# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 9 August 2015 |
| Platform | Quiet Systems |
| Series | DC-Y-2015 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

DEF CON 23 flips the object: unauthenticated civil GPS and consumer Phantom 3 / Bebop services can move or ground the airframe. A third talk is policy only. Black Hat USA, Europe, and Asia are NIL.

### Key judgments

1. **[Assessment — High confidence]** Unicorn Team’s SDR GPS work and Robinson / Mitchell’s consumer-drone talk are the first leftover-inventory venue signals that treat the airframe as the victim. Civil GPS L1 C/A is unauthenticated by design; no vendor CVE was assigned to the GPS talk.
2. **[Assessment — High confidence]** Robinson / Mitchell establish that consumer DJI Phantom 3 and Parrot Bebop accept GNSS / Wi-Fi / magnetometer disruption and expose unauthenticated host services on aircraft Wi-Fi, so flight can be forced down or the airframe taken over without a paired controller. No CVE or Exploit-DB ID was found.
3. **[Inference — Moderate confidence]** The Cagle / Cheng policy talk does not change the technical trust path. Absence of a patch identifier is not evidence vendors closed GNSS or host-service trust before this cutoff.

## 01. Huang / Yang: unauthenticated civil GPS lets an SDR displace vehicle and DJI geofence fixes

*Event / publication dates: presented 7 August 2015 (Friday 15:00 PT), DEF CON 23, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | dependency |
| Product | Civil GPS L1 C/A (unauthenticated by design); DJI geofence / no-fly logic and other vehicle GNSS as demonstrated objects |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Lin Huang and Qing Yang (Unicorn Team, Qihoo 360) presented “Low-cost GPS simulator – GPS spoofing by SDR” at DEF CON 23. The DC23 archive, media.defcon.org slides, media.defcon.org video, and InfoconDB are the primary record. eWeek, Forbes (Brewster; Olson), and RTL-SDR.com covered the talk, including drone GPS consequence. Speakers said they integrated existing open-source GPS / SDR projects; no dedicated Unicorn Team repo URL was verified with the talk. No CVE, advisory, or Exploit-DB ID was found.

**Exposure.** Sense: the navigation fix is a lie. Move: a displaced fix can move a vehicle or a DJI geofence / no-fly decision. Act follows whatever the autopilot does with a false position, including hold, RTH, or boundary logic.

**Intelligence assessment.** [Assessment — High confidence] The failure class is a protocol property of unauthenticated civil GNSS, not a one-vendor bug. [Assessment — High confidence] Named outlets corroborate a drone / geofence demonstration. [Uncertainty] No talk-released repo URL is verified. [Inference — Moderate confidence] Any Passport that only records “GPS lock valid” is incomplete without authenticated PNT or out-of-band position checks.

**Opportunity.** Passport civil GNSS as unauthenticated L1 C/A unless a receiver proves otherwise. Lab geofence and RTH behavior under a false fix (consequence, not a recipe). Kestrel DJI against other vehicle GNSS shown in the same talk class. Watch for a CVE that will not appear in this window.

**LRRK relevance.** Sense-Move-Act on the navigation dependency. Control Fabric for any stack that treats GNSS as trusted truth. Passport and Lab. Watch. KAT: RF at L1 → receiver fix → autopilot mode / geofence.

**Confidence.** High on the talk, slides, video, and design property. Moderate on which DJI firmware builds matched the demo. Low on a vendor patch — none is published.

## 02. Robinson / Mitchell: consumer Phantom 3 / Bebop accept disruption and expose unauthenticated host services

*Event / publication dates: DEF CON 23, 6–9 August 2015, Las Vegas (official YouTube upload 25 December 2015 is after-record).*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | software |
| Product | DJI Phantom 3; Parrot Bebop |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Michael Robinson and Alan Mitchell presented “Knocking my neighbor’s kid’s cruddy drone offline” at DEF CON 23. media.defcon.org holds the updated slides and the video. The DC23 archive and index list the conference. Failure class: consumer DJI Phantom 3 / Parrot Bebop accept GNSS / Wi-Fi / magnetometer disruption and expose unauthenticated host services on the aircraft Wi-Fi, so flight can be forced down or the airframe taken over without a paired controller. No CVE, Exploit-DB ID, or GitHub research repo was found.

