LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 July 2015 | | Platform | Quiet Systems | | Series | DKSR-M-2015-07 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF First document-dated public record that a professional (not toy) UAS telemetry radio can be intercepted and rerouted. The conference mapping lands in March 2016. ### Key judgments 1. **[Assessment — High confidence]** Thesis dated July 2015. Preface Amsterdam 25 June 2015. U-Today 20 August 2015 says the defense was “last month.” 2. **[Assessment — High confidence]** Unnamed professional UAV (~€20–25k) using Digi XBee 868LP telemetry and WEP Wi-Fi to a tablet GCS. No CVE. Manufacturer withheld as a loan condition. 3. **[Uncertainty]** Exact day the PDF became world-readable. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Rodday: professional-UAV thesis (document month) *Event / publication dates: Thesis dated July 2015; preface 25 June 2015* | Field | Value | | --- | --- | | Component | firmware | | Product | Unnamed professional UAV (police / critical-infrastructure class) using Digi XBee 868LP and WEP Wi-Fi to a tablet GCS | | CVE / advisory | no CVE | | Patch | none as a CVE. Thesis: XBee on-board encryption or application-layer encryption; WEP is not a fix. | | Exploit status | public writeup | **Verified record — [Fact — A1] Rodday, University of Twente, July 2015. https://essay.utwente.nl/fileshare/file/67577/Rodday_MA_EEMCS.pdf** **Exposure.** Cleartext telemetry and Remote AT reroute on the professional radio; WEP on the tablet hop. Move/Act. **Intelligence assessment.** [Assessment — High confidence] July 2015 as thesis month. [Uncertainty] First world-readable PDF day. Manufacturer not named — do not guess. **Opportunity.** Date the thesis. Map the public-control-link case at RSA / Black Hat Asia (March 2016). Do not invent a CVE. **LRRK relevance.** Control Fabric. Watch. **Confidence.** High on month. Medium on PDF first-online day. ## Forward indicators 1. U-Today press (20 August 2015). 2. RSA 2 March 2016 and Black Hat Asia 31 March 2016. 3. IEEE NOMS paper (April 2016). > **Collection integrity.** One thesis in a four-month research line. Taxonomy reserved for the 2016-03 conference disclosure. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>