Woman Allegedly Hacked Flight School, Cleared Planes With Maintenance Issues To Fly (vice.com) 67
A woman allegedly hacked into the systems of a flight training school in Florida to delete and tamper with information related to the school's airplanes. In some cases, planes that previously had maintenance issues had been "cleared" to fly, according to a police report. The hack, according to the school's CEO, could have put pilots in danger. From a report: Lauren Lide, a 26-year-old who used to work for the Melbourne Flight Training school, resigned from her position of Flight Operations Manager at the end of November of 2019, after the company fired her father. Months later, she allegedly hacked into the systems of her former company, deleting and changing records, in an apparent attempt to get back at her former employer, according to court records obtained by Motherboard. The news of her arrest was first reported by local TV station News Channel 8.
Derek Fallon, the CEO of Melbourne Flight Training called the police on January 17, 2020, and reported that five days before, he logged onto his account for Flight Circle, an app his company uses to manage and keep track of its airplanes, and found that there was missing information. Fallon found that someone had removed records related to planes with maintenance issues and reminders of inspections had all been deleted, "meaning aircraft which may have been unsafe to fly were purposely made 'airworthy,'" according to a document written by a Melbourne Airport Police officer.
Derek Fallon, the CEO of Melbourne Flight Training called the police on January 17, 2020, and reported that five days before, he logged onto his account for Flight Circle, an app his company uses to manage and keep track of its airplanes, and found that there was missing information. Fallon found that someone had removed records related to planes with maintenance issues and reminders of inspections had all been deleted, "meaning aircraft which may have been unsafe to fly were purposely made 'airworthy,'" according to a document written by a Melbourne Airport Police officer.
Re:So what's the charge? (Score:5, Insightful)
Attempted murder or what?
Being a Floridiot.
Re: (Score:3)
It's the new superhero! You've enjoyed the adventures of Florida Man, now thrill to the tales of Florida Woman!
Re: (Score:2)
Re: (Score:2)
When I read "Florida Man" I always picture a wannabe wearing long johns and a red bath towel as a cape (both moth eaten) with an F on his chest.
Re: (Score:3)
In fact, it sounds so good I'd probably pirate it.
Re: (Score:2)
That's Fartman
Re: (Score:2)
They're quite similar. Fartman can be distinguished by the burnt dry rotting cloth over his butt.
Re: (Score:2)
"The bitter worker now faces charges that include fraudulent use of computers and two counts of unauthorized access to a computer network."
Donâ(TM)t aircraft (Score:2)
Still have paper logbooks for maintenance?? I thought it was mandatory?
Re: (Score:3)
Re: (Score:3)
Comment removed (Score:5, Insightful)
Re: (Score:3)
I'm not trying to justify what this woman did, but it looks to me like her aim was to cause chaos, not to cause actual deaths. Pilots would have taken the planes out, gotten ready to fly them, and then found they couldn't, and the mismatch between what the computer said and what the paperwork said would have resulted in several days of exasperation, followed by a shutdown while the company rebuilds its computer records.
Doesn't it depend on what exactly the maintenance was? The pilot inspection doesn't go terribly far into depth which what was fixed with what was ailing a plane. If something deep in an engine or obscure part of a plane isn't visible in a walk-around, they can't see it. There has to be some level of trust.
What she (allegedly) did was pretty egregious. I wonder what the punishment will be, because what she (allegedly) did has an impact far beyond just that one place. It erodes confidence. It begs the ques
Re: (Score:3)
What she (allegedly) did was pretty egregious. I wonder what the punishment will be, because what she (allegedly) did has an impact far beyond just that one place. It erodes confidence. It begs the question of who are these places hiring?
People who don't say on their resume that their sociopaths.
Re: (Score:2)
What she (allegedly) did was pretty egregious. I wonder what the punishment will be, because what she (allegedly) did has an impact far beyond just that one place. It erodes confidence. It begs the question of who are these places hiring?
People who don't say on their resume that their sociopaths.
Surely. Hopefully they do background checks though.
Re: (Score:2)
Re: (Score:2)
A preflight check is not going to catch an intermittent failure or a component past its service life, both of which would be in the records.
