Security

Flying through Seattle’s hacked airport

Comment

Image Credits: Devin Coldewey/TechCrunch

Several days after the Port of Seattle announced a “possible” cyberattack on its systems, Seattle-Tacoma Airport is still largely offline, causing chaos among travelers and acting as a standing warning against taking cybersecurity lightly. Ask me how I know.

The outage resulting from the recent hack has not, fortunately, caused planes to fall out of the sky or Air Traffic Control to double-book a runway. Those resources, run by the feds, are considerably more locked down.

Rather than catastrophe, what we have now — and for the foreseeable future, since authorities have offered no timeline for restoration — is an object lesson in why we have rules about where we put our eggs.

For my part, I found out on Sunday when — and I hesitate even to mention it, because no one seems to know about this miraculous service — I went to reserve my place in the security line via the SEA Spot Saver. The service was offline, and throwing the kind of error that you don’t have to be a sysadmin to know means deeper problems.

If I had been a good reporter and read my own publication over the weekend, I would have known this was the result of, among other things, the entire user-facing DNS configuration of the Port’s web architecture being totally cooked. (The Spot Saver site is still offline, but the function has been resuscitated by Clear for now.)

Luckily I was not checking a bag and security was light, possibly due to a jackknifed semi blocking all southbound traffic on I-5.

At the airport, the large screens one would ordinarily loiter under to find one’s flight were ominously dark. But considering the endless construction at Sea-Tac, I chalked this up to electrical work.

It was only at the “S” gates that the extent of the problem became clear. Every screen in the area was dark; the TVs above the waiting areas, the multi-display arrays directing travelers to gates, the monitors of the gate agents, and the gate info displays themselves.

Though my boarding pass had directed me to a gate, there was no way to be sure that was the correct one, so I checked with the agents there. They confirmed it, and I asked about the hack.

“It definitely is a bit of a… show,” the airline agents agreed, politely eliding the same part of the word I had. All airport systems shared by multiple airlines were down. Baggage handling, they said, was getting the worst of it. The agents were (tell no one!) ignoring their own baggage size rules and didn’t bother collecting “volunteers” to gate check bags and speed up boarding. Inter-airline communications were labored.

The gate desk was mostly offline, I was told, as it’s a shared system between Alaska, Delta, and anyone else who comes to the “S” gates. The gate was unable to display the flight number, boarding groups, or any delays — a half-hour for my flight — except over the public address system — which was extremely competitive due to the need to constantly repeat current gate numbers. Nearby, one gate had paper signs announcing the flight that had last departed, though that was obviously hours earlier. (Sea-Tac airport spokesperson Perry Cooper told me in an email that my experience was “not typical of the rest of the airport.”)

a photo of the S4 gate at Seattle-Tacoma airport with switched-off displays with a piece of paper taped to the screen, saying ICELANDAIR FI680.
Gate S-4 at Seattle-Tacoma airport, with no gate information due to the cyberattack. Image Credits: TechCrunch

The tablets for checking people in were working, “but limited,” the agents said. Changing flights or seats was not happening. (“I think maybe I got upgraded to first,” I ventured hopefully, but they just shooed me away.)

In situations where the digital infrastructure crashes, it can happen that those who cling to analog resources look smart rather than quaint. No so today. As I waited, every few minutes someone would walk up to the gate with a paper ticket telling them this was where they departed from. Some were lucky enough to be told it was just a few steps away, while one unfortunate soul was redirected all the way to the “N” gates — the polar opposite, as you may imagine, of the “S” gates.

The solution, as proffered by gate agents and paper signs taped to blank displays alike, was to use the app. But it’s precisely because of problems like this week’s that no one can ever really trust “the app,” because “the app” is as likely to get the hacker treatment as the rest of the Port.

What was extraordinary was that a suspected malicious hacker was able to tank so many systems in one go. We don’t have to expect that the baggage direction, gate guidance, and security handling can’t be completely siloed and separate. This is an airport, not a nuclear power plant.

