Slashdot Mirror


How To Hijack a Drone For $400 In Less Than an Hour

Trailrunner7 writes "The skies may soon be full of drones – some run by law enforcement agencies, others run by intelligence agencies and still others delivering novels and cases of diapers from Amazon. But a new project by a well-known hacker Samy Kamkar may give control of those drones to anyone with $400 and an hour of free time. Small drones, like the ones that Amazon is planning to use to deliver small packages in short timeframes in a few years, are quite inexpensive and easy to use. They can be controlled from an iPhone, tablet or Android device and can be modified fairly easily, as well. Kamkar, a veteran security researcher and hacker, has taken advantage of these properties and put together his own drone platform, called Skyjack. The drone has the ability to forcibly disconnect another drone from its controller and then force the target to accept commands from the Skyjack drone. All of this is done wirelessly and doesn't require the use of any exploit or security vulnerability."

161 comments

  1. Here we go... by Anonymous Coward · · Score: 0

    When drones are outlawed, only outlaws will operate drones.

    1. Re:Here we go... by craigminah · · Score: 2, Funny

      They'll only outlaw "assault drones", regular drones with the same capabilities as assault drones but who look less scary will be legal.

    2. Re: Here we go... by Badblackdog · · Score: 4, Funny

      If you like your drones... You may keep your drones...

    3. Re:Here we go... by slick7 · · Score: 1

      They'll only outlaw "assault drones", regular drones with the same capabilities as assault drones but who look less scary will be legal.

      Says the CIA (Criminals In Action).

      --
      The mind conceives, the body achieves, the spirit manifests.
    4. Re:Here we go... by davester666 · · Score: 1

      These are not the drones you are looking for?

      --
      Sleep your way to a whiter smile...date a dentist!
    5. Re:Here we go... by iamhassi · · Score: 1

      It may look less scary and be legal but if a drone can carry a 5 lbs package it can carry five 14 ounce fragmentation hand grenades.

      --
      my karma will be here long after I'm gone
    6. Re:Here we go... by RockDoctor · · Score: 1
      A pound is 14 ounces?

      Actually, I'll have to go and check that now ... or would if I cared about a defunct measurement system that I don't actually have to deal with weights in - just measures. Is it 12 or 16 ounces to the pound. Or drachams to the goat, or something? 14 stones to the pound? Insane.

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
  2. No, this will not work on Amazon's drones. by Anonymous Coward · · Score: 5, Insightful

    In TFA he is hacking a Parrot AR wifi drone. If Amazon ever gets off the ground (ahem) with their drones, they will likely be autonomous, using GPS to guide them to their location. Monitoring and flight plan changes would likely occur by satellite as well. That's not to say that they are immune from attack, but none of the types of drones described in the summary (law enforcement, intelligence agencies, Amazon) are going to be susceptible to his attack.

    1. Re:No, this will not work on Amazon's drones. by Anonymous Coward · · Score: 0

      As Besos said in the interview, they are autonomous and use GPS. Anyone that uses unencrypted comms for this (yes you Parrot) should be ashamed. Even automotive keyfobs have encryption and rolling codes.

    2. Re:No, this will not work on Amazon's drones. by Grax · · Score: 1

      Agreed! The article implies that his "awesome" hack gives him infinite control of the skies. It really only gives him control of one kind of toy drone and then only until they release an update that blocks his hack.

    3. Re:No, this will not work on Amazon's drones. by number17 · · Score: 1

      Exactly! A giant net is still the best option.

    4. Re:No, this will not work on Amazon's drones. by romons · · Score: 1

      The Iranians supposedly hijacked a 'real' military drone by faking GPS signals.

      If you know where the drone is going, you just overpower the GPS signal. Military drones probably have some redundancy built into an encrypted channel (GPS is, after all, a military system) but I don't think Amazon is going to have that capability. They could use redundancy by video, ala google car, I suppose, particularly if they are covering a fairly small geographic area. They would want that anyway, since GPS drifts around. Don't want the package delivered in the pool. They could also use both GPS and the russian system in many places.

      Another possibility would be a LORAN type system, broadcast from their facilities. It might only serve as a check, and allow the drones to return if GPS went completely dark. If GPS goes dark, however, I think we have bigger problems than getting our drones back.

      --
      Go to Heaven for the climate, Hell for the company -- Mark Twain
  3. Without a security vulnerability? by sheetsda · · Score: 5, Insightful

    "All of this is done wirelessly and doesn't require the use of any exploit or security vulnerability"

    "...detects the wireless signal sent out by a target drone, injects WiFi packets into the target’s connection, de-authenticates it from its real controller and then authenticates it to the Skyjack drone"

    Uhh... for what definition of "security vulnerability" is this not a "security vulnerability"?

    1. Re:Without a security vulnerability? by plover · · Score: 2, Interesting

      A security vulnerability implies that at some level, there had to have been the faintest vague attempt at being secure.

      He exploited a vulnerability, to be sure, but he seems uncomfortable calling it a security vulnerability.

      --
      John
    2. Re:Without a security vulnerability? by viperidaenz · · Score: 1

      Because the product is designed to behave this way. If it's documented, it's a feature, not a bug.

    3. Re:Without a security vulnerability? by gl4ss · · Score: 1

      so there is no option to use wpa or any wifi security at all? that's what it implies.

      breaking wpa would imply a security vulnurability.

      and dunno how it could be "like those used by amazon" since amazon doesn't yet use or have any.

      --
      world was created 5 seconds before this post as it is.
    4. Re:Without a security vulnerability? by viperidaenz · · Score: 1

      It sounds like it does what ever the AR done software does when it pairs with the drone. There is no screen or keyboard on the drone to enter a WPA key.

      What ever they're doing, its not new. This was discussed two years ago http://www.ardrone-flyers.com/forum/viewtopic.php?t=2151

    5. Re:Without a security vulnerability? by Anonymous Coward · · Score: 0

      If I use my universal remote to change the channel on your TV, have I used any exploit or security vulnerability? Am I suddenly a stunningly skilled guru at computer security? The drone in question is a toy, not a serious security device. When he uses this against the MQ-1 Predator, I will pay more attention.

  4. No vulnerabilities? Really? by Anonymous Coward · · Score: 4, Insightful

    All of this is done wirelessly and doesn't require the use of any exploit or security vulnerability.

    Between me and the author of this sentence, I think we have two different definitions of "security vulnerability".

    1. Re:No vulnerabilities? Really? by Control-Z · · Score: 1

      If he is referring to the unlikely Amazon delivery drones, I really don't understand that sentence at all. How would he know what security the drones will have in place? It's a safe bet Amazon wouldn't communicate unencrypted with them.

  5. Aquire a drone for even less? by Anonymous Coward · · Score: 0, Insightful

    You could also get a drone by robbing a Best Buy with a $10 knife... Is it no longer stealing just because there's a cool hack involved?

    1. Re:Aquire a drone for even less? by Anonymous Coward · · Score: 1

      Is it no longer stealing just because there's a cool hack involved?

