146 karma · joined May 20, 2015
First you have the hardware itself, your drones. Best is to create them yourself. As there aren't many of the shelf products and they are mostly coming from China where safety concerns aren't that high valued as US and EU. For example letting them do a return to home, is a nightmare. As they will just fly across your other drones and hit other while doing. We have also incorporated lots of redundancy, so that we have different ways to communicate with the drone. And also a manual override so that you can steer the drone personally into safety.
Next you have the software. That will steer the drones. You have two possibilities for that. Either pre-program all drones with a gps path and send a start signal. Or do it our way and realtime manage the drones (ofcourse with backup path if communcation fails). On the lower level of the software we have our red box that does collision avoidance. So even if you ask the drones to go through each other, that box will stop them before they hit eachother. On top of that we have the real route planning that should produce non-hitting paths. Real-time planning is harder to implement. But it makes sure that you can replace drones if pre-flight checks doesn't let the drone fly. And also makes sure you can adapt the show mid-air. For example to sync up with a live performance.
And then the 'boring' part. Getting a license. We have already created more than 800 pages of certification and safety procedures. Just to get a license. That is because in a lot of countries drones are certified as airplanes. So procedures are also like airplanes. Flying a normal drone is possible, but for drone shows you have to get 3 exceptions certified. Namely flying at night, flying in formation and automatic flying. And by creating your own drone, you also need to homologate and certify your drone.
Hope I gave you a little hint of what is needed ;)
The issue is apparently with the hydraulics system of the grid fins that had a problem. It was nice to see that the gimballing engines recovered the spin before the sea landing.
Apart from the legal stuff and a lot off egocentric 'we can do it better', she has one point. There are many companies giving a lot of money for security, manually scrubbing all exploits that come out, create their own patches. While some lack the basic security guidelines. I think this money can be better spend upstream, to create tools so they can test patches for exploits better and create a faster security update release pipeline, so that all downstream and customers can rely on the security releases and that it can be released quicker to everyone. (Controversial: Maybe even adding automatic security updates to the package itself, like wordpress did, so that customer cannot be on a release with exploits)
Though saying to your client that they cannot reverse engineer to look for security problems, is totally not done! What is next? "Exploits will not be fixed, because the users has signed an agreement that they will not hack?"
Though saying to your client that they cannot reverse engineer to look for security problems, is totally not done! What is next? "Exploits will not be fixed, because the users has signed an agreement that they will not hack?"
If that is one of the following (or higher), you are save: 9.10.2-P3, 9.9.7-P2, 9.9.5-3ubuntu0.4, 9.8.1.P1-4ubuntu0.12, 9.9.5-4.3ubuntu0.3, 9.9.5-9ubuntu0.2, 9.9.4-18.el7_1.3, 9.8.2-0.37.rc1.el6_7.2, 9.3.6-25.P1.el5_11.3, 9.7.0-21.P2.el5_11.2, 9.8.4.P1-6+nmu2+deb7u2~bpo60+1, 9.7.3-1~squeeze16, 9.8.4.P1-6+nmu2+deb7u6, 9.9.5-9+deb8u2, 9.9.5-11
Ofcourse everything is easier if automated, so that is exactly what following page does: https://scan.patrolserver.com/bind/CVE-2015-5477
As this takes a lot of resources, do you find it usefull? Or do you think the 40.000 is already representative?
Responsibilities: Creating advanced fingerprinting tools to check server software version and exploits
If you are interested please mail info@patrolserver.com
That is the reason why security is hard ;)