← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Def Cuts

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/Def Cuts/years/2024.md
Imported-content SHA-256
51ac56db6d7e52bddcc6a8c8cbe74a85185da176eff10778f859cc1e62364cf0
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 12 December 2024 |
| Platform | Quiet Systems |
| Series | DC-Y-2024 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

DEF CON 32 moved the kinematic record into Aerospace Village. Four unique titled items: GNSS time spoofing that can void certificates and ground an aircraft, Android GCS as a widened control plane, a lab ArduPilot / MAVLink simulator, and an introductory survey. Black Hat 2024 briefings were NIL. Main track was NIL.

### Key judgments

1. **[Assessment — High confidence]** Four unique titled village items are the entire 2024 verified set. The Damn Vulnerable Drone workshop given at Red Team Village and again at Aerospace Village is one item.
2. **[Assessment — High confidence]** DEF CON 32 main-track speakers, IoT / Hardware / RF village pages, Aerospace Village manned-aviation and space talks, and Black Hat USA / Europe / Asia 2024 briefing landings added no in-scope title.
3. **[Inference — Moderate confidence]** The decision-relevant 2024 signal is Sense: GNSS time as a certificate and airworthiness dependency, not a new airframe CVE.

## 01. GNSS time spoofing can void certificates and ground an aircraft

*Event / publication dates: Saturday 10 August 2024, 12:30 PT, DEF CON 32 Aerospace Village, Creator Stage 3.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | dependency |
| Product | GNSS-disciplined aircraft time and onboard certificates (no named vendor product) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Ken Munro presented *GPS spoofing: it's about time, not just position* on the Aerospace Village DEF CON 32 talk schedule (`https://www.aerospacevillage.org/defcon-32-talk-schedule`). Failure class on that record: GNSS time spoofing (forward clock roll) can void onboard certificates and ground an aircraft even when operators only expect position spoofing. No CVE, advisory, Exploit-DB ID, or GitHub repo was published with the talk. An after-record video exists on the DEF CON channel (`https://www.youtube.com/watch?v=wSVdfOn737o`).

**Exposure.** Sense: vehicle time is a GNSS product, not only a position product. Act: a voided certificate can take a craft out of service — a physical grounding — without a successful position hijack.

**Intelligence assessment.** [Assessment — High confidence] This is the 2024 talk that names a kinematic Sense failure with a stated physical consequence. [Uncertainty] No vendor, aircraft type, or CVE is on the village page. [Inference — Moderate confidence] Passports that record “GNSS anti-spoof” as position-only miss the time-to-certificate path.

**Opportunity.** Passport whether onboard identity and airworthiness certs are disciplined to GNSS time, and what happens on a forward clock roll. Watch vendor responses that treat spoofing as a navigation-only event. Lab the certificate-validity outcome, not a spoof recipe.

**LRRK relevance.** Sense and Passport. Watch on GNSS-time assumptions in Control Fabric (any signing or cert that trusts vehicle clocks). Kestrel the same GNSS-time dependency across airframes that share a cert stack. Sense-Move-Act: Sense fails first; Act is the grounding.

**Confidence.** High on the village schedule and stated failure class. Moderate as a product case: no named type or CVE.

## 02. Android GCS and companion apps widen the drone control plane

*Event / publication dates: Saturday 10 August 2024, 12:00 PT (1 hour), DEF CON 32 Aerospace Village workshop.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | software |
| Product | DJI Android-based GCS stacks; QGroundControl; Mission Planner |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | none public |

**Verified record — [Fact — A1]** Jonathan Waterman presented *Secure the Skies: A Modern Android Security Research Framework for Drone Ground Control Stations and Applications* on the Aerospace Village DEF CON 32 workshop schedule (`https://www.aerospacevillage.org/defcon-32-workshop-schedule`). Failure class on that page: Android GCS and companion apps, including DJI Android-based stacks and open GCS such as QGroundControl / Mission Planner, widen the drone control-plane attack surface beyond the airframe. No CVE, advisory, Exploit-DB ID, or GitHub repo was published with the talk. No after-record URL was found as of inventory collection.

**Exposure.** Move and Act sit in the handset and companion app, not only in the autopilot. A compromised GCS can command or inhibit the vehicle without a new airframe flaw.

**Intelligence assessment.** [Assessment — High confidence] The village page names the control-plane shift and the product classes (DJI Android stacks, QGroundControl, Mission Planner). [Uncertainty] No CVE or patched build is attached. [Inference — Moderate confidence] Passports that stop at the airframe firmware hash miss the Android GCS as a kinematic trust node.

**Opportunity.** Passport GCS package identity, update channel, and whether the app is treated as in-scope with the airframe. Kestrel the same Android GCS family across mixed DJI and open-stack fleets. Lab the app-to-vehicle command path as a trust boundary, without a how-to.

**LRRK relevance.** Control Fabric and Passport on the GCS. Campaign and Watch for any operation that assumes the phone is outside the vehicle trust path. Sense-Move-Act: Move and Act are commanded from the ground application.

**Confidence.** High on the workshop page and named product classes. Low as a vulnerability case: no CVE and no after-record.

