LC-2 · Software Danger Reports
LrrK Def Cuts
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Def Cuts **LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems. | Field | Value | | --- | --- | | Collection cutoff | 12 December 2024 | | Platform | Quiet Systems | | Series | DC-Y-2024 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF DEF CON 32 moved the kinematic record into Aerospace Village. Four unique titled items: GNSS time spoofing that can void certificates and ground an aircraft, Android GCS as a widened control plane, a lab ArduPilot / MAVLink simulator, and an introductory survey. Black Hat 2024 briefings were NIL. Main track was NIL. ### Key judgments 1. **[Assessment — High confidence]** Four unique titled village items are the entire 2024 verified set. The Damn Vulnerable Drone workshop given at Red Team Village and again at Aerospace Village is one item. 2. **[Assessment — High confidence]** DEF CON 32 main-track speakers, IoT / Hardware / RF village pages, Aerospace Village manned-aviation and space talks, and Black Hat USA / Europe / Asia 2024 briefing landings added no in-scope title. 3. **[Inference — Moderate confidence]** The decision-relevant 2024 signal is Sense: GNSS time as a certificate and airworthiness dependency, not a new airframe CVE. ## 01. GNSS time spoofing can void certificates and ground an aircraft *Event / publication dates: Saturday 10 August 2024, 12:30 PT, DEF CON 32 Aerospace Village, Creator Stage 3.* | Field | Value | | --- | --- | | Venue | village | | Component | dependency | | Product | GNSS-disciplined aircraft time and onboard certificates (no named vendor product) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** Ken Munro presented *GPS spoofing: it's about time, not just position* on the Aerospace Village DEF CON 32 talk schedule (`https://www.aerospacevillage.org/defcon-32-talk-schedule`). Failure class on that record: GNSS time spoofing (forward clock roll) can void onboard certificates and ground an aircraft even when operators only expect position spoofing. No CVE, advisory, Exploit-DB ID, or GitHub repo was published with the talk. An after-record video exists on the DEF CON channel (`https://www.youtube.com/watch?v=wSVdfOn737o`). **Exposure.** Sense: vehicle time is a GNSS product, not only a position product. Act: a voided certificate can take a craft out of service — a physical grounding — without a successful position hijack. **Intelligence assessment.** [Assessment — High confidence] This is the 2024 talk that names a kinematic Sense failure with a stated physical consequence. [Uncertainty] No vendor, aircraft type, or CVE is on the village page. [Inference — Moderate confidence] Passports that record “GNSS anti-spoof” as position-only miss the time-to-certificate path. **Opportunity.** Passport whether onboard identity and airworthiness certs are disciplined to GNSS time, and what happens on a forward clock roll. Watch vendor responses that treat spoofing as a navigation-only event. Lab the certificate-validity outcome, not a spoof recipe. **LRRK relevance.** Sense and Passport. Watch on GNSS-time assumptions in Control Fabric (any signing or cert that trusts vehicle clocks). Kestrel the same GNSS-time dependency across airframes that share a cert stack. Sense-Move-Act: Sense fails first; Act is the grounding. **Confidence.** High on the village schedule and stated failure class. Moderate as a product case: no named type or CVE. ## 02. Android GCS and companion apps widen the drone control plane *Event / publication dates: Saturday 10 August 2024, 12:00 PT (1 hour), DEF CON 32 Aerospace Village workshop.* | Field | Value | | --- | --- | | Venue | village | | Component | software | | Product | DJI Android-based GCS stacks; QGroundControl; Mission Planner | | CVE / advisory | no CVE | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Jonathan Waterman presented *Secure the Skies: A Modern Android Security Research Framework for Drone Ground Control Stations and Applications* on the Aerospace Village DEF CON 32 workshop schedule (`https://www.aerospacevillage.org/defcon-32-workshop-schedule`). Failure class on that page: Android GCS and companion apps, including DJI Android-based stacks and open GCS such as QGroundControl / Mission Planner, widen the drone control-plane attack surface beyond the airframe. No CVE, advisory, Exploit-DB ID, or GitHub repo was published with the talk. No after-record URL was found as of inventory collection. **Exposure.** Move and Act sit in the handset and companion app, not only in the autopilot. A compromised GCS can command or inhibit the vehicle without a new airframe flaw. **Intelligence assessment.** [Assessment — High confidence] The village page names the control-plane shift and the product classes (DJI Android stacks, QGroundControl, Mission Planner). [Uncertainty] No CVE or patched build is attached. [Inference — Moderate confidence] Passports that stop at the airframe firmware hash miss the Android GCS as a kinematic trust node. **Opportunity.** Passport GCS package identity, update channel, and whether the app is treated as in-scope with the airframe. Kestrel the same Android GCS family across mixed DJI and open-stack fleets. Lab the app-to-vehicle command path as a trust boundary, without a how-to. **LRRK relevance.** Control Fabric and Passport on the GCS. Campaign and Watch for any operation that assumes the phone is outside the vehicle trust path. Sense-Move-Act: Move and Act are commanded from the ground application. **Confidence.