9 ms·
Somebody used spoofed ADSB signals to raster the meme of JD Vance
https://archive.ph/VrEtg https://archive.ph/VrEtg
https://globe.adsbexchange.com/?icao=adfdf9&lat=26.678&lon=-80.030&zoom=14.4&showTrace=2026-01-28 https://globe.adsbexchange.com/?icao=adfdf9&lat=26.678&lon=-...
- sammy2255 8mo agoThis has gotta be some sort of federal crime
- Scoundreller 8mo agoDoubt it did anything in RF, only sent packets to adsbexchange’s web service that its volunteers feed it. Also Adsbexchange has had some… history: https://www.reddit.com/r/ADSB/comments/10l2euc/adsb_exchange_the_largest_unfiltered_network_has/ https://www.reddit.com/r/ADSB/comments/10l2euc/adsb_exchange... https://hackaday.com/2023/01/26/ads-b-exchange-sells-up-contributors-unhappy/ https://hackaday.com/2023/01/26/ads-b-exchange-sells-up-cont...
- HNisCIS 8mo agoADSB sites aren't any sort of official thing. You can send whatever data you want to them. Just because it's there doesn't mean it ever went over the air as an ADSB broadcast.
- TimorousBestie 8mo agoAn interesting question. Assuming the FAA has the authority to enforce ADSB requirements (an open question post-Chevron), I can’t find any regulation saying non-aircrafts cannot transmit ADSB. Only ones saying aircrafts in certain categories must. There’s probably some non-interference requirement somewhere (FCC spectrum licensing perhaps), but I’m not seeing it immediately. All this is in the hypothetical that RF was transmitted, which as others point out it probably wasn’t.
- 15155 8mo ago(Assuming this were actually RF) This is easily-prosecutable willful interference or possibly aircraft sabotage: ADS-B operates in licensed bands and uses an already highly-contended modulation scheme and transmission protocol.
- deleted 8mo ago[deleted]
- tjohns 8mo agoIt would be under the FCC regs, not the FAA regs. Whatever transmitter you're using would not be type-accepted for operation on the 1080 MHz or 978 MHz band. (47 USC § 301) Additionally, RF operation with the intent of willful interference is inherently illegal. (47 USC § 333)
- TimorousBestie 8mo agoExcellent, thanks.
- fc417fc802 8mo agoWhat if you removed a genuine ADS-B unit from a plane and installed it in your vehicle? Also does impersonation necessarily qualify as interference? Naively, I'd expect interference to refer to jamming.
- pear01 8mo agoI believe this was "spoofed" only in the sense that a particular provider/online platform accepted data via an API that was abused to draw this on that platform only. Searching around it seems it was not found if you looked on other platforms, so it might not even have been a crime. I believe they didn't emit any real "signals" just took advantage of an API that should probably be better secured.
- observationist 8mo agoAt worst it'd be a violation of the site ToS - it's a crowdsourced community data based system, and not any sort of an official, important system. The account doesn't seem to have been banned, so maybe the admins are just rolling with the joke.
- deleted 8mo ago[deleted]
- fc417fc802 8mo ago> an API that should probably be better secured. I think the API is secured? The entire premise is that a volunteer creates an account and uploads ADS-B telemetry. Detecting falsified data is a separate matter.
- darthwalsh 8mo agoSounds like authentication is working great, but their authorization design may be flawed.
- filleduchaos 8mo agoHow is it flawed? That is the nature of crowdsourcing.
- advisedwang 8mo agoIt's almost certainly a violation of the Computer Fraud and Abuse Act because it's an extremely broad law.
- sophacles 8mo agoTBF so is your reply and mine.
