← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2016-03.md
Imported-content SHA-256
fe84330971b1e01cfa7a4e19754f3ff6b45c95fe71e43d8dfc7533acce58f762
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 March 2016 |
| Platform | Quiet Systems |
| Series | DKSR-M-2016-03 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

First named-conference, on-stage record that a professional UAS radio — not a toy Wi-Fi AP — is the trust boundary. Same unauthenticated-C2 class as Marty 2014.

### Key judgments

1. **[Assessment — High confidence]** RSA San Francisco 2 March 2016 (live demo; BBC / Forbes / Verge same day). Black Hat Asia briefings 31 March–1 April 2016.
2. **[Assessment — High confidence]** Same unnamed professional UAV / Digi XBee 868LP / WEP tablet hop as the 2015 thesis. No CVE. No ICS-CERT.
3. **[Uncertainty]** Manufacturer still unnamed. Do not guess.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Rodday: Hacking a Professional Drone (RSA / Black Hat Asia)

*Event / publication dates: RSA 2 March 2016. Black Hat Asia briefings 31 March and 1 April 2016. RSA week 29 February–4 March 2016*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Unnamed professional UAV using Digi XBee 868LP telemetry + WEP Wi-Fi GCS hop |
| CVE / advisory | no CVE. Digi XBee encryption existed as an unused option. |
| Patch | none as a fielded CVE. Manufacturer told press it would fix in the next-generation model. |
| Exploit status | public writeup |
| Taxonomy | CWE-306 (class) · CAPEC-272 · ATT&CK ICS T1692.001 (T0855) · OWASP IoT I2 · EMB3D TID-406 |

**Verified record — [Fact — A1] Black Hat slides https://blackhat.com/docs/asia-16/materials/asia-16-Rodday-Hacking-A-Professional-Drone.pdf · briefings https://blackhat.com/asia-16/briefings.html · UT news https://www.utwente.nl/en/news/2016/3/474324/former-dacs-student-nils-rodday-demonstrated-at-rsa-security-conference-in-san-francisco-how-to-hack-drones · [Fact — B2] BBC 2 Mar 2016 https://www.bbc.com/news/technology-35709676 · Forbes https://www.forbes.com/sites/thomasbrewster/2016/03/02/surveillance-drone-hacked/ · The Verge https://www.theverge.com/2016/3/2/11145904/drone-hijack-nils-rodday-security**

**Exposure.** Cleartext telemetry, Remote AT MITM, WEP on the tablet hop. Professional radio is the C2 bearer. Move/Act.

**Intelligence assessment.** [Assessment — High confidence] 2 March and 31 March dates. High that no CVE was assigned. Same unauthenticated C2 class as Marty; CWE-306 is class, not an NVD ID on this radio.

**Opportunity.** Passport XBee encryption enabled vs unused. Date NOMS as the archival paper (April), not a second vuln.

**LRRK relevance.** Control Fabric. Watch.

**Confidence.** High.

## Forward indicators

1. IEEE NOMS paper / demo (April 2016).
2. A named manufacturer advisory (never found).

> **Collection integrity.** Conference disclosure of the 2015-07 research line. Not a new CVE. Not padded. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>