# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 8 August 2021 |
| Platform | Quiet Systems |
| Series | DC-Y-2021 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

2021 kinematic content is village-only: civil GPS geolocation of UAVs can be displaced without a protocol CVE, unauthenticated GPS / ADS-B / MAVLink drives a case for onboard detection, a research quadcopter isolates mission keys in a seL4 VM, and one Aerospace Village talk treats the UAV as a sensor. DEF CON 29 main stage and all Black Hat regions are NIL.

### Key judgments

1. **[Assessment — High confidence]** Civil GPS receivers on UAVs will accept a stronger false geolocation, so navigation can be displaced without a protocol CVE (RF Village, Mehmet Onder Key).
2. **[Assessment — High confidence]** The year’s UAS technical record lives in Aerospace Village and RF Village. Main-stage and Black Hat USA / EU / Asia briefings are NIL for kinematic titles.
3. **[Inference — Moderate confidence]** A Passport that records “GPS fix + MAVLink on the wire + keys in software” without authenticity, detection, or isolation evidence will overstate Sense and Control Fabric on research and fielded quads.

## 01. Civil GPS receivers accept a stronger false UAV geolocation

*Event / publication dates: August 2021, DEF CON 29 RF Village program.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | dependency |
| Product | civil GPS receivers on UAVs |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Mehmet Onder Key presented “SPOOFING GEOLOCATION OF UAVs” at the DEF CON 29 RF Village (treated as the Wireless / RF village). After-record: media.defcon.org DC29 villages video (filename uses “RF Vllage”); RTL-SDR.com DEF CON 29 SDR-video note. Official village tree: media.defcon.org DEF CON 29 villages. Failure class: civil GPS receivers on UAVs accept stronger false geolocation from an SDR, so navigation can be displaced without a protocol CVE. No CVE, advisory, Exploit-DB ID, or GitHub research repo was found.

**Exposure.** Sense (civil GPS) becomes false Move (displaced navigation). No flight-stack CVE is required. Physical consequence: the airframe is not where its navigator believes it is.

**Intelligence assessment.** [Assessment — High confidence] The RF Village after-record exists and states the civil-GPS receiver class. [Assessment — High confidence] This continues the 2019 SwRI / 2020 Sathaye integrity thread onto a UAV object. [Uncertainty] Receiver SKUs are not a CNA list. [Inference — Moderate confidence] Authenticated or fused PNT is the Passport field that would change this picture; “3D fix” will not.

**Opportunity.** Passport GPS authenticity and fusion. Lab displaced-navigation outcomes, not an SDR recipe. Watch for a CVE that names a UAV receiver; none in this window. Kestrel civil receivers used on UAVs as one dependency class.

**LRRK relevance.** Sense-Move-Act. Dependency. Watch (RF Village). Lab and Campaign GNSS-dependent UAVs. KAT: GPS input → navigator → path. Control Fabric is downstream of a false Sense.

**Confidence.** High on the village video. Moderate as a case for all civil-GPS UAVs. Low on unlisted receivers.

## 02. Unauthenticated GPS, ADS-B, and MAVLink push detection onto the airframe

*Event / publication dates: 7 August 2021, 11:30–11:55 PT (virtual), DEF CON 29 Aerospace Village.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | software |
| Product | UAV intrusion detection using onboard logs (MAVIDS; Jason Whelan) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Jason Whelan presented “Defending the Unmanned Aerial Vehicle: Advancements in UAV Intrusion Detection” at Aerospace Village during DEF CON 29. Official schedule: aerospacevillage.org/defcon-29. After-record: media.defcon.org DC29 Aerospace Village video; Infosecurity.US village write-up (27 October 2021); GitHub repository https://github.com/jasonotu/MAVIDS. Failure class: UAVs that depend on unauthenticated GPS / ADS-B and MAVLink telemetry need onboard log-based detection because those underlying links cannot be re-engineered quickly. No CVE and no Exploit-DB ID were found.

