VDP in Aviation How it shouldn't be done!

Matt Gaffney

DEF CON 33 · Day 1 · Main Stage

Overview

Matt Gaffney, known as "gaffers," delivers a candid and critical assessment of Vulnerability Disclosure Programs (VDPs) within the aviation sector, highlighting pervasive failures and offering pragmatic advice for both researchers and disclosure recipients. This talk, born from Gaffney's personal and often frustrating experiences in aviation security research, serves as a stark warning and a call to action for an industry grappling with expanding attack surfaces and slow-moving change. Gaffney underscores that while aviation's safety-critical nature demands rigorous security, the current VDP landscape is frequently dysfunctional, characterized by stonewalling, dismissal of legitimate findings, and a dangerous reliance on security by obscurity.

Watch on YouTube

Visual summary for VDP in Aviation How it shouldn't be done! by Matt Gaffney
Visual summary for VDP in Aviation How it shouldn't be done! by Matt Gaffney

Key moments

  1. 0:00 Introduction to aviation VDP and speaker background
  2. 2:00 First VDP case: EFB vulnerability disclosure challenges
  3. 2:58 Vendor's initial response: 'Not a vulnerability, but a feature.'
  4. 4:30 Years later, EFB vendor stonewalls on vulnerability
  5. 5:00 Successful disclosure of regulatory gap, leading to changes
  6. 7:00 Third party reports their own system vulnerability

VDP in Aviation How it shouldn't be done!

Speakers: Matt Gaffney, Hacker, Aviation Security Researcher

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=oI3zxDWldKE

Overview

Matt Gaffney, known as "gaffers," delivers a candid and critical assessment of Vulnerability Disclosure Programs (VDPs) within the aviation sector, highlighting pervasive failures and offering pragmatic advice for both researchers and disclosure recipients. This talk, born from Gaffney's personal and often frustrating experiences in aviation security research, serves as a stark warning and a call to action for an industry grappling with expanding attack surfaces and slow-moving change. Gaffney underscores that while aviation's safety-critical nature demands rigorous security, the current VDP landscape is frequently dysfunctional, characterized by stonewalling, dismissal of legitimate findings, and a dangerous reliance on security by obscurity.

The talk is not merely a complaint but a constructive critique, providing real-world "good, bad, and ugly" scenarios to illustrate common pitfalls. Gaffney's unique perspective as a veteran, hacker, and aviation enthusiast who was "forced into research" due to industry resistance, lends significant weight to his observations. He emphasizes that effective vulnerability management in aviation is not just about patching code, but about fostering trust, facilitating open communication, and aligning industry practices with the realities of modern cybersecurity threats, all while acknowledging the unique regulatory and operational constraints of aircraft systems.

Background

▶ Watch: Introduction to aviation VDP and speaker background (0:00)

Matt Gaffney's journey into security research within aviation began not by choice, but out of necessity. As he recounts, he was "forced into research" through the VDP process when his expert assessments of vulnerabilities were met with denial and dismissal by vendors. This personal experience of being told "stuff I knew to be right was not right" spurred him to rigorously research and defend his findings, ultimately exposing deep-seated issues in how the aviation industry handles security disclosures.

The aviation sector presents a unique and challenging environment for vulnerability management. Unlike typical software, changes to aircraft systems, even software patches, cannot be implemented overnight. Gaffney vividly describes the pace of change as "trying to sprint through treacle," with progress often measured in "years or even decades." This inherent slowness is compounded by a complex regulatory framework and a culture that, historically, has not been accustomed to rapid cybersecurity response. Prior to his work, Gaffney served in the British Army and worked for the UK foreign and commonwealth office, bringing a disciplined and analytical mindset to his aviation security roles, which began in 2016. His research has spanned critical areas including Electronic Flight Bags (EFBs), Personally Identifiable Information (PI) in aircraft, drones, website vulnerabilities, CVEs for Java, and notably, social engineering. His interest in social engineering stems from observations that organizations often underestimate insider threats, believing "we'll never fall for that"—a belief he proved wrong through practical application.

