photos-Des Plaines, Ill.-Home of Great Lakes Office-Federal Arrogance Administration (FAA)
Romulus, Michigan-Home of Federal Arrogance Administration (FAA)-John Mayfield, Manager
Romulus, Michigan-Home of Federal Arrogance Administration (FAA)-John Mayfield, Manager
James W. Tegtmeier (FAA) condones CORRUPTION at Federal ARROGANCE Administration-1987 Luther College
Photos-Des Plaines, Ill.-Home of Great Lakes Office-Federal Arrogance Administration (FAA)
The Federal Arrogance Administration (FAA)-Daniel Elwell and The Art of Incompetence
My nightmare dealing with Ronald Wood and Frank Arrighi Federal Arrogance Administration (FAA)
Dan Elwell Staff Meeting Pictures-Federal Arrogance Administration (FAA)
Teri Bristol-Tina Amereihn Federal Arrogance Administration (FAA) February Quality Award Winners
BFF Sorority Sisters-Federal Arrogance Administration (FAA)
Teri Bristol-Wedding Photos-Chief Operating Officer-Federal Arrogance Administration (FAA)
Tina Amereihn-Wedding Photos-Chief of Staff-Federal Arrogance Administration (FAA)
FAA Chief Daniel Elwell and his Cast of Characters
Des Plaines Ill. Federal ARROGANCE Administration (FAA) Great Lakes Region-Office of the Director
Great Lakes Region-Federal Arrogance Administration (FAA)-Office of the Director
Dan Elwell and the Keystone Cops of The Federal Arrogance Administration (FAA)
In Pictures-Federal Arrogance Administration (FAA) Problem Solving Team
The difference between talking with FAA General Attorney James William Tegtmeier and a bag of rocks
James Tegtmeier versus A bag of Rocks
What is the difference between The Cowardly Lion and Jim Keefer-FAA Great Lakes Deputy Director?
The Cowardly Lion versus James Keefer
What did we receive from Teri Lynn Bristol and her $278,426 salary and bonus for 2017? Bupkiss!
James Frank Arrighi-The Vindictive Forked-Tongued Face of the Washington D.C. FAA
Ronald W. Wood-The Vindictive Forked-Tongued Face of the Oberlin, Ohio FAA
Richard M. Kula--THE EPITOME OF ARROGANCE
Geralyn Zachas-FAA Administrative Officer in office of Susan Mowery Schalk
James Gregory Keefer--THE EPITOME OF ARROGANCE
Susan Kay Mowery-Schalk--THE EPITOME OF ARROGANCE
Susan Kay Mowery-Schalk--Federal Employee Profile
I strongly believe the FAA and Ronald Wood are guilty of violating the RICO Act
Professional football champions 1920-2017.
New York Congressman Steve Israel calls the FAA the "Federal Arrogance Administration."
FAA corruption exposing activists learn from famed Nazi hunters
Ron Wood, James Arrighi expected to feel the wrath of millions for routing planes over Milford HS
The lack of professionalism perfectly exemplified in the office of the Connecticut Attorney General
High levels of exposure to aircraft noise linked to serious physical/mental health issues
Tell Colorado senators to support amendments addressing aviation noise
Phoenix legal defeat prompts FAA to address noise concerns
Maryland asks court to urge FAA to change low flight paths near BWI because of noise
FAA tells airline passengers-We are a safety agency, not a creature comfort agency
I went out with a decibel reader, and just a normal jet flying over is 85 decibels
California Congressman Brad Sherman (D-Sherman Oaks) released a letter he sent to Dan Elwell FAA
The FAA, she added, has been "derelict in its duties" to residents
Lawmakers To Meet, Demand FAA Public Hearing On Helicopter Noise
Three cheers to the Washington Post, Paul Verchinski-Columbia, Lori Aratani (Wash Post reporter)
Corruption is Rampant at the FAA-New York Employees 2017
Why are the sixty-nine top people at the FAA allowed to keep their jobs?
Request help/Contact/Request a meeting with Peters, Stabenow, Trott,
Peters, Stabenow, Trott, Tash, Evans, Danley, McPherson, Wood, Arrighi
Michigan Corruption Hall of Fame-Sen. Gary Peters (scheduler-Courtney A. Evans) Kwame Kilpatrick
Federal Highway Administration United States and Puerto Rico Employees U.S.-2017
Thanksgiving Utensils c/o Ronald W. Wood and James Frank Arrighi-
Daniel K. Elwell's FAA covers up another failure
Corruption is Rampant at the FAA-Maryland Employees 2017
Corruption is Rampant at the FAA-Delaware Employees 2017
Sky Justice National Network-The Great American Patriots of Culver City, California
Corruption is Rampant at the FAA-California Employees in Year 2017
Federal Aviation Administration High Level Organization Chart (text only): November 2018
FAA Great Lakes Region Corruption starts at the top with Susan M. Schalk and Company
Corruption is Rampant at the FAA-Indiana Employees
November 07-08, 2018 FAA Public Input Sessions cancelled w/o warning-FAA afraid of public backlash
If private individuals like me do not stand up to the bullying tactics of FAA, who is going to?
FAA (Federal Aviation Administration) Metroplex Question and Answer session
Corruption is Rampant at the FAA-Wisconsin Employees in Year 2017
FAA Corruption starts at the top
Corruption is Rampant at the FAA-Virginia Employees in Year 2017
Corruption is Rampant at the FAA-Washington D.C. Employees in Year 2017
Corruption is Rampant at the FAA-Illinois Employees in Year 2017
Corruption is Rampant at the FAA-Ohio Employees in Year 2017
Corruption is Rampant at the FAA-Michigan Employees in Year 2017
Corruption is Rampant at the FAA
Let's love God's earth-Piano version sung and arranged by Jeremy Palmer-link to music on staff paper
Let's love God's earth-Electronic version with English Horn arranged by Jeremy Palmer
Let's love God's earth-Trumpet version by Scott McCullough
Oscar Robertson, Isaiah Thomas, Charles Barkley taking heat
God was a flip-flopper in Glendale, Arizona on Saturday night. January 17, 2016
Poor Walt Disney must be turning over in his grave
Part two-Playing the What If game in sports-Nate Thurmond
Playing the What If game in sports
Athlete and crowd behavior sickens me
ESPN is The King of Hypocrisy
"Once you have wrestled, everything else in life is easy." Dan Gable
Big Ten, Big Twelve and SEC non-conference opponents broken down by team.
