Live data from Hacker News

Ships fooled in GPS spoofing attack suggest Russian cyberweapon

newscientist.com

61–70 of 78 posts

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#61

This is fairly old news. Reports are a year or two old and suggest that Russian security uses GPS spoofing anywhere V. Putin may be located, presumably as a defense against drone type attacks or surveillance. The spoofed location is often an airport. The black sea spoofing could be related to a visit to e.g., Sochi. Alternatively Russia could be deploying the spoofers on ships now, which would seem to have offensive…

Can attest this. Area near Kremlin is spoofed to Vnukovo airport for several years already. There were reports about putin's dacha spoofed to the nearest aiport too. I really do not know about reasons and efficacy. Professional grade multi-gnss receivers can easily filter this crap out, at least they could 5 years ago...

But is it only Kremlin spoofing? I been to wisit DC/White House hoods many time and every time I had problem using google or apple maps. Signal was all over the place.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#62
post #33

Earlier quoted context omitted.

Sounds like a semi-reliable Putin Detector could be set up if you wanted to...

Let's think through that. In order to spoof GPS, you need to overpower the true GPS signal with your own. You put some transmitters in a location, and anyone attempting to get a GPS fix while in that location gets spoofed data and the wrong location. Now, if you're close enough to get the spoofed signal, you're close enough to see Putin's entourage and know he's probably nearby. If you're not close, you don't get spo…

GPS signal is very weak, it would not take much to overpower the signal from a good distance I think.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#63

Not only old news as suggested in other comments, but not hard to do either; IIRC, this was done 1 or 2 DEF CONs ago, not only for GPS, but also for older systems that use radio beacons (Aircraft? not sure..) and A-GPS (spoofing GSM radios).

http://www.rtl-sdr.com/spoofing-gps-locations-with-low-cost-...

Yes! That's the one I was looking for. I guess going for 2014 or older wasn't going to get me the 2015 presentations ;-)

It is pretty effective in illustrating how easy it is to break such a system. Easy as in, you don't need a big nation state actor to do this.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#64

Not only old news as suggested in other comments, but not hard to do either; IIRC, this was done 1 or 2 DEF CONs ago, not only for GPS, but also for older systems that use radio beacons (Aircraft? not sure..) and A-GPS (spoofing GSM radios).

http://www.rtl-sdr.com/spoofing-gps-locations-with-low-cost-...

Funnily enough I have a legitimate use for this: correcting GPS drift in a location with poor GPS availability. I would love to carry around a Raspberry Pi with an attached SDR that let me fine tune the signal so it's accurate versus showing me across the street, down the block or aimlessly wandering in circles.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#65
I wonder if this played any role in the recent Navy accident. It seems there were multiple safeguards which failed, but it would be very interesting if there were GPS issues as well.

http://www.cnn.com/2017/06/16/politics/us-navy-destroyer-col...

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#66

I wonder if this played any role in the recent Navy accident. It seems there were multiple safeguards which failed, but it would be very interesting if there were GPS issues as well. http://www.cnn.com/2017/06/16/politics/us-navy-destroyer-col...

Unlikely. The ACX crystal was traveling in a straight line for hundreds of miles before the collision. Just before the collision she made a slight turn to port in order to navigate a narrow straight. Her trajectory was entirely consistent with her destination. There's no indication she didn't know exactly where she was. (And I mean that literally: the ship knew where it was. The evidence indicates that the crew was asleep.)

Reference: http://blog.rongarret.info/2017/06/theres-something-very-odd...

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#67
post #39

Earlier quoted context omitted.

M-code encryption doesn't protect against rebroadcast, which is what this attack seems to be. And beam-forming has its own limitations which can be fairly easily overcome by signal strength. It may be that military mitigation involves defining a carefully circumscribed envelope of signal strength, checks against inertial references, alternative time sources, etc. But it's not trivial or laughable.

M-code contains time and ephemeris data, yes? (Since it's supposed to be "autonomous".) It seems like it would be quite easy to detect replay attacks.

The receiver likely doesn't have an accurate enough clock to reliably detect a quick (a tiny fraction of a second) replay attack if it can't hear the original transmitters due to intentional interference; most GPS systems would treat any differences between internal time and the time from the GPS data as a sign that their clock is drifting and needs to be adjusted, and it should be that way because their clock is inaccurate and drifting.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#68

This is fairly old news. Reports are a year or two old and suggest that Russian security uses GPS spoofing anywhere V. Putin may be located, presumably as a defense against drone type attacks or surveillance. The spoofed location is often an airport. The black sea spoofing could be related to a visit to e.g., Sochi. Alternatively Russia could be deploying the spoofers on ships now, which would seem to have offensive…

Sounds like a semi-reliable Putin Detector could be set up if you wanted to...

Yes, but the opponent will only see a largish region, probably [a few 1000 km big UPDATE: from other comments here, it seems the region can be much smaller], where the GPS is off and the opponent would usually already know his location to that precision.

Still it might be a worth-while excersise for the NSA -- not so they can target Putin. But to provide one more signal for when he makes some unexpected, hush-hush trip to some central Asian republic or some-such.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#69
post #58

Earlier quoted context omitted.

It would also be fairly short-lived in battle, since the spoofer is broadcasting its own location in a highly accurate "place ordnance here" manner.

More likely it is broadcasting the position of the satellite it is spoofing, with altered timing. edit: that doesn't prevent other means of locating the source of an rf signal

You can't spoof the encrypted signal by simulating a satellite, you have to capture the real signal and rebroadcast it as an overpowering signal so targets can't get the direct broadcast at their location.

This means that everyone who is getting the overpowered signal will compute the same location, which will be the antenna of the spoofer.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#70

Earlier quoted context omitted.

Is this really possible? I don't know much technical details about GPS, but I thought a large component was time-based. If my understanding is correct, wouldn't rebroadcasting fail because the times didn't match correctly?

The question is: match with what? Part of the GPS calculation is to figure out what time it is. There is no reference needed other than what the satellites broadcast. If you are rebroadcasting the entire GPS signal it includes all of the satellites, and will be self-consistent. Also, in the case of a rebroadcast it need not be delayed by more than something on the order of a microsecond or so. If the receiver has som…

Also, in the case of a rebroadcast it need not be delayed by more than something on the order of a microsecond or so.

That only works if the spoofer is very close by.

One microsecond is 1000 feet. (Recall the "Grace Hopper nanosecond" as a start.) So, if the spoofing signal rebroadcast originates 5 miles away, that's 26 microseconds of delay right there.

If the receiver has some sort of out-of-channel time reference that is accurate to nanosecond levels I suppose that could be used as a check, but that sort of thing takes an atomic clock and doesn't fit in a wristwatch.

You're way off in your accuracy estimate.

Oven controlled crystal oscillators have been around for at least 50 years. Probably a lot more. And they're dirt cheap. All they are is some temperature stabilization around an ordinary crystal oscillator. Quoting from the (always highly accurate) :) Wikipedia:

The short term frequency stability of OCXOs is typically 1x10−12 over a few seconds, while the long term stability is limited to around 1x10−8 (10 ppb) per year by aging of the crystal https://en.wikipedia.org/wiki/Crystal_oven#Accuracy

An OCXO isn't practical in a tiny drone or a wristwatch, but it's highly practical in any military instrument that weighs more than a few pounds.

Post reply on HN