      Is anybody suggesting that it's no longer stealing just because there's a cool hack involved?

    2. Re:Aquire a drone for even less? by Anonymous Coward · · Score: 1

      If someone is flying a drone that's programmed to follow any unauthenticated instructions broadcast to it from anyone, and someone takes the drone up on that offer and broadcasts instructions to it, what are they doing wrong?

    3. Re:Aquire a drone for even less? by Garridan · · Score: 2

      Your honor, the child entered my van of its own volition, and received the free candy that it sought. What did I do wrong?

      Sending instructions? Nothing (on the surface) wrong with that... but the content of those instructions is crucial to an ethical evaluation of them. Steal a drone / kidnap a kid? Bad. Make the drone do a little dance upon delivering a package / teach the kid a funny joke? Not bad.

    4. Re:Aquire a drone for even less? by Anonymous Coward · · Score: 0

      If you leave the front door to your house open, allowing entry to anyone, and someone walks in off the street and goes to sleep in my bed, what are they doing wrong?

    5. Re:Aquire a drone for even less? by nightsky30 · · Score: 1

      Very well put.

    6. Re: Aquire a drone for even less? by Anonymous Coward · · Score: 1

      Spooning your brother?

  6. Simple: just turn off the wireless by Neo-Rio-101 · · Score: 4, Interesting

    For something like Amazon's purported drones... all you'd have to do is to hardcode the delivery address and HQ into the drone before flying, and make sure it doesn't accept any incoming signals by turning the wireless off. Now, if we want to talk about trying to get the drone's GPS systems confused, that would be something else! (Actually I'm still wondering if the drone would be smart enough to land on pavement or miss entirely and drop packages on a customer roof or balcony.)

    --
    READY.
    PRINT ""+-0
    1. Re:Simple: just turn off the wireless by Anonymous Coward · · Score: 0

      Technology being what it is on a clear day they can probably navigate by aerial mapping imagery and inertial sensors if GPS is compromised.

    2. Re:Simple: just turn off the wireless by plover · · Score: 1

      I was wondering about that, too. Maybe they'll have the drone autonomously fly to the target's address, then have a human pilot land it on the doorstep, guiding it via GPRS, 4G, or something similar.

      --
      John
    3. Re:Simple: just turn off the wireless by Anonymous Coward · · Score: 1

      It would likely be a Destination Landing Pad. I suspect the optimal setup would be a subscription service, and the landing pad would be part of the subscription.

    4. Re:Simple: just turn off the wireless by sjames · · Score: 1

      I don't think they're smart enough to reliably drop packages on the roof or even in the pool, but I understand they're motion capturing paper boys on their routes to see if they can learn the secret.

    5. Re:Simple: just turn off the wireless by Zwergin · · Score: 3, Interesting

      (Sorry, did not realize I was not signed in. ) It would likely be a Destination Landing Pad. I suspect the optimal setup would be a subscription service, and the landing pad would be part of the subscription. ~Zwergin

    6. Re:Simple: just turn off the wireless by Fnord666 · · Score: 3, Funny

      Actually I'm still wondering if the drone would be smart enough to land on pavement or miss entirely and drop packages on a customer roof or balcony

      Hopefully they don't use the code that delivers care packages in Call of Duty then.

      --
      'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
    7. Re:Simple: just turn off the wireless by wvmarle · · Score: 1

      GPS is not reliable or accurate enough for doorstep deliveries, will need some human controller.

      The max. accuracy of normal GPS is about 1m, which is already a bit coarse for doorstep delivery and in urban areas receivers may get confused by reflections off of buildings. And even if GPS were accurate enough, you'd need to know really accurate coordinates of that doorstep, or that park bench where the person ordering the pizza is.

      So certainly a human operator will have to do the last part of the trip.

    8. Re:Simple: just turn off the wireless by rk · · Score: 4, Insightful

      DGPS can get 10cm resolution if done right, and DGPS coverage is not a problem for most residences in the US and certainly not in the areas I'm sure Amazon will pilot (no pun intended) this system. Vision systems are getting more sophisticated and can probably find the front door reliably with sufficient accuracy once on the scene. I'm curious to know how it will handle apartments, though.

    9. Re:Simple: just turn off the wireless by Dan541 · · Score: 3, Funny

      I'm curious to know how it will handle apartments, though.

      A cannon to launch the parcel through the window?

      --
      An SQL query goes to a bar, walks up to a table and asks, "Mind if I join you?"
    10. Re:Simple: just turn off the wireless by asmkm22 · · Score: 1

      That sounds about like my normal CoD support drop...

    11. Re:Simple: just turn off the wireless by Anonymous Coward · · Score: 0

      There aren't going to be any Amazon drones. This is called PR, plant an intriguing story in the news and get everybody talking about your core business proposition for the christmas season.

      christmas. amazon. delivery. christmas. amazon. delivery. christmas. amazon. delivery.

      anybody not get the message yet?

    12. Re:Simple: just turn off the wireless by Smauler · · Score: 1

      The accuracy of GPS is not the problem. The problem is places where GPS is useless.

      To be honest, if I can order something and it be in my drive in about 1/2 an hour, that is good enough, where I am living now. I can keep an eye out for it. I live in the middle of nowhere, and there's no chance of it being picked up by someone else. I have lived in towns and cities, though. Some of my previous residences had hundreds of people walking by the front door every hour. GPS does not work there, and it never will, no matter how accurate it is.

    13. Re:Simple: just turn off the wireless by Neo-Rio-101 · · Score: 1

      That's a pretty good idea. That way you could ensure that the drone lands in your backyard so that the package and drone doesn't get swiped from your front door by a passerby.

      --
      READY.
      PRINT ""+-0
    14. Re:Simple: just turn off the wireless by adolf · · Score: 2

      Apartments are easy! Just drop it on the communal stoop, wait for someone to steal the package, and send an SMS alert about "successful delivery" some hours later.

      Just like it works right now, with UPS, USPS, FedEx [...].

      (Speaking of SMS delivery alerts: A decade or more ago, I was getting delivery alerts in near real-time to my (then) fancy-pants alphanumeric pager (via SMTP). I'd greet the driver at the door, and usually by the time I was unboxing the stuff my pager would go off.

      What happened to the timeliness of this stuff? It's been terrible for the past few years.)

    15. Re:Simple: just turn off the wireless by MollyB · · Score: 1

      I'm still wondering if the drone would be smart enough to land on pavement,

      Rats. I was so looking forward to telling it, "Thanks. Now get off my lawn..."

    16. Re:Simple: just turn off the wireless by Gadget27 · · Score: 1

      Right, I was thinking the same thing when trying to help explain how this might work to my wife. I suspect that there would be a large landing zone 'card' of some sort, something that can be stored, unfolded and put out on your property. It would probably be provided for free. I'm imagining a black background with Amazon logo, and a large QR code that the drone can use to identify the landing zone. The drone would know how to fly to the general coords of the recipient's shipping address, at which point it would then locate the proper landing zone for delivery.