SEC non-conference football schedule.
The Mid-American Conference plays the toughest non-conf football schedule in the country annually
2012 Top Ten Worst Zoos for Elephants
Worst Zoos for Elephants - Hall of Shame
What college football conferences will be most represented in the NFL playoffs on Jan. 12-13, 2013
The colleges with most reps on the four winning teams of the NFL playoffs of Jan. 05-06, 2013
What college football conferences will be most represented in the NFL games on Sun., Jan. 6, 2013
What college football conferences will be most represented in the NFL games on Sat., Jan. 5, 2013
Three Cheers for Northern Illinois University of the Mid-American Conference going to the Orange Bow
States providing the most elite level High School football prospects
High School football to National Football League success rate
2012-2013 NBA player demographics
Letter to the editor: I will NOT VOTE for Vicki Barnett in this 2012 election.
Only 10 players received grades of 90.0 or above in the 2012 NFL draft.
States providing the most quality Defensive Backs to the NFL.
States providing the most quality Offensive Guards to the NFL.
States providing the most quality Tight Ends to the NFL.
States providing the most quality Offensive Ends to the NFL.
States providing the most quality running backs to the NFL.
Would you rather have the linebackers from California, Ohio, Pennsylvania or Texas?
Colleges in the state of California produce the greatest quantity of NFL offensive tackles
In Peyton Manning's 1998 NFL draft class 243 college players were selected.
1936-2011-Notable second round draft choices-including 26 in the NFL Hall of Fame.
1936-2011 NFL First round draft choices Saints-Colts (year-round-selection)
1936-2011 NFL First round draft choices Panthers-Redskins (year-round-selection)
1936-2011 NFL First round draft choices Forty Niners-Packers (year-round-selection)
1936-2011 NFL First round draft choices Bears-Cardinals (year-round-selection)
1936-2011 NFL First round draft choices Bears-Cardinals (year-round-selection)
Edmond Azadian-The Profile of Parliamentary Elections in Armenia (part 2 of 2)
Edmond Azadian-The Profile of Parliamentary Elections in Armenia (part 1 of 2)
Rita Dilanian-The latest tasteless act by the city of Farmington Hills Michigan
Martha Kouyoumdjian Mekaelian-Christmas-Some things Should Never be compromised.
Forbes Magazine names Farmington Hills (with Troy and Warren) 10th most miserable city in America
George Sarkisian-These colleges will be represented by the Patriots/Giants in the 2012 super bowl
How many Top-100 high school football players participated in the 2012 NFL playoffs?
January 15, 2012-Who today remembers the Armenians?
George Sarkisian-12/17/11-Is the best college football played NORTH or SOUTH of Mason-Dixon line?
George Sarkisian-Dec. 11, 2011-Michigan AD is "Hypocrite of the Year" in college football
George Sarkisian-Acclaimed Film maker Hrayr Toukhanian presents 2011 Vasbouragan Society Celebration
George Sarkisian-Which team deserves to be ranked where?
George Sarkisian-Which div 1-a college football teams should be allowed to play for the championship
George Sarkisian-Week Eleven report card-2011 div 1-a college football
George Sarkisian-Penn State-It saddens all of us.
George Sarkisian-Elect Ginsberg and Kahn to Farmington Board of Education November 08, 2011
George Sarkisian-The What Ifs of the NBA draft--birth year 1936 through 1949.
George Sarkisian-The What Ifs of the NBA draft-birth years 1920s-1930s.
George Sarkisian-Part Three-2011 National Football League player demographics
George Sarkisian-Part Two-2011 National Football League player demographics
George Sarkisian-2011 National Football League player demographics
George Sarkisian-Rita Dilanian-2011 Farmington Hills endorsements
George Sarkisian-Top fund raiser, Rita Dilanian, digusted with Farmington Arts Commission
George Sarkisian-2011 div 1-a college football results--weeks one through six
George Sarkisian-Derek Jeter ends up wearing the goat horns in 2011
George Sarkisian-Home field advantage in weeks one-five of the 2011 season div 1-a college football
George Sarkisian-The Home Field advantage in 2011 div 1-a college football.
George Sarkisian-Wall of Shame results-2011 season: Weeks one and two div 1-a college football
George Sarkisian-Results-week one 2011 college football div 1-a wall of shame
George Sarkisian-THANK YOU, STEVE JOBS! Adopted by Armenians
George Sarkisian-2011 season, week 1 and 2, div 1-a college football, wall of shame
George Sarkisian-Rest in Peace-Camp Dearborn
George Sarkisian-Lack of organization in the Ohio State athletic department
George Sarkisian- Shame on all 93 div 1-a football schools playing div 1-aa opponents in 2011
George Sarkisian-Let me tell you the story of former National Football League player Greg Gaines
George Sarkisian-Letter to the Editor: Alabama and Michigan lead the 2011 Wall of Shame for div 1-a
George Sarkisian-Letter to the Editor: University of Notre Dame Mission Statement
George Sarkisian-Compare salary increases for Michigan University administrators
George Sarkisian-Dan Gable is the most accomplished sports person in the history of the USA.
George Sarkisian-Projected winners March 26-27, 2011 NCAA men's basketball tournament.
George Sarkisian-Projected winners March 24-25, 2011 NCAA men's basketball tournament.
George Sarkisian-hold NFL criminally responsible
George Sarkisian-suspend Mika Brzezinski
George Sarkisian-I did not watch the 2011 super bowl
George Sarkisian-boycott the super bowl
George Sarkisian-OSU's Gordon Gee stands for "Goofball"
George Sarkisian-2010 div 1-a college football wall of shame
George Sarkisian-Shame on Messers. Goodell, Selig, Stern, and Bettman:
George Sarkisian-Which side are we supposed to feel sorry for in the potential upcoming NFL lockout?
George Sarkisian-2009 NFL salaries by position
George Sarkisian-Thank God, the 2010 super bowl is over!

