2) The military uses the Precision (P) code which is encrypted and should be impossible to spoof unless you break the encryption. That is quite unlikely.
3) All radio signals are vulnerable to jamming. In order to jam, you must transmit, however... which means that your jammer is a beacon that the military can direction-find on[3]. If you piss off the military too much, they will turn off your jammer. Permanently.
[1] http://en.wikipedia.org/wiki/Global_Positioning_System#Satel...
* If you steal a key, it will stop working after a brief time (probably hours to days).
* Knowing the decryption key does not (necessarily) mean you can perform the encryption.
Here is a more skeptical article: http://www.theregister.co.uk/2011/12/21/spy_drone_hijack_gps...
There has been at least one valid spoofing demo: http://www.ae.utexas.edu/news/archive/2012/todd-humphreys-re...
"During the spoofing demonstration at White Sands, the research team took control of a hovering UAV from about a kilometer away. Next year, they plan to perform a similar demonstration on a moving UAV from 10 kilometers away."
That demo was a much simpler scenario than what the Iranians claimed to have done. The demo was a stationary UAV and it was most likely using the civilian (C/A code) signals rather than the (classified) encrypted P-code. They also knew exactly where the UAV was, and could likely see it.