The industry's unpreparedness for modern VDPs is further evidenced by common, dismissive responses Gaffney and others have encountered. Ken Monroe of Pentest Partners, for example, compiled a "bingo sheet" of frequently heard phrases, including: "We've had no reports of our product being hacked before," "Our normal users would never do that," "It's not a problem," "We use military-grade encryption" (a phrase Gaffney, as a former military member, strongly distrusts), and the infamous "That is intended functionality," or "It's not a vulnerability, but a feature"—the very response Gaffney received early in his career. These responses highlight a systemic issue: a lack of understanding, a culture of denial, and an overreliance on outdated security paradigms, particularly security by obscurity, which Gaffney unequivocally states "doesn't work."

Key Findings

▶ Watch: Vendor's initial response: 'Not a vulnerability, but a feature.' (2:58)

Matt Gaffney's talk unveils several critical findings regarding the state of Vulnerability Disclosure Programs (VDPs) and security posture within the aviation industry:

  1. Systemic Dysfunction in VDPs: The primary finding is that VDPs in aviation are frequently broken, leading to protracted disputes, stonewalling, and a breakdown of trust between researchers and manufacturers/operators. Gaffney's personal experiences, spanning multiple years and incidents, consistently demonstrate an industry ill-equipped to handle external security disclosures effectively.
  2. Initial Dismissal and Resistance are Common: Researchers often face immediate pushback, with legitimate vulnerabilities being dismissed as "features" or "not a problem." This initial denial necessitates extensive research and advocacy from the disclosing party, significantly delaying remediation and increasing frustration.
  3. Communication Failures are Rampant: A pervasive lack of communication from disclosure recipients is a major impediment. Gaffney stresses "communicate, communicate, communicate" as the cornerstone of effective VDP, noting that even an update stating "no update" is better than silence, which leaves researchers feeling ignored.
  4. Legal Involvement Often Harms, Not Helps: Engaging legal teams prematurely or aggressively can intimidate researchers, driving them underground or towards less desirable public disclosure avenues. Legal representation should be a last resort, not a first response.
  5. "Security by Obscurity" is a Dangerous Reliance: Gaffney directly challenges the industry's often-implicit reliance on the idea that if vulnerabilities aren't public, they don't exist or won't be exploited. He explicitly states, "security by obscurity alone... doesn't work," especially as aircraft become increasingly connected "flying data centers" with expanding attack surfaces.
  6. Aviation's Pace of Change Dictates VDP Timelines: The inherent slowness of aviation—where fixes can take "years or even decades" and are measured in "years or even decades"—means the standard 60-day disclosure rule common in other tech sectors is often impractical. This requires a different approach to agreed-upon timelines and expectations for public disclosure.
  7. Insider Threat is a Major Focus: While not a direct VDP finding, Gaffney's mention of social engineering and the industry's focus on insider threat underscores a recognition of vulnerabilities beyond purely technical exploits, suggesting a broader security awareness, even if VDPs remain a challenge.
  8. Vulnerability Disclosure Can Be Misused: Both researchers and recipients can err. Researchers who use disclosure as a "business opportunity" (e.g., bringing sales teams to disclosure calls) undermine trust. Recipients who ignore, belittle, or threaten researchers also damage the process.

These findings collectively paint a picture of an industry in urgent need of VDP maturity, where collaboration, transparency, and a realistic understanding of cybersecurity threats replace historical complacency and resistance.

Technical Deep Dive

▶ Watch: Years later, EFB vendor stonewalls on vulnerability (4:30)

Matt Gaffney's talk delves into several real-world scenarios, illustrating the technical context and the often-fraught VDP processes. While specific exploit details are withheld due to ongoing sensitivities, the narrative provides ample insight into the types of vulnerabilities encountered and the organizational responses.

