Skip to main content
Tech Privacy

A $100 gadget researchers say could reroute a 737

Researchers built a coin-sized device that can be inserted into a vulnerable port in Boeing 737s—and used to hack into the aircraft’s computer system.

3 min read

TOPICS: Tech Privacy / Cybersecurity & InfoSec / Vulnerability Disclosure

TL;DR: What does it take to hack a Boeing 737? The answer might be a tiny $100 gadget that easily slots into a port accessible through an external hatch on the plane. Researchers say that this physical hacking method they created is a sign that aviation cybersecurity needs a 21st-century refresh.

What happened: The coin-sized device can take over the plane’s autopilot, modifying calculations that could impact takeoff and where the aircraft flies—all potentially without tipping off the pilot, according to researchers from the University of California at San Diego and Oberlin College.

The object can fit into a port accessible through a (typically unlocked) hatch on the outside of the aircraft—which Wired notes is “routinely within reach” of many airport personnel. And, despite its small form factor, the device also has wi-fi capabilities, which could potentially give the attacker remote control of it.

The good news is the gadget is just a prototype to show how easy-to-hide, wi-fi-enabled hardware could compromise a plane’s computer. And the researchers say there’s a simple, immediate fix (if messy)—fill this particular port with epoxy.

Why researchers did this: The team behind the device has been studying ways to hack planes for almost a decade and a half now. The hope is that this research will push the aviation industry to be more vigilant about cybersecurity threats—similar to what happened in the auto industry after researchers’ work on car hacking. (They’re also not publicly revealing every detail of how the plane hack works, or which exact port they targeted, for obvious reasons.)

Tech news that makes sense of your fast-moving world.

Tech Brew breaks down the biggest tech news, emerging innovations, workplace tools, and cultural trends so you can understand what's new and why it matters.

By subscribing, you accept our Terms & Privacy Policy.

Don’t freak out yet: This isn’t a five-alarm fire that should have people canceling their flights, researchers note. Boeing is also in the loop—the research team first reached out to the 737 manufacturer over six years ago.

Boeing told Wired that it conducted its own review of the 737’s current design, but believes that the “layers of protection in place” are enough to reduce the risk of such an attack actually happening. (How reassuring that is from Boeing is up to you.) And, to date, there’s been no publicly reported incident of a commercial flight’s computer system getting hacked.

Bottom line: There were over 6,700 Boeing 737s in service as of last June, per International Air Transport Association data—making it one of the most popular commercial aircraft models today. There’s no need to panic, but one lead researcher noted that if he were in the aviation industry’s shoes, he “would not sleep on this one.” —WK

Also in aviation…

About the author

Whizy Kim

Whizy is a writer for Tech Brew, covering all the ways tech intersects with our lives.

Tech news that makes sense of your fast-moving world.

Tech Brew breaks down the biggest tech news, emerging innovations, workplace tools, and cultural trends so you can understand what's new and why it matters.

By subscribing, you accept our Terms & Privacy Policy.