Upgrade your security strategy for the AI era.

Cybersecurity 101: On-Board WiFi Whoops
A customer recently asked “What happened with the WiFi on that recent Delta air flight, and should I be worried about it?” The answer is “we don’t know for sure, but it was likely to be mostly harmless.” Let’s dive into the topic:
On a Delta air flight from Las Vegas recently, the flight made the news because of issues with the on-board WiFi system. While the news made it out to be a dire emergency, the likelihood is that there wasn’t all that much going on. While - at the time of this writing - the investigation is still ongoing, there are more likely situations that could easily explain what happened.
What we know:
According to statements from both Delta and the Federal Aviation Administration (FAA), a second WiFi network identifier (known as a SSID) became available for users in the passenger cabin of the plane. This SSID, labeled “Delta WiFi Fast,” was not an official WiFi hotspot, and was not managed by the flight crew or by the airline. The flight crew quickly disabled all WiFi to the passenger cabin and alerted the passengers not to connect to the new SSID, and the flight continued towards its destination. The FAA continues to investigate the situation, but no final determination has been reached on any other facts of the incident.
The story made the news because this flight was leaving Las Vegas at the end of one one of the largest hacker conferences, DEFCON; meaning that many persons with the knowledge and equipment to perform a WiFi takeover were likely to be on board the flight.
Now, we should definitely point out what did NOT happen on this flight. There is no evidence or reports that the on-board WiFi was “hijacked” or taken over. Both the real WiFi SSID and the second, fake, SSID were available until the crew took the real one offline entirely. Additionally, the plane and its systems were never in any danger. Flight deck WiFi and all of the instruments and systems necessary to keep the plane safely in the air use completely different connections - separate WiFi SSID’s that are pre-set, and radio connectivity that doesn’t rely on WiFi at all. The plane and the passengers were not in any danger.
What might have happened: Scenario 1
The more likely scenario is that someone on the plane turned on a WiFi travel router and named its SSID “Delta WiFi Fast.” Travel routers are fairly common tools used by technology professionals when we travel. They allow one WiFi connection to be shared by multiple devices, which is very handy when a hotel or other location charges for access to WiFi by device. The travel router connects to the official WiFi hotspot, and then broadcasts its own SSID that the user’s devices connect to, bridging the connection and sharing the WiFi bandwidth.
Doing this on an aircraft is not recommended, as it can be confusing to passengers and crew, but security is still maintained and private information (when using HTTPS websites and secure apps) is still private. While the user of the travel router may be able to figure out what websites you visit, they can’t figure out what pages you visited or what data you shared back and forth with those websites.
It’s possible that someone from DEFCON renamed their travel router to “Delta WiFi Fast” as some form of joke, or just to see who would connect to it instead of the official hotspot.
What might have happened: Scenario 2
It is possible - though less probable due to info we’ll discuss below - that a specific type of portable router could have been powered up to snoop on other passengers. Commonly referred to as a “WiFi Pineapple” because of the most popular brand-name of such devices, these devices can dig much deeper into the data flowing across them from the unofficial hotspot to the real hotspot. With the proper configuration and planning, a pineapple can decode SSL traffic (HTTPS) and even keep a record of all transmissions and data that flows across it. This isn’t easy to do, and if done improperly will present several tell-tale signs that it is going on.
Why scenario 1 is more likely
The main reason why scenario 1 is more likely in this case is the lack of any mention of browser or application errors by passengers on the flight. If a pineapple were in use, the security certificates which encrypt and protect web and application traffic between you and websites and services would have recognized that things were not correct. The technique - SSL decryption - is common in corporate networks, but requires a tremendous amount of planning, configuration, and ongoing maintainance. Setting SSL decryption up properly at 35,000 feet is no small task, and will almost always fail and create very visible warning messages in any modern browser on either a mobile device or laptop. Mobile apps would also show error messages as the security chain they are expecting to be validated cannot be validated properly. Given the number of social media and Reddit posts about the incident, and the total lack of messages talking about browser or app errors, scenario 1 is significantly more likely to be what actually happened.
So, is airplane WiFi safe?
Overall, the answer is yes. Provided you are connected to the official WiFi hotspot (which you can find in the seat-back pamphlet) and you don’t ignore warnings or errors in browsers or apps, then your communications are protected. Even if you relay through a travel router, the owner can see your DNS calls (basically the online address of the websites you go to) but nothing else. Stick to sites that use HTTPS and apps that use basic security, and you will be browsing safely the whole trip. If your company requires the use of a VPN or other security tools, make sure they’re online and working even when you are in flight. In other words, follow basic online safety protocols and even if there’s a travel router tricking you into connecting to it, what you send back and forth is still unusable by the threat actor running the router.
About the Author:
Michael DeNapoli is a seasoned Senior Solutions Architect with more than 25 years of experience in cybersecurity, solution architecture, and enterprise systems design. Throughout his career, he has led technical strategy, security architecture, and advanced solution development for organizations ranging from emerging security vendors to global enterprises. Michael’s expertise spans cybersecurity operations, cloud architecture, technical sales leadership, security posture management, and identity protection, with a proven track record of guiding clients through complex technology challenges. Today, he brings his deep industry knowledge to Pondurance as a Senior Solutions Architect, helping organizations strengthen their security foundations with clarity and confidence.


.png)