One of Gaffney's seminal experiences involved Electronic Flight Bags (EFBs) during the entry into service of a new aircraft. His initial task was to create a secure build for these critical devices, which he believed he had locked down effectively. After a five-day penetration test by a third party, the pentesters initially declared the system "good" after just one day. However, further probing revealed a significant problem. While Gaffney doesn't disclose the exact nature of the vulnerability, he highlights its severity by describing the reaction of the airline's chief pilots: their "eyes went wide like saucers" upon understanding the potential safety impacts. This incident underscores that seemingly technical flaws can have profound operational and safety consequences in aviation.

Gaffney's disclosure to the EFB software supplier was met with the infamous retort: "that's not a vulnerability, but a feature." This initiated a grueling nine-month challenging discourse, which necessitated Gaffney's continuous research to counter the vendor's claims. The discussions eventually involved regulators, leading to the vendor "reluctantly agreed[ing] to make some changes." Due to the slow pace of aviation, a several-year action plan was agreed upon. Years later, after changing employers, Gaffney attempted to follow up on the vulnerability's status. His inquiries were met with four months of stonewalling, followed by a flat refusal to discuss, citing "you're no longer our client" and "our code is IP." Gaffney powerfully counters this, stating, "the code is IP, but the vulnerability isn't." He maintains possession of this critical information and offers to share it with legitimate operators in the industry who "need to know this information" under formal contact, ensuring it reaches the right hands without public disclosure.

A more recent incident involved a gap in regulation and its implementation by multiple Original Equipment Manufacturers (OEMs). This discovery, made accidentally during another investigation, was not a single vulnerability but a systemic issue. Gaffney had already conducted two years of research into the relevant regulations, granting him an intimate understanding that allowed him to successfully argue his case despite initial pushback. This led to multiple collaborative work sessions across OEMs and time zones, including on-wing tests, resulting in significant changes to Instructions for Continued Airworthiness (ICAs) and operational procedures across numerous airlines worldwide. This example showcases a more positive outcome, where diligent research and persistent advocacy led to industry-wide improvements, with regulators kept informed throughout the process.

Another case involved a third-party supplier informing Gaffney's company that "you have a sensitive system visible to the internet." This immediately raised alarms within his team, leading to an investigation. However, the overnight investigation revealed the exposed system was not theirs, but the reporting company's own test environment, which they had failed to secure according to their own guidance. This "known goal" situation highlights the importance of due diligence before making accusations and the contractual implications when third parties fail to meet security obligations.

Gaffney also touched upon a disclosure handled by the Aerospace Village at DEF CON. Researchers had followed the responsible disclosure process to completion, but the manufacturer had simply accepted the risk without remediation, failing to negotiate public disclosure timelines or communication plans. The talk was nearly blocked at Defcon until the researchers provided "all the receipts," demonstrating their adherence to the VDP. This incident underscores that even when researchers follow protocol, manufacturers can undermine the process by dismissing findings or failing to engage responsibly.

Finally, Gaffney recounted an authentication bypass vulnerability discovered on a publicly facing aerospace website seven years prior. The researcher's repeated attempts to contact the company were met with silence, compounded by the absence of an official VDP. After exhausting all formal avenues, the researcher resorted to social media, which finally provoked a reaction. While the vulnerability was eventually fixed, the bridges between the researcher and the company remained "broken," illustrating the long-term damage caused by poor VDP handling.

The increasing connectivity of aircraft, turning them into "flying data centers" generating "gigabytes of data every single flight," is a recurring theme. This expanding attack surface means that vulnerabilities, whether specific to avionics (like the TCAS CD vulnerability mentioned) or more general CVEs impacting ground systems and tooling, will continue to emerge. Gaffney's experiences underscore that the technical challenges are compounded by organizational and cultural resistance, making effective VDPs crucial for the future security of aviation.

