LC-2 · Software Danger Reports
LrrK Def Cuts
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Def Cuts **LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems. | Field | Value | | --- | --- | | Collection cutoff | 13 August 2023 | | Platform | Quiet Systems | | Series | DC-S-06 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF DEF CON 31’s only inventoried kinematic main-track talk is Melendez / García on disposable airframes: unprotected DIY command links stay exposed to RF denial, so frequency-hopping designs degrade C-UAS jamming. ### Key judgments 1. **[Assessment — High confidence]** David Melendez and Gabriela “Gabs” García presented *Spread spectrum techniques in disposable drones for anti drone evasion* on DEF CON 31 Track 4, 12 August 2023; official speaker page and media.defcon.org slides exist. 2. **[Assessment — High confidence]** Inventory records no CVE published with the talk, no Exploit-DB ID, and no GitHub repo published with the talk. Exploit-status: public writeup. 3. **[Inference — Moderate confidence]** The physical consequence is a disposable airframe that continues to fly under RF denial that commodity C-UAS still expect to work — a C-UAS effectiveness gap, not a named OEM flight-stack CVE. ## 01. Frequency-hopping disposable airframes degrade C-UAS RF denial *Event / publication dates: DEF CON 31 Track 4, Saturday 12 August 2023, 11:00 PT (45 min). Collection cutoff is DEF CON 31 Sunday, 13 August 2023.* | Field | Value | | --- | --- | | Venue | DEF CON | | Component | firmware | | Product | disposable DIY drones; commodity C-UAS RF denial | | CVE / advisory | none published with the talk | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** Talk title *Spread spectrum techniques in disposable drones for anti drone evasion*; speakers David Melendez and Gabriela “Gabs” García; official URL https://www.defcon.org/html/defcon-31/dc-31-speakers.html#Melendez. After-record: media.defcon.org slides (`David Melendez Gabriela Gabs García - Spread spectrum techniques in disposable drones for anti drone evasion.pdf`) and demos on the same presentations directory; DEF CON channel video cited by after-record outlets (`8Ng91UY3D2M`). **[Fact — A1]** CVE / advisory: none published with the talk. Exploit-DB ID: none found. GitHub repo: none published with the talk. Exploit-status: public writeup. **Exposure.** Control Fabric: DIY command links that remain unprotected against RF denial. Adjacent C-UAS: jamming that assumes those links stay on an expected, stoppable channel. Move: the disposable airframe continues the flight the C-UAS meant to end. Sense on the C-UAS side is a missed or degraded engagement, not a new UAV CVE. **Intelligence assessment.** **[Assessment — High confidence]** This is the sole 2023 inventoried kinematic talk (year count: 1). **[Assessment — High confidence]** Failure class is unprotected DIY command links versus frequency-hopping airframes that degrade C-UAS jamming — a defense-evasion property of the command path, not a catalogued product ID. **[Uncertainty]** InfoconDB listed a “Strix Interceptor” C-UAS demo that is not on the live DEF CON 31 speakers page and has no village primary page; it stays unrecorded. **[Inference — Moderate confidence]** Continuity with Melendez’s 2018 Interceptor / nanodrone work: C-UAS that assume a default consumer command link fail against a non-default disposable design. **Opportunity.** Passport C-UAS RF denial against non-default, hopping, disposable command links — not only against open Wi-Fi / DJI-default bearers. Campaign “jammer covers the site” as unevidenced Act. Watch for a CVE or vendor advisory this talk did not publish. Do not treat the slides or demo files as a build guide. **LRRK relevance.** Control Fabric on disposable airframes. Adjacent C-UAS effectiveness. Watch / Campaign for over-claimed RF denial. Lab the defended-volume claim, not a hopping recipe. Sense-Move-Act: C-UAS fails to stop Move. **Confidence.** High on the official DC31 speaker page, media.defcon.org slides, and the year-count of one. Moderate on YouTube as a cited after-record rather than a media.defcon.org video-and-slides file. Nil on CVE, EDB, and a talk-tied repo. ## Forward indicators 1. A C-UAS vendor advisory or third-party retest addresses frequency-hopping disposable command links as a named class. 2. A later BH/DC talk publishes a CVE or repo with this 2023 showing (inventory: none). 3. Aerospace Village or Black Hat 2023-class pages later add an in-scope kinematic title that this cutoff left NIL. > **Collection integrity.** Built from leftover inventory 2023-01 only. Official sources: defcon.org DC31 speakers (`#Melendez`); media.defcon.org DC31 presentations (slides + demos). YouTube cited only as the after-record outlet pointer already in the inventory. Aerospace Village DC31 talk list searched and excluded (space / ISS / 737 / radiosonde / satellite-comms; GPS as a satellite service, not a vehicle/UAS briefing). InfoconDB “Strix Interceptor” demo excluded (no live speakers-page or village primary). IoT / Hardware / RF village 2023: no in-scope title. Black Hat 2023 briefings: NIL. Slides, demos, and video treated as metadata; spread-spectrum recipes, command-link procedures, and payloads excluded. No invented talks. CVE / EDB / GitHub / exploit-status copied from the inventory: none published with the talk / none found / none published with the talk / public writeup. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>