Live data from Hacker News

Satellite reveals immense scale of GPS signal tampering

space.com

91–100 of 107 posts

Re: Satellite reveals immense scale of GPS signal tampering

#91
post #87

Earlier quoted context omitted.

> A typical PC clock is +/-100ppm. After 1 hour that's 0.36s Are you confident in these numbers? They add up to 52 minutes of drift/year. Good modern quartz watches specify 5 seconds/year drift, almost 3 orders of magnitude better.

Yes, albeit 100ppm is bad/cheap crystals. 50-30ppm is normal. The difference with a quartz watch is that it's factory calibrated with the load capacitance on the crystal, and that it's a 32768Hz tuning fork. For a variety of reasons, generating higher frequency clocks off 32768Hz is... "annoying" (huge PLL ratio, very slow feedback loop step), and typical crystals in the 10-100MHz range are just less precise and ther…

> typical crystals in the 10-100MHz range

I think most quarts watches oscillate at 32 kHz = 2^15 Hz, high precision quartz watches at 8.4 MHz = 2^23 Hz.

> The actual problem is stability over temperature

Apparently, designers of these watches compensating for that somehow: https://en.wikipedia.org/wiki/Quartz_clock#Thermal_compensat...

> benefits from being kept at constant-ish body temperature

Some people take off their watches every day before going to sleep.

These high-end quartz oscillators are probably too expensive to use in commodity computers. Still, the cost shouldn’t look too bad when compared to a price or an airplane, marine vessel, or most military equipment.

Re: Satellite reveals immense scale of GPS signal tampering

#92

Earlier quoted context omitted.

Atomic clocks are not precise enough, they need nuclear clocks, which are not developed yet: https://thoriumclock.eu/

GPS uses atomic clocks, not sure why we'd need something more precise for a timing reference on any other satellite system, unless you wanted to get like millimeter-level accuracy using nothing but satellites (and that would require a lot more than just a better clock on the sats).

With nuclear clocks, GPS will be unnecessary.

Re: Satellite reveals immense scale of GPS signal tampering

#93
post #61

Earlier quoted context omitted.

I don't think this helps against someone receiving the signals (all satellites) and rebroadcasting them. The effect of that would be that any receiver of those rebroadcasted signals will believe they are located where the receiver of the rebroadcast is located (just the time is slightly off/late, but that doesn't help much without a reference to check against.)

> […] (just the time is slightly off/late, but that doesn't help much without a reference to check against.) The 'time sync' does not need to be done in the same absolutely sense ( time_t is the same everywhere), but only in the relative sense: Various approaches exist for time synchronization [15,16,17,18]. TESLA only requires the receiver to know an upper bound on the delay of its local clock with respect to the se…

> Knowing the (rough) broadcast delay from sender to receiver is sufficient.

You're citing things without understanding them.

First, you've mangled that summarisation, knowing an upper bound on delay is not the same as knowing delay.

Second, that's true for using TESLA for data streams. Not for when the timing of the stream itself is the information content. That bound on delay translates into a spatial zone of spoofability. The RFC refers to the content being timely (not stale) and authenticated, but timely is not the same as using the timing itself as data.

Re: Satellite reveals immense scale of GPS signal tampering

#94
post #87

Earlier quoted context omitted.

Yes, albeit 100ppm is bad/cheap crystals. 50-30ppm is normal. The difference with a quartz watch is that it's factory calibrated with the load capacitance on the crystal, and that it's a 32768Hz tuning fork. For a variety of reasons, generating higher frequency clocks off 32768Hz is... "annoying" (huge PLL ratio, very slow feedback loop step), and typical crystals in the 10-100MHz range are just less precise and ther…

> typical crystals in the 10-100MHz range I think most quarts watches oscillate at 32 kHz = 2^15 Hz, high precision quartz watches at 8.4 MHz = 2^23 Hz. > The actual problem is stability over temperature Apparently, designers of these watches compensating for that somehow: https://en.wikipedia.org/wiki/Quartz_clock#Thermal_compensat... > benefits from being kept at constant-ish body temperature Some people take off t…

We're in agreement; 1ppm is 31.5s/yr so this lines up with OCXO performance / keeping the crystal at constant temperature. It's still 1km zone of spoofability per hour without resync.

(GPS sync is a question of nanoseconds.)

Re: Satellite reveals immense scale of GPS signal tampering

#95

> When we fly over North America, for example, we see a beautiful signal all the time I think by “fly”, they mean several hundred km in the air where you have sharply reduced below-the-horizon blocking. Anyone got any leads on Doppler shift detecting equipment? Not hard to detect you’re getting spoofed or jammed with based on that. Power levels being all improbable wouldn’t be hard to detect either. Difficult to dete…

>Anyone got any leads on Doppler shift detecting equipment? All radio receivers? Detecting the radio doppler frequency shift for satellites is kinda trivial. Spoofing/jamming systems also trivially include doppler shifts. The more someone is trying to interfere with your specific location, the harder it is to defeat the spoofing.

Seems like there's a gap for distributed gnss jamming/spoofing detection systems, not unlike what we have for lightning detection and flight tracking.

Unfortunately gpsjam.org relies on ADS-B data and if you don't have a lot of flights (or ads-b receivers) in an area, it leaves a lot of gaps. Plus it's far from real-time.

Re: Satellite reveals immense scale of GPS signal tampering

#96
post #93

Earlier quoted context omitted.