Re: (Score:1)
No. She deleted aircraft squawks. Pilot complaints about the aircraft. This is a problem that another pilot found with the plane and needs to be addressed. Often a problem removes the plane from being airworthy. Even something as minor as the fuel gauge not working can ground an airplane (the FSDO can give you a pass to fly it back for maintenance). It can be as major as cracks forming, something breaking in flight and so on. Things you wouldn't necessarily notice upon inspection. The pilot is not a mechani
Re: (Score:3)
An aircraft in for maintenance could not be checked out, flown, and crashed, because if you read the article, she deleted:
The entire schedule and blocked out all the instructors and pilots for the next day
The aircraft information for all 12 planes including make, model, and tail number
Maintenance reminders
Squawks (pilot reported maintenance problems with the airplanes)
She did not remove aircraft maintenance records, only the reminders and the current pilot reported problems. On the planes which could not be
Re: (Score:2)
Re:Don't aircraft (Score:3)
Yes. Paper logs are mandatory. The online information is handy, but the information in the paper logs is definitive: when I sign my plane's journey log I'm signing a legal document. Going through a plane's logs to confirm when various maintenance is due (e.g. prop inspection, ELT certification) can be a chore on a plane that flies a lot.
This is also why a plane without logs is worth very little. All time-limited parts must be replaced or otherwise certified before the plane can fly again.
...laura
Re: (Score:2)
Unfortunately that's not fully correct. There is no requirement for paper maintenance records. There are requirements for signatures but those can be digital.
Re: (Score:2)
Depends on the country. In Canada paper records are mandatory.
Tampering with aircraft maintenance logs? (Score:1)
That's a paddlin'
Ex employee had account... (Score:1)
From the article
"...would likely have had to come from an employee with Melbourne Flight Training with 'administrator rights..."
didn't hack shit... can't let that get in the way of a bullshit headline...
Re: (Score:1)
You don't own or control the english language. People have been using 'hacked' to mean 'unauthorized access' for a long time. Get over it.
Re: (Score:2)
some old definition they looked up says vaccines come from the thing being vaccinated against.
You can't get much older than Latin. Vacca is Latin for cow because the first one used cowpox.
Re: (Score:2)
Language evolves, the meanings of words changes. Now attend your cognitive therapy session.
Re: (Score:2)
People have been incorrectly using 'hacked' to mean 'unauthorized access' for a long time.
Fixed that for you.
Be that as it may, languages evolve, and fast, and what was incorrect usage becomes the norm later on. I don't disagree with you with how people use the word "hacking", but the new meaning is now the norm and for here to stay (and for those who work in software or security, it pays to understand it.) No reason to split grammatical hairs over it.
Re: (Score:1)
From the article "...would likely have had to come from an employee with Melbourne Flight Training with 'administrator rights..."
didn't hack shit... can't let that get in the way of a bullshit headline...
Of course not. These editors apparently gave themselves quota on posting at least one "ebil haxx0rz!!!1!" headline a day. So if it's a slow news day they just have to call "using a working credential" "hacking".
You won't learn what is hacking from slashdot. But you can look at EditorDavid, msmash, and BeauHD their "hacking" headlines to learn what it is not. Just like you can look at their "summaries" to learn what summaries are not. Similar rules to Betteridge's law of headlines.
You don't own or control the English language. People have been using 'hacked' to mean 'unauthorized access' for a long time. Get over it.
Those people don't contro
Re: (Score:2)
It's unclear how she allegedly obtained his password.
She obtained authorized access to the administrator account. Maybe it was social engineering. Maybe she guessed his password. Maybe she found a flaw in the security. Regardless, it was some form of a hack.
Re: (Score:1)
Heck, maybe they didn't change passwords after she left....
Re: (Score:2, Informative)
This is probably the answer. She used the old credentials for her role (Flight Operations Manager) which weren't changed between November 2019 when she left and January 2020 when the police were called.
Re: (Score:2)
Re: (Score:2)
It's unclear how she allegedly obtained his password.
She obtained authorized access to the administrator account. Maybe it was social engineering. Maybe she guessed his password.
None of those are "hacking". The use of the word "hacking" in this story is just lame clickbait.
