A $225 GPS spoofer can send sat-nav-guided vehicles into oncoming traffic
arstechnica.com
arstechnica.com
* by fooling the vehicle into driving the wrong way through a one-way street.
That's a serious asterisk. I think there are much more interesting worst-case applications for this, like kidnapping, randsom, misdirecting emergency responders etc. Some of those are mentioned by the article, but the headline just causes doubt and disappointment.
Google/Apple/whatever directions send delivery vehicles down roads with under-height structures all the time and they rarely get can-opened. GPS directions are inaccurate enough in urban environments that people have to pay enough attention for this attack to not work very well. People will generally defer to the local signage when it comes to which lane you need to be in for a turn and which way you can't drive down a street or how tall a bridge actually is.
Edit: Relevant XKCD. Causing crashes isn’t hard period. https://m.xkcd.com/1958/
Roads are everywhere, most of them completely unprotected, and you don't actually have to physically and visibly interfere with the road.
They aren't protected. We know this from the numbers of deaths that occur each year on the railways.
In the UK there's an order of magnitude more roads than railways. In the US there are two orders of magnitude more.
Trainset involved: 70 (Sud-Est)
Service: train 736, Grenoble to Paris
Location: PN 74, Voiron
Injuries: 2 dead, 60 injured
[Edit: date: 23 September 1988]
A special road transport with a weight of 80 tons became stranded on level
crossing 74. Train 736, rounding a curve toward the crossing, ploughed into it
at 110 km/h (68 mph). The large mass of the road vehicle made this crash much
worse than it might otherwise have been; the engineer and one passenger died,
and many more were injured when the first trailer was ripped open by debris.
Only the leading power unit derailed. This wreck, the most violent to date,
became a reference for the design and crash testing of safety features for the
next generation of TGV, as embodied by today's Duplex trainsets. These newer
trains have several deformable sections, at the front and rear of the power unit
and at the front of the first trailer, to manage and absorb crash energy without
damage to passenger compartments. Trainset 70 was never returned to service, and
the trailing unit 23140 became a spare in the Sud-Est fleet.Sounds very dangerous. If an aircraft was landing in poor visibility they could use that to make t crash.
https://en.wikipedia.org/wiki/Localizer_performance_with_ver...
> As of September 17, 2015 the Federal Aviation Administration has published 3,567 LPV approaches at 1,739 airports. This is greater than the number of published Category I ILS procedures.
I see what you did there... ;)
EU's GNSS has PRS (Public Regulated Service) is authenticated and can be used in sensitive applications for civilian uses. US has GPS modes that are protected but they seem to be only for military.
There is also Wide Area Augmentation System (WAAS) and European Geostationary Navigation Overlay Service (EGNOS). They augment GPS/Golnass and Galileo and provide integrity and more accuracy.
Typically new sat-nav systems have multi-constellation capability and they can receive from from GPS/GNSS/Golnass. Even new smartphones have that capability. Of course, if all of them are unprotected, you can spoof them all parallel.
direct link to paper: https://people.cs.vt.edu/gangwang/sec18-gps.pdf
What about autonomous trains? Cause that would off the rails.
From what i can understand, this separation of concerns is a safer option
Besides, signing doesn't necessarily help - the easiest way to GPS spoof is simply to re-broadcast the signals received at a nearby point at higher power, so the victim receiver thinks it's at that point.
There is recent work on doing this: https://web.stanford.edu/group/scpnt/gpslab/pubs/papers/Lo_I...
replay attack does make sense, but isn't it identified uniquely by time? i mean the content of the payload is basically very accurate time. if a device notices the time doesn't change - it can detect spoofing.
Receiving the same signal over and over would be suspicious, but unless you have some other method to determine time and position, what are you going to do?