    17. Re:Simple: just turn off the wireless by RockDoctor · · Score: 1

      I'm imagining a black background with Amazon logo, and a large QR code that the drone can use to identify the landing zone.

      Within hours of Bozos or whatever his name is deploying one, the country (whichever country) will be blanketed with people "hacking" their own fakes using paper, a ruler, a pen and some ingenuity.

      If you deployed a paper "target" with the address for someone one street further away from the Amazon depot compared to your house, and the Amazon drone delivered the parcel to you, would that be theft? (Note : this is a private delivery service ; not the state mail system.)

      Signing for the parcel ... that would probably make it theft by misrepresentation a.k.a. fraud. But IANAL.

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
    18. Re:Simple: just turn off the wireless by Gadget27 · · Score: 1

      That's an excellent point, regarding hijacking other people's QR code addressed landing zones. It would be easy to imagine that such an action would be considered theft, or at least can be successfully argued as being so. Putting out a duplicate landing zone with a code that is supposed to be uniquely identifiable is a sort of misrepresentation and fraud I would imagine. It seems it would be the same as if you pried the numbers off your neighbors house and applied them to your own in order to confuse and trick the local UPS delivery man. Doing so also implies the intent to steal. At least, that all seems like common sense to me, but IANAL either. One way I can see to combat this is to have unique QR codes for each delivery that you print out at the time of order... it would be more difficult, though not impossible, to hijack shipments this way. It does create an extra burden on the recipient, as well as on the guys who write the software for the drones, as Im sure reading a code from a 8 1/2 x 11 piece of paper poses a bit more of a challenge versus something much larger printed on nearly all the surface of a landing zone.

    19. Re:Simple: just turn off the wireless by RockDoctor · · Score: 1

      as Im sure reading a code from a 8 1/2 x 11 piece of paper poses a bit more of a challenge versus something much larger printed on nearly all the surface of a landing zone.

      The "Parrot AR.Drone 2.0 Quadricopter" ships at a 4 pounds weight and a shipping size of 23in by 23in (by 0.5in - I don't believe that last one ; probably 5in deep). Say that the Amaz-drone has twice the landing weight (for 5lb of payload, and some improvements in lightening the airframe and battery). Then to a first approximation you'd think that it's footprint is going to be twice the area, and so sqrt(2) times larger in linear dimensions. so you'd need a landing pad of 32in square. Approximately.

      Actually, Would you necessarily have to print out a full landing pad QR for each delivery. Probably QR wouldn't do it, but I can envisage a QR-like code where most of the pad could use large (visible from a longer distance) codes to give the address of the site (associated with postcode, or street number / house number, perhaps) but allow for a single sheet (A4 or the American size) which contains the authentication for that particular delivery.

      Ah ; problem : what if you've got two deliveries made on one day. Or you don't know which day the delivery will actually happen. Or, for that matter, if a bird shits in the middle of your authentication code?

      It's a complex problem they're proposing solving.

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
    20. Re:Simple: just turn off the wireless by Gadget27 · · Score: 1

      When I first thought of the idea of the printable QR code, I was actually thinking along the lines you are... as an insert to a larger landing zone. I do think you idea is better, having the address information hard coded on the landing zone and having more of an authentication code printout being added per delivery.

      Regarding multiple deliveries on a day, or not knowing what day something will deliver, I don't know if such things will be much of an issue when I think of typical uses cases for such a service. I am going to assume that 30 minute deliver will come at a premium price. Perhaps they will end up offering a subscription service like they do with the current Prime accounts. In either case, I imagine that opting to have something delivered that fast would likely mean, or perhaps require, that you are there to actually receive shipment once the drone arrives. I would think if you wanted something that fast, you would already be there in order to make use of said package that fast, otherwise why not just opt for standard 1 or 2 day delivery? As far as knowing what shipment is what, I'd would think its a safe bet to make that drone deliveries would have very accurate, high resolution tracking, perhaps similar to how one can track the location and status of any commercial airliner that you know the flight number of. I don't think there would be a question what is being delivered when. Why not even use its on board camera(s) to stream a private live video of the flight as it approaches your house, assuming there is adequate mobile coverage between point A to point B. That would be fun, at least the first couple times you see it.

      As for the bird shit problem, I admit you got me stuck on that one. I suppose there would have to be some sort of backup authentication mechanism in place to handle such incidents. Maybe if primary authentication cannot be made, a photo of your LZ and/or current GPS coordinates on a map are sent to your mobile device app/email for you to approve. It may have to even make an automated call so it gets your immediate attention... I dont know, that is a tough problem to crack.

  7. Guns. by Anonymous Coward · · Score: 0

    Would you Americans please stop using guns to shoot each other, and aim them up at these things instead? Cheers.

    1. Re:Guns. by Garridan · · Score: 1
    2. Re:Guns. by Macgrrl · · Score: 1

      Someone beat you to it already.

      --
      Sara
      Designer, Gamer, Macgrrl in an XP World
  8. Haar cascade? by fatgraham · · Score: 1

    Does anyone have any haar-like classifiers for drones yet? Just for research of course.

  9. Much ado about nothing by Anonymous Coward · · Score: 0

    He's basically saying that "hey, this consumer drone has no security", and the most powerful signal wins.

    That's pretty much true of any consumer RC product.

    Newer-generation control systems in commercial & law-enforcement drones will likely use encrypted communications.

    1. Re:Much ado about nothing by Anonymous Coward · · Score: 0

      Even hobbyist grade consumer drones are not susceptible to this hack. This only affects a handful of "toy" drones like the Parrot AR which were never designed to be secure in the first place.

    2. Re:Much ado about nothing by pepty · · Score: 1
      Posted 4 hrs before this story:

      RF Safe-Stop Shuts Down Car Engines With Radio Pulse

      As the vehicle entered the range of the RF Safe-stop, its dashboard warning lights and dials behaved erratically, the engine stopped and the car rolled gently to a halt. Digital audio and video recording devices in the vehicle were also affected.''It's a small radar transmitter,' said Andy Wood, product manager for the machine. 'The RF [radio frequency] is pulsed from the unit just as it would be in radar, it couples into the wiring in the car and that disrupts and confuses the electronics in the car causing the engine to stall.'"

      Should do the trick for the encrypted ones.

  10. Congratulations! by StripedCow · · Score: 1

    You just gave Bigcorp a good testbed for free.

    --
    If Pandora's box is destined to be opened, *I* want to be the one to open it.
  11. No security vulnerability by Arancaytar · · Score: 1

    Because accepting a wifi connection without authenticating its source is totally not a vulnerability.

    In other news, you could own every single computer connected to the internet, without using any security vulnerabilities, as long as it runs an ssh server without a root password.