- eleventyseven 8mo agoViolating terms and conditions is not a CFAA violation, per the Supreme Court case Van Buren v US (https://www.politico.com/news/2021/06/03/supreme-court-cybercrime-law-491764 https://www.politico.com/news/2021/06/03/supreme-court-cyber...) which narrowed to actual fraud and data theft. "The Government’s interpretation of the statute would attach criminal penalties to a breathtaking amount of commonplace computer activity,” Barrett wrote. “If the ‘exceeds authorized access’ clause criminalizes every violation of a computer-use policy, then millions of otherwise law-abiding citizens are criminals." adsbexchange is a user-generated content platform where you can submit decoded radio signals to a common database. Sending fake data to adsbexchange is as much a CFAA violation as posting hoaxes to Wikipedia or a social media platform.
- kevin_thibedeau 8mo agoPrecedent won't get in the way of a tribal retaliation. They've proven that they can't be consistent with fundamental laws they've sworn to uphold.
- lovecg 8mo agoAgreed with other commenters that nothing was likely actually broadcast, but if it was it would definitely be highly illegal and you’d have feds knocking down your door pretty quickly. They don’t joke around with illegal transmissions like that.
- Scoundreller 8mo ago[flagged]
- idontwantthis 8mo agoCan someone explain what this means? Where would this have been seen?
- JasonADrury 8mo ago> Where would this have been seen? on HN, mostly
- burkaman 8mo agoMost planes broadcast their position using ADS-B, and some websites collect these signals and visualize them so you can track flight paths. Somebody broadcast a fake flight path that draws a picture of JD Vance on these sites: https://globe.adsbexchange.com/?icao=adfdf9&lat=26.678&lon=-80.030&zoom=14.4&showTrace=2026-01-28 https://globe.adsbexchange.com/?icao=adfdf9&lat=26.678&lon=-...
- JasonADrury 8mo ago> Somebody broadcast a fake flight path They didn't actually "broadcast" anything. This was created by uploading fake data to absexchange.
- HNisCIS 8mo agoNo, someone probably setup a fake feeder pretending to be an ADSB receiver.
- zeeZ 8mo agoTo expand on that, those websites mostly operate on random volunteers self hosting a (starting price) fairly cheap receiver and antenna with an open source stack that feeds the ADS-B data to the website operator in exchange for nothing or free "premium" benefits. The spoofer could have just sent them fake location information drawing an image using latitude, longitude and altitude for color (in the default view flight paths have different colors based on the altitude of the plane at that point in time). They could have built an antenna and actually broadcast this data, but that would be a lot more effort and most likely some form of crime.
- guerrilla 8mo agoFor those wondering, https://knowyourmeme.com/memes/jd-vance-edited-face-photoshops https://knowyourmeme.com/memes/jd-vance-edited-face-photosho...
- deevus 8mo agoI had a few chuckles reading that. Thanks.
- aaronbrethorst 8mo agoI'm disappointed it doesn't seem to have a link to this Vance/Trump 'makeup' video. https://www.reddit.com/r/StrangeAndFunny/comments/1jm9kn4/jd_vance_putting_on_donald_trumps_makeup/ https://www.reddit.com/r/StrangeAndFunny/comments/1jm9kn4/jd...
- randycupertino 8mo agoA drag makeup artist has an entire series called "Queer Eye for the MAGA Guy" on republican makeup recreations: https://www.youtube.com/watch?v=u6hK_UEGBs4&list=PLNZQj4dOgdXOnVk0cDZeqYZE9n3_FD71P https://www.youtube.com/watch?v=u6hK_UEGBs4&list=PLNZQj4dOgd...
- Fnoord 8mo agoCan you explain what is funny about it? I genuinely don't understand.
- Am4TIfIsER0ppos 8mo agoAre funny faces funny? Are edited images funny? Are edited funny faces funny? Perhaps it just isn't your sort of humor.
