17 ms·
Insurgents Hack U.S. Drones
- Shamiq 17y agoInstead of hack, it should read "Insurgents intercept U.S. Drone video feeds"
- rms 17y agoThat's more clear, perhaps, but this is certainly a hack
- Devilboy 17y ago'Fixing the security gap would have caused delays' '... it would have added to the Predator's price' If you're paying $20 million each you'd think another million to ensure your targets don't see you coming would be a no-brainer?
- jpwagner 17y agoWhile I obviously think they need to close the security gaps, I just want to make a comment on your comment: it's that kind of thinking that keeps our taxes increasing and our economy in shambles. I'm with @tsally on the solution to this kind of problem...
- pyre 17y ago@tsally is advocating having 'real' hackers hack on the thing to find vulnerabilities. In this case though, the vulnerability was known but it would have cost more money to actually fix it. Having people attack the thing for vulnerabilities still wouldn't change the fact that you would need to pay however much money to do the fixing.
- jpwagner 17y agopff, you didn't address what I said... "it's only another $1MM"
- pyre 17y agoI was addressing the last thing that you said.
- jpwagner 17y agoquit these goading, troll tactics please there is no contradiction: yes "real" hackers, yes spend money, no don't say "just another million" sheesh
- pyre 17y agoWhere did I say 'just another million?' From where I stand, you seem to be opposed to spending more money on something to make it work, and I'm arguing that by agreeing with having hackers hack on the device doesn't fix it on it's own. It still costs money. Whether it's "just another million" or "just another $100,000" is irrelevant. The thing won't fix itself for free and at $20 million a pop it's a waste of money if the thing is broken. Note: I'm not goading, trolling or whatever it is you think I'm doing. This thread is a conversation, and I'm responding to what you said.
- jpwagner 17y ago...and I'm responding to what you said No, you're not, you're actually ignoring my words. Please stop. Note: You have made one lifetime submission and it was flagged and marked 'dead.' I will not call you a troll, but please stop.
- deleted 17y ago[deleted]
- anigbrowl 17y agoYou think operators won't notice and switch to something else? That strategy never works.
- tsally 17y agoI have a thought. How about next time the military just flies one of these things down to Defcon and lets people have a go. The hackers get a cool toy to play with a for a day and the military gets a free fairly sophisticated penetration test. I'm sure the flaw would have been found; instructions on how to intercept satellite data with about $100 worth of hardware have been floating around for years. I'll edit this post in a minute with details for anyone that's interested. EDIT: * One possible LNB: http://bit.ly/7AGe7e http://bit.ly/7AGe7e * Possible dishes: http://bit.ly/4NfMN1 http://bit.ly/4NfMN1 * One possible receiver (for digital, you'll need a different one for analog): http://bit.ly/4zHyND http://bit.ly/4zHyND * Useful forum: http://www.satelliteguys.us/free-air-fta-discussion/ http://www.satelliteguys.us/free-air-fta-discussion/ That setup is enough to pick up signals from satellites (locations: http://www.google.com/#hl=en&q=satellite+index http://www.google.com/#hl=en&q=satellite+index). If you do this as a hobby you might want to spend the money on a motor to tilt/pan your dish for you. ;-) The article implies that such a setup is pretty much what the insurgents used to intercept video from the drones. The drone bounces its video up to a satellite and the satellite bounces back down to the operator. The insurgents just grab it when it's coming down to the operator from the satellite. I'm pretty sure (or at least I hope) the receiver would have to be modified to decompress/decrypt the drone data properly. It'll do just fine if you're scanning for legit TV signals.
- potatolicious 17y agoThe question is, what do our defence contractors care more about: making their weapons actually work? Or merely selling them?
- vaksel 17y agoi'm sure lack of reliability is part of their business plan. You make the perfect humvee, and suddenly the army stops buying as many. There is a reason the AK47 is so much more reliable than the M16. And it's been out for like 60 years now.
- likpok 17y agoThe AK is more reliable because it is less accurate. The tolerances on the various mechanical parts are higher, but as a result they are looser.
- slackerIII 17y agoSounds like a great opportunity to feed some false information to the insurgents.
- Kliment 17y ago"said people familiar with the matter" WSJ is really going down in journalistic quality, it seems. But seriously, problem known for a decade, "they're dumber than us so they can't use it" attitudes, in a device at that price point, you'd expect they'd think about these things. Reminds me of the Boeing report on Columbia. ( http://www.edwardtufte.com/bboard/q-and-a-fetch-msg?msg_id=0001yB&topic_id=1 http://www.edwardtufte.com/bboard/q-and-a-fetch-msg?msg_id=0... )
- jjs 17y ago"People familiar with the matter" has been WSJ's phrase for an unnamed source for years.