**Exposure.** Move: flight forced down or the airframe taken over. Sense: GNSS and magnetometer as disrupted inputs. Act: unauthenticated host services on the aircraft become a path to the vehicle without the paired controller.

**Intelligence assessment.** [Assessment — High confidence] This is the first leftover-inventory DEF CON talk that names Phantom 3 and Bebop as victims. [Assessment — High confidence] Exploit status is public writeup, not catalogued and not reported in the wild in this inventory. [Uncertainty] No vendor advisory identifier was found, so patch state is none, not “quietly fixed.”

**Opportunity.** Passport Phantom 3 and Bebop Wi-Fi host-service authentication and GNSS / magnetometer trust. Kestrel against Hill 2013 (same family as collector) and Luo 2016 (Phantom 3 as multi-vector victim). Campaign consumer Wi-Fi aircraft as one class.

**LRRK relevance.** Control Fabric, Passport, Watch, Lab. Sense-Move-Act on named consumer airframes. KAT: aircraft Wi-Fi / GNSS / magnetometer → flight state.

**Confidence.** High on the talk, slides, and video. Moderate as a patch case — no advisory to close against.

## 03. Cagle / Cheng: civilian UAS policy gap, not a command-link disclosure

*Event / publication dates: DEF CON 23, 6–9 August 2015, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | hardware |
| Product | Civilian UAS (policy object; no SKU disclosure) |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | none public |

**Verified record — [Fact — A1]** Matt Cagle and Eric Cheng presented “Who Will Rule the Sky? The Coming Drone Policy Wars” at DEF CON 23. media.defcon.org holds the video. The DC23 archive lists the conference. Failure class is a policy / regulatory gap around civilian UAS, not a technical command-link or GNSS failure. No CVE, advisory, Exploit-DB ID, or GitHub research repo was found.

**Exposure.** Policy around who may fly, not a Sense-Move-Act trust failure in software, firmware, or a datalink. No patch applies.

**Intelligence assessment.** [Assessment — High confidence] The talk is in-scope as a DEF CON UAS record and out of scope as a vulnerability disclosure. [Inference — Low confidence] Regulatory debate may change update or identification duties later; nothing in this record shows a 2015 technical control change.

**Opportunity.** Watch policy only when it changes patch access, remote ID, or update trust. Do not map this talk to a CWE or exploit status other than none public.

**LRRK relevance.** Watch. Not Control Fabric. Campaign separately from GNSS and host-service failures in signals 01–02.

**Confidence.** High on the talk existing. High that it is not a technical disclosure.

## Forward indicators

1. A vendor advisory or CVE on Phantom 3, Bebop, or civil-GNSS receivers after this cutoff.
2. Recurrence of SDR GNSS talks that name RTH / geofence / autopilot mode as the physical consequence.
3. A Black Hat USA / Europe / Asia kinematic briefing (all NIL in 2015).
4. MAVLink / ArduPilot / Pixhawk command-link talks — still NIL on these stages.

> **Collection integrity.** Searched media.defcon.org DEF CON 23 presentations, video-and-slides, and villages; defcon.org DC23 archive, index, and village-talks page; Black Hat USA 2015 briefings; Black Hat Asia 2015 briefings and schedule; Black Hat Europe 2015 listings; InfoconDB; eWeek, Forbes, RTL-SDR.com. Three counted talks, all DEF CON 23. Black Hat USA / Europe / Asia 2015 are NIL. DEF CON 23 villages are NIL for UAV / GNSS-vehicle / MAVLink / DJI / Parrot talks. SkyJack remains out of venue. Humphreys / UT Austin stayed out. HOPE, Nullcon 2015 Rahul Sasi, THOTCON / GrrCON / CODE BLUE, ADS-B / ATC, and car CAN talks stayed out. No invented talks. No exploit steps. CVE / Exploit-DB: none found. No dedicated Unicorn Team repo URL verified with the GPS talk.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
