Live data from Hacker News

Satellite reveals immense scale of GPS signal tampering

space.com

31–40 of 107 posts

Re: Satellite reveals immense scale of GPS signal tampering

#31
post #30
post #27

Earlier quoted context omitted.

An even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible.

Because an attacker can just replay legitimate broadcasts with slightly skewed time and origin and introduce huge errors into the fix.

Just because we can't solve all current problems doesn't mean we shouldn't solve any current problems.

If you want to prevent replaying as well, add a counter.

Re: Satellite reveals immense scale of GPS signal tampering

#32
post #27

Earlier quoted context omitted.

An even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible.

Why would that make spoofing impossible?

Because attackers wouldn't be able to send legitimate-looking data to GPS receivers any more.

Re: Satellite reveals immense scale of GPS signal tampering

#34
post #16

Ops.group published a report on GPS spoofing back in 2024.[1] It's bad. Ops.group is an organization for dispatchers and pilots, the people who decide the routes aircraft take and fly them. They are really angry about it. Key concerns: - The greatest safety concern is the degraded functionality of the Ground Proximity Warning System (GPWS). The system does not operate correctly after spoofing, even if GPS coverage is…

> spoofing

I don't understand how "spoof-to" works. If you have to mimic a satellite then isn't everyone going to get a different location? Unless you're tracking a specific target how can you intentionally spoof them to a desired location? I'd assume the best you could do is create a fixed offset.

> The military wants to go mostly inertial and is working on better inertial systems.

Given the drift rate this is an idea for munitions but exceptionally difficult to actually operate in a vehicle.

Re: Satellite reveals immense scale of GPS signal tampering

#35
post #32

Earlier quoted context omitted.

Why would that make spoofing impossible?

Because attackers wouldn't be able to send legitimate-looking data to GPS receivers any more.

Yes that's what spoofing is, but why wouldn't they be able to?

(EDIT: I see the other reply thread is already asking the same thing, didn't intend to ask about the same thing)

Re: Satellite reveals immense scale of GPS signal tampering

#36
post #16

Ops.group published a report on GPS spoofing back in 2024.[1] It's bad. Ops.group is an organization for dispatchers and pilots, the people who decide the routes aircraft take and fly them. They are really angry about it. Key concerns: - The greatest safety concern is the degraded functionality of the Ground Proximity Warning System (GPWS). The system does not operate correctly after spoofing, even if GPS coverage is…

Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for authentification.

They're falling back to the C/A (coarse, civilian) signal. Part of the attack is to drown out the frequency where the P (fine, military) signal is so they can more easily attack the civilian signal.

There's another frequency they could be using that is higher power but hasn't been put into production yet.

Re: Satellite reveals immense scale of GPS signal tampering

#37
post #31
post #30

Earlier quoted context omitted.

Because an attacker can just replay legitimate broadcasts with slightly skewed time and origin and introduce huge errors into the fix.

Just because we can't solve all current problems doesn't mean we shouldn't solve any current problems. If you want to prevent replaying as well, add a counter.

> Just because we can't solve all current problems doesn't mean we shouldn't solve any current problems.

Obviously not, but solving problems is always a cost benefit and we went from all spoofing is impossible to some spoofing is possible. What is the benefit of doing this and what is the cost?

> If you want to prevent replaying as well, add a counter.

It's not clear that would be able to prevent spoofing if the attacker could overwhelm and degrade the real signal.

Re: Satellite reveals immense scale of GPS signal tampering

#38
post #27

Earlier quoted context omitted.

Bigger WTF is why critical systems still use unencrypted gps signal. It is like using plain SMTP emails for banking transactions, and relying on "sender" for authentification.

An even bigger WTF is why GPS data isn't signed with some official key so spoofing is impossible.

Galileo already contains this function for the navigation message via OSNMA, and GPS CHIMERA is soon to be operational, with the latter actually including crytographic "signatures" in the spreading code itself, so if you use these two constellations you become really harder to spoof.

Of course, they dont protect against jamming.

Re: Satellite reveals immense scale of GPS signal tampering

#40
post #21
post #6

Earlier quoted context omitted.

GNSS receivers are passive devices that receive beacons broadcasted from the satellites. It's technically impossible to spy on someone with GNSS.

And 99.99% of those GNSS receivers are connected to the internet. Or are in proximity to an (American controlled/designed) internet connected device.

This sounds like you have an issue with internet connected devices.
Post reply on HN