← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Def Cuts

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/Def Cuts/years/2020.md
Imported-content SHA-256
33b2b1406ca1d26785aca2490dbc737920b468ef8bf84fdb0a7847e1f16e13c8
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 9 August 2020 |
| Platform | Quiet Systems |
| Series | DC-Y-2020 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

DEF CON Safe Mode is a short kinematic year: Aerospace Village opens with a civil-GPS integrity workshop for UAVs and self-driving vehicles, and Hack The Seas puts UUVs on the village record as a contest with no vendor CVE. Main stage and all Black Hat regions are NIL.

### Key judgments

1. **[Assessment — High confidence]** Unauthenticated civil GPS used by UAVs and self-driving vehicles can be denied or misled; that failure class, and published mitigations, are the first Aerospace Village UAS lesson (Sathaye, “GPS Spoofing 101”).
2. **[Assessment — High confidence]** No CVE, advisory, or Exploit-DB record is attached to either 2020 in-scope talk. DroneWarz did not run a DEF CON village after the DC28 in-person cancellation.
3. **[Inference — Moderate confidence]** A Passport that records “GPS 3D fix” without authenticity or fusion evidence will overstate Sense on both air and ground vehicles; the later Sathaye UAV-takeover paper is out of this window and is not this village talk.

## 01. Civil GPS integrity is the first Aerospace Village UAS lesson

*Event / publication dates: August 2020, DEF CON 28 Safe Mode, Aerospace Village virtual program.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | dependency |
| Product | civil GPS as used by UAVs and self-driving vehicles |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Harshad Sathaye presented “GPS Spoofing 101” at Aerospace Village during DEF CON 28 Safe Mode. Official schedule: aerospacevillage.org/def-con-28-schedule. After-record: media.defcon.org Safe Mode Aerospace Village video; TIB AV-Portal 49201; Infosecurity.US village write-up (8 December 2020); RTL-SDR.com village SDR-talks note. Failure class: unauthenticated civil GPS used by UAVs and self-driving vehicles can be denied or misled; the talk is a workshop on that failure and published mitigations. No CVE, advisory, or Exploit-DB ID was found. No GitHub repository was published with this village talk. A later USENIX Security 2022 UAV-takeover paper by the same researcher is out of window and is not this record.

**Exposure.** Sense (civil GPS) on air and ground vehicles. False or denied position becomes false Move. Mitigation discussion is on the record; a protocol CVE is not.

**Intelligence assessment.** [Assessment — High confidence] Aerospace Village’s first DEF CON year includes a titled UAS/vehicle-GNSS workshop with a media.defcon.org after-record. [Assessment — High confidence] This is the same civil-GNSS integrity class as SwRI 2019, now in a UAS village frame. [Uncertainty] Receiver SKUs and the exact mitigation set are workshop-level, not a CNA ID. [Inference — Moderate confidence] Do not fold the 2022 USENIX paper back into this Safe Mode talk.

**Opportunity.** Passport GPS authenticity and fusion (IMU / other PNT). Lab denial vs misleading as two outcomes. Watch for a talk-tied repo or CVE; neither exists at this cutoff. Keep the 2022 paper on a later Watch list only.

**LRRK relevance.** Sense-Move-Act. Dependency. Watch (Aerospace Village now exists). Lab published mitigations as claims, not as recipes. Campaign GNSS-dependent UAVs and UGVs together. KAT: GPS input → navigation.

**Confidence.** High on the village schedule and the media.defcon.org video. Moderate as a general civil-GPS case. Low on unlisted receivers.

## 02. Hack The Seas puts UUVs on the village record without a CVE

*Event / publication dates: August 2020, DEF CON 28 Safe Mode, Hack The Seas Village program.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | hardware |
| Product | unmanned underwater vehicles (village contest framing) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | none public |

**Verified record — [Fact — A1]** Nina Kollars presented “40,000 Leagues-UUV Death Match” at Hack The Seas Village during DEF CON 28 Safe Mode. After-record: media.defcon.org Safe Mode villages video. Official village tree: media.defcon.org DEF CON 28 Safe Mode villages. Failure class: village contest framing of unmanned underwater vehicle (UUV) security; no vendor CVE or catalogued flaw is attached. No GitHub research repo and no Exploit-DB ID were found.

**Exposure.** Underwater kinematic path (UUV). Contest framing only. No established Sense, Move, or Act failure on a named product.

**Intelligence assessment.** [Assessment — High confidence] The titled UUV village talk exists. [Assessment — High confidence] Exploit status is none public; this is not a software-danger ID. [Uncertainty] Platform makes and contest scoring are not independently specified. [Inference — Low confidence] Treat as Watch that UUVs entered the DEF CON village record, not as a Control Fabric finding.

**Opportunity.** No patch to verify. Watch Hack The Seas / later undersea villages for a titled product talk. Do not Passport a death-match contest as a UUV assessment.

**LRRK relevance.** Watch. Lab and KAT do not attach. Campaign should not ingest this as a vulnerability. Sense-Move-Act is the domain (undersea), not a demonstrated failure.

**Confidence.** High that the village video exists. High that no CVE is attached. Low as a decision signal.

## Forward indicators

1. A talk-tied Sathaye repository or CNA ID for civil GPS on UAVs (none at this cutoff; 2022 USENIX paper is later).
2. Whether Aerospace Village 2021 keeps a UAS/vehicle-GNSS thread or shifts entirely to manned aviation and space.
3. Whether DroneWarz returns after the DC28 cancellation (inventory: it did not run as a DEF CON village after that cancellation).
4. A titled Hack The Seas / UUV product talk with a vendor or CVE (this year has none).

> **Collection integrity.** Public sources only. Inventory leftover for 2020: two talks, used as two signals. Collection cutoff is DEF CON 28 Safe Mode Sunday, 9 August 2020 (virtual; in-person DC28 cancelled). Searched: media.defcon.org Safe Mode presentations and video-and-slides (main stage NIL for drone / UAV / GNSS-vehicle / MAVLink); Safe Mode villages; aerospacevillage.org DC28 schedule; Black Hat USA 2020 briefings and Arsenal (NIL); Black Hat Europe 2020 briefings (NIL); Black Hat Asia 2020 briefings (NIL); IoT / Wireless / Hardware Village 2020 (NIL). **Village note.** No brand named “Drone Village” in 2017–2021. DroneWarz did not run a DEF CON village after the DC28 cancellation (cyberdefensecenter.org/dronewarz). Aerospace Village begins at DEF CON Safe Mode (DC28, 2020). **Excluded:** Aerospace Village ILS / ADS-B / TCAS / 737 / 747 / ACARS / satellite talks (manned aviation or space, not UAS / vehicle GNSS); USENIX Security 2022 Sathaye UAV-takeover paper (out of window, not BH/DC this year); DroneWarz cage / CTF without a titled recorded talk; paid trainings; HOPE / SAINTCON / Nuit du Hack / Codemotion. No invented talks. No CVE, Exploit-DB ID, or GitHub URL invented. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>