7 ms·
That's cool! Reminds me of the way the Iranian most likely got control over a US drone a couple of years back. They jammed communication signals and faked GPS
by patrickas 13y ago
That's cool! Reminds me of the way the Iranian most likely got control over a US drone a couple of years back.
They jammed communication signals and faked GPS data when automatic "go back to home base" landing procedure kicked in.
http://www.informationweek.com/security/attacks/iran-hacked-gps-signals-to-capture-us-dr/232300666 http://www.informationweek.com/security/attacks/iran-hacked-...
- jug6ernaut 13y agoHow can they fake the gps signal, the military uses encrypted GPS?
- unoti 13y agoThe article is interesting. Take a look at it. "By putting noise [jamming] on the communications, you force the bird into autopilot... Notably, it's also much easier than trying to crack the encrypted remote-control communications channel. With the drone relying solely on GPS to determine its latitude, longitude, altitude, and velocity, the Iranians then broadcast carefully spoofed GPS coordinates..."
- tlrobinson 13y agoParent comment says the military uses encrypted GPS, which should protect against this type of attack.
- michaelt 13y agoWhat do you suppose a drone does if the command channel and the encrypted GPS signal are both unavailable/jammed but the unencrypted GPS signal is available? In any case, you don't have to be able to decrypt a GPS signal to be able to replay it - you fly a plane 200m above the drone, record whatever's coming over the air from the satellites and you know precisely what would be at the drone's antenna if it were 200m higher. Rebroadcast that at the drone's antenna et Voilà, the drone thinks it's 200m higher than it is.
- jevinskie 13y agoI would hope the engineers designing the drone would NOT fall back to the unencrypted channels precisely because of spoofing attacks. I would think they would rather have the drone use inertial guidance to get it to a friendly area where its secrets would be safer. It may not be able to land without GPS but it would have prevented it from falling into "enemy" hands. Perhaps even activate a self destruct mechanism(s).
- eksith 13y agoThat would only work if it had a really silly default similar in a way to "automatically connect to available Wi-Fi network" even when it's unsecured. It's possible the manufacturer may have overlooked something like that, but if it is in a military capacity, I doubt they would have left a gaping hole like that. Electronic countermeasures have been in use for several decades now so jamming/hijacking etc... would have been considerations in the design and they may have introduced hardening against those.
- makomk 13y agoTraditionally, I believe receivers had to lock onto the civilian GPS signal before even trying to lock the encrypted military GPS. Besides, encryption doesn't stop you from receiving the existing signal and repeating it with a well-tuned delay, which is all you really need to do to fake GPS...
- stanfordkid 13y agoWell that would only work if they are using the most simplistic encryption on the planet (i.e an XOR cipher or something like that). In general replaying the same data through an encryption algorithm should not result in the same encrypted result being generated. Thus if you were to replay the existing signal it should decrypt to nonsense.
- jevinskie 13y agoThe parent isn't talking about MITMing the signal to modify it, just to delay/buffer it. No need to decrypt/encrypt. If you could delay the signals from different satellites by different amounts, would that not also change the position?
- deleted 13y ago[deleted]
- fnordfnordfnord 13y agoGPS signals are very weak. Simply broadcast your own fake signals at the target.
- VLM 13y agoIt helps if the opposition is dumb enough to use a predictable route each day such that you've got a known plaintext attack. Then it amounts to playing yesterday's path, very loudly, today, and it'll fly in a straight line thinking its right on course. Technically you need multiple recordings so you can switch between them to trick it to climb, descend, etc on command. Also it helps if the opposition insists on not only flying the same exact "known plaintext" route over and over, but using a predictable precise number like 3000.000 meters on that route.
- mapt 13y agoThe military possesses control over encrypted GPS. The military doesn't actually use it, though, for the most part - the keys are sensitive state secrets, and distributing them apparently requires the proverbial man chained to a suitcase level of paperwork. The encrypted channels are sufficiently underused that drones whose very design is secret that we fly down the Iran-Afghanistan border aren't equipped with them, and so are vulnerable to Iran spoofing a landing-capture course.
- dzhiurgis 13y agoWasn't there rumours that Russians got ahold of the keys?
- jevinskie 13y agoI found an interesting slide deck that talks a bit about spoofing and key management. [0] Apparently there are different levels of classification for keys. (pg 23) But they must be derived keys, right? The satellites are only broadcasting one signal, not multiple signals each keyed to one receiver. I think there can only be one possible cipherstream (and thus one key) in the very low bandwidth signal. [0] http://www.ko4bb.com/Manuals/05)_GPS_Timing/GPS_-_SAASM_brfg_7-04.pdf http://www.ko4bb.com/Manuals/05)_GPS_Timing/GPS_-_SAASM_brfg...
- dredmorbius 13y agoSounds like a really solid argument for mission-specific or date-specific encryption keys.
- jordanthoms 13y agoIs this symmetric or asymmetric? Seems the keys would only be sensitive if it's the former, given that there (AFAIK) isn't much difference in accuracy between the encrypted and civilian signals anymore. Although, given the very old hardware in the GPS sattelites maybe asymmetric would require too much processing power.
- jonknee 13y agoObviously no one involved is talking, so it's pure conjecture. Iran had previously captured intact drones though, so it's possible they were able to pull out the keys. Or it's possible that the public GPS was used after a period of having the encrypted GPS jammed (that's the kind of behavior that will never be confirmed). Finally, it could have just been BS that GPS was what went wrong. That's not a bad guess. http://www.wired.com/dangerroom/2011/12/iran-drone-hack-gps/ http://www.wired.com/dangerroom/2011/12/iran-drone-hack-gps/
- mrb 13y agoWhy do you, non-cryptographer people, think that encrypted GPS is perfectly secure? Pretty much all crypto implementations have flaws (numerous SSL/TLS discovered and fixed over the years, Android package signing, Xbox game code signing, etc.) GPS encryption was designed 20+ years ago. It is almost guaranteed it has (known and unknown) flaws.
- tarre 13y agoYou don't need to fake it. You just need to know the location of the satellites and delay the signals appropriately.
- bhitov 13y agoI imagine if signal was jammed and only C/A codes were rebroadcast the drone would use those instead of nothing. edit: Assuming that navigation was relying only on GPS
- josefresco 13y agoMost likely is the key term...I read your source link, and the link the article supplied as their source (which then referenced a comment on FoxNews) and there appears to be only speculation as to how it happened but no concrete evidence (besides the fact that it was mostly in-tact)
- bhitov 13y ago"the way the Iranian most likely got control over a US drone" That is a very bold claim which I believe requires far more citation than you have provided. https://en.wikipedia.org/wiki/Iran%E2%80%93U.S._RQ-170_incident#Capture_of_the_drone https://en.wikipedia.org/wiki/Iran%E2%80%93U.S._RQ-170_incid...