# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 5 December 2019 |
| Platform | Quiet Systems |
| Series | DC-Y-2019 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

2019 is the first year in this window where Sense itself is the failure: unauthenticated civil GNSS can force an unmanned ground vehicle off its lane, RF C-UAS tuned to DJI OcuSync / Lightbridge miss other swarm airframes, and consumer Wi-Fi drone control planes are gathered into a public console at Black Hat Europe Arsenal.

### Key judgments

1. **[Assessment — High confidence]** Unauthenticated civil GNSS is sufficient, in a legally constrained mobile test, to drive a UGV off-lane, off-road, or to a stop. SwRI presented that result at Black Hat USA and again at the DEF CON 27 Car Hacking Village.
2. **[Assessment — High confidence]** RF C-UAS detectors trained on DJI OcuSync / Lightbridge do not cover small or non-DJI swarm airframes that use other command links (DroneWarz “SWARM”).
3. **[Inference — Moderate confidence]** A Passport that records “GNSS locked” or “DJI-band C-UAS present” without a Lab of authenticity or non-DJI links will overstate Sense and Act.

## 01. Unauthenticated civil GNSS drives a UGV off its lane

*Event / publication dates: Black Hat USA 2019 Briefings 7 August 2019, 10:30 PT (25 min); DEF CON 27 Car Hacking Village, August 2019. Same research; one signal.*

| Field | Value |
| --- | --- |
| Venue | Black Hat USA / village |
| Component | dependency |
| Product | civil GNSS as used by an unmanned ground vehicle (Southwest Research Institute test) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Victor Murray (Southwest Research Institute) presented “Legal GNSS Spoofing and its Effects on Autonomous Vehicles” at Black Hat USA 2019 Briefings and “Legal Over-the-Air Spoofing of GNSS and its Effects on Autonomous Vehicles” at the DEF CON 27 Car Hacking Village. Official / index: InfoconDB BH USA 2019 entry. After-record: Black Hat USA-19 Wednesday white paper PDF (i.blackhat.com); YouTube gxwkovHh3Ac; media.defcon.org DC27 Car Hacking Village video; TIB AV-Portal 48571; PCMag coverage; SwRI Technology Today. Failure class: unauthenticated civil GNSS lets a mobile, legally constrained spoofing system force an unmanned ground vehicle off-lane, off-road, or to a stop. No CVE, advisory, Exploit-DB ID, or GitHub research repo was found.

**Exposure.** Sense (position/time from civil GNSS) collapses into Move (path and stop). The vehicle acts on a false location. This is a dependency failure, not a vendor autopilot CVE.

**Intelligence assessment.** [Assessment — High confidence] The two venues are one SwRI finding. [Assessment — High confidence] The physical consequence is on the record: off-lane, off-road, or stopped. [Uncertainty] Which UGV stack and receiver SKU were used is not turned into a CVE. [Inference — Moderate confidence] Any UAV, UGV, or dock that treats civil GNSS as an integrity source shares this class until authenticity is Passport-ed.

**Opportunity.** Passport GNSS authenticity (civil-only vs authenticated / fused). Lab off-lane and stop behavior under a legally constrained spoof, not a protocol recipe. Watch for a CNA ID; none exists in this window. Kestrel across GNSS-dependent UGVs and UAVs as one dependency class.

**LRRK relevance.** Sense-Move-Act. Dependency on the kinematic path. Watch and Lab. Campaign GNSS-dependent vehicles as one class. Control Fabric is downstream: a false Sense becomes a false Move. KAT: GNSS input → navigation law → path.

**Confidence.** High on the briefing PDF, village video, and named outlets. Moderate as a case for every civil-GNSS vehicle. Low on unlisted receiver SKUs.

## 02. DJI-tuned RF C-UAS miss non-DJI swarm airframes

*Event / publication dates: August 2019, DEF CON 27 DroneWarz Village program.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | hardware |
| Product | RF C-UAS detectors tuned to DJI OcuSync / Lightbridge |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Ryan Schonfeld and Jeff Parisi (RAS) presented “SWARM” at the DEF CON 27 DroneWarz Village. Official village page: defcon.org DC27 villages. After-record: media.defcon.org DC27 DroneWars Village video. Failure class: RF C-UAS detectors tuned to DJI OcuSync / Lightbridge miss small or non-DJI swarm airframes that use other command links. No CVE, Exploit-DB ID, or GitHub research repo was found.

**Exposure.** Sense (RF C-UAS detect) fails; Move (the swarm continues) and Act (stop / cue) never start. The gap is detector training, not a DJI CVE.

**Intelligence assessment.** [Assessment — High confidence] The titled DroneWarz talk exists and states a DJI-band coverage hole. [Uncertainty] Detector vendor names and swarm-radio types are not independently listed as a CVE set. [Inference — Moderate confidence] C-UAS Campaigns that Lab only OcuSync / Lightbridge will report false Sense on mixed fleets.