- profgubler 17y agoThis is a grave oversight, but often it isn't the military that needs convincing of the intelligence of the enemy it is the politicians. These politicians and often news pundits have often said things such as why are we spending so much money on this war when we are fighting people who use sticks and stones. So it is a catch 22 when you have to cater to the politicians you are often enabling your enemy. Not that I think we shouldn't have government or politicians and internal opposition, it is just that I wish politicians would do less grand standing and more actual thinking.
- tlrobinson 17y agoIt's amusing that they consider the lack of encryption a mere "flaw". Seems like a huge oversight to me.
- jsm386 17y agoThe potential drone vulnerability lies in an unencrypted downlink between the unmanned craft and ground control. The U.S. government has known about the flaw since the U.S. campaign in Bosnia in the 1990s, current and former officials said. But the Pentagon assumed local adversaries wouldn't know how to exploit it, the officials said.
- dotBen 17y agoThis is actually a deeper problem - we (the US/UK/Western world) assumes the middle east doesn't have the same level of technical competency as us. Iran is a pretty well educated country, and while Iraq and Afghanistan doesn't have the same level of education in the tech/science areas, there are many sympathizers who are well educated -- including educated in UK, US, etc. There's actually a lot of comparisons to be drawn here with startup culture vs big business. Once again the smaller, less resourced are able to bring down the big players by being more nimble and not feeling the need to build everything "in house". To the "in house" point - the US probably spent high $100ks of mine and other tax payers money building viewing software for these drones vs the insurgents who use $25 Russian shareware. Now, I'm not saying that the government should be running SkyCatcher to view streams - but I bet they didn't include opensource options into their video viewer solution that would have saved $$$ in upfront and ongoing maintenance costs.
- jmatt 17y agoWow, It's amazing they couldn't fix this over the last decade. Even a simple obfuscation, anything is better than raw data that is so easily viewable and worse verifiable. I would assume there is plenty of people with experience encrypting and decrypting radio / satellite signals for the military in the US. Maybe the problem lies in it not being a software problem, but rather some horrid design that relegates it to hardware. Either way now that this is public knowledge it needs to be fixed appropriately.
- deleted 17y ago[deleted]
- naveensundar 17y agoThe potential drone vulnerability lies in an unencrypted downlink between the unmanned craft and ground control. What about the uplink?
- Retric 17y agoI assume that's encrypted for obvious reasons. However, encrypting live video feeds requires a lot more prepossessing power than encrypting telemetry so they apparently left it out. Honestly, from a classic military standpoint encrypted video does little for you. If you can intercept the transmission then you know where the drone is. The only advantage is knowing what it is looking at, but a traditional army is large enough knowing something is in the area is enough. It's only gorilla style fighting when it becomes particularly useful.
- stcredzero 17y agoGuerrilla, BTW. The thing is, these drones' primary use is against insurgents, AFAIK.
- dflock 17y agoIt is now, but I don't think this was intended to their primary mission profile when they were designed, over a decade ago. A lot of the intended uses were more traditional than the ones that reality has presented.
- jac_no_k 17y agoAnybody remember the movie Body of Lies? Would be interesting to feed the insurgents a different video feed from what is actually be used.
- waterlesscloud 17y agoIt's possible, though unlikely, that the entire report is deliberate misinformation.
- ars 17y agoI hope instead of shutting it down, the military feeds them false information. If done right, it could make a good trap.
- deleted 17y ago[deleted]
- johnyzee 17y agoI hope, instead of merely listening in, the insurgents start to jam and crash the drones. Sorry, but a different view needs to be represented. To a lot of people the foreign occupation of Iraq is a grave injustice, not just some big game.
- astine 17y agoWhile I want the US to pull out of Iraq as much as anybody, I think that you have to dead in the skull to root for the insurgents. Most of the problems in Iraq right now are primarily due to religious extremists terrorizing the locals and fighting with Americans to push their agendas. No matter how bad Iraq is now, it will be worse off if these people take over.
- cousin_it 17y agoNo matter how bad Iraq is now, it will be worse off if these people take over. So? The concept of American responsibility for the well-being of foreign citizens is the root of this whole war problem. Let my people go!