- randycupertino 8mo agoMy favorite one is "Emo JD Vance" with the heavy eyeliner and the scene haircut: https://www.amazon.com/Vance-Meme-Emo-Republican-Conservative/dp/B0F252BPK9 https://www.amazon.com/Vance-Meme-Emo-Republican-Conservativ... Yassified Vance, which a Republican congressman actually created and posted as a legit fan edit is also very funny: https://x.com/KatAbughazaleh/status/1841491297145634831 https://x.com/KatAbughazaleh/status/1841491297145634831
- eep_social 8mo agoedit: op also has this, disregard hugged but someone caught it: https://archive.is/VrEtg https://archive.is/VrEtg
- jacquesm 8mo agoIt's still there as of now: https://globe.adsbexchange.com/?icao=adfdf9&lat=26.678&lon=-80.030&zoom=14.4&showTrace=2026-01-28 https://globe.adsbexchange.com/?icao=adfdf9&lat=26.678&lon=-...
- belter 8mo ago[flagged]
- jacquesm 8mo agoNo way... wtf?
- andrewflnr 8mo agoThis is not even a surprise. Trump has been a fan of Putin for years.
- jacquesm 8mo agoIt may not be a surprise to you but it is a surprise to me because there are many other characters that he could be a fan of , he's literally giving Putin top billing here, right next to a picture of what seems to be him and his granddaughter. What's next? Pol Pot? Stalin? Kim?
- blell 8mo ago[flagged]
- jacquesm 8mo agoBecause?
- actionfromafar 8mo agoYeah... Putin has many more nukes.
- andrewstuart 8mo agoPlease explain the tech.
- sneak 8mo agoADS-B is packet data telemetry broadcast unencrypted and unauthenticated by aircraft on 1090MHz. Anyone can receive it, and many do. FlightRadar and others have networks of people with receivers that forward all received packets to central servers. The aircraft self-report location, heading, altitude, etc, so anyone can transmit packets making ghost planes. I am somewhat surprised nobody has stashed an ADS-B spoofer near ATL or AMS that just broadcasts tracks of A380 tail numbers crossing the runways perpendicular at 500 ft AGL or something. They have primary radar, sure, but I imagine there would still be a temporary disruption until people figured out what was going on. I think this is the first case I’ve seen of ADS-B spoofing in the wild. EDIT: this was spoofed reports to the data aggregators via the internet, not broadcast on radio waves. I’ve still never seen or heard tell of RF ADS-B spoofing.
- pixl97 8mo agoFake signals are not uncommon, but mostly accidental. They are dealt with very quickly when causing traffic control problems
- mywittyname 8mo agoI'm guessing this doesn't cause traffic control problems due to the no-fly zone over that area?
- pixl97 8mo agoProbably is not causing traffic issues. With that said I'm sure a number of TLA's are looking into it already, so whoever did it has hopefully took a number of infosec steps not to get caught and questioned.
- sneak 8mo agoSure, but traffic control problems can still be caused (temporarily) by abuse of the frequency/protocol by those intending to cause disruption. Can you tell me more about the fake signals? Who sends them? Why? How often?
- mvdtnz 8mo ago[flagged]
- estimator7292 8mo ago[flagged]
- mulhoon 8mo agoNot millions, but still, they have a point.
- ipsum2 8mo agoNot just HN, this is pretty much all over the web.
- AreShoesFeet000 8mo agoYou should’ve taken the opportunity to not have been so unnecessarily aggressive.
- danpalmer 8mo agoThe traffic that the top of HN generates is remarkably little. It'll be Reddit that is causing this.
- Imustaskforhelp 8mo agoI find it absolutely crazy how I spent around 20 minutes trying to find the rough estimates and predictions with everything to essentially summarize into the same statement which you wrote. Although I would consider that even reddit might not be enough to cause a death wall if the infrastructure behind it is organized. There could be a software mis configuration option, I find it the most plausible option personally.