**Exposure.** Sense (GPS / ADS-B) and Control Fabric (MAVLink telemetry). Detection is a Watch function on the vehicle because the links themselves remain unauthenticated. Move and Act can change before a ground operator notices.

**Intelligence assessment.** [Assessment — High confidence] The village talk, the media.defcon.org video, and the named MAVIDS repo exist. [Assessment — High confidence] The failure class is missing authentication on those links, not a new autopilot CVE. [Uncertainty] Which flight-stack versions MAVIDS was demonstrated on is a repo/Passport question. [Inference — Moderate confidence] Onboard detection is a compensating control, not a substitute for an authenticated Control Fabric.

**Opportunity.** Passport whether GPS, ADS-B, and MAVLink are authenticated or only logged. Lab detection coverage as a Watch claim. Do not treat the GitHub repo as a patch. Campaign unsigned MAVLink + civil GPS as one class.

**LRRK relevance.** Watch and Lab. Control Fabric (MAVLink) and Sense (GPS / ADS-B). Kestrel across stacks that ship those links unsigned. KAT: unauthenticated telemetry → late or missed detection.

**Confidence.** High on the talk and the named repo. Moderate on detection as a complete substitute for authentication.

## 03. Mission keys in a seL4 VM are the HACMS village test, not a CVE

*Event / publication dates: 6 August 2021, 11:30–11:55 PT (virtual), DEF CON 29 Aerospace Village.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | software |
| Product | research quadcopter with mission / telemetry keys in a formally verified seL4 VM (HACMS; Collins Aerospace / Loonwerks) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Darren Cofer (Collins Aerospace; activity credits also I. Amundson, E. Barker, E. Hellman, M. Podhradsky, S. Zhuang) presented “Steal This Drone: High-Assurance Cyber Military Systems” at Aerospace Village during DEF CON 29. Official schedule: aerospacevillage.org/defcon-29. After-record: media.defcon.org DC29 Aerospace Village video; Loonwerks publications page (cofer2021defcon); Loonwerks “Steal-This-Drone-README” PDF. Failure class: mission / telemetry keys on a research quadcopter are isolated in a formally verified seL4 VM; the village activity tests whether that isolation holds. No CVE or Exploit-DB ID was found. No GitHub repository was published with the talk (HACMS / seL4 quadcopter challenge is described in the Loonwerks paper).

**Exposure.** Control Fabric and identity: keys that authorize mission and telemetry. If isolation fails, those keys become usable against the airframe (Move / Act). This is an assurance test, not a vendor advisory.

**Intelligence assessment.** [Assessment — High confidence] The village talk and the Loonwerks after-record exist. [Assessment — High confidence] The object is key isolation on a research quadcopter, not a fielded SKU CVE. [Uncertainty] Whether isolation held in the village activity is a Lab outcome, not restated here from a secondary. [Inference — Moderate confidence] A Passport that says “seL4 on board” without an isolation-test event is incomplete.

**Opportunity.** Passport where mission / telemetry keys live (isolated VM vs general-purpose software). Lab the isolation claim as a hypothesis with limits. Watch for a later HACMS CVE or repo; none is talk-tied in this window.

**LRRK relevance.** Passport and Lab. Control Fabric (keys). Campaign high-assurance vs commodity quads as different classes. KAT: key store → command path. Watch the village result, not a CNA ID.

**Confidence.** High on the talk and Loonwerks pages. Moderate as a case for fielded military UAS. Low on unstated village-activity outcomes.