Re: (Score:2)
Re: (Score:2)
If I guess the password to your email account is that hacking or something else?
If you use a random password generator to guess the password is that hacking?
Re: (Score:2)
Yes. It's very lame hacking but it is technically hacking.
Re: (Score:2)
So a mentally generated random password (a lucky guess) could also be hacking by loose usage of agreed upon terms. Pointless to get stuck on that point when the article is not written from a domain specific news source.
Re: (Score:2)
You seem to be mistaking me for someone who cares. All I did was agree that using a brute force attack on a password would (barely) qualify as hacking.
In fact, using research and applied psychology to guess right first try would be more impressive. Getting the password through social engineering would also show more skill than brute forcing.
Re: (Score:2)
Yes, brute force attempts to gain root access are a kind of hacking.
Re: (Score:2)
Re: (Score:2)
Yep, she made unauthorized use of credentials that should have been revoked when she was terminated.
Get back at them? (Score:1)
Is this hacking? (Score:2)
Isn't hacking getting into systems that you don't have the credentials to get into? Seems like she had access that was never revoked when she left.
Re: (Score:3)
No company should ever rely on the threat of law to keep former employees in line, but the law makes it clear that her access is legally revoked regardless of actual access.
Re: (Score:2)
TIL. Thanks
Re: (Score:2)
Nevertheless, while illegal, you aren't "hacking" by any reasonable use of the word. Unauthorized use of credentials, misuse of property, digital tresspass... whatever... but 'hacking' (in the modern 'cracking' sense requires a 'breach'... not simply using your old still working keys.
Just as we don't call you a "safecracker" if you get fired from Wendy's and then sneak into the back room and empty the safe on your way out because they haven't changed the combination yet. A burglar sure, a criminal, very mu
Re: (Score:2)
Where the company could face liability is if someone were injured or killed because proper maintenance wasn't done. At that point, both the company and the person who accessed the system without authorization would be codefendants, and almost certainly a court would find the company partially liable for the injury or death. But that's civil law. From a criminal standpoint, if she gained unauthorized access to the system (even if by using her old credentials), she could be found guilty.
Wouldn't have done anything anyway. (Score:3)
While digital maintenance databases are important (mainly for archiving), there is always paper master that has to get physically signed off before the plane can fly. That paper master is then entered into the database when the job is complete.
So "clearing the airplane to fly" in the computer would have done absolutely nothing. The mechanic doesn't care what the computer says, it's only a way of bookkeeping and tracking preventive mx.
Re: (Score:1)
However, if the system was relied upon for squawks including one's that should completely ground the plane. This could result in an aircraft taking to the ski when it wasn't airworthy or in the worst case truly unsafe. So if say the airplane was grounded until checked/repaired but the keys were returned to the pool at dispatch. Dispatch
Re: (Score:2)
In a perfect world.
Pilots have been known to fly into the ground because of a single broken altimeter. If a pilot is willing to angle downwards for 30 minutes because the altimeter says he is climbing, he is willing to take a plane out flying because the computer says maintenance was done on it.
This reminds me of when my construction crew built the wrong building after the office sent 2 blueprints and one of them was outdated, but we did not know that.
Southwest Should Hire Her (Score:2)
Maybe she can get their planes back in the air.
Only life on the line (Score:2)
"aircraft which may have been unsafe to fly were purposely made 'airworthy,'"
The plane not airworthy but the pilot spongeworthy?
Imagine the loss.
That's sabotage and terrorism. (Score:2, Insightful)
She should be crushed as an example and locked up for life. There is no redemption but her punishment can at least be exemplary and give what remains of her life a bit of value.
The US is a strange place where victimless crimes are punished cruelly but victimful crimes often punished lightly.
Re: (Score:2)
As for what you said about the US in general We’re actually slowly but surely moving away from victimless crimes. When I was a kid, getting caught with weed was probably jail time, and dont get
Re: (Score:1)
She used her dads creds, thatâ(TM)s not hacking
It's amazing how many companies don't lock the account when someone leaves. A company that I ended up suing still didn't lock mine 6 months later. Who knows, it may still not be locked today. The company is a computer company.
Bobby Drop Tables (Score:1)
To be fair she was just booking her son. Little Bobby Drop Tables.