Demo / Proof of Concept

▶ Watch: Successful disclosure of regulatory gap, leading to changes (5:00)

While Matt Gaffney's talk did not feature a live demonstration or explicit proof-of-concept for a new vulnerability, it extensively detailed real-world scenarios and past incidents where vulnerabilities were identified and disclosed. His presentation focused on the process of vulnerability disclosure in aviation, rather than showcasing specific technical exploits. The "demos" in this context were the recounted experiences of disclosures, the pushback received, and the eventual, often arduous, paths to resolution or non-resolution. For example, his description of the EFB vulnerability and the pilots' reaction ("eyes went wide like saucers") served as an anecdotal "proof of concept" for the impact of the flaw, even without a technical demonstration. Similarly, the Aerospace Village incident highlighted how researchers had "dropped all the receipts" to prove their due diligence, effectively demonstrating their adherence to responsible disclosure protocols.

Defensive Implications

▶ Watch: Third party reports their own system vulnerability (7:00)

Matt Gaffney's talk provides a comprehensive roadmap for improving vulnerability disclosure in aviation, offering actionable advice for both the recipients of disclosures (aerospace companies, OEMs, airlines) and the researchers who submit them.

For Aerospace Companies and Disclosure Recipients:

  1. Establish and Actively Monitor a Robust VDP: This is paramount. A VDP must be more than just a static webpage; it needs clear channels like security.txt files on websites and a dedicated, actively monitored [email protected] email address. The program should be designed to receive, acknowledge, and process submissions efficiently.
  2. Engage with Researchers: Ignoring submissions or stonewalling is counterproductive. Companies must engage responsibly and professionally, recognizing that researchers are often trying to help improve security.
  3. Prioritize Communication: Gaffney stresses "communicate, communicate, communicate." Even if there's no significant update, informing the researcher of the status prevents frustration and builds trust. Silence is interpreted as dismissal.
  4. Strategic Use of Legal Counsel: Legal representation should be used "only when necessary." Early or aggressive legal involvement can intimidate security researchers, driving them to hide or disclose vulnerabilities through less desirable, public channels.
  5. Agree on Disclosure Timelines and Plans: Companies should work collaboratively with researchers to agree on timelines for public disclosure, message details, and remediation plans. Once agreed, adherence to this plan is crucial. The aviation industry's slow pace means the standard 60-day disclosure rule often won't apply, requiring longer, mutually agreed-upon timelines.
  6. Avoid Counterproductive Behaviors: Do not ignore the problem, belittle the concerns in a submission, make threats, or attempt to damage a researcher's reputation. These actions erode trust and harm long-term security.
  7. Thoughtful Use of NDAs: While sometimes necessary for sharing sensitive information to aid a researcher's understanding, NDAs should not be forced or used to simply silence researchers. Understanding the researcher's motivation (e.g., public recognition vs. genuine desire to learn/improve the industry) can guide this decision.
  8. Abandon Security by Obscurity: This is a critical defensive shift. In an increasingly connected aviation ecosystem, relying on the idea that vulnerabilities won't be found if they're not publicly disclosed is a dangerous fallacy. Proactive security measures and transparent VDPs are essential.

For Security Researchers and Submitters:

  1. Check for and Follow VDPs: Always make every effort to go through formal channels first. If a company has a VDP, researchers should adhere to its guidelines.
  2. Engage Responsibly: Stick to facts, leave emotion out of communications, and understand the unique constraints of the aviation industry.
  3. Leverage Industry Resources: The Aviation ISAC is highlighted as an excellent resource for connecting researchers with the right people within companies, or at least with adjacent contacts who can facilitate disclosure.
  4. Communicate All Details: Provide comprehensive and factual information about the vulnerability, its potential impact, and proposed mitigations.
  5. Manage Expectations on Timelines: Understand that fixes in aviation can take "years," not weeks or months. The standard 60-day disclosure rule may not apply, and researchers might need to enter into agreements for extended non-disclosure.
  6. Accept Information Limitations: Researchers should not get upset if mitigation details cannot be fully shared due to proprietary information or ongoing security concerns.
  7. Uphold Agreements and Laws: Do not breach NDAs, ignore laws, or disregard agreed-upon requests. Professionalism is key to building credibility.
  8. Avoid Commercializing Disclosure: Do not use vulnerability disclosure as a business opportunity by bringing sales or marketing teams into the conversation. This undermines the intent of disclosure and erodes trust.

