DEF CON 33 - VDP in Aviation   How it shouldn't be done!  - Matt Gaffney

DEF CON 33 - VDP in Aviation How it shouldn't be done! - Matt Gaffney

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 21:29

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Matt Gaffne's presentation reveals the challenging landscape of vulnerability disclosure in aviation, sharing real-world examples and practical guidance for improving collaboration between security researchers and aviation companies.

Key Takeaways:

  • Vulnerability disclosure in aviation moves at a glacial pace, with fixes taking years rather than days due to stringent safety requirements and regulatory constraints
  • Aviation companies often dismiss valid vulnerabilities (like Gaffne's EFB vulnerability initially called a "feature"), requiring extensive proof and regulatory involvement before addressing issues
  • Effective vulnerability disclosure programs need to be more than just web pages—they must be actively monitored with clear communication channels
  • Both researchers and companies should prioritize constant communication throughout the disclosure process
  • Companies should avoid belittling researchers' concerns, forcing NDAs unnecessarily, or using disclosures as business opportunities
  • Researchers should understand aviation's unique timeline constraints, be willing to enter restrictive agreements when necessary, and follow formal channels before escalating

The aviation industry must shift from relying on security by obscurity to establishing transparent vulnerability disclosure processes that recognize researchers as partners in enhancing safety rather than threats to be managed.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Uh so I have to apologize the projector is not working. So I do have slides which will be recorded into the talk but unfortunately you can't see them. Um so um this is a talk about vulnerability and aviation um vulnerability disclosure um and basically give you some examples of how it should not be done and then some advice on how to do it better. So I'm going to give some real world examples what I call the good, bad and the ugly. some dos and don'ts for both researchers and recipients of disclosures. So, I'm Matt Gaffne, also known as gaffers, u hacker, veteran, aviation nerd. I used to be in the British Army uh for for quite a long time. I've also worked for the UK foreign and comworth office and various French companies. I spent quite a bit of time in France, but I've been working in a…