LC-2 · Software Danger Reports
LrrK Def Cuts
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Def Cuts **LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems. | Field | Value | | --- | --- | | Collection cutoff | 7 August 2011 | | Platform | Quiet Systems | | Series | DC-Y-2011 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF The 2011 record is one research line on two stages: a surplus target-drone plus open autopilot and XBee telemetry used as a standoff RF payload truck (WASP), briefed at Black Hat USA and again at DEF CON 19. ### Key judgments 1. **[Assessment — High confidence]** Perkins and Tassey’s WASP work is the only verified kinematic class this year. Black Hat Europe 2011 is NIL for UAV / GNSS-vehicle briefings. 2. **[Assessment — High confidence]** The failure class is the airframe as an RF truck, not a disclosed command-link takeover of a third-party UAV. No CVE, advisory, or Exploit-DB ID attaches. 3. **[Inference — Moderate confidence]** ArduPilot plus commodity XBee telemetry, shown in public as an autonomous payload bearer, is an early Control Fabric fact for later Passport work on unsigned hobby links. ## 01. Perkins / Tassey: WASP surplus drone as a standoff RF payload truck *Event / publication dates: presented 3 August 2011 (Wednesday 16:45 PT), Black Hat USA 2011, Las Vegas.* | Field | Value | | --- | --- | | Venue | Black Hat USA | | Component | hardware | | Product | WASP (Wireless Aerial Surveillance Platform); surplus target-drone airframe; open autopilot; XBee telemetry | | CVE / advisory | none found | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** Richard Perkins and Mike Tassey presented “Aerial Cyber Apocalypse: If we can do it... they can too.” on the Black Hat USA 2011 archive. Wired (August 2011), Dark Reading, and ABC News covered the same WASP build as a surplus Army-target airframe turned into a hacker RF platform. InfoconDB lists Tassey as presenter. No CVE or Exploit-DB ID was found for the talk window. **Exposure.** Sense and Act: standoff wireless / cellular collection from an autonomous airframe. Move is the delivery path (the truck), not a disclosed victim-vehicle hijack. **Intelligence assessment.** [Assessment — High confidence] Named-outlet after-record corroborates the briefing object as WASP, not a vendor bug class. [Uncertainty] The Black Hat archive page is the official listing; slide-level product pins sit with the DEF CON after-record. [Inference — Moderate confidence] A surplus airframe plus open autopilot is enough to put RF payloads over a target without a new airframe design. **Opportunity.** Passport hobby autopilot and XBee-class telemetry as unsigned bearers. Kestrel this truck class against later collector UAVs (2014 Snoopy, 2016 Danger Drone). Watch for a vendor or military statement on surplus-airframe reuse — none is in this record. **LRRK relevance.** Watch and Control Fabric. Campaign “UAV-as-RF-truck.” Lab the open-autopilot plus commodity telemetry pairing. Sense-Move-Act: the airframe moves a payload that senses. **Confidence.** High on the briefing and press after-record. Moderate as a reusable case — product versions are not pinned. ## 02. Tassey / Perkins: Wireless Aerial Surveillance Platform on ArduPilot and XBee *Event / publication dates: presented 7 August 2011 (Sunday 16:00 PT), DEF CON 19, Las Vegas.* | Field | Value | | --- | --- | | Venue | DEF CON | | Component | hardware | | Product | WASP; ArduPilot; XBee datalink | | CVE / advisory | none found | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** Mike Tassey and Rich Perkins presented “Wireless Aerial Surveillance Platform” at DEF CON 19. The DEF CON 19 archive, media.defcon.org slides, and media.defcon.org video are the primary record. InfoconDB cross-checks the title. The inventory failure class is the same WASP class as the Black Hat USA briefing: an autonomous UAV carrying wireless / cellular payloads over an ArduPilot plus XBee datalink. **Exposure.** Sense (aerial wireless / cellular payload) and Move (autonomous airframe on an open autopilot). The datalink is the control fabric for the truck, not a disclosed hijack of someone else’s craft. **Intelligence assessment.** [Assessment — High confidence] Slides plus video make this the A1 technical record of the same research briefed three days earlier at Black Hat USA. [Assessment — High confidence] No CVE, advisory, or Exploit-DB ID attaches. [Inference — Moderate confidence] Naming ArduPilot and XBee on stage is a Watch marker for later unsigned-link work, not evidence of a 2011 catalogued flaw. **Opportunity.** Lab ArduPilot plus XBee as a pair: who may speak on the telemetry bearer. Passport “open autopilot / commodity radio” as a fabric class. Kestrel against 2012 Paparazzi and later MAVLink-stage gaps (those talks are NIL in this window). **LRRK relevance.** Control Fabric, Lab, Watch. KAT path is radio and autopilot as payload truck, not victim command injection. **Confidence.** High on the talk, slides, and video. Moderate on treating ArduPilot / XBee as a standing fabric risk without a contemporaneous advisory. ## Forward indicators 1. A venue talk that treats ArduPilot, XBee, or a GCS datalink as the victim command path. 2. A CVE or vendor advisory on hobby autopilot telemetry. 3. Recurrence of surplus or low-cost airframes as RF trucks at Black Hat or DEF CON. 4. Any Black Hat Europe kinematic briefing (2011 is NIL). > **Collection integrity.** Searched media.defcon.org DEF CON 19 presentations and video-and-slides; defcon.org DC19 archive; Black Hat USA 2011 archives; Black Hat Europe 2011 archive listings and contemporaneous coverage; InfoconDB; Wired, Dark Reading, ABC News. Two counted talks are the same WASP research at two venues. Black Hat Europe 2011 is NIL. Out-of-venue items (SkyJack, Humphreys / UT Austin civil-GPS UAV capture, HOPE 2012 “Pwn the Drones,” ADS-B / ATC, car CAN) stayed out. No invented talks. No exploit steps. CVE / Exploit-DB / GitHub research repo: none found. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>