← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2025-07.md
Imported-content SHA-256
ccfabd996a00c47fd7746f1e7554afca0ed2f056b246e74388ecdf9d1cd671de
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 July 2025 |
| Platform | Quiet Systems |
| Series | DKSR-M-2025-07 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

Galileo OSNMA becomes an operational service. Civil GNSS navigation messages can be authenticated by a capable receiver. This is a control, not a CVE.

### Key judgments

1. **[Assessment — High confidence]** Initial Service declared 24 July 2025 (EUSPA/ESA; EC article 22 July).
2. **[Assessment — High confidence]** OSNMA does not prevent jamming and does not by itself stop all spoofing.
3. **[Inference — Moderate confidence]** UAV Passports should grow an OSNMA-capable field; brochure support is not evidence.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Galileo OSNMA Initial Service

*Event / publication dates: Operational 24 July 2025; EC article 22 July 2025*

| Field | Value |
| --- | --- |
| Component | hardware |
| Product | Galileo Open Service (E1-B I/NAV) OSNMA; any capable GNSS receiver |
| CVE / advisory | no CVE |
| Patch | not applicable (new service) |
| Exploit status | not applicable |

**Verified record — [Fact — A1] https://defence-industry-space.ec.europa.eu/galileo-leads-way-gnss-spoofing-protection-osnma-2025-07-22_en · https://www.euspa.europa.eu/newsroom-events/news/galileo-open-service-navigation-message-authentication-adds-another-layer**

**Exposure.** Sense (GNSS) gains an optional authenticity check. Relevant to Sathaye 2022 and the GPS-time vs MAVLink-signing argument.

**Intelligence assessment.** [Assessment — High confidence] Date and service scope established. [Inference — Moderate confidence] Fielded UAS that do not implement OSNMA are unchanged.

**Opportunity.** Passport OSNMA as evidenced receiver support plus keys, not a checkbox.

**LRRK relevance.** Sense. KAT from signed nav data to actuator still has to be shown.

**Confidence.** High on the date.

## Forward indicators

1. A DJI/Autel/u-blox product note that OSNMA is actually used in the flight stack.
2. A paper that spoofs despite OSNMA (expected class: meaconing / non-Galileo).

> **Collection integrity.** Control, not a vulnerability. Included because it changes a Passport field for kinematic GNSS. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>