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts

One researcher's discovery suggests troubling oversights in Boeing's cybersecurity.

ANDY GREENBERG
mail@wired.com
submit@wired.com

SECURITY 08.07.2019 03:29 PM

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
One researcher's discovery suggests troubling oversights in Boeing's cybersecurity.

https://www.wired.com/story/boeing-787-code-leak-security-flaws/?verso=true

www.georgesarkisian.com-investigative reporter exposing the corruption in government, politics and big business.

https://www.wired.com/story/boeing-787-code-leak-security-flaws/?verso=true

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
One researcher's discovery suggests troubling oversights in Boeing's cybersecurity.

ANDY GREENBERG
mail@wired.com
submit@wired.com

SECURITY 08.07.2019 03:29 PM

A Boeing Code Leak Exposes Security Flaws Deep in a 787's Guts
One researcher's discovery suggests troubling oversights in Boeing's cybersecurity.

Late one night last September, security researcher Ruben Santamarta sat in his home office in Madrid and partook in some creative googling, searching for technical documents related to his years-long obsession: the cybersecurity of airplanes. He was surprised to discover a fully unprotected server on Boeing's network, seemingly full of code designed to run on the company's giant 737 and 787 passenger jets, left publicly accessible and open to anyone who found it. So he downloaded everything he could see.