By adhering to these principles, both sides can move towards a more mature, collaborative, and ultimately more secure aviation environment, mitigating risks effectively in an industry where the stakes are exceptionally high.

Key Takeaways

  • Aviation VDPs are Critically Underdeveloped: The industry frequently exhibits systemic failures in vulnerability disclosure, characterized by denial, stonewalling, and a lack of formal processes, leading to unaddressed risks and eroded trust.
  • Communication is Paramount: Effective and consistent communication, even when there are no significant updates, is the single most important factor for successful vulnerability disclosure, preventing frustration and fostering collaboration between researchers and industry.
  • "Security by Obscurity" is a Dangerous Fallacy: Relying on the non-disclosure of vulnerabilities as a primary security strategy is ineffective and dangerous in a world where aircraft are increasingly connected "flying data centers" with ever-expanding attack surfaces.
  • Aviation's Unique Context Demands Adapted VDPs: Due to the inherently slow pace of change, regulatory hurdles, and safety-critical nature of aircraft systems, standard disclosure timelines (e.g., 60 days) are often unrealistic. VDPs in aviation require longer, mutually agreed-upon timelines and a more patient approach.
  • Both Researchers and Recipients Share Responsibility: Successful disclosure hinges on responsible engagement from researchers (following VDPs, sticking to facts, avoiding commercialization) and transparent, non-hostile engagement from industry (establishing VDPs, communicating, avoiding legal threats).
  • Leverage Industry Resources for Better Outcomes: Organizations like the Aviation ISAC can play a crucial role in bridging the gap between researchers and manufacturers, facilitating disclosures and helping to navigate the complex aviation security landscape.

About the Speaker(s)

Matt Gaffney, known in the security community as "gaffers," is a distinguished figure in aviation cybersecurity. He describes himself as a hacker, veteran, and aviation nerd. His career began with service in the British Army for a significant period, followed by work for the UK foreign and commonwealth office and various French companies. Since 2016, Gaffney has dedicated his expertise to the aviation sector.

His journey into security research was not by design but by necessity, as he was "forced into research" through the VDP process when his valid security findings were initially dismissed by industry players. This experience ignited his passion for rigorously investigating and advocating for cybersecurity improvements. His research portfolio is extensive, covering critical areas such as Electronic Flight Bags (EFBs), Personally Identifiable Information (PI) in aircraft, drones, website vulnerabilities, CVEs for Java, and his "personal favorite," social engineering, which he learned to demonstrate the reality of insider threats to skeptical organizations. Beyond his professional roles, Gaffney is also a dedicated volunteer at the Aerospace Village, further contributing to the security community. He explicitly stated during his talk that he was speaking purely as "gaffers" and not on behalf of any employer, past or present, underscoring his independent and candid perspective.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Gaffney brings genuine domain credibility and real war stories to a topic the aviation security community actually needs to hear — VDP dysfunction in a safety-critical, glacially-paced industry. The talk is honest, practitioner-grounded, and delivers actionable guidance for both sides of a disclosure. It won't teach a technical researcher anything new about exploitation, but that's not what it's trying to do.

Heather Calloway (CISO) — SOLID

Gaffney delivers a credible, experience-grounded critique of VDP dysfunction in aviation — the problems are real, the sector-specific context is useful, and the dual-audience framing (researchers and recipients) is practical. But the talk stays at the level of process complaint and etiquette guidance rather than reaching the governance and accountability failures that actually explain why aviation VDPs are broken.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33