LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 March 2016 | | Platform | Quiet Systems | | Series | DKSR-M-2016-03 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF First named-conference, on-stage record that a professional UAS radio — not a toy Wi-Fi AP — is the trust boundary. Same unauthenticated-C2 class as Marty 2014. ### Key judgments 1. **[Assessment — High confidence]** RSA San Francisco 2 March 2016 (live demo; BBC / Forbes / Verge same day). Black Hat Asia briefings 31 March–1 April 2016. 2. **[Assessment — High confidence]** Same unnamed professional UAV / Digi XBee 868LP / WEP tablet hop as the 2015 thesis. No CVE. No ICS-CERT. 3. **[Uncertainty]** Manufacturer still unnamed. Do not guess. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Rodday: Hacking a Professional Drone (RSA / Black Hat Asia) *Event / publication dates: RSA 2 March 2016. Black Hat Asia briefings 31 March and 1 April 2016. RSA week 29 February–4 March 2016* | Field | Value | | --- | --- | | Component | firmware | | Product | Unnamed professional UAV using Digi XBee 868LP telemetry + WEP Wi-Fi GCS hop | | CVE / advisory | no CVE. Digi XBee encryption existed as an unused option. | | Patch | none as a fielded CVE. Manufacturer told press it would fix in the next-generation model. | | Exploit status | public writeup | | Taxonomy | CWE-306 (class) · CAPEC-272 · ATT&CK ICS T1692.001 (T0855) · OWASP IoT I2 · EMB3D TID-406 | **Verified record — [Fact — A1] Black Hat slides https://blackhat.com/docs/asia-16/materials/asia-16-Rodday-Hacking-A-Professional-Drone.pdf · briefings https://blackhat.com/asia-16/briefings.html · UT news https://www.utwente.nl/en/news/2016/3/474324/former-dacs-student-nils-rodday-demonstrated-at-rsa-security-conference-in-san-francisco-how-to-hack-drones · [Fact — B2] BBC 2 Mar 2016 https://www.bbc.com/news/technology-35709676 · Forbes https://www.forbes.com/sites/thomasbrewster/2016/03/02/surveillance-drone-hacked/ · The Verge https://www.theverge.com/2016/3/2/11145904/drone-hijack-nils-rodday-security** **Exposure.** Cleartext telemetry, Remote AT MITM, WEP on the tablet hop. Professional radio is the C2 bearer. Move/Act. **Intelligence assessment.** [Assessment — High confidence] 2 March and 31 March dates. High that no CVE was assigned. Same unauthenticated C2 class as Marty; CWE-306 is class, not an NVD ID on this radio. **Opportunity.** Passport XBee encryption enabled vs unused. Date NOMS as the archival paper (April), not a second vuln. **LRRK relevance.** Control Fabric. Watch. **Confidence.** High. ## Forward indicators 1. IEEE NOMS paper / demo (April 2016). 2. A named manufacturer advisory (never found). > **Collection integrity.** Conference disclosure of the 2015-07 research line. Not a new CVE. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>