Yet at the same time it seems wrong that the resilience of the system is so lacking. Sure, the airport intranet might go down — but the full on public-facing website? Baggage routing and gate updates, too? All on the same network? We’ve understood the necessity of breaking apart critical systems for centuries, and have built it into our power and network infrastructure so that when one person runs two hairdryers at the same time, it doesn’t knock out the whole neighborhood.

I’m not complaining because I was inconvenienced. To be honest, this airport trip was no better or worse for me personally than any other. But I saw countless people being put out due to what amounts to badly secured, probably woefully understaffed government IT infrastructure.

When the feds talk about refurbishing critical infrastructure, this is what they’re talking about. Yes, it’s also the ’80s-era computer running on COBOL that controls the traffic lights, dams, or missile silos. But it’s events like this — not so much the recent CrowdStrike outage debacle, actually — that really show the soft, vulnerable underbelly of local and national systems. Critical infrastructure, like airports, have a disturbingly large attack surface that have comparatively few resources dedicated to their upkeep.

It’s not that an airport isn’t as valuable of a target as, say, a financial institution or a data broker, but that’s changing. Ransomware, for instance, has proven highly profitable and easy to automate, and AI (you knew it had to figure somewhere) is supercharging credential theft via spear-phishing operations. All this to say that the trend of unlikely targets — schools, libraries, and hospitals — being held to ransom is only going to intensify — but these attacks can be prevented, just as they can in private industry where they have expected them for decades.

Anyone traveling through Sea-Tac should definitely budget a bit more time to get through the airport and install the relevant apps. State and city authorities are doing their best to keep everyone informed on this crisis page.

More TechCrunch

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! The EV…

Uber cozies up to more AV companies, Canoo loses another founder and Waymo sees potential in teen riders

Ahead of the NFL and college football (NCAAF) seasons, Apple announced new updates for its sports-focused app, including Live Activities for all leagues, a new “dynamic drive tracker” that visualizes…

Apple Sports gets updated ahead of football season with Live Activities, play-by-play and more

One of the people who successfully sued the National Association of Realtors (NAR) to change real estate commissions has co-founded a new real estate startup. It all began in 2017…

After winning a landmark case against real estate agents, this startup aims to replace them with a flat fee

X, the Elon Musk-owned platform formerly known as Twitter, is marking some links to news organization NPR’s website as “unsafe” when users click through to read the latest story about…

X caught blocking links to NPR, claiming the news site may be ‘unsafe’

Apple is likely to unveil its iPhone 16 series of phones and maybe even some Apple Watches at its Glowtime event on September 9.

Apple event 2024: How to watch the iPhone 16 launch

Codeium, a startup developing an AI-powered tool to rival GitHub Copilot, has raised $150 million at a $1.25 billion valuation.

GitHub Copilot competitor Codeium raises $150M at a $1.25B valuation

Seattle’s Airport is still largely offline, causing chaos among travelers and acting as a standing warning against taking cybersecurity lightly.

Flying through Seattle’s hacked airport
Image Credits: Devin Coldewey/TechCrunch

Earlier this month, Google released a new feature with the Pixel 9 series phone to let users add the photographer in the group photo by swapping someone out and taking…

Two Oxford PhDs are building an app to let you remix photos into memes

Meta is now letting preteens with parent-managed accounts explore different experiences in its online virtual reality (VR) platform, Horizon Worlds, with certain restrictions in place. The company announced that parents…

Meta now allows preteens to explore Horizon Worlds with parent’s permission

Intel has found its first — and perhaps only — cloud customer for its Gaudi 3 AI accelerator chips: IBM Cloud.

IBM Cloud to offer Intel’s Gaudi 3 AI chips next year

Google said the findings were an example of how exploits developed by spyware makers can end up in the hands of “dangerous threat actors.”