## 04. The UAV is used as a sensor, not only as a victim

*Event / publication dates: 7 August 2021, 15:00–15:50 PT (virtual), DEF CON 29 Aerospace Village.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | hardware |
| Product | UAV used as an airborne Wi-Fi collection platform (Matt Gaffney, Drone Security Research Series Ep6) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Matt Gaffney presented “Drone Security Research Series – Ep6 Hacking with drones” at Aerospace Village during DEF CON 29. Official schedule: aerospacevillage.org/defcon-29. After-record: YouTube M0BDHT43Ucc. Failure class: prior episodes in the series address MAVLink weaknesses; this scheduled village talk uses a UAV as an airborne Wi-Fi collection platform against physical-security range limits (drone as sensor, not only as victim). No CVE, Exploit-DB ID, or GitHub research repo was found. Gaffney’s separate DC29 “VDP in aviation” talk is manned-aircraft disclosure process and is out of topic.

**Exposure.** Sense (payload / collection) and physical-security range. The airframe extends a sensor past a perimeter that assumed ground-level RF limits. Not a flight-stack CVE.

**Intelligence assessment.** [Assessment — High confidence] The village slot and the YouTube after-record exist. [Assessment — Moderate confidence] The in-scope object is the UAV-as-sensor use, not a new MAVLink ID (those sit in prior episodes, not this filing’s primary). [Uncertainty] Collection targets and range figures are not turned into a product CVE. [Inference — Moderate confidence] Passport and site Campaigns that only model ground sensors will understate airborne Sense.

**Opportunity.** Passport payload class (collection vs EO/IR vs none). Watch later series episodes as after-record, not as this village slot. Do not Lab a collection workflow from this filing.

**LRRK relevance.** Sense-Move-Act (Sense as payload). Watch. Campaign site perimeters against airborne collectors. Lab range assumptions, not a Wi-Fi recipe. Kestrel ground-only vs airborne Sense.

**Confidence.** High on the schedule. Moderate on the YouTube after-record as the sole media copy. Low as a vendor-flaw signal.

## Forward indicators

1. A CNA ID or vendor advisory for civil-GPS receivers on UAVs (none at this cutoff).
2. MAVIDS repo: flight-stack versions and whether detection is claimed as a substitute for MAVLink signing.
3. HACMS / Loonwerks: a talk-tied repo or a published isolation-test disposition.
4. Whether DEF CON 30 returns kinematic content to the main stage (DC27–DC29 main stage NIL).
5. Whether a brand named “Drone Village” appears; it does not in 2017–2021, and DroneWarz was no longer a DEF CON village in 2021.

> **Collection integrity.** Public sources only. Inventory leftover for 2021: four talks, used as four signals (no same-research merge). Collection cutoff is DEF CON 29 Sunday, 8 August 2021. Searched: media.defcon.org DC29 presentations and video-and-slides (main stage NIL for drone / UAV / GNSS-vehicle / MAVLink); DC29 villages; aerospacevillage.org/defcon-29; Black Hat USA 2021 briefings and Arsenal (NIL); Black Hat Europe 2021 briefings (NIL); Black Hat Asia 2021 briefings (NIL); IoT Village / Hardware Village 2021 (NIL). RF Village item recorded because the object is UAV geolocation. **Village note.** No brand named “Drone Village” in 2017–2021. DroneWarz was no longer a DEF CON village in 2021. Aerospace Village began at DC28 Safe Mode (2020) and is the 2021 UAS home. RF Village at DC29 is treated as the Wireless / RF village. **Excluded:** Aerospace Village IFE, Hack-a-Sat, space hitchhikers, Garmin GTN750 / ADS-B, CPDLC, NASA cFS, FAA CISO, and VDP-in-aviation (manned aviation or space); Leeloo Granger DC29 “Evaluating Wireless Attacks on Real-World Avionics Hardware” (Garmin GTN750 manned navigator); Matt Gaffney DC29 “VDP in aviation” (manned-aircraft disclosure process — distinct from Ep6); DroneWarz cage / CTF without a titled recorded talk; paid trainings; HOPE / SAINTCON / Nuit du Hack / Codemotion; USENIX Security 2022 Sathaye UAV-takeover paper (out of window). No invented talks. No CVE or Exploit-DB ID invented. GitHub copied from inventory only (jasonotu/MAVIDS). No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
