# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 9 August 2015 |
| Platform | Quiet Systems |
| Series | DC-S-02 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

DEF CON 23 put a low-cost SDR GPS simulator on the main stage: unauthenticated civil GNSS can accept a displaced fix, including DJI geofence / no-fly logic and other vehicle GNSS, with no vendor CVE attached to the talk.

### Key judgments

1. **[Assessment — High confidence]** Lin Huang and Qing Yang (Unicorn Team, Qihoo 360) presented *Low-cost GPS simulator – GPS spoofing by SDR* at DEF CON 23 on 7 August 2015; slides and video are on media.defcon.org.
2. **[Assessment — High confidence]** The failure class is a protocol property of civil GPS L1 C/A (unauthenticated by design). Inventory records no CVE, no Exploit-DB ID, and no talk-released Unicorn Team repo.
3. **[Inference — Moderate confidence]** Any Passport that treats “GNSS lock” as a trusted Sense input is incomplete after this showing; the physical consequence is a moved or mis-fenced vehicle, not a new chip bug.

## 01. Civil GPS L1 C/A accepts an SDR-sourced fix, including DJI no-fly logic

*Event / publication dates: DEF CON 23, 7 August 2015 (Fri 15:00 PT). Collection cutoff is DEF CON 23 Sunday, 9 August 2015.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | dependency |
| Product | civil GPS L1 C/A; DJI geofence / no-fly logic and other vehicle GNSS |
| CVE / advisory | none found (civil GPS L1 C/A is unauthenticated by design; no vendor CVE assigned to this talk) |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Talk title *Low-cost GPS simulator – GPS spoofing by SDR*; speakers Lin Huang and Qing Yang (Unicorn Team, Qihoo 360); DEF CON 23 official archive https://defcon.org/html/links/dc-archives/dc-23-archive.html. After-record: media.defcon.org slides (`DEF CON 23 - Lin-Huang-Qing-Yang-GPS-Spoofing.pdf`) and video (`DEF CON 23 - Lin Huang and Qing Yang - Low-cost GPS simulator - GPS spoofing by SDR.mp4`). Named after-record outlets: eWeek Unicorn Team GPS piece; Forbes (Brewster, Qihoo / drone GPS; Olson, GPS spoofing at DEF CON); RTL-SDR.com low-cost TX SDR note. InfoconDB is a cross-check only. **[Fact — A1]** CVE / advisory: none found. Exploit-DB ID: none found. GitHub research repo: none found as a talk-released repo (speakers said they integrated existing open-source GPS / SDR projects; no dedicated Unicorn Team repo URL verified with the talk). Exploit-status: public writeup.

**Exposure.** Sense: the GNSS receiver is the lied-to sensor. Move: a displaced fix changes navigation, including DJI geofence / no-fly logic named in the inventory. Act is downstream of that false position (the vehicle complies with a fence or route that is no longer the real one). Peripheral / dependency: civil L1 C/A as a shared trust source across UAS and other vehicles.

**Intelligence assessment.** **[Assessment — High confidence]** This is the 2015 DEF CON landmark for low-cost SDR as a civil-GNSS integrity failure, not a DJI firmware CVE. **[Assessment — High confidence]** Physical consequence is a receiver fix that no longer matches the real location, so geofence / no-fly and other GNSS-guided behavior can be wrong. **[Uncertainty]** Black Hat USA / Europe / Asia 2015 were NIL for this work; it is a DEF CON 23 record only. **[Inference — Moderate confidence]** Later legal-GNSS and UAV-geolocation talks (2019 Murray, 2020–2021 village GPS items) are the same dependency class, not a new radio.

**Opportunity.** Passport civil L1 C/A as unauthenticated. Do not treat “GPS lock” or “inside / outside a DJI fence” as evidence of position integrity. Watch for a vendor CVE this talk never received. Lab multi-constellation / authenticated GNSS only as a contrast, not as a how-to.

**LRRK relevance.** Sense and Move on any GNSS-guided air or ground vehicle. Passport of the navigation dependency. Watch / Kestrel for repeats of the unauthenticated-civil-GNSS class. Control Fabric only insofar as geofence and RTH consume the false fix.

**Confidence.** High on the official DC23 record, media archive, and the “no CVE because unauthenticated by design” inventory note. Moderate on named-outlet color. Nil on EDB and a talk-tied GitHub URL.

## Forward indicators

1. A vendor CVE or advisory is assigned to DJI geofence / no-fly behavior under a false civil-GNSS fix (inventory: none for this talk).
2. A later BH/DC briefing treats authenticated GNSS or multi-sensor anti-spoof as a Passport requirement rather than a demo.
3. An Exploit-DB or talk-released Unicorn Team repo appears and can be cited as a named record only.

> **Collection integrity.** Built from leftover inventory 2015-01 only. Official sources: defcon.org DC23 archive; media.defcon.org DC23 presentations and video-and-slides; named eWeek / Forbes / RTL-SDR.com after-records. InfoconDB cross-check only. Black Hat USA / Europe / Asia 2015 remain NIL for UAV / GCS / GNSS-vehicle briefings. DEF CON 23 villages remain NIL for kinematic titles. Slides and video treated as metadata; SDR procedures, simulator recipes, and payloads excluded. No invented talks. CVE / EDB / GitHub / exploit-status copied from the inventory: none found / none found / none found as a talk-released repo / public writeup.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
