I know the title here is the same as the article, but why the heck did sophos choose "Texas college" for the something done by the University of Texas? I assumed from the title it was done by some small school somewhere in Texas, not UT.
Drone hijacked by UT hackers with $1,000 spoofer
11–20 of 81 posts
Re: Drone hijacked by UT hackers with $1,000 spoofer
#12There are a few good comments[1] on the article page that point out that Military drones use an encrypted GPS channel that isn't susceptible to this specific attack. A much more sophisticated attack would have to be used to take over a military drone. [1]: http://nakedsecurity.sophos.com/2012/07/02/drone-hackedwith-...
Re: Drone hijacked by UT hackers with $1,000 spoofer
#13The researchers from UT built a system to protect against GPS spoofing. In order to prove that their protection system works, they had to demonstrate that GPS spoofing is feasible. Without exception, every news item on this only mentions the spoofing part, and not the protection part.
Military unmanned systems use encrypted GPS that is not vulnerable to the attack demonstrated.
Its possible to make a vehicle fly erratically, or even cause it to crash by spoofing GPS. But to take control requires a lot more than what was demonstrated. An error of 1us in the spoofed signal corresponds to 1000ft -- that's why the actual descriptions of the vehicle say 'banked hard' or 'veered' off course.
GPS jamming is so much easier than spoofing and results in the same thing.
Re: Drone hijacked by UT hackers with $1,000 spoofer
#14Each one of these could be a potential missile used against us. This seems to be exaggerated. Wouldn't you need a drone on American soil, already right next to the target, in order to crash it by sending falsified GPS coordinates?
Re: Drone hijacked by UT hackers with $1,000 spoofer
#15I bet you DHS will turn this horrible news into a good PR, something like "we noticed they could take over our drone, but you see if we get additional 10 billion in funding, we could use encryption over GPS and then all our drones will be safe again".
Re: Drone hijacked by UT hackers with $1,000 spoofer
#16Each one of these could be a potential missile used against us. This seems to be exaggerated. Wouldn't you need a drone on American soil, already right next to the target, in order to crash it by sending falsified GPS coordinates?
Or against US soldiers.
Is it possible to somehow sign GPS coordinates? (Perhaps sync an internal clock at each mission's start, and check a time-based signature?)
If not, are there practical challenges to integrating the output of a drone's engine and calculating the path travelled, instead of naively believing satellite coordinates?
Actually, wind must make that difficult. For a car, you can attach a magnet to each wheel and count the surges as it passes a sensor on each rotation, to give you an idea of where you are. Due to the external forces on a drone, you would probably want to measure forces with an accelerometer/gyroscope, not engine output.)
What are the challenges involved in such? Is internal-location tracking even feasible?
Re: Drone hijacked by UT hackers with $1,000 spoofer
#17I know the title here is the same as the article, but why the heck did sophos choose "Texas college" for the something done by the University of Texas? I assumed from the title it was done by some small school somewhere in Texas, not UT.
Re: Drone hijacked by UT hackers with $1,000 spoofer
#18Egads, the news coverage of this is horrible fear mongering. The researchers from UT built a system to protect against GPS spoofing. In order to prove that their protection system works, they had to demonstrate that GPS spoofing is feasible. Without exception, every news item on this only mentions the spoofing part, and not the protection part. Military unmanned systems use encrypted GPS that is not vulnerable to the…
Does it? Can't the drone tell that the GPS input that it's getting is inconsistent and fall back to flying home using dead reckoning?
Re: Drone hijacked by UT hackers with $1,000 spoofer
#19Egads, the news coverage of this is horrible fear mongering. The researchers from UT built a system to protect against GPS spoofing. In order to prove that their protection system works, they had to demonstrate that GPS spoofing is feasible. Without exception, every news item on this only mentions the spoofing part, and not the protection part. Military unmanned systems use encrypted GPS that is not vulnerable to the…
> GPS jamming is so much easier than spoofing and results in the same thing. Does it? Can't the drone tell that the GPS input that it's getting is inconsistent and fall back to flying home using dead reckoning?
Edit: the low-cost sensors can be augmented with sensors other than GPS too, like vision processing. This has been demonstrated but is not yet in widespread usage. I expect to see this become more common due to demonstrated vulnerabilities in GPS.
Re: Drone hijacked by UT hackers with $1,000 spoofer
#20I know the title here is the same as the article, but why the heck did sophos choose "Texas college" for the something done by the University of Texas? I assumed from the title it was done by some small school somewhere in Texas, not UT.
There is only one school in texas worth knowing about.