GAO: US aviation comms lack sufficient cyber protections
The US Government Accountability Office warned that weak cybersecurity at the FAA puts aircraft communication channels at risk. The ACARS and CPDLC applications are generally unencrypted and lack authentication, leaving them vulnerable to interception, spoofing and flood-based denial-of-service attacks.
- ACARS and CPDLC are generally unencrypted and lack authentication
- Threats include interception, spoofing and flood-based DoS attacks
- FAA has not fully implemented a risk-based cybersecurity program
- Report came the same day a cable cut hit US East Coast telecoms
Read next
Security