** High on the workshop page and named product classes. Low as a vulnerability case: no CVE and no after-record. ## 03. Lab simulator restates unauthenticated ArduPilot / MAVLink command and telemetry *Event / publication dates: Friday 9 August 2024, 13:00 PT, DEF CON 32 Red Team Village Track 4; Saturday 10 August 2024, 13:30 PT, Aerospace Village workshop. One titled research item, two rooms.* | Field | Value | | --- | --- | | Venue | village | | Component | software | | Product | Damn Vulnerable Drone (ArduPilot / MAVLink lab simulator) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** Nick Aleks and Rudy Mendoza presented *Open Source Drone Hacking Simulator* (Aerospace Village) / *Simulated Drone Hacking* (Red Team Village). Official Aerospace Village workshop page: `https://www.aerospacevillage.org/defcon-32-workshop-schedule`. The village page links `https://github.com/nicholasaleks/Damn-Vulnerable-Drone` as a named lab repo. Failure class on the record: simulated ArduPilot / MAVLink stacks are used to teach known unauthenticated command-and-telemetry failure classes in a lab, not a live product CVE. No CVE, advisory, or Exploit-DB ID. No after-record URL was found as of inventory collection. **Exposure.** Move and Act on a simulated vehicle: unauthenticated command and telemetry are the failure class. The physical consequence on a live unsigned stack of the same class is unauthorized mission change, inhibit, or crash. This filing records the class, not a procedure. **Intelligence assessment.** [Assessment — High confidence] The two village listings are one item. [Assessment — High confidence] The GitHub name is a lab simulator record, not a vendor advisory. [Inference — Moderate confidence] Operators who treat “lab only” as “not our stack” will miss that ArduPilot / MAVLink unsigned command-and-telemetry is the same Control Fabric class on live vehicles. **Opportunity.** Passport whether a fielded ArduPilot / MAVLink link refuses unsigned command and telemetry. Lab the simulator as a teaching aid for that Passport question. Do not treat a public lab repo as evidence of a new product CVE. **LRRK relevance.** Control Fabric and Lab. KAT from radio or GCS peer to autopilot command handler. Kestrel unsigned MAVLink across ArduPilot-family fleets. Sense-Move-Act: Move and Act are the commanded functions. **Confidence.** High that the workshop and repo exist as named records. Moderate that any given live fleet still accepts the taught class — that is a Passport question, not a talk fact. ## 04. Introductory drone-security survey names no product CVE *Event / publication dates: Saturday 10 August 2024, 10:30 PT (1 hour), DEF CON 32 Aerospace Village workshop.* | Field | Value | | --- | --- | | Venue | village | | Component | software | | Product | UAS hardware, firmware, and protocols (survey; no named product) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Hahna Kane Latonick presented *Introduction to Drone Security* on the Aerospace Village DEF CON 32 workshop schedule (`https://www.aerospacevillage.org/defcon-32-workshop-schedule`). Failure class on that page: introductory survey of UAS hardware, firmware, and protocol risk — no named product CVE on the village page. No Exploit-DB ID, no GitHub repo published with the talk, no after-record URL as of inventory collection. **Exposure.** Survey only. No named Sense, Move, or Act failure on a stated product. Useful as a village marker that UAS security was taught, not as a vulnerability record. **Intelligence assessment.** [Assessment — High confidence] The page is a survey listing, not a CVE or advisory. [Uncertainty] Slide contents were not on a public after-record at collection. [Inference — Low confidence] Any product-specific claim attributed to this hour without slides is unverified. **Opportunity.** If slides or video land, re-score for named products or CVEs. Until then, do not Passport a fleet from this title. **LRRK relevance.** Lab and Watch as a teaching marker. Not a Campaign or Control Fabric finding on its own. **Confidence.** High that the workshop was scheduled. Low as a software-danger case. ## Forward indicators 1. Vendor or airworthiness response to GNSS-time spoofing as a certificate-validity event, not only a position event. 2. A CVE or after-record for the Waterman Android GCS workshop that names a package or patched build. 3. After-record slides or video for the Aleks / Mendoza simulator and the Latonick survey (none found at collection). 4. A Black Hat 2024 briefing page that later posts an in-scope UAS title (briefing landings were NIL). 5. Evidence that a fielded ArduPilot / MAVLink fleet refuses unsigned command and telemetry — the Passport that turns the lab class into a fleet fact. > **Collection integrity.** Public sources only. No invented talks. No exploit steps, PoCs, or payloads. Also searched in 2024 and excluded: Aerospace Village *Fly Catcher* (ADS-B spoof *detection* for manned traffic) and other aviation/space talks; DEF CON 32 main-track speaker list (no drone / UAV / MAVLink / PX4 title); IoT / Hardware / RF village pages. The DVD workshop appears twice (Red Team Village Friday 9 August; Aerospace Village Saturday 10 August) and is filed as one signal. Black Hat USA / Europe / Asia briefings 2022–2026: NIL. Excluded as not talks or not in filter: paid trainings; Drone Zone or cage/CTF activities without a named talk; manned-aviation datalinks (CPDLC, AFDX, TCAS, ADS-B-only); satellite / space-mission talks without a vehicle GNSS or UAS datalink focus. Last in-scope conference day 2024 is Black Hat Europe, 12 December 2024. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>