Now, nearly a year later, Santamarta claims that leaked code has led him to something unprecedented: security flaws in one of the 787 Dreamliner's components, deep in the plane's multi-tiered network. He suggests that for a hacker, exploiting those bugs could represent one step in a multi­stage attack that starts in the plane’s in-flight entertainment system and extends to highly protected, safety-critical systems like flight controls and sensors.

Andy Greenberg writes about security for wired. He is the author of the forthcoming book Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers.

Boeing flatly denies that such an attack is possible, and it rejects his claim of having discovered a potential path to pull it off. Santa­marta himself admits that he doesn't have a full enough picture of the aircraft—or access to a $250 million jet—to confirm his claims. But he and other avionics cybersecurity researchers who have reviewed his findings argue that while a full-on cyberattack on a plane's most sensitive systems remains far from a material threat, the flaws uncovered in the 787's code nonetheless represent a troubling lack of attention to cybersecurity from Boeing. They also say that the company's responses have not been altogether reassuring, given the critical importance of keeping commercial airplanes safe from hackers.

At the Black Hat security conference today in Las Vegas, Santamarta, a researcher for security firm IOActive, plans to present his findings, including the details of multiple serious security flaws in the code for a component of the 787 known as a Crew Information Service/Maintenance System. The CIS/MS is responsible for applications like maintenance systems and the so-called electronic flight bag, a collection of navigation documents and manuals used by pilots. Santamarta says he found a slew of memory corruption vulnerabilities in that CIS/MS, and he claims that a hacker could use those flaws as a foothold inside a restricted part of a plane's network. An attacker could potentially pivot, Santamarta says, from the in-flight entertainment system to the CIS/MS to send commands to far more sensitive components that control the plane's safety-critical systems, including its engine, brakes, and sensors. Boeing maintains that other security barriers in the 787's network architecture would make that progression impossible.

Santamarta admits that he doesn't have enough visibility into the 787's internals to know if those security barriers are circumventable. But he says his research nonetheless represents a significant step toward showing the possibility of an actual plane-hacking technique. "We don't have a 787 to test, so we can't assess the impact," Santamarta says. "We’re not saying it’s doomsday, or that we can take a plane down. But we can say: This shouldn’t happen."

Flying Firewalls

In a statement, Boeing said it had investigated IOActive's claims and concluded that they don't represent any real threat of a cyberattack. "IOActive’s scenarios cannot affect any critical or essential airplane system and do not describe a way for remote attackers to access important 787 systems like the avionics system," the company's statement reads. "IOActive reviewed only one part of the 787 network using rudimentary tools, and had no access to the larger system or working environments. IOActive chose to ignore our verified results and limitations in its research, and instead made provocative statements as if they had access to and analyzed the working system. While we appreciate responsible engagement from independent cybersecurity researchers, we’re disappointed in IOActive’s irresponsible presentation."

In a follow-up call with WIRED, a company spokesperson said that in investigating IOActive's claims, Boeing had gone so far as to put an actual Boeing 787 in "flight mode" for testing, and then had its security engineers attempt to exploit the vulnerabilities that Santamarta had exposed. They found that they couldn't carry out a successful attack. Honeywell, which supplied Boeing with the code for the CIS/MS, also wrote in a statement to WIRED that "after extensive testing, Honeywell and its partners determined there is no threat to flight safety as the 787’s critical systems cannot be affected."

"Every piece of software has bugs. But this is not where I’d like to find the bugs."

STEFAN SAVAGE, UCSD

IOActive's attack claims—as well as Honeywell's and Boeing's denials—are based on the specific architecture of the 787's internals. The Dream­liner's digital systems are divided into three networks: an Open Data Network, where non-sensitive components like the in-flight entertainment system live; an Isolated Data Network, which includes somewhat more sensitive components like the CIS/MS that IOActive targeted; and finally the Common Data Network, the most sensitive of the three, which connects to the plane's avionics and safety systems. Santamarta claims that the vulnerabilities he found in the CIS/MS, sandwiched between the ODN and CDN, provide a bridge from one to the other.

But Boeing counters that it has both "additional protection mechanisms" in the CIS/MS that would prevent its bugs from being exploited from the ODN, and another hardware device between the semi-sensitive IDN—where the CIS/MS is located—and the highly sensitive CDN. That second barrier, the company argues, allows only data to pass from one part of the network to the other, rather than the executable commands that would be necessary to affect the plane's critical systems.