Russian government hackers found using exploits made by spyware companies NSO and Intellexa

Butterflies AI, the new social network where humans and AIs interact with each other, is launching a new Clones feature that turns you into an AI character. This latest addition…

Social network Butterflies AI adds a feature that turns you into an AI character

Uber is making a strategic investment into Wayve as an extension of the U.K.-born startup’s previously announced $1.05 billion Series C round. The partnership will also see the two companies…

UK’s Wayve secures strategic investment from Uber to further develop self-driving tech

After spending four days in police custody, the founder and CEO of messaging app Telegram, Pavel Durov, was put under formal investigation in France on Thursday for a wide range…

France formally charges Telegram founder, Pavel Durov, over organized crime on messaging app

Reliance Industries, India’s largest company by market capitalization, is not sitting out the AI frenzy that has gripped the tech world.

Reliance skips IPO updates for Jio and Retail in AI dominated event

Durex India has exposed customers’ personal information, including full names, email and postal addresses, and order details.

Durex India spilled customers’ private order data

Apple has added yet more AI features in its latest developer betas for iOS 18.1, and this time we’re getting the ability to remove objects from photos.

Apple’s new iOS developer beta lets you remove objects from pictures using AI

New Enterprise Associates (NEA) is getting back into the secondaries game.  The Silicon Valley-based VC raised more than $468 million for NEA Secondary Opportunity Fund, according to an SEC filing.…

NEA quietly reenters the secondaries market

One-click checkout tech company Bolt is still waiting to find out if shareholders will sign off on a proposed funding round with stipulations that founder Ryan Breslow would return as CEO. In…

One of Bolt’s proposed new backers, The London Fund, has been scrubbing its web page

Whatever size the tranche ends up being it’ll be OpenAI’s biggest outside infusion of capital since January 2023.

OpenAI reportedly in talks to close a new funding round at $100B+ valuation

Reddit’s mobile and web applications went down on Wednesday afternoon, with more than 150,000 users reporting outages on Downdetector as of 1:30 p.m. in San Francisco. When trying to access…

Reddit back online after a software update took it down

For months, a tech forum ran wild asking if the Converge 2 accelerator program actually happened. We finally found out.

OpenAI’s Converge 2 program has been shrouded in mystery

Bluesky on Wednesday introduced the ability to hide replies, as well as a way to detach your original post from someone’s quote post.

Bluesky adds ‘anti-toxicity’ tools and aims to integrate ‘a Community Notes-like’ feature in the future

Featured Article

Fluid Truck’s board ousted its sibling co-founders amid allegations of mismanaging funds

Fluid Truck, a startup that was founded to disrupt the commercial vehicle rental industry, has ousted its sibling co-founders — CEO James Eberhard and chief legal counsel Jenifer Snyder — according to sources familiar with the matter. The shakeup, which employees have described as a hostile takeover, was led by…

Fluid Truck’s board ousted its sibling co-founders amid allegations of mismanaging funds

Meta announced Wednesday that users on Threads will be able to see fediverse replies on other posts besides their own.

Threads deepens its ties to the open social web, aka the ‘fediverse’

Just weeks ago, during an interview with TechCrunch, Thomas Ingenlath laid out his plan to turn Polestar into a self-sustaining company. Now, he’s out.  Polestar said Tuesday Ingenlath has resigned as…

Polestar is getting a new CEO amid EV sales slump

Midjourney, the AI image-generating platform that’s reportedly raking in more than $200 million in revenue without any VC investment, is getting into hardware. The company made the announcement in a…

Midjourney says it’s ‘getting into hardware’

Hiya, folks, welcome to TechCrunch’s regular AI newsletter. If you want this in your inbox every Wednesday, sign up here. Say what you will about generative AI. But it’s commoditizing…

This Week in AI: AI is rapidly being commoditized

OpenSea, which calls itself the “world’s largest” nonfungible token (NFT) marketplace, received a Wells notice from the SEC, the company said in a blog post Wednesday, indicating the regulator may…

SEC takes aim at NFT marketplace OpenSea

Kissner previously served as Twitter’s chief information security officer, and held senior security and privacy positions at Apple, Google, and Lacework.

Ex-Twitter CISO Lea Kissner appointed as LinkedIn security chief