    1. Re:No security vulnerability by TangoMargarine · · Score: 1

      The logic is that you can't circumvent security if the security is nonexistent. I suppose it's still considered "breaking and entering" if you just walk in their unlocked front door (or is it just trespassing unless you commit some other crime in the process?), although you didn't break anything.

      --
      Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
  12. Arrr! by RDW · · Score: 2

    Finally a method of DVD piracy that the DMCA can't touch!

  13. Stealing an Amazon Drone by Metabolife · · Score: 2

    What's to stop someone from forcefully taking down an Amazon drone, then placing it into a Faraday cage while they disassemble it and get the free hardware?

    1. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      What's to stop someone hijacking a ups truck, then placing it into a chop shop while they yadda yadda.

    2. Re:Stealing an Amazon Drone by BadPirate · · Score: 1

      My plan is almost complete! MUAHAHAHA

      http://www.armaghplanet.com/blog/wp-content/uploads/2012/05/image-of-James-bond-spaceships.png

      ALT - (Photo is from James Bond, US Space ship getting eaten by Spectre ship in an attempt at starting world war)

      --
      - Holy crap, I've got MOD points! Who thought that was a good idea.
    3. Re:Stealing an Amazon Drone by umafuckit · · Score: 3, Insightful

      What's to stop someone from forcefully taking down an Amazon drone, then placing it into a Faraday cage while they disassemble it and get the free hardware?

      The fact that it's vapourware and will never see active service?

    4. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 5, Insightful

      a truck driver

    5. Re:Stealing an Amazon Drone by physicsphairy · · Score: 2

      Jeff Bezos circling above in an Apache attack helicopter.

    6. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      What's to stop someone from stealing a UPS truck while the driver is busy taking a package to the door?

    7. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      When I read the story about Amazon's drone delivery, my first thought was: "Will it be able to escape when I throw a blanket on it?"

    8. Re:Stealing an Amazon Drone by 14erCleaner · · Score: 1

      There's also the fear of prison. These things will be transmitting live video feeds back to home base. If they actually existed, that is.

      --
      Have you read my blog lately?
    9. Re:Stealing an Amazon Drone by Dunbal · · Score: 0, Troll

      Yes, thank goodness we live in a crime free world where the fear of prison prevents all crimes.

      --
      Seven puppies were harmed during the making of this post.
    10. Re:Stealing an Amazon Drone by wvmarle · · Score: 1

      And after taking control over that thing, what's stopping you from disconnecting the video stream as well?

    11. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 1

      I hear that the security system protecting most current home deliveries (I think they call it "a human") breaks down if you point a simple kinetic projectile emitter at it!

    12. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      COME ON MODS THAT WAS FUNNY. Apache is software, and an attack helicopter, and a helicopter that attacks with software.

      Its funny because Apache means both 'attack helicopter' (http://en.wikipedia.org/wiki/Boeing_AH-64_Apache) AND software (http://www.apache.org/). It activates two regions of the brain simultaneously, leading to a humor response.

      http://www.youtube.com/watch?v=EkSwszgdfNw

    13. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      http://www.youtube.com/watch?v=mgIsd7q0SI4

    14. Re: Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      So... For every â10 worth of stuff I order... I get a FREE Amazon Dron

    15. Re:Stealing an Amazon Drone by radish · · Score: 1

      What's to stop someone from forcefully taking a UPS truck, then placing it into a garage while they disassemble it and get the free hardware?

      Not much, other than the law. People steal delivery trucks sometimes, and they're a lot easier to steal than an aircraft in flight. The concept of delivering packages by wheeled vehicle still seems to work despite this flaw.

      --

      ---- Den ene knappen er powerknapp, den andre er Bender voice knapp "Bite My Shiny Metal Ass"

    16. Re:Stealing an Amazon Drone by PolygamousRanchKid+ · · Score: 1

      'round my parts, a horde of kids will be chasing them drones with Louisville Sluggers, while chanting:

      "Pinata! Pinata! Pinata!"

      "Hey! Mine had an iPhone in it! Cool!"

      "Su Madre! Mine had yet another copy of "Fifty Shades of Grey" . . .

      --
      Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
    17. Re:Stealing an Amazon Drone by SeaFox · · Score: 1

      a truck driver

      You believe a UPS worker getting paid $12/hr is going to stop someone with a gun who wants to take his fully insured company truck?

    18. Re:Stealing an Amazon Drone by hairyfish · · Score: 2, Funny

      There's is a whole order of magnitude more effort involved in hijacking and stealing a truck than knocking a drone out of the sky. Especially since an unexpected drone crash is a very high risk anyway. If I see one of these things I'll be hitting tennis balls at them purely for shits and giggles. If they happen to be in the way of my game of backyard cricket then fuck them.

    19. Re:Stealing an Amazon Drone by hairyfish · · Score: 1

      1. Effort.
      2. Risk of being caught.
      3. Length of sentence when you do get caught.
      None of these apply to drone 'interference'. Kids will be knocking these things out of the sky with rocks, the whole idea is unfeasible.

    20. Re:Stealing an Amazon Drone by hairyfish · · Score: 1

      It's a lot harder to hide a truck. Any 12 year old can knock a drone out of the sky (with some skill/luck) and stomp on it.

    21. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      They get paid alot more then $12/hr you useless dipshit fuck.

    22. Re:Stealing an Amazon Drone by Anonymous Coward · · Score: 0

      They shut down the truck and take the keys with them. Seriously. Even if the distance from truck to door is 10 meters or less.

      -- green led

    23. Re:Stealing an Amazon Drone by eth1 · · Score: 1

      I was thinking more along the lines of "decorating" my house with balloons on wires (kind of like the navy did in WWII), and if any of these flies over my house, there's a good chance it will end up "crashed" in my yard.

    24. Re:Stealing an Amazon Drone by BasilBrush · · Score: 1

      In most of the developed world crime is falling, and has been for years. Whilst there's no conclusive proof that one of the reasons is increasing security cam coverage, I suspect it's no coincidence.

  14. Slashdot needs a better "Stupid Submission" filter by Anonymous Coward · · Score: 0

    Any company that leaves their drones susceptible to a simple hijack deserves to go bankrupt buying drones.

    Let's see... Just put a GPS / visual flight plan in the thing that cannot be replaced without a secure connection or a physical connection.

  15. Skyjack only works for WiFi drones! by cciRRus · · Score: 4, Informative

    While pro-grade multicopters like those to be deployed by Amazon operate at 2.4GHz, they do not use WiFi as their radio system! Typically, these multicopters are fitted radio systems such as Futaba, JR, Spektrum or 9X, and therefore Skyjack will not be able to take them down.

    --
    w00t
    1. Re:Skyjack only works for WiFi drones! by Anonymous Coward · · Score: 1

      Maybe not. But I'm willing to bet many will be lost to .308 or .30-06 rounds...