- Imustaskforhelp 8mo agoI mean HN has around ~5 Million unique users Most are from US or from a HN user: population, well technically switzerland iirc (https://news.ycombinator.com/item?id=33450094 https://news.ycombinator.com/item?id=33450094) But I don't know, I feel like there are definitely times where people create two accounts on HN or more or lose access of previous or want better names (I am thinking of creating a new account on HN myself) so assume half to go through ~2.5 million users Over the span of one decade+ year though, a lot of people completely leave the forum and so I would consider frequent users to be around ~ 1 million Then the people who are actually active a lot of days or are weekly active or monthly active and tonight's the night (dexter reference) that they open it,I would assume ~500k users I would consider these ~500k impressions to be an average estimate on a really really impactful HN post on front page & they all might come through say ~24 hours. I am being more generous and assuming 500k HN impressions on 3-6 hours timeframe then technically the server just has to handle like ~46 users/sec or ~23 users/sec But even on a really high estimate we assume ~500 users/sec But I have seen some benchmarks of websites/frameworks/languages which are able to handle 5k-10k requests as a really low to decent estimate depending on the task I do feel like its something that I can architect ~500 users/sec on some hetzner box most likely at max for ~30-40 usd/month or using their smallest plan with cloudflare tunnels for around I guess ~2.99 euros or 3 euros per month I feel like its definitely possible to survive the "HN wall of death" but any of my websites haven't gone and hit this wall but if anyone of your projects or anyone can anecdotally tell me something it would be interesting & we can discuss it. Also I have seen this one person who was able to survive this HN wall of death on a literal 780 mb alpine server using lighthttpd. Which if we are assuming racknerd or dedirock or something can get to around ~7$/yr or ~6.70-ish$/yr deal from black friday & you can get such deals on websites like lowendtalk for quite a low price. Though these providers have comparatively low bandwidth if you actually want the cheapest somehow option and want to survive this HN wall of death. (these providfe around 1TB-2TB/month iirc) Personally I feel like netcup (my preferred provider) / IONOS might be better options as they are still cheap while giving more lenient bandwidth or you can also find probably some really cheap high bandwidth black friday deals around the 7$/yr mark as well I think I am getting off topic but I really like german hosting providers usually for the most part except the only thing I do hate a (little?) about them is that I have observed that they have a reputation of being exceptionally strict to the rules/some have the more ban first-ask-later approach which um might suck if your project is a little unconvential or quite frankly it can sometimes conflict with my morals as I always feel a little bit of hestitation around building around such system.
- fortran77 8mo agoMost likely they spoofed the reporting API to "FlightAware" or other ADSB crowd-data-sourced sites and didn't spoof "ADSB Signals"
- colechristensen 8mo agoActually spoofing ADSB radio signals could very well land you in prison with a $100,000 fine. The FCC is very eager to find and fine you for these kinds of stunts. Spamming flightaware is much less severe, but still... it's not cute to mess with life-safety critical infrastructure.
- fc417fc802 8mo agoFlightAware isn't safety critical. If it was then being able to spoof it in this manner would be negligence on the part of the operator.
- deleted 8mo ago[deleted]
- deleted 8mo ago[deleted]
- foota 8mo agoThe FCC and the FAA are two federal agencies that really don't want to mess with, so I hope for their sake they didn't actually spoof it. (.... I wish there were an FBB as well)
- cm2187 8mo agoplus they did that right next to an airport
- cyanydeez 8mo agoDepends, how much did DOGE fuck with their leadership and management. We now have to both identify obama judges, trump judges and trump bootlickers.
- varenc 8mo agoSeems like it wasn't actually spoofed radio signals, but spoofed data collection uploaded to adsbexchange. Still seems unlikely to make the FAA happy, but not as bad. I assume air traffic controllers aren't relying on adsbexchange?
- jjwiseman 8mo agoMaybe not "rely" on, but some definitely use public ADS-B aggregator sites.
- ryandrake 8mo agoI highly doubt any ATC on duty is looking at a public ADS-B aggregator as a real time source of information for his or her job.
- jjwiseman 8mo agoThere are non-radar towers that don't have scopes. They may have a traffic display, or maybe not. They might choose to use a public ADS-B aggregator site because it gives them situational awareness, but they don't use it to provide radar services to aircraft. That's my understanding from listening to a lot podcast episodes with air traffic controllers, anyway. I think it's an unofficial, non-FAA approved kind of thing that can make their jobs easier. See https://www.faa.gov/air_traffic/publications/atpubs/atc_html/chap_6.html https://www.faa.gov/air_traffic/publications/atpubs/atc_html... for non-radar ATC procedures.