## 03. Lab simulator restates unauthenticated ArduPilot / MAVLink command and telemetry

*Event / publication dates: Friday 9 August 2024, 13:00 PT, DEF CON 32 Red Team Village Track 4; Saturday 10 August 2024, 13:30 PT, Aerospace Village workshop. One titled research item, two rooms.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | software |
| Product | Damn Vulnerable Drone (ArduPilot / MAVLink lab simulator) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Nick Aleks and Rudy Mendoza presented *Open Source Drone Hacking Simulator* (Aerospace Village) / *Simulated Drone Hacking* (Red Team Village). Official Aerospace Village workshop page: `https://www.aerospacevillage.org/defcon-32-workshop-schedule`. The village page links `https://github.com/nicholasaleks/Damn-Vulnerable-Drone` as a named lab repo. Failure class on the record: simulated ArduPilot / MAVLink stacks are used to teach known unauthenticated command-and-telemetry failure classes in a lab, not a live product CVE. No CVE, advisory, or Exploit-DB ID. No after-record URL was found as of inventory collection.

**Exposure.** Move and Act on a simulated vehicle: unauthenticated command and telemetry are the failure class. The physical consequence on a live unsigned stack of the same class is unauthorized mission change, inhibit, or crash. This filing records the class, not a procedure.

**Intelligence assessment.** [Assessment — High confidence] The two village listings are one item. [Assessment — High confidence] The GitHub name is a lab simulator record, not a vendor advisory. [Inference — Moderate confidence] Operators who treat “lab only” as “not our stack” will miss that ArduPilot / MAVLink unsigned command-and-telemetry is the same Control Fabric class on live vehicles.

**Opportunity.** Passport whether a fielded ArduPilot / MAVLink link refuses unsigned command and telemetry. Lab the simulator as a teaching aid for that Passport question. Do not treat a public lab repo as evidence of a new product CVE.

**LRRK relevance.** Control Fabric and Lab. KAT from radio or GCS peer to autopilot command handler. Kestrel unsigned MAVLink across ArduPilot-family fleets. Sense-Move-Act: Move and Act are the commanded functions.

**Confidence.** High that the workshop and repo exist as named records. Moderate that any given live fleet still accepts the taught class — that is a Passport question, not a talk fact.

## 04. Introductory drone-security survey names no product CVE

*Event / publication dates: Saturday 10 August 2024, 10:30 PT (1 hour), DEF CON 32 Aerospace Village workshop.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | software |
| Product | UAS hardware, firmware, and protocols (survey; no named product) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | none public |

**Verified record — [Fact — A1]** Hahna Kane Latonick presented *Introduction to Drone Security* on the Aerospace Village DEF CON 32 workshop schedule (`https://www.aerospacevillage.org/defcon-32-workshop-schedule`). Failure class on that page: introductory survey of UAS hardware, firmware, and protocol risk — no named product CVE on the village page. No Exploit-DB ID, no GitHub repo published with the talk, no after-record URL as of inventory collection.

**Exposure.** Survey only. No named Sense, Move, or Act failure on a stated product. Useful as a village marker that UAS security was taught, not as a vulnerability record.

**Intelligence assessment.** [Assessment — High confidence] The page is a survey listing, not a CVE or advisory. [Uncertainty] Slide contents were not on a public after-record at collection. [Inference — Low confidence] Any product-specific claim attributed to this hour without slides is unverified.

**Opportunity.** If slides or video land, re-score for named products or CVEs. Until then, do not Passport a fleet from this title.

**LRRK relevance.** Lab and Watch as a teaching marker. Not a Campaign or Control Fabric finding on its own.

**Confidence.** High that the workshop was scheduled. Low as a software-danger case.

## Forward indicators

1. Vendor or airworthiness response to GNSS-time spoofing as a certificate-validity event, not only a position event.
2. A CVE or after-record for the Waterman Android GCS workshop that names a package or patched build.
3. After-record slides or video for the Aleks / Mendoza simulator and the Latonick survey (none found at collection).
4. A Black Hat 2024 briefing page that later posts an in-scope UAS title (briefing landings were NIL).
5. Evidence that a fielded ArduPilot / MAVLink fleet refuses unsigned command and telemetry — the Passport that turns the lab class into a fleet fact.

> **Collection integrity.** Public sources only. No invented talks. No exploit steps, PoCs, or payloads. Also searched in 2024 and excluded: Aerospace Village *Fly Catcher* (ADS-B spoof *detection* for manned traffic) and other aviation/space talks; DEF CON 32 main-track speaker list (no drone / UAV / MAVLink / PX4 title); IoT / Hardware / RF village pages. The DVD workshop appears twice (Red Team Village Friday 9 August; Aerospace Village Saturday 10 August) and is filed as one signal. Black Hat USA / Europe / Asia briefings 2022–2026: NIL. Excluded as not talks or not in filter: paid trainings; Drone Zone or cage/CTF activities without a named talk; manned-aviation datalinks (CPDLC, AFDX, TCAS, ADS-B-only); satellite / space-mission talks without a vehicle GNSS or UAS datalink focus. Last in-scope conference day 2024 is Black Hat Europe, 12 December 2024.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>