LC-2 · Software Danger Reports
LrrK Def Cuts
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Def Cuts **LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems. | Field | Value | | --- | --- | | Collection cutoff | 29 July 2012 | | Platform | Quiet Systems | | Series | DC-Y-2012 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF DEF CON 20 puts open UAS software on the main stage — Paparazzi as a research stack, Anderson on hobby autopilots making military-class kinematics widely available — without a command-link or GNSS disclosure. ### Key judgments 1. **[Assessment — High confidence]** Both verified talks are DEF CON 20. Black Hat USA 2012 and Black Hat Europe 2012 are NIL for drone / UAV / UAS / MAVLink / GNSS-vehicle briefings. 2. **[Assessment — High confidence]** Neither talk is a platform vulnerability disclosure. No CVE, advisory, or Exploit-DB ID attaches. Paparazzi’s named GitHub repo is the platform tree, not a vuln PoC. 3. **[Inference — Moderate confidence]** Public, open autopilot and GCS stacks become a Lab and Passport baseline: later Sense-Move-Act failures will land on software that this year’s record already treats as widely available. ## 01. Esden: Paparazzi open UAS software and hardware on the public stage *Event / publication dates: presented 29 July 2012 (Sunday 16:00 PT), DEF CON 20, Las Vegas.* | Field | Value | | --- | --- | | Venue | DEF CON | | Component | software | | Product | Paparazzi UAV (open-source UAS software and hardware); platform repo https://github.com/paparazzi/paparazzi | | CVE / advisory | none found | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Piotr Esden-Tempski (esden), with panelists listed on the slides as dotAero, misterj, and cifo, presented “The Paparazzi Platform: Flexible, Open-Source, UAS Software and Hardware” at DEF CON 20. DEF CON 20 archive, defcon.org / media.defcon.org slides, and InfoconDB are the primary record. The slides / talk name https://github.com/paparazzi/paparazzi as the platform repo, not a vulnerability PoC repo. Failure class is an open UAS autopilot plus GCS stack presented as research / hobby, not a disclosed command-link failure. **Exposure.** Move and Sense sit in an open autopilot and GCS that anyone can build. Act is whatever payload the airframe carries. No unauthorized-command disclosure is in this record. **Intelligence assessment.** [Assessment — High confidence] This is the first A1 venue record in the leftover inventory that names a specific open UAS software tree. [Assessment — High confidence] Exploit status remains none public. [Uncertainty] DIY Drones / ArduPilot community projects pre-existed; they are not this talk’s repo. **Opportunity.** Passport Paparazzi (and peer open stacks) as “open GCS + autopilot, auth state unknown.” Lab signing / pairing on the GCS–airframe path. Kestrel against ArduPilot / later PX4 when those names reach these stages (MAVLink talks are NIL in 2010–2016). **LRRK relevance.** Control Fabric, Lab, Passport. Watch the platform repo as a stack identity, not as an exploit catalog. Sense-Move-Act on an open UAS that is now a conference object. **Confidence.** High on the talk, slides, and named repo. High that this is not a vuln disclosure. ## 02. Anderson: open hobby autopilots make military-class UAS kinematics widely available *Event / publication dates: presented 27 July 2012 (Friday 14:00 PT), DEF CON 20, Las Vegas.* | Field | Value | | --- | --- | | Venue | DEF CON | | Component | software | | Product | Open-source hobby autopilots; DIY Drones / 3D Robotics community (talk is social / legal / economic, not a SKU disclosure) | | CVE / advisory | none found | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Chris Anderson (Wired / DIY Drones / 3D Robotics) presented “Drones!” at DEF CON 20. The DEF CON 20 archive, media.defcon.org video, and InfoconDB list the talk. No CVE, Exploit-DB ID, or talk-specific research repo was found. DIY Drones / ArduPilot community projects pre-existed the talk. Failure class: open-source hobby autopilots make military-class UAS kinematics widely available. The talk is social / legal / economic, not a platform vuln disclosure. **Exposure.** Move: the kinematics of a UAS become a public software problem. Sense and Act follow the same open stacks. No command-link or GNSS failure is disclosed. **Intelligence assessment.** [Assessment — High confidence] The venue object is proliferation and use, not a CVE. [Inference — Moderate confidence] Wide availability of hobby autopilots is the precondition for later collector-truck and victim-vehicle talks. [Uncertainty] No talk-specific repo URL is verified. **Opportunity.** Campaign open hobby autopilots as a single Watch class. Passport “which autopilot / GCS” on later airframes. Do not treat this talk as evidence of a 2012 command-link patch. **LRRK relevance.** Watch and Campaign. Sense-Move-Act availability, not a Control Fabric hole. Lab later, when a named stack is the victim. **Confidence.** High on the talk and archive. High that exploit status is none public. ## Forward indicators 1. A DEF CON or Black Hat talk that discloses a Paparazzi, ArduPilot, or GCS command-link failure. 2. A CVE or advisory on an open UAS stack named on these stages. 3. Black Hat USA or Europe kinematic briefings (both NIL in 2012). 4. After-record that is in-venue only — Humphreys / UT Austin civil-GPS UAV capture stays out of this series. > **Collection integrity.** Searched media.defcon.org DEF CON 20 presentations and video-and-slides; defcon.org DC20 archive; Black Hat USA 2012 briefing archives; Black Hat Europe 2012 archives; InfoconDB keyword sweep for drone / UAV / UAS / MAVLink / GNSS-vehicle. Two counted talks, both DEF CON 20. Black Hat USA 2012 and Black Hat Europe 2012 are NIL. Out-of-venue items (Todd Humphreys / UT Austin civil-GPS UAV capture — 2012 DHS / ION / congressional record, no BH/DC talk; SkyJack; HOPE 2012 “Pwn the Drones”; ADS-B / ATC; car CAN) stayed out. No invented talks. No exploit steps. CVE / Exploit-DB: none found. Paparazzi platform repo copied from the inventory; no talk-specific ArduPilot research repo found. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>