    2. Re:Skyjack only works for WiFi drones! by Omega+Hacker · · Score: 1

      I *highly* doubt the Amazon drones will be operated by some hobbyist Futaba or Spektrum protocol. Doing such a thing would be absolutely ludicrous from just about every angle possible. First of all, such protocols are nothing more than "stream-of-servo" positioning commands, and very badly suited to autonomous drone control. Honestly they're pretty badly suited to manual drone control IMO. Second, they are even less secure than WiFi. I'm going to take a wild guess and say that the Amazon drones will be cellular-controlled, with high-end SSL used to send the drone a set of GPS coordinates (waypoints, etc.), and the drone will handle *every* control aspect from there on out, as it should.

      --
      GStreamer - The only way to stream!
    3. Re:Skyjack only works for WiFi drones! by Anonymous Coward · · Score: 0

      if you're operating anything that can kill people on unlicensed spectrum, you ought to be convicted and imprisoned.

    4. Re:Skyjack only works for WiFi drones! by drinkypoo · · Score: 2

      and the drone will handle *every* control aspect from there on out, as it should.

      I don't think so. I think they'll plot the entire route, waypoint by waypoint, down to delivery of the actual package. The drone will do waypoint following and collision avoidance, but that's it. That's a lot cheaper in terms of power budget, because your drone doesn't have to be quite so clever.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    5. Re:Skyjack only works for WiFi drones! by asmkm22 · · Score: 1

      It doesn't really matter what the various drones use. They will get hacked, because they're convenient targets designed to accept remote communications from someone.

    6. Re:Skyjack only works for WiFi drones! by Anonymous Coward · · Score: 0

      Isn't the entire premise faulty -- just connecting to the network doesn't mean you will automatically be able to reverse engineer and break whatever custom security protocols are in place for the fully encrypted protocol being sent over it.

      (ignoring that the physical layer would be a completely different technology anyway)

    7. Re:Skyjack only works for WiFi drones! by Anonymous Coward · · Score: 0

      ....or 12 guage....

  16. Law Enforcement Drones? by codegen · · Score: 3, Insightful

    The articles describe a wifi hack. Last I checked wifi has a range of 300 feet. There are some ways in which this can be extended to several miles but that involves large (i.e. 10ft) antennas. If you honestly think that law enforcement and amazon are using wifi to control their drones then I think you need to look a bit closer.

    --
    Atlas stands on the earth and carries the celestial sphere on his shoulders.
    1. Re:Law Enforcement Drones? by Anonymous Coward · · Score: 0

      Last I checked wifi has a range of 300 feet. There are some ways in which this can be extended
      to several miles but that involves large (i.e. 10ft) antennas.

      You must have old data...

      Patch and Yagi Antenna(s?) are quite assuredly not 10ft tall... and dishes are very... very likely not to exceed a couple feet across and will operate up to a (theoretical maximum) of 20 miles... give or take a radio troll or two.

    2. Re:Law Enforcement Drones? by cdwiegand · · Score: 1

      Wha? Yagi wifi antennas are certainly NOT 10 feet tall. 18" long - http://www.mfjenterprises.com/Product.php?productid=MFJ-1800. 15 dbi (so if your current antenna is 3 dbi this is a 12 dbi increase, or say 100x+ish). Very directional, though.

      And no one sane running a drone "program" would use normal wifi - they'd get a control frequency from the FCC and go that route.

      --
      . Define sqrt(x) as something really evil like (x / rand()), and bury it deep. Watch your coworkers go nuts.
    3. Re:Law Enforcement Drones? by asmkm22 · · Score: 1

      I think he's talking about building for about $400, then flying that drone close enough to another drone where the wifi magic works, and take control of it that way.

    4. Re:Law Enforcement Drones? by codegen · · Score: 2

      My distance was off. I was thinking of the 125 mile shot that used two 12ft dishes. (http://www.davemoorecomputers.com/Wifi-Shootout-Archives/Website-05/index.html) The article mentions the Amazon drones. They are intended operate in a 10 mile radius. You aren't going to do that with wifi.

      --
      Atlas stands on the earth and carries the celestial sphere on his shoulders.
    5. Re:Law Enforcement Drones? by codegen · · Score: 1

      And no one sane running a drone "program" would use normal wifi - they'd get a control frequency from the FCC and go that route.

      That was my main point. The articles mention law enforcement and amazon. They are not going to control the drones with wifi.

      --
      Atlas stands on the earth and carries the celestial sphere on his shoulders.
    6. Re:Law Enforcement Drones? by codegen · · Score: 1

      My point is neither law enforcement or Amazon is going to use a drone that uses wifi at all.

      --
      Atlas stands on the earth and carries the celestial sphere on his shoulders.
    7. Re:Law Enforcement Drones? by adolf · · Score: 1

      You're forgetting something important: Radio is traditionally used for broadcast and does not traditionally suffer the problems of long-range point-to-point Wifi links.

      Who said Amazon's drones would be controlled with Wifi, anyway? There's a myriad of other ways of efficient, reliable, low-speed (and inefficient, less reliable, high-speed) wireless technologies.

      Remember POCSAG? It's what is (still!) used for 1-way alphanumeric pagers. It's plenty fast enough to tell a swarm of drones where to go, and can have a high-power transmitter in a singular fixed location that can easily cover ten miles of range. A POCSAG receiver can run for weeks or months from a single AA battery: It is perhaps the most ideal solution.

      Talking back to home base is a bit more challenging, but with the pervasiveness of cellular data should not be a big deal (and the cellular radio can be turned completely off once the communications are sent).

      (Disclaimer: I install and maintain paging terminals. Everyone wants their smartphone to do everything, as well they should, and everyone is rightfully obsessed with Wifi...but there's no better alternative to a pager when lives are on the line (hospitals) or when production problems happen (factories) than a paging terminal with a real power amplifier and a gain antenna, with zero dependance on services provided by the outside world. 10 miles is -easy-. Trivial, even. Add a little bit of well-understood public-key encryption, and gosh: You've got a secure, low-speed wide-area control channel for your army of drones. It can be jammed with intentional interference, but control cannot be taken over without Hard Math.)

      (Also: Although it doesn't seem like it these days, one can send an awful lot of Real Data in a short time at 9,600bps.)

  17. How To Hijack UPS For $200 In Less Than 5 minutes by Anonymous Coward · · Score: 1

    A gun.
    Illegal will still be illegal.

  18. Not too advanced, but cool concept. by Anonymous Coward · · Score: 0

    This only affects parrotAR drones, which specifically are meant to be easy to use and have no security. Something like an Amazon drone or military drones will most likely have some authentication mechanism. But still, this is something to consider in popular drone design.

  19. So if you have a toy drone... by Stewie241 · · Score: 1

    So if you have a toy drone you can take over other toy drones? Could be great fun at a toy drone party but I don't see how it has anything to do with law enforcement drones or Amazon drones.

    I'm sure it would never cross the minds of intelligence agencies, law enforcement agencies or Amazon to authenticate the controller.

  20. Warflying by stewsters · · Score: 1

    I have all those components except the parrotAr2 drone. Early Christmas present?