> […] (just the time is slightly off/late, but that doesn't help much without a reference to check against.) The 'time sync' does not need to be done in the same absolutely sense ( time_t is the same everywhere), but only in the relative sense: Various approaches exist for time synchronization [15,16,17,18]. TESLA only requires the receiver to know an upper bound on the delay of its local clock with respect to the se…

> Knowing the (rough) broadcast delay from sender to receiver is sufficient. You're citing things without understanding them. First, you've mangled that summarisation, knowing an upper bound on delay is not the same as knowing delay. Second, that's true for using TESLA for data streams. Not for when the timing of the stream itself is the information content. That bound on delay translates into a spatial zone of spoof…

If you wish to know how well Galileo+TESLA work, see perhaps:

> Global Navigation Satellite Systems (GNSS) are critical for infrastructure like energy, telecommunications, and transportation, making their accuracy vital. To enhance security especially against location spoofing, in 2024, the Galileo GNSS system adopted the Timed Efficient Stream Loss-Tolerant Authentication (TESLA) protocol, for Navigation Message Authentication (NMA). However, past and present TESLA versions have lacked formal verification due to challenges in modelling their streaming and timing mechanisms. Given the importance of formal verification in uncovering protocol flaws, this work addresses that gap by formally modelling and verifying the latest TESLA protocol used in Galileo; we verify Galileo’s TESLA protocol in the well-known Tamarin prover. We discuss our findings and, since this is work-in-progress, we contextualise them in terms of next steps for us, as well as for future Navigation Message Authentication protocols inside GNSS systems.

> Then, security-wise, via 8 lemmas, we show: […] timeliness of the messages: the receiver will reject messages (even when they have cryptographic integrity) if they were received outside of their validity time-interval; […] replay-related security: i.e., replay attacks are possible, but only if the acceptability time interval is not violated (i.e., messages replayed too late will be rejected). […]

* https://www.ndss-symposium.org/ndss-paper/auto-draft-620/

* https://dx.doi.org/10.14722/spacesec.2025.23009

Re: Satellite reveals immense scale of GPS signal tampering

#97

Earlier quoted context omitted.

> spoofing I don't understand how "spoof-to" works. If you have to mimic a satellite then isn't everyone going to get a different location? Unless you're tracking a specific target how can you intentionally spoof them to a desired location? I'd assume the best you could do is create a fixed offset. > The military wants to go mostly inertial and is working on better inertial systems. Given the drift rate this is an id…

There are low-drift-rate inertial solutions, but they have high cost and big size (i.e. laser gyroscopes and accelerometers, with atomic clocks). So I assume that the research effort is directed towards reducing the cost and size.

The problem with that is if you turn off power to the aircraft then the IMU no longer maintains state and you will need to realign it on startup. The procedures for this are broadly incompatible with military missions.

Re: Satellite reveals immense scale of GPS signal tampering

#98
post #61

Earlier quoted context omitted.

I don't think this helps against someone receiving the signals (all satellites) and rebroadcasting them. The effect of that would be that any receiver of those rebroadcasted signals will believe they are located where the receiver of the rebroadcast is located (just the time is slightly off/late, but that doesn't help much without a reference to check against.)

It's been a few years since I've worked with this stuff but I'm under the impression that you can do this sort of replay only for a short amount of time. If so, is there a point? If the receiver expects a key to have been revealed at a particular timestep, it won't accept a replayed message with that key after that, so you can't record and replay indefinitely. EDIT: Unless you indeed meant to instantly replay - would…

The point is to prevent missiles and drones from impacting their intended targets.

For most payloads and targets, this requires very little distortion.

Re: Satellite reveals immense scale of GPS signal tampering

#99

Earlier quoted context omitted.

>Anyone got any leads on Doppler shift detecting equipment? All radio receivers? Detecting the radio doppler frequency shift for satellites is kinda trivial. Spoofing/jamming systems also trivially include doppler shifts. The more someone is trying to interfere with your specific location, the harder it is to defeat the spoofing.

Seems like there's a gap for distributed gnss jamming/spoofing detection systems, not unlike what we have for lightning detection and flight tracking. Unfortunately gpsjam.org relies on ADS-B data and if you don't have a lot of flights (or ads-b receivers) in an area, it leaves a lot of gaps. Plus it's far from real-time.

For that you need a custom GPS receiver stack and as well as the technical hurdles of designing the receiver in an expanded way to detect spoofing (by the way it's not just spoofing, in normal circumstances GPS signals will reflect off of things and you'll get perfectly natural "spoofing" which you have to properly reject) you'll also have to deal with the fact that GPS receivers are export controlled unless they meet certain requirements.

Re: Satellite reveals immense scale of GPS signal tampering

#100
post #75

Earlier quoted context omitted.

It would take those devices having synchronized atomic clocks, which they do not.

Is it really not possible to converge a location from implicit signals like frequency shift from relative motion? My intuition, maybe wrong, is that with enough compute and a thorough enough ephemeris of what should be broadcasting what, you could derive location.

Its an active research topic called signal of opportunity navigation, and papers has been written saying this is possible, some of the uses the idea you mentioned. I used to be involved in using starlink signals for positioning and there are problems:

1. Public ephemeris from space-track (celestrak) is notoriously inaccurate after a while. Less of a problem for starlink as they give free access to high accuracy ephemeris from their onboard GPS receiver: https://starlink.com/satellite-operators

2. For proprietary signals like starlink they can change signals whenever they want without telling you and break your positioning algorithm. For example, starlink used to transmit some sort of narrowband CW wave at their frequency band, which can be received by cheap ($20 ish) RTL-SDR dongle and satellite TV antenna: https://www.rtl-sdr.com/receiving-starlink-signals-with-an-r... . Everyone speculates that its a beacon signal, research papers were written trying to exploit doppler positioning from those signals. Then the signal disappears, as its possible that they don't intentionally transmit those signal. They you can't use cheap hardware to capture the signal, you need expensive hardware that can capture the full 250 MHz bandwidth. This is not a problem if you use standardized signals where they can even intentionally add positioning signals like 5G or digital TV

Post reply on HN