"Although we do not provide details about our cybersecurity measures and protections for security reasons, Boeing is confident that its airplanes are safe from cyberattack," the company's statement concludes.

Boeing says it also consulted with the Federal Aviation Administration and the Department of Homeland Security about Santamarta's attack. While the DHS didn't respond to a request for comment, an FAA spokesperson wrote in a statement to WIRED that it's "satisfied with the manufac­turer’s assessment of the issue."

"This Is Security 101"

The new claims of software flaws come against the backdrop of the ongoing scandal over Boeing's grounded 737 Max aircraft, after that aircraft's faulty controls contributed to two crashes that killed 346 people. At the same time, Santamarta has his own history of unresolved disagree­ments with the aerospace industry over its cybersecurity measures. He previously hacked a Panasonic Avionics in-flight entertainment system. And at last year's Black Hat conference, for instance, he presented vulnerabilities in satellite communication systems that he said could be used to hack some non-sensitive airplane systems. The Aviation Industry Sharing and Analysis Center shot back in a press release that his findings were based on "technical errors." Santamarta countered that the A-ISAC was "killing the messenger," attempting to discredit him rather than address his research.

But even granting Boeing's claims about its security barriers, the flaws Santamarta found are egregious enough that they shouldn't be dismissed, says Stefan Savage, a computer science professor at the University of California at San Diego, who is currently working with other academic researchers on an avionics cybersecurity testing platform. "The claim that one shouldn't worry about a vulnerability because other protections prevent it from being exploited has a very bad history in computer security," Savage says. "Typically, where there's smoke there's fire."

Savage points in particular to a vulnerability Santamarta highlighted in a version of the embedded operating system VxWorks, in this case customized for Boeing by Honeywell. Santamarta found that when an application asks to write to the underlying computer's memory, the tailored operating system doesn't properly check that it's not instead over­writing the kernel, the most sensitive core of the operating system. Combined with several application-level bugs Santamarta found, that so-called parameter-check privilege escalation vulnerability represents a serious flaw, Savage argues, made more serious by the notion that VxWorks likely runs in many other components on the plane that might have the same bug.

"Every piece of software has bugs. But this is not where I’d like to find the bugs. Checking user parameters is security 101," Savage says. "They shouldn't have these kinds of straightforward vulnerabilities, especially in the kernel. In this day and age, it would be inconceivable for a consumer operating system to not check user pointer parameters, so I'd expect the same of an airplane."

"This shouldn’t happen."

RUBEN SANTAMARTA, IOACTIVE

Another academic avionics cybersecurity researcher, Karl Koscher at the University of Washington, says he's found such serious security flaws in an aircraft component as those Santamarta reported in the CIS/MS. "Perhaps Boeing intentionally treated it as untrusted, and the rest of the system can handle that untrusted bit," Koscher says."But saying, 'It doesn’t matter because there are mitigations further down' isn’t that good an answer. Especially if some of the mitigations turn out to be not as robust as you think they are."

Koscher also points to the CIS/MS access to the Electronic Flight Bag, full of documents and navigation materials a plane's pilot might refer to via a tablet in the cockpit. Corrupting that data could cause its own form of mayhem. "If you can create confusion and misinformation in the cockpit, that could lead to some pretty bad outcomes," Koscher notes. (A Boeing spokesperson says that the EFB can't be compromised from the CIS/MS, either, despite both being located in the same part of the 787's network.)

Big, Flying Collections of Computers

To be clear, neither Savage nor Koscher believe that, based on Santamarta's findings alone, a hacker could cause any immediate danger to an aircraft or its passengers. "This is a long way from an imminent safety threat. Based on what they have now, I think you could let the IOActive guys run amok on a 787 and I'd still be comfortable flying on it," Savage says. "But Boeing has work to do."

Assessing whether IOActive's findings truly represent a step toward a serious attack is difficult, Savage points out, simply due to the impossible logistics of airplane security research. Companies like Boeing have the means to comprehensively test a quarter-billion-dollar aircraft's security, but also have deep conflicts of interest about what results they publish. Independent hackers like IOActive's Santamarta don't have the resources to carry out those complete investigations—even as highly resourced state hackers or others willing to test on live, airborne planes might.

Santamarta's research, despite Boeing's denials and assurances, should be a reminder that aircraft security is far from a solved area of cybersecurity research. "This is a reminder that planes, like cars, depend on increasingly complex networked computer systems," Savage says. "They don't get to escape the vulnerabilities that come with this."

Enter supporting content here