United Airlines waits 6 months to patch critical flaw submitted to bug bounty program
A security researcher found and reported a critical vulnerability to United Airlines that could allow an attacker to “completely manage any aspect of a flight reservation using United’s website.” He claims United Airlines, which announced a bug bounty program about six months ago, didn’t deploy a fix for five months and only plugged the holes after he threatened to publicly disclose the unpatched vulnerability.
United Airlines launched its bug bounty program last May, promising to hand out loyalty miles instead of cash for finding flaws; United’s in-flight systems were off limits as the company did not want researchers hunting for bugs in its Wi-Fi, entertainment systems or avionics. The program received a lot of press as it followed security researcher Chris Roberts joking tweet about live-testing United 737/800 aircraft systems; it also followed as a U.S. Government Accountability Office report (pdf) which warned that aircraft avionics systems could be at risk due to Internet connectivity.
To read this article in full or to leave a comment, please click here