    1. Re:Warflying by unique_parrot · · Score: 1

      I've sold my parrotAR2 because it is just a toy.
      Limited range (even with router-wifi extender).
      Even a walkera ladybug with fpv will give you more fun.

  21. "High-power"? by zooblethorpe · · Score: 1

    The target range of the Skyjack drones is limited by the range of the WiFi card, but Kamkar said he uses a very powerful WiFi adapter called the Alfa AWUS036H, which produces 1000mW of power.

    So this "very powerful" Wi Fi outputs 1000 milliwatts ... which equals one watt.

    Am I missing something, or is this just bad reporting?

    --
    "What in the name of Fats Waller is that?"
    "A four-foot prune."
    1. Re:"High-power"? by Actually,+I+do+RTFA · · Score: 1

      So this "very powerful" Wi Fi outputs 1000 milliwatts ... which equals one watt.

      Am I missing something, or is this just bad reporting?

      That's the highest power WiFi you can broadcast without violating FCC regulations. With a highly directional antenna, it should reach pretty far.

      --
      Your ad here. Ask me how!
    2. Re:"High-power"? by aXis100 · · Score: 1

      Normal wifi transmitters are only 30mW - and can still achieve 10km using a high gain directional antenna. So yeah, 1W is pretty powerfull.

  22. Security Vulnerability by rmdingler · · Score: 1

    "You keep using that word. I don't think that means what you think it means."

    --
    Happiness in intelligent people is the rarest thing I know.

    Ernest Hemingway

  23. Related article by sootman · · Score: 0
    --
    Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.
  24. What I fear will happen by mysidia · · Score: 2

    If Amazon can make a drone to deliver packages ---- then someone else can make a drone to "tail" Amazon drones, and grab the package after delivery; taking it off to some prescribed location for reappropriation.

    1. Re:What I fear will happen by Anonymous Coward · · Score: 0

      Just like someone can currently tail a UPS or FedEx driver and grab the packages after delivery?
      Of course since these drones initially are planned for 30 minute delivery you can be sure someone is probably waiting at the door for this stuff and if they see a drone attempting to swoop down for their shit I'm sure they could easily stop it.

    2. Re:What I fear will happen by radish · · Score: 1

      Or you could just, you know, walk down the street and pick up packages left by the UPS guy today.

      I see this type of comment all the time and yet I get packages from Amazon left on my doorstep multiple times a week. They're left in plain view, just like the drone would, and in 5 years of living here I haven't lost a single one. Sure if I lived in a large city I might not have a doorstep to leave it on, but I get the impression they're aiming this plan pretty squarely at the suburbs, and package theft just doesn't seem to be an issue here.

      --

      ---- Den ene knappen er powerknapp, den andre er Bender voice knapp "Bite My Shiny Metal Ass"

    3. Re:What I fear will happen by hairyfish · · Score: 1

      I'm pretty sure that the novelty of knocking a drone out of the sky will be a whole world more appealing to bored troublemakers than snatch and grabbing a driver/customer. I personally am looking forward to trying to take one of these out purely for a laugh. I'm sure I'm not the only one.

    4. Re:What I fear will happen by mysidia · · Score: 1

      Or you could just, you know, walk down the street and pick up packages left by the UPS guy today.

      You would look very suspicious if you did this, and there would be a great risk that a neighbor or homeowner would see you. Most packages left on a porch not requiring signature are not very valuable, so you would need many before it began to be worth it for the criminal ---- like winning the lottery, and the average criminal isn't going to think it's worth the high risk.

      Drones may change the equation; since no one will think a drone carrying a package around is suspicious --- Amazon does it. The worst that happens is you lose a drone to seizure/interference, after picking up probably hundreds or thousands of packages.

  25. real drone/plane? by Anonymous Coward · · Score: 0

    is that for a real drone or one of those remote controlled copters?

  26. One fun approach to the preservation of privacy by PopeRatzo · · Score: 1

    Three words: "Drone Knockout Game".

    --
    You are welcome on my lawn.
  27. Re:How To Hijack UPS For $200 In Less Than 5 minut by rmdingler · · Score: 1

    Sure. But. The number of people willing to steal remotely is an order of magnitude greater than the number of people willing to do up close and personal armed robbery. Mira! A car analogy: It's like killing a person with your pickup instead of with a knife.

    --
    Happiness in intelligent people is the rarest thing I know.

    Ernest Hemingway

  28. The assumption by Anonymous Coward · · Score: 0

    Hate to tell the author but any decent drone wouldn't use WIFI for communication

  29. They are not remote controlled by tusam · · Score: 1

    The Amazon drones aren't even remote controlled, but autonomous http://youtu.be/6in-MZeeeGk?t=12m26s

    (And even though there's probably some backup control channel and remote telemetrics it's very likely not wifi.)

  30. Everything old is new again by roc97007 · · Score: 4, Insightful

    Ok, so hang on, In a previous life as a military contractor, I used to do this with 1980's technology. This (TFA) sounds like a cheap, brute force approach, that actually works fairly well. You overwhelm the subject with a much stronger signal, and depend on the receiver's automatic gain control to limit the amplitude, putting the "real" control signal down in the noise. You then have the drone's full attention.

    The usual countermeasure is to encrypt the control signal. Then, you can still do a DOS (in today's terminology), but you can't get the drone to obey your commands.

    The counter-counter measure to this is to break the encryption so you can control the craft. Flash back to those supercomputers that hobbyists were building by clustering lots and lots of game consoles. Just saying'.

    Then, there's counter-counter-counter measures like hopping between frequencies and so forth, but for every technique there's a counter-technique, and I suspect computers have gotten fast enough to analyze tricky incoming signals and mimic them fairly quickly.

    Someone brought up GPS -- Amazon's little copters can't be hacked because they're autonomous, using GPS for navigation. Well guess what -- GPS is just another signal. As we learned in the middle east, it is possible to spoof those signals and get a drone to land in a place it didn't expect.

    The counter to *that* is inertial guidance. But realistically, Amazon and most government agencies probably won't have the budget for that.

    Optical guidance? (and optical surveillance in general) Green lasers with automated tracking and aiming triangulating by noise, or emitted RF, or visual recognition. Anyone with robotics experience should be able to at least theorize a solution.

    Wow, the next few years are going to be *fun*.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    1. Re:Everything old is new again by drinkypoo · · Score: 1

      The counter to *that* is inertial guidance. But realistically, Amazon and most government agencies probably won't have the budget for that.

      An off-the-shelf IMU costing less than $100 as a completed product gives you enough information to tell if your position is shifting in the way that the GPS claims, with a little software trickery. You can certainly detect something like that, and then start retracing your steps. One or two retries and the drone just flies home.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    2. Re:Everything old is new again by Eskarel · · Score: 0

      When they toss the first couple jackasses who do it as a joke into federal PMITA prison for the rest of their lives the joke will wear pretty thin. It's not even a case where it'd be a disproportionate response, anyone actually doing this for the lulz needs to be off the street for a long time.

