4 ms·
Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for au
by bebe83939 4mo ago
Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for authentification.
- stavros 4mo agoAn even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible.
- stinkbeetle 4mo agoWhy would that make spoofing impossible?
- stavros 4mo agoBecause attackers wouldn't be able to send legitimate-looking data to GPS receivers any more.
- stinkbeetle 4mo agoYes that's what spoofing is, but why wouldn't they be able to? (EDIT: I see the other reply thread is already asking the same thing, didn't intend to ask about the same thing)
- stavros 4mo agoBecause, due to how cryptography works, nobody other than the entity holding the signing key (ie the one that deployed the satellites) can produce valid signatures for that key.
- 15155 4mo agoBecause an attacker can just replay legitimate broadcasts with slightly skewed time and origin and introduce huge errors into the fix.
- stavros 4mo agoJust because we can't solve all current problems doesn't mean we shouldn't solve any current problems. If you want to prevent replaying as well, add a counter.
- stinkbeetle 4mo ago> Just because we can't solve all current problems doesn't mean we shouldn't solve any current problems. Obviously not, but solving problems is always a cost benefit and we went from all spoofing is impossible to some spoofing is possible. What is the benefit of doing this and what is the cost? > If you want to prevent replaying as well, add a counter. It's not clear that would be able to prevent spoofing if the attacker could overwhelm and degrade the real signal.
- throw0101a 4mo ago>> An even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible. > Because an attacker can just replay legitimate broadcasts with slightly skewed time and origin and introduce huge errors into the fix. Galileo uses a signing system (Timed Efficient Stream Loss-Tolerant Authentication, TESLA) to protect the authenticity of its messages, including preventing replays: * https://gssc.esa.int/navipedia/index.php/Galileo_Open_Service_Navigation_Message_Authentication https://gssc.esa.int/navipedia/index.php/Galileo_Open_Servic... * https://datatracker.ietf.org/doc/html/rfc4082 https://datatracker.ietf.org/doc/html/rfc4082 (TESLA) * https://people.eecs.berkeley.edu/~tygar/papers/TESLA_broadcast_authentication_protocol.pdf https://people.eecs.berkeley.edu/~tygar/papers/TESLA_broadca... * https://users.ece.cmu.edu/~adrian/projects/stream/node1.html https://users.ece.cmu.edu/~adrian/projects/stream/node1.html
- eqvinox 4mo agoI don't think this helps against someone receiving the signals (all satellites) and rebroadcasting them. The effect of that would be that any receiver of those rebroadcasted signals will believe they are located where the receiver of the rebroadcast is located (just the time is slightly off/late, but that doesn't help much without a reference to check against.)
- tatjam 4mo agoGalileo already contains this function for the navigation message via OSNMA, and GPS CHIMERA is soon to be operational, with the latter actually including crytographic "signatures" in the spreading code itself, so if you use these two constellations you become really harder to spoof. Of course, they dont protect against jamming.
- deleted 4mo ago[deleted]
- themafia 4mo agoThey're falling back to the C/A (coarse, civilian) signal. Part of the attack is to drown out the frequency where the P (fine, military) signal is so they can more easily attack the civilian signal. There's another frequency they could be using that is higher power but hasn't been put into production yet.