Live data from Hacker News

Insurgents Hack U.S. Drones

online.wsj.com

21–30 of 141 posts

Re: Insurgents Hack U.S. Drones

#21
post #6

I have a thought. How about next time the military just flies one of these things down to Defcon and lets people have a go. The hackers get a cool toy to play with a for a day and the military gets a free fairly sophisticated penetration test. I'm sure the flaw would have been found; instructions on how to intercept satellite data with about $100 worth of hardware have been floating around for years. I'll edit this p…

The question is, what do our defence contractors care more about: making their weapons actually work? Or merely selling them?

i'm sure lack of reliability is part of their business plan. You make the perfect humvee, and suddenly the army stops buying as many.

There is a reason the AK47 is so much more reliable than the M16. And it's been out for like 60 years now.

Re: Insurgents Hack U.S. Drones

#22
post #15
post #6

I have a thought. How about next time the military just flies one of these things down to Defcon and lets people have a go. The hackers get a cool toy to play with a for a day and the military gets a free fairly sophisticated penetration test. I'm sure the flaw would have been found; instructions on how to intercept satellite data with about $100 worth of hardware have been floating around for years. I'll edit this p…

The article said that people knew the potential existed since the mid 90's so the problem was't ignorance it was arrogance and apathy.

Awesome quote: "Fixing the security gap would have caused delays, according to current and former military officials. It would have added to the Predator’s price. Some officials worried that adding encryption would make it harder to quickly share time-sensitive data within the U.S. military, and with allies."

Re: Insurgents Hack U.S. Drones

#23
post #21

Earlier quoted context omitted.

The question is, what do our defence contractors care more about: making their weapons actually work? Or merely selling them?

i'm sure lack of reliability is part of their business plan. You make the perfect humvee, and suddenly the army stops buying as many. There is a reason the AK47 is so much more reliable than the M16. And it's been out for like 60 years now.

The AK is more reliable because it is less accurate. The tolerances on the various mechanical parts are higher, but as a result they are looser.

Re: Insurgents Hack U.S. Drones

#24
post #6

I have a thought. How about next time the military just flies one of these things down to Defcon and lets people have a go. The hackers get a cool toy to play with a for a day and the military gets a free fairly sophisticated penetration test. I'm sure the flaw would have been found; instructions on how to intercept satellite data with about $100 worth of hardware have been floating around for years. I'll edit this p…

I played with sky grabbing few years back.

Receiver you linked is set-top box, you need PCI receiver card, such as SkyStar (http://www.technisat.com/index381f.html?nav=PC_products,en,7...)

No, you don't have to modify the receiver, card captures IP traffic just out of the box with right software. There was another free alternative to SkyGrabber that runs on Linux, but I can't recall the name now.

edit: grammar

edit 2: I found it! Homepage http://sites.google.com/site/skynetr32/skynet.%3Ar32_index_e...

Screenshot: http://sites.google.com/site/skynetr32/skynetr323gh7.jpg

Re: Insurgents Hack U.S. Drones

#25
Part of the problem is that the military awards contracts that are sometimes decades long. What was "good enough" security in 1990 is not looking so hot 20 years on. The US military machine may not perform as well as it has in the past in the new era of betas, hotfixes and patches.

I will not be at all surprised when insurgent "rc-plane" drones start showing up with cell phones, arduinos, grenades and duct-tape.

Re: Insurgents Hack U.S. Drones

#26
post #16

The potential drone vulnerability lies in an unencrypted downlink between the unmanned craft and ground control. The U.S. government has known about the flaw since the U.S. campaign in Bosnia in the 1990s, current and former officials said. But the Pentagon assumed local adversaries wouldn't know how to exploit it, the officials said.

This is actually a deeper problem - we (the US/UK/Western world) assumes the middle east doesn't have the same level of technical competency as us.

Iran is a pretty well educated country, and while Iraq and Afghanistan doesn't have the same level of education in the tech/science areas, there are many sympathizers who are well educated -- including educated in UK, US, etc.

There's actually a lot of comparisons to be drawn here with startup culture vs big business. Once again the smaller, less resourced are able to bring down the big players by being more nimble and not feeling the need to build everything "in house".

To the "in house" point - the US probably spent high $100ks of mine and other tax payers money building viewing software for these drones vs the insurgents who use $25 Russian shareware. Now, I'm not saying that the government should be running SkyCatcher to view streams - but I bet they didn't include opensource options into their video viewer solution that would have saved $$$ in upfront and ongoing maintenance costs.

Re: Insurgents Hack U.S. Drones

#27
post #15
post #6

I have a thought. How about next time the military just flies one of these things down to Defcon and lets people have a go. The hackers get a cool toy to play with a for a day and the military gets a free fairly sophisticated penetration test. I'm sure the flaw would have been found; instructions on how to intercept satellite data with about $100 worth of hardware have been floating around for years. I'll edit this p…

The article said that people knew the potential existed since the mid 90's so the problem was't ignorance it was arrogance and apathy.

Oldest mistake in the book: since the adversaries dress differently, speak a different language, and are a different race, assume they must be idiots.

The WSJ reporter fell into the same trap: Iraqis and Afghans couldn't have figured out how to tap a video feed on their own; they must have had Iranian help.

Re: Insurgents Hack U.S. Drones

#28
post #27
post #15

Earlier quoted context omitted.

The article said that people knew the potential existed since the mid 90's so the problem was't ignorance it was arrogance and apathy.

Oldest mistake in the book: since the adversaries dress differently, speak a different language, and are a different race, assume they must be idiots. The WSJ reporter fell into the same trap: Iraqis and Afghans couldn't have figured out how to tap a video feed on their own; they must have had Iranian help.

Well by that reasoning the reporter should think the Iranian's are idiots as well so what you're saying makes no sense.

Re: Insurgents Hack U.S. Drones

#29
post #16

The potential drone vulnerability lies in an unencrypted downlink between the unmanned craft and ground control. The U.S. government has known about the flaw since the U.S. campaign in Bosnia in the 1990s, current and former officials said. But the Pentagon assumed local adversaries wouldn't know how to exploit it, the officials said.

Wow, It's amazing they couldn't fix this over the last decade. Even a simple obfuscation, anything is better than raw data that is so easily viewable and worse verifiable. I would assume there is plenty of people with experience encrypting and decrypting radio / satellite signals for the military in the US. Maybe the problem lies in it not being a software problem, but rather some horrid design that relegates it to hardware.

Either way now that this is public knowledge it needs to be fixed appropriately.

Re: Insurgents Hack U.S. Drones

#30
If there is prosecution for bad designers, the people who used off-the-shelf unencrypted solutions for a military device in the 21st century should be put in prison. They just cost taxpayers much more money if not actual lives on the ground.

This is the equal of having an open directory on a website and saying it doesn't matter because no-one will know what the domain or ip is. Security-by-obscurity is asinine, someone can always figure out what you've done.

This also strikes me as a great way to insist on more budget money when you've been told you won't get any more money - throw some fear, uncertainty and doubt at it.

Post reply on HN