**Opportunity.** Passport C-UAS RF coverage by link family, including non-DJI. Lab a mixed swarm, not a single DJI airframe. Watch DroneWarz for a later titled technical talk; this is the 2019 recorded item.

**LRRK relevance.** Watch and Lab. C-UAS Sense on the Control Fabric of someone else’s airframe. Kestrel DJI-tuned vs other-link detectors. Sense-Move-Act: missed Sense, so no Act.

**Confidence.** High on the village video. Moderate as a market-wide C-UAS claim. Low on unnamed detector SKUs.

## 03. Consumer Wi-Fi drone control planes land in a public console

*Event / publication dates: 5 December 2019, Black Hat Europe 2019 Arsenal (London).*

| Field | Value |
| --- | --- |
| Venue | Black Hat EU |
| Component | software |
| Product | Hobbico C-me and Flitt at release; Parrot and DJI listed as planned (DroneSploit) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Alexandre D'Hondt and Yannick Pasquazzo presented “Drone Hacking with DroneSploit” at Black Hat Europe 2019 Arsenal. Official page: blackhat.com/eu-19/arsenal/schedule (entry 18217). After-record: Praxisec post 5 December 2019; PortSwigger Daily Swig coverage of the Arsenal demo; GitHub repository https://github.com/dhondta/dronesploit (Black Hat Europe Arsenal 2019 badge and slides linked from the repo). Failure class: consumer drone Wi-Fi / app control planes are gathered into a public pentest console. No CVE and no Exploit-DB ID were found. This filing records the named console and the named products as status only.

**Exposure.** Control Fabric on consumer airframes: the existing Wi-Fi / app command path. Move and Act on a toy or prosumer quad if that path is reachable. Not a protocol CVE.

**Intelligence assessment.** [Assessment — High confidence] The Arsenal slot, the Praxisec after-record, the Daily Swig writeup, and the named GitHub repo exist. [Assessment — High confidence] Scope at release is Hobbico C-me and Flitt; Parrot and DJI are listed as planned, not as completed CVE work. [Uncertainty] Whether a given fielded build still exposes the same Wi-Fi / app plane is a Passport question, not settled by the Arsenal page. [Inference — Moderate confidence] Consumer Wi-Fi command planes will keep appearing in public consoles until pairing and command authentication are default.

**Opportunity.** Passport those SKUs for authenticated pairing vs open Wi-Fi command. Lab only to verify a vendor fix, not to reproduce a console workflow. Watch the GitHub repo for later module claims; do not treat “planned” as a finding.

**LRRK relevance.** Control Fabric. Watch the public console as a status object. Campaign consumer Wi-Fi quads as one class. Lab pairing and command authentication. KAT: app/Wi-Fi plane → flight controller.

**Confidence.** High on the Arsenal page and the named repo. Moderate on planned Parrot / DJI coverage. Low on untested SKUs.

## Forward indicators

1. A CNA / NVD ID for civil-GNSS integrity on vehicles (none in this window).
2. C-UAS vendors stating non-DJI / swarm-link coverage with a Lab-able claim.
3. DroneSploit repo: completed Parrot or DJI modules vs “planned” (status only).
4. Whether DEF CON 28 carries kinematic content on the main stage (DC27 main stage was NIL).
5. Any Exploit-DB ID tied to these four talks (none found).

> **Collection integrity.** Public sources only. Inventory leftover for 2019: four talks, used as three signals (SwRI GNSS at Black Hat USA and the Car Hacking Village is one research program). Collection cutoff is the last day of Black Hat Europe 2019, 5 December 2019 (Arsenal date on the inventory). DEF CON 27 Sunday was 11 August 2019; BH Europe is the later in-scope conference. Searched: media.defcon.org DC27 presentations and video-and-slides (main stage NIL for drone / UAV / GNSS-vehicle / MAVLink); DC27 villages; Black Hat USA 2019 briefings and Arsenal schedule (JS shell; no additional kinematic Arsenal title via InfoconDB or named outlets); Black Hat Europe 2019 briefings (NIL; Arsenal item only); Black Hat Asia 2019 briefings (NIL); IoT / Wireless / Hardware Village 2019 (NIL). Car Hacking Village GNSS item is in scope because the object is GNSS of vehicles. **Village note.** No brand named “Drone Village” in 2017–2021. DroneWarz is the DEF CON drone village (full village DC26–DC27). Aerospace Village has not started (begins DC28 Safe Mode, 2020). **Excluded:** Aerospace manned-aviation / space (not yet a DC village this year); DroneWarz cage / CTF without a titled recorded talk; paid trainings; HOPE / SAINTCON / Nuit du Hack / Codemotion; pre-window Luo / Rodday. No invented talks. No CVE or Exploit-DB ID invented. GitHub copied from inventory only (dhondta/dronesploit). No exploit steps, payloads, or console recipes.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