    3. Re:Everything old is new again by roc97007 · · Score: 1

      I'm not interested in people who do it for laughs. (Although, there will probably be some who do it just to see what kind of chaos they can create. The same morons who point laser pointers at commercial aircraft.) As soon as the profit/risk ratio is favorable, someone will do it, either to acquire the cargo, acquire the craft itself, or prevent the craft from doing whatever it was trying to do. Just pointing out that there are known techniques.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    4. Re:Everything old is new again by Anonymous Coward · · Score: 0

      "Optical guidance? (and optical surveillance in general) Green lasers..."

      Works great until those leaves get in the way.

      The solution is multimodal. A lot of systems already support it. The reason why it's not used often is bandwidth, most 2.4Ghz non-wifi chips have some AES capability and coupled with other measures, you can secure your system up to jamming attacks.

    5. Re:Everything old is new again by roc97007 · · Score: 1

      The counter to *that* is inertial guidance. But realistically, Amazon and most government agencies probably won't have the budget for that.

      An off-the-shelf IMU costing less than $100 as a completed product gives you enough information to tell if your position is shifting in the way that the GPS claims, with a little software trickery. You can certainly detect something like that, and then start retracing your steps. One or two retries and the drone just flies home.

      I wasn't aware that IMUs had gotten that cheap. (I haven't done this stuff in many years.) But that just takes us to the next level, where IMU accumulated error and gradual GPS draw-off techniques are employed. More difficult, but still possible.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    6. Re:Everything old is new again by Overzeetop · · Score: 1

      So you spoof the GPS to be within the dead reckoning band of the IMU and wind allowances (which can't easily be accounted for). It takes longer to hijack and transfer to a safe spot for collection, but not out of the bounds of possibility.

      --
      Is it just my observation, or are there way too many stupid people in the world?
    7. Re:Everything old is new again by swillden · · Score: 1

      The counter-counter measure to this is to break the encryption so you can control the craft. Flash back to those supercomputers that hobbyists were building by clustering lots and lots of game consoles.

      If you use decent encryption in your counter measure, this counter-counter measure is useless. It doesn't matter even if the attacker has a cluster of real supercomputers.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    8. Re:Everything old is new again by Anonymous Coward · · Score: 0

      >The counter to *that* is inertial guidance. But realistically, Amazon and most government agencies probably won't have the budget for that.

      These aren't cruise missiles so there's no need for a self contained positional reference like inertial guidance. LIDAR and stereo camera terrain matching is enough. Let's see someone try to fake the physical signature of 10 square km of buildings remotely.

      And, by the way, a compass would probably already be a self-contained enough measure of heading to tell you when your GPS is lying.

    9. Re:Everything old is new again by Anonymous Coward · · Score: 0

      >So you spoof the GPS to be within the dead reckoning band of the IMU and wind allowances

      Yeah, a slow walk. The drone would run out of gas before you got it anywhere useful. Not to mention that both the sender and receiver would notice it was overdue.

    10. Re:Everything old is new again by AHuxley · · Score: 1

      The US gov handed out a lot of old 'mil' tech (~small tanks, weapons systems) and drones to a lot of "small" cities over the past 10 years. With FAA approval now more understood the drones will soon be watching more regional ports, truck movements, airports and main roads 24/7.
      A lot of groups doing 'import/export' work are going to be spending big on counter-counter measures to ensure their shipments are not tracked :)

      --
      Domestic spying is now "Benign Information Gathering"
    11. Re:Everything old is new again by Eskarel · · Score: 1

      There are, but there's always a risk of this sort of thing, as has been pointed out delivery drivers aren't immune from theft either.

    12. Re:Everything old is new again by adolf · · Score: 1

      Thank you for summing up the state of affairs. You've done better than most. :)

      Inertial guidance isn't so far-fetched. Ridiculously-small accelerometers are getting mighty good, as are tiny gyroscopes (both of which can be found in many modern smartphones, sipping very little power indeed). Combine both of them with sufficient resolution, and you've got inertial guidance.

      Combine that with other signals (constant transmitters of any type, including local TV and radio stations... even Wifi AP broadcasts are well-mapped in populated areas, and such maps can be trivially augmented with accumulated data collected by other drones in-flight) and an altimeter (also included on many new phones) and the system will be quite secure enough to drop off a package of goods in the absence of GPS.

      It will be computationally-expensive, but low-power CPUs are increasingly ridiculously fast, and software-defined radios ridiculously easy, and solid-state storage density keeps getting better. A drone could have its own map of how the RF landscape looks, and follow it to the target without any GPS at all, and the energy required to do so would be dwarfed by the energy required to simply keep the thing aloft.

      With all of these data inputs and the energy required to survey, triangulate, and use, any intentional jamming ("DOS") will have to be tailored to the specific area of operation: This makes an out-of-the-box solution impossible.

      And that jamming device (or devices) will be very easy to locate, given one or more clueful person, a suitable directional antenna, the most modest of spectrum analyzers, and drivers to ferry them about.

      And since Amazon's drone proposal is not a wartime mechanism, the findings can be simply reported to LEO to take care of it. It's not the end of the world if someone's diaper delivery winds up on some miscreant's stoop instead, or if the service is down for a few hours while a bunch of jack-booted thugs ("police") find and disable the ridiculously well-honed jamming device.

      In summation: Sensors are cheap enough and there is enough RF floating around in the populated areas of the US where drone delivery could ever be a viable option, that low-altitude drone navigation ought to be a very secure system by default, GPS availability or not. You'd have to jam everything at once (a spark gap can do that), but you'll be easy to find.

      And detecting GPS falsing is easy, too: "Hmm. GPS says I'm here, but most of the other indications are that I'm way the hell over there. I'll trust the other sensors, since GPS is obviously not working." (The same works in the opposite direction, too.)

    13. Re:Everything old is new again by Anonymous Coward · · Score: 0

      The counter to *that* is inertial guidance. But realistically, Amazon and most government agencies probably won't have the budget for that.

      My satnav from 5 years ago had rudimentary inertial guidance for when the GPS signal was lost in dense urban areas. I'm pretty sure that the company developing the drone for Amazon can figure something out... but that is beside the point.

      Holy freaking christ you are seriously bring up GPS spoofing as a means to hijack a simple Amazon delivery? Yes, I'm sure as we have seen when a FOREIGN MILITARY wants to bring down a drone it has the capability to do so, but holy crap you don't think for a moment that if GPS spoofing started to become a thing that you wouldn't have the freaking US military, FBI, FCC, and a load of other government agencies taking a particularly keen interest in tracking down whomever was interfering with such a critical component of our infrastructure?

      For pete's sake, in my CURRENT life as a military contractor, I can tell you that it's pretty freaking easy to track down someone who is emitting a signal on a frequency that they shouldn't be on, and the penalties for doing so, intentionally, are pretty damned severe.