- noonespecial 17y agoPart of the problem is that the military awards contracts that are sometimes decades long. What was "good enough" security in 1990 is not looking so hot 20 years on. The US military machine may not perform as well as it has in the past in the new era of betas, hotfixes and patches. I will not be at all surprised when insurgent "rc-plane" drones start showing up with cell phones, arduinos, grenades and duct-tape.
- ThinkWriteMute 17y agoIt's dreadfully easy to shop build a rocket, especially in America where places like Radioshack exist.
- ErrantX 17y agohttp://diydrones.com/ http://diydrones.com/ :)
- alecco 17y agoThe gas jet propelled ones have max speed of 200mph, while predators have 135mph. Can't wait for some sort of anti-predator with EMP gun or something making the 5M investment look stupid :) [With some kick ass AI doing the find-kill, soldiers shouting "f* NPCs"] [Note: I know emp guns weight ~50kg]
- nettdata 17y agoWhy bother with anything like an EMP? At the cost of the DIY, it's disposable... just fly right into the thing and physically knock it out of the sky. BattleBots in Space. That's a pirated video I'd watch.
- _ck_ 17y agoIf there is prosecution for bad designers, the people who used off-the-shelf unencrypted solutions for a military device in the 21st century should be put in prison. They just cost taxpayers much more money if not actual lives on the ground. This is the equal of having an open directory on a website and saying it doesn't matter because no-one will know what the domain or ip is. Security-by-obscurity is asinine, someone can always figure out what you've done. This also strikes me as a great way to insist on more budget money when you've been told you won't get any more money - throw some fear, uncertainty and doubt at it.
- ashwinl 17y agoAs @noonespecial alludes to, some of the comments on the WSJ site and (less so) here are made incognizant of the complexities of the systems and timelines of procurement, testing and deployment. @tsally the DEF CON suggestion is a good point. Because of ITAR, it is unlikely that the actual "toy" will be provided, but a comparable subsystem wouldn't be out of the question. E.g. The DoD regularly operates rapid reaction challenges with a simulated problem from theater - see http://www.kirtland.af.mil/news/story.asp?id=123120737 http://www.kirtland.af.mil/news/story.asp?id=123120737 Something similar could be done with DEF CON. I think it is important to maintain perspective when stories like this come out. Contrary to some of the comments, defense contractors and researchers/engineers at gov't R&D labs do put the priorities of the warfighter first. Consider that many of the engineers/contractors/researchers/etc working on technology development are combat veterans themselves. The issue is that we face adaptive adversaries.
- ruslan 17y agoWonder how soon they find a way to spoof drone video streams with some open sourced software, probably VLC ;-)
- conanite 17y agothe U.S. military found pirated drone video feeds on other militant laptops What is the meaning of "pirated" here? Are they going to sue militants for copyright infringement?
- ShardPhoenix 17y agoPerhaps they're using it in a sense similar to "pirate radio".
- joshfinnie 17y agoIsn't "pirate radio" a radio station that broadcasts illegally? If I am listening to my local pirate radio station, I myself am not a pirate. I think the use of pirate here is just to sensationalize the situation.
- vtrac 17y agoThey're labeling them "pirates" so that the MPAA and the RIAA will get on the case. Those guys are relentless.
- mjgoins 17y agoNew definitions of words creep into usage all the time, and this is one I've been noticing. Folks are using "pirate" to mean "intercept" or "surreptitiously copy", rather than the traditional usage (leaving aside the even older meaning, of course) of simply "distribute copyrighted material".
- deleted 17y ago[deleted]
- e40 17y agoHave we already forgotten of "pirated cable (video)"?
- gaius 17y agoThe drone recorded footage of the insurgents drinking grog and cursing landlubbers.
- scotty79 17y agoWar machine sending data through unprotected channel? In XXI century? After two world wars and a cold war? How?
- deleted 17y ago[deleted]
- deleted 17y ago[deleted]
- marltod 17y agoThe problem is that the people in charge of deciding what to approve/buy for the Military are not qualified. They get the position of authority by being successful in the military not by proving they understand the technology of the things they are buying. I can see how this happened. Say the military guy had two choices of what to buy for video feed products. Product 1. Fully encrypted video 15 frames per second and a 5 second delay. Product 2. No encryption video at 30 fps and 1 second delay. At the demo he says "product 2 is much better lets get that". When product 2 is questioned about security they say something like "we have proprietary codecs". From the miliary guy's point a view a codec is just as good as encryption.
