Live data from Hacker News

Satellite reveals immense scale of GPS signal tampering

space.com

21–30 of 107 posts

Re: Satellite reveals immense scale of GPS signal tampering

#21
post #6
post #4

I honestly see this jamming as a win. GNSS is a global blanket opt-in American spyware.

GNSS receivers are passive devices that receive beacons broadcasted from the satellites. It's technically impossible to spy on someone with GNSS.

And 99.99% of those GNSS receivers are connected to the internet. Or are in proximity to an (American controlled/designed) internet connected device.

Re: Satellite reveals immense scale of GPS signal tampering

#22
post #7

Earlier quoted context omitted.

Competing with four free GNSS constellations is an interesting business model for sure...

I would guess the business model is 'pay us and we'll give you the encryption key to our coded transmissions'. Those coded transmissions are far harder to jam unless you have the key. So it's all about selling to as many customers as possible whilst having not a single customer leak the key. That's why militaries use keys that rotate daily and won't let anyone else use the military signal.

Why wouldn't they use public key cryptography for that?

Re: Satellite reveals immense scale of GPS signal tampering

#23
post #16

Ops.group published a report on GPS spoofing back in 2024.[1] It's bad. Ops.group is an organization for dispatchers and pilots, the people who decide the routes aircraft take and fly them. They are really angry about it. Key concerns: - The greatest safety concern is the degraded functionality of the Ground Proximity Warning System (GPWS). The system does not operate correctly after spoofing, even if GPS coverage is…

> Before this, everybody in the industry thought GPS solved the aerial navigation problem.

Many people in industry believed this but no one with a brain ever did. The vulnerability of GPS has been cause for concern for a long time, and the decimation of the VOR network has always had a lot of people up in arms.

Re: Satellite reveals immense scale of GPS signal tampering

#24

Earlier quoted context omitted.

I would guess the business model is 'pay us and we'll give you the encryption key to our coded transmissions'. Those coded transmissions are far harder to jam unless you have the key. So it's all about selling to as many customers as possible whilst having not a single customer leak the key. That's why militaries use keys that rotate daily and won't let anyone else use the military signal.

Why wouldn't they use public key cryptography for that?

Your satellite doesn't want to be sending out lots of different signals - due to a limited power budget.

So you have to send out one (or maybe a couple) of signals protected by a key.

Yes, you can distribute that key individually to clients using public key cryptography over the same link (and many services like pay TV do exactly that).

But fundamentally any client who is able to decrypt the main stream can also share the key with someone evil who can use that info to jam the same stream.

Re: Satellite reveals immense scale of GPS signal tampering

#25
post #16

Ops.group published a report on GPS spoofing back in 2024.[1] It's bad. Ops.group is an organization for dispatchers and pilots, the people who decide the routes aircraft take and fly them. They are really angry about it. Key concerns: - The greatest safety concern is the degraded functionality of the Ground Proximity Warning System (GPWS). The system does not operate correctly after spoofing, even if GPS coverage is…

Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for authentification.

Re: Satellite reveals immense scale of GPS signal tampering

#26
post #7

Earlier quoted context omitted.

Competing with four free GNSS constellations is an interesting business model for sure...

I would guess the business model is 'pay us and we'll give you the encryption key to our coded transmissions'. Those coded transmissions are far harder to jam unless you have the key. So it's all about selling to as many customers as possible whilst having not a single customer leak the key. That's why militaries use keys that rotate daily and won't let anyone else use the military signal.

No they're harder to spoof. Jamming is easy, but requires more power to achieve a desired effect and as they note they're planning to operate a low altitude constellation with closer transmitters as a result, so harder to swamp the signal for the receiver.

Re: Satellite reveals immense scale of GPS signal tampering

#27
post #16

Ops.group published a report on GPS spoofing back in 2024.[1] It's bad. Ops.group is an organization for dispatchers and pilots, the people who decide the routes aircraft take and fly them. They are really angry about it. Key concerns: - The greatest safety concern is the degraded functionality of the Ground Proximity Warning System (GPWS). The system does not operate correctly after spoofing, even if GPS coverage is…

Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for authentification.

An even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible.

Re: Satellite reveals immense scale of GPS signal tampering

#28

Earlier quoted context omitted.

Why wouldn't they use public key cryptography for that?

Your satellite doesn't want to be sending out lots of different signals - due to a limited power budget. So you have to send out one (or maybe a couple) of signals protected by a key. Yes, you can distribute that key individually to clients using public key cryptography over the same link (and many services like pay TV do exactly that). But fundamentally any client who is able to decrypt the main stream can also shar…

> jam the same stream.

To add to that, other people won't be able to spoof the original stream (as that needs the private key), but instead only jam it.

It would be the same failure mode as SSL certificates.

Re: Satellite reveals immense scale of GPS signal tampering

#29
post #27

Earlier quoted context omitted.

Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for authentification.

An even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible.

Why would that make spoofing impossible?

Re: Satellite reveals immense scale of GPS signal tampering

#30
post #27

Earlier quoted context omitted.

Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for authentification.

An even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible.

Because an attacker can just replay legitimate broadcasts with slightly skewed time and origin and introduce huge errors into the fix.
Post reply on HN