- paulirish 8mo agoThis was not spoofed at the ADS-B layer. It was just spoofed to adsb exchange. (While typically a feeder contributes to multiple sites, this one didn't.) eg: - https://globe.adsb.fi/?icao=adfdf9&lat=26.678&lon=-80.030&zoom=14.4&showTrace=2026-01-28 https://globe.adsb.fi/?icao=adfdf9&lat=26.678&lon=-80.030&zo... - https://adsb.lol/?icao=adfdf9&lat=26.678&lon=-80.030&zoom=14.4&showTrace=2026-01-28 https://adsb.lol/?icao=adfdf9&lat=26.678&lon=-80.030&zoom=14... Relevant discussion on r/adsb: https://www.reddit.com/r/ADSB/comments/1qp3q9n/interesting/ https://www.reddit.com/r/ADSB/comments/1qp3q9n/interesting/ where they note it's also absent on FR24, airplanes.live, and theairtraffic.com. The adsb-x feeder map: https://map.adsbexchange.com/mlat-map/ https://map.adsbexchange.com/mlat-map/ They probably won't have a hard time identifying who contributed that data.
- ryandrake 8mo agoYea, this is more like vandalizing Wikipedia than spoofing or interfering with safety-critical systems. It's juvenile, but probably not crashing any planes. It'll get reverted, and then presumably the adsb exchange website will tighten up their security.
- antonvs 8mo ago> It's juvenile Juvenile times call for juvenile measures. In case you haven’t noticed, the US is being run by a bunch of arrested development high school bullies. Juvenile is one of the only languages they understand.
- zombot 8mo ago+N. If I could, I would give you multiple upvotes.
- morpheuskafka 8mo agoAnd is Vance or Trump watching Flightradar24 in their free time? And if they did, would they even get mad at this and not find it funny? And if they did get mad at it, would they do anything at all? If they did something, would it be anything desirable or just trying to retaliate at whoever drew this?
- decimalenough 8mo agoUnless I'm much mistaken, Vance's face is centered over Mar-a-Lago! https://maps.app.goo.gl/fjqtAa2qgcWsJvFfA https://maps.app.goo.gl/fjqtAa2qgcWsJvFfA https://globe.adsbexchange.com/?icao=adfdf9&lat=26.680&lon=-80.062&zoom=13.5&showTrace=2026-01-28×tamp=1769575448 https://globe.adsbexchange.com/?icao=adfdf9&lat=26.680&lon=-...
- belter 8mo agoIf you get the DF17 frames and extract the airborne position messages Type Codes 9–18. Then CPR decode them into latitude/longitude....plus plot enough spoofed positions so the point cloud forms a QR code like raster on the map, then scan the rendered pattern...you get a URL to the unredacted Epstein files.
- jacquesm 8mo agoHehe, you had me all the way to the punchline, that was funny.
- jjwiseman 8mo agoAs other commenters noted, this is almost certainly not RF spoofing, just sending bad data to an aggregator (ADS-B Exchange) over the internet. This instance of spoofing is notable for being the first that I know of that wasn't primitive vector art or text, but a raster image! In that area of Florida multiple receivers would have picked up actual ADS-B broadcasts. ADS-B aggregators do have various anti-spoofing measures, but they're not impossible to circumvent. The only case of actual RF spoofing of aircraft transponder signals that I know of was actually done by the U.S. Secret Service, which interfered with passenger jet collision alert systems (TCAS) by apparently broadcasting bogus signals near Ronald Reagan National Airport (KDCA): https://nymag.com/intelligencer/article/aviation-flights-white-house-tcas-drones.html?utm_source=insta&utm_medium=s1&utm_campaign=nym https://nymag.com/intelligencer/article/aviation-flights-whi...
- jjwiseman 8mo ago(Of course if you were spoofing ADS-B RF signals you wouldn't necessarily need to be anywhere near the spoofed locations. Just like with GPS spoofing.)