- andr 17y agoThat poses an interesting technical question - how do you achieve military-grade encryption over a communications line with heavy packet loss (assuming the drone->satellite connection is like that)? Most self-synchronizing ciphers would have too much of a lag for real time operation. Perhaps two synchronized pseudo-random number generators, driven by synchronized clocks, could be used for variable key generation for a symmetric cipher.
- mbreese 17y agoI am assuming that there already exists an encrypted communications channel between the ground and the UAV (command and control). So, it would be trivial to include a command to switch encryption keys at specific intervals.
- motters 17y agoHaving an unencrypted video broadcast on a military drone is just a dumb idea by whoever manufactured it. Encryption would seem to be the most minimal requirement for such an application.
- KWD 17y agoI agree. My first thought when reading the article was "WTF? No encryption?". Would be interested in learning more about the company that makes these, and how something so obvious was not done.
- jedc 17y agoIf they were first deployed in the 1990's, the technology was developed in the 1980's. Easily deployable software to grab the signals out of the air was probably outside the realm of what seemed possible then. Why it hasn't been fixed since is shocking!
- stcredzero 17y agoReminds me of Brian Singer's documentary "Spin," which is no longer available on YouTube. It was made of raw Satellite feed going down to local news stations.
- sunny_s 17y agosome of it is here http://www.brasschecktv.com/page/43.html http://www.brasschecktv.com/page/43.html
- vidarh 17y agoConsumer satellite TV was around from the early 80's, and the struggle to scramble the signal in ways that people wouldn't get around to get free TV started promptly... They really had no excuse - while they might not expect some random guy with a little dish and a laptop, they should have been expecting hostile governments from easily having the capability.
- 17y ago
- TallGuyShort 17y agoThey say there's "no evidence" that they were able to take control of the plane's in flight. Since nobody bothered to encrypt the video feed, and they're saying there's "no evidence", it sounds to me like they also didn't bother to encrypt the control signals. Nice...
- richardw 17y agoIs there any chance the problem is technical? Encryption increasing latency (at least for the pilot's view), anything like that?
- eli 17y ago"The military [is] trying to solve the problems by better encrypting the drones' feeds." Where by "better encrypting" they mean "using any encryption at all"
- stcredzero 17y agoPredator drones are built by General Atomics Aeronautical Systems Inc. of San Diego. Some of its communications technology is proprietary, so widely used encryption systems aren't readily compatible, said people familiar with the matter. If some Russian software could intercept it, it wasn't that proprietary!
- johnwatson11218 17y agoIs anyone talking about the potential to not just grab video but to send control signals? What if the enemy could actually take control of one of these drones? Is that channel encrypted? How about sending back false video to not allow the true operators to know what is really going on or to generate false positives.
- gaius 17y agoIf an enemy could take control of a Reaper he wouldn't... Until it was returning to base at the end of its mission, at which point he'd fire its Hellfire missiles right into the control building. Then the dominoes would fall like a house of cards. Checkmate!
- rapind 17y agoDo you think obsfucation and spam could solve this problem? Could they setup cheap broadcasters all over the place that constantly send out fake videos and develeop a sophisticated filter they can use themselves that the insurgents wouldn't have access to? Then they wouldn't have to rework the drones themselves, and they could constantly rework the spam and the filter to stay ahead of them.
- rbanffy 17y agoGood thinking. There are a lot of simple, inexpensive measures that could be used to neutralize their advantages. OTOH, if you know where are the satellites drones use and the frequencies they employ, it would be trivial to just set up a very directional antenna coupled to a high-power noise generator to render the drone's controllers more or less blind and the drones useless. At least until they evolve into autonomous drones.
- lallysingh 17y agoNote that "skygrabber" is the #5 search phrase on google right now. http://www.google.com/trends/hottrends?sa=X&oi=prbx_hot_trends&ct=title&q=skygrabber http://www.google.com/trends/hottrends?sa=X&oi=prbx_hot_...
- joe_the_user 17y agoWhether this particular mistake was avoidable or not, the event raises bigger issues. The military is building more and more lethal, radio-controlled robots. No networked device can be guaranteed to be secure. Computers have been hacked since they existed. The hacking of satellites is endemic. A civilian hacker was supposedly holding a military satellite hostage a while back. Thus this strategy makes it likely that hackers will get the ability to command a lethal device sooner or later. The risks of this might be worth the rewards in terms of avoiding casualties, projecting power, etc. But there hasn't been much public discussion of the choices that are involved here. There should be.