    14. Re:Everything old is new again by roc97007 · · Score: 1

      Jeeze, calm down. Yes, the satnav in my truck also has rudimentary inertial guidance. It has an electronic compass and is aware of the truck's speed, and doesn't have to deal with altitude. It also tends to be "sticky" to roads, assuming that you must be on the nearest road even if the guidance indicates you're driving through a field. (And sometimes it gets it wrong.) As a current military contractor, you know about accumulated error in inertial guidance systems -- it just takes longer and is more difficult to draw off. It then becomes a question of escalation, until cost/reward becomes unfavorable for one side or another.

      But why are you so shocked that someone would spoof GPS? TFA talks about hijacking a drone. What part of "hijacking" do you think might be legal?

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    15. Re:Everything old is new again by roc97007 · · Score: 1

      There are, but there's always a risk of this sort of thing, as has been pointed out delivery drivers aren't immune from theft either.

      Absolutely true, as anyone who delivers pizzas for a living can tell you. I wonder if part of the equation might be that the penalty for stealing/destroying a drone may be less than robbing/injuring a human? (Probably true, as long as the drone is non-military.)

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  31. Re: How To Hijack UPS For $200 In Less Than 5 minu by Anonymous Coward · · Score: 0

    God knows I wouldn't have murdered all those people if I had to use a knife instead of my car. I would have had to cut back to four, maybe five, murders a day if I were so inconvenienced.

  32. What the hell? by BringsApples · · Score: 1

    “The only security on the Parrot drones is that when the owner is connected to it, no one else is able to control it. This is why I need to use a wifi chipset that allows me to inject packets as I need to exploit wifi and deauthenticate the true owner who is controlling it,” Kamkar said.

    So I've gotta ask, what would stop someone from doing this same thing on either side. On one side, you've got those that could hijack your parrot using the same tactics that you are using to hijack the drone. On the other side, whatever you do to protect your parrot, could be implemented to protect the drone, right? Am I missing something? Also, what's to stop parrots from buzzing around doing the same "evil" that Google did with wireless routers.

    --
    Politics; n. : A religion whereby man is god.
  33. $400? by gallondr00nk · · Score: 2

    You can do it for less than that. Just use a fishing net with a very long pole.

    CAPTCHA: patience.

  34. lol by Anonymous Coward · · Score: 0

    What drones that are used for anything but hobby use actually use WiFi for their C2 link?

    I think the author means "parrot AR drone" not "drone".

  35. Drone wars by Wolfling1 · · Score: 2

    Begun the drone wars have

  36. Bezos Butt Fucked 60 Minutes by Anonymous Coward · · Score: 0

    Bezos use a few 100k dollars cash to payola 60 Minutes Execs into letting him Butt Fuck 60 Minutes and America ... that he soooo loves.

    QED

  37. Specific Drone by Anonymous Coward · · Score: 0

    So, this works with a specific drone made by a specific company using a particular block of MAC addresses and is limited to a WiFi hack (which means it is within a few hundred feet).

    So, basically if you see a guy flying one of these in the park, you can launch yours to go hack his, disconnect his iPad and have it come to you. At which time he is going to run over to you and punch you right in the face for stealing his drone.

  38. magnetron by codepunk · · Score: 2

    Microwave oven magnetron and a small parabolic dish wifi antenna and all your drone belong to me.

    --


    Got Code?
  39. "well-known"? by Anonymous Coward · · Score: 0

    Never heard of the guy. Stop assuming everybody's heard of your personal idols, you. Not everybody cares about the coloured hats-crowd.

  40. WHO-HOO!!! by grep+-v+'.*'+* · · Score: 1

    ... if the drone would be smart enough to land on pavement or miss entirely and drop packages on a customer roof or balcony

    I've *ALWAYS* wanted to call up Domino's / Pizza Hut and say, "I'm traveling down the freeway -- deliver a large pizza to me." And with a (fast enough) drone flying beside me, now I can!

    Finding me in real time is no problem anymore -- just ask my phone's GPS or bug(!) the NSA. I'm sure those taps in the data center are all BI-directional.

    After all, what's a few packet swaps between friends?

    --
    If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
  41. I can get Amzon drone for only 10$ by Anonymous Coward · · Score: 0

    ... just by something from them and they will send it to you.

  42. It's a joke.. I built a drone. flight times.. LOL by Anonymous Coward · · Score: 0

    6000mah LiPo gets me 20 minutes of agile flight at most. After that I am risking a crash or a hard landing. When I fly via autopilot I have to be ready to take over control at any time. If the GPS gets several bad fixes in a row the quad could go off course. Microwave Radio interference can really mess up GPS reception.
    I have no problems when I fly along the beach or in my neighborhood but if I take it to work and try to fly via gps in the industrial park I have to take control eventually.

    It's too easy to hijack a drone. You can hijack easily just by fooling the GPS. This is easier than you may think.

    I'd like to see a DIY anti-drone rocket propelled net project.

             

  43. WooHoo! Sky Pirates finally arrive! by DaveV1.0 · · Score: 1

    No airships but steam/diesel punk is bleeding into the real world!

    --
    There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
  44. Hardly necessary by Anonymous Coward · · Score: 0

    The Parrot AR Drone can only go a couple hundred feet from the person controlling it. If someone hacks it, they are standing within eyesight of you... just watch them to see where they take your drone, then beat them up and get your drone back. Done.

  45. They're going to need to Cam and Arm those thangs by gx5000 · · Score: 1

    A slingshot with a scope will be much cheaper and I dare say more in use by the time these things go up....

    --
    End of Line.
  46. Misleading... by g0bshiTe · · Score: 1

    The author is giving misleading statements. What he's done is hacked a Parrot, this is not the type of drone nor system Amazon is likely to use. In fact what they showed in their video doesn't use a Wifi connection at all. It uses 2.4 ghz wireless that has automatic rolling channels to eliminate the possibility of squelching anothers frequency. The transmissions from drone to controller are also encrypted.

    --
    I am Bennett Haselton! I am Bennett Haselton!
  47. Re:It's a joke.. I built a drone. flight times.. L by g0bshiTe · · Score: 1

    I fly with a bunch of guys that build quads - multis etc. Not one uses gps that could be fooled short of overriding the gps entirely, even then the pilot is as you said on the sticks. One guy I fly with build an octo for DARPA, I dare say that thing is bullet proof.

    --
    I am Bennett Haselton! I am Bennett Haselton!
  48. DR Garage by Dareth · · Score: 1

    I want to know who this DR Garage is! He signs for all of my UPS deliveries!

    --

    I only look human.
    My mother is a halfling and my dad is an ogre, so that makes me an Ogreling
  49. All your drone... by Anonymous Coward · · Score: 0

    ... are belong to us.

  50. Amazon by Anonymous Coward · · Score: 0

    I can imagine the customer service calls/emails to Amazon.
    "My books and year supply of turtle wax never arrived"
    - - "Well sir, it appears that your shipment was taken out by a bunch of 6th grade boys with BB guns somewhere in a field in Arkansas."