- Nextgrid 8mo agoSurely the receiver would run plausibility checks on the received messages and reject spoofed locations that are physically impossible to receive by said receiver?
- mschuster91 8mo ago> spoofed locations that are physically impossible to receive by said receiver? Wait until you hear about Sporadic-E or Aurora. RF is a weird place full of natural phenomena making the impossible very possible.
- Nextgrid 8mo agoBut even if that was the case, is there any value for a receiver to be receiving those? Surely those messages would be picked up by a receiver closer to the transmitter anyway. I think the value in spoofing rejection is greater than the probability of a transmission reflecting from beyond the horizon and not being already being picked up by a local receiver.
- aa_is_op 8mo agoIsn't this actually illegal?
- altairprime 8mo agoIt’s not “illegal broadcast which engages the FAA and FCC to hunt you down” illegal, but that doesn’t exclude other prosecutions.
- filleduchaos 8mo agoOther persecutions for what? Sending crap data to an API is not a crime.
- altairprime 8mo agoIt's literally "computer fraud and abuse" in every sense of the word, so one assumes that an avenue of potential prosecution and possible conviction would be under the CFAA act. This does not, of course, guarantee that a conviction would be made and upheld at appeal, but this community is quite familiar with the dire harm that federal prosecution for misuse of computer services can impose on individuals, no matter how misguided that prosecution may be. Prosecution can be wielded as a form of persecution that does not require a conviction as outcome to be successful, and that is the a pressing risk now faced by whoever did this.
- KnuthIsGod 8mo agoHow long before domestic terrorism charges are laid ? Everthing seems to be domestic terrorism in the US these days.
- mindslight 8mo agoDomestic terrorism is now an official policy goal of the "US" government, so yes, there is a lot of it.
- abustamam 8mo agoEasy to justify the murder of your political opponents by calling them domestic terrorists. What's almost more frightening is how many people actually buy it.
- mindslight 8mo agoI'm still chewing on the idea of how many supporters are bots or at least bot-adjacent (ie manufactured social proof), and what can even be done about that. When I go to my local [small, suburban] protest in a balanced red-blue area, lately it's been many honks and agreements, and only a handful of angry grimaces. So I think the tide has long ago shifted, which makes sense what with the terror gangs executing Americans and all. The question is how we can organize into meaningful opposition when most activity happens online these days, and every non-echo-chamber forum still has extremist nutjobs who derail productive conversation. I'd think that Congressional offices are seeing a similar dynamic too, inundated with robocalls from "constituents", the occasional untraceable threat of violence to their families if they step out of line, etc.
- burnt-resistor 8mo agoThis is just yet another cost and side-effect of a deeply unpopular, business-destroying, corrupt regime.
- burnt-resistor 8mo agoSince most of these ADS-B collection sites are patchworks of unofficial/best effort, that seems like a great attack vector for nation state-level spoofing to interrupt flight planning, capacity planning, other tertiary air transport operations, and make civilians nervous. It's analogous to "hobby" code running key infrastructure of the internet without serious processes and auditing, testing, and verification. It would be far better and more reliable to have the FAA do it by providing authoritative single source of truth as (selectively) open data rather than depend upon the whims / greed / sloppiness of an over-privatized utility. ATCs need and/or have this data anyhow, so in the future, it should be provided. How do less neoliberal European countries do it?
- habinero 8mo agoThese are hobbyist sites, not critical infrastructure. Commercial aviation doesn't use them. > It's analogous to "hobby" code running key infrastructure of the internet I have some bad news my dude lol
- dayyan 8mo agoHilarious
- jjwiseman 8mo agoIt's happening again. Spoofing is in progress, rendering another image. ADS-B Exchange has blocked access to the ICAOs/hexes in question--if you try to look at their history you get redirected to the base map. https://x.com/TheIntelFrog/status/2016841289556168990 https://x.com/TheIntelFrog/status/2016841289556168990
- tanseydavid 8mo agoReality is just so @#$%^&* weird these days. Feels like a bad dream.