Russia Suspected In GPS-Spoofing Attacks On Ships (wired.co.uk) 194
How did a 37-ton tanker suddenly vanish from GPS off the coast of Russia? AmiMoJo shares a report from Wired:
The ship's systems located it 25 to 30 miles away -- at Gelendzhik airport... The Atria wasn't the only ship affected by the problem... At the time, Atria's AIS system showed around 20 to 25 large boats were also marooned at Gelendzhik airport. Worried about the situation, captain Le Meur radioed the ships. The responses all confirmed the same thing: something, or someone, was meddling with the their GPS...
After trawling through AIS data from recent years, evidence of spoofing becomes clear. GPS data has placed ships at three different airports and there have been other interesting anomalies. "We would find very large oil tankers who could travel at the maximum speed at 15 knots," said a former director for Marine Transportation Systems at the U.S. Coast Guard. "Their AIS, which is powered by GPS, would be saying they had sped up to 60 to 65 knots for an hour and then suddenly stopped. They had done that several times"...
"It looks like a sophisticated attack, by somebody who knew what they were doing and were just testing the system..." says Lukasz Bonenberg from the University of Nottingham's Geospatial Institute. "You basically need to have atomic level clocks."
The U.S. Maritime Administration confirms 20 ships have been affected -- all traveling in the Black Sea -- though a U.S. Coast Guard representative "refused to comment on the incident, saying any GPS disruption that warranted further investigation would be passed onto the Department of Defence." But the captain of the 37-ton tanker already has his own suspicions. "It looks like the Russians define an area where they don't want the GPS to apply."
After trawling through AIS data from recent years, evidence of spoofing becomes clear. GPS data has placed ships at three different airports and there have been other interesting anomalies. "We would find very large oil tankers who could travel at the maximum speed at 15 knots," said a former director for Marine Transportation Systems at the U.S. Coast Guard. "Their AIS, which is powered by GPS, would be saying they had sped up to 60 to 65 knots for an hour and then suddenly stopped. They had done that several times"...
"It looks like a sophisticated attack, by somebody who knew what they were doing and were just testing the system..." says Lukasz Bonenberg from the University of Nottingham's Geospatial Institute. "You basically need to have atomic level clocks."
The U.S. Maritime Administration confirms 20 ships have been affected -- all traveling in the Black Sea -- though a U.S. Coast Guard representative "refused to comment on the incident, saying any GPS disruption that warranted further investigation would be passed onto the Department of Defence." But the captain of the 37-ton tanker already has his own suspicions. "It looks like the Russians define an area where they don't want the GPS to apply."
GPS Spoofing (Score:5, Funny)
It's all fun and games until a ship runs aground or collides with something, and an eye gets poked out
Re: GPS Spoofing (Score:1)
What is US Coast Guard doing in the black Sea? There is no US territory, unless they've annexed Turkey.
Re: GPS Spoofing (Score:4, Funny)
They thought they were in the Mediterranean but something was wrong with their GPS.
Re: (Score:2)
The USS John McCain and Fitzgerald incidents comes to mind.
And even though the GPS system requires atomic clocks a system to cause trouble doesn't have to have the same precision - it just has to cause headache by offsetting incoming data.
Re: (Score:3)
Nice excuse. Military vessels are supposed to have radar you know? What if they had to, shudder, fight an actual war where the enemy doesn't have their GPS transponder on to begin with?
Re: (Score:2)
Nice excuse. Military vessels are supposed to have radar you know? What if they had to, shudder, fight an actual war where the enemy doesn't have their GPS transponder on to begin with?
Mmm. Not to mention, in boot camp they're all issued with personal sets of Binocular Integrated Optical facilities Mk 1.
Re: (Score:3)
Why? Because it happened at sea?
For the Fitzgerald accident there is consistent AIS data that indicates that the freighter sent correct GPS positions. Also we don't see any ships in the vicinity being affected, their AIS-Data (in effect their position based on the GPS-data they received) should show anomalies if their GPS was affected by a spoofing attack.
In addition the US-Navy doesn't use civilian GPS, it's questionable that their GPS-based-systems can be spoofed as easily. Also they should have redundant
Re: Circle Jerk RUSSIA Trolling!!! (Score:2)
You're an annoying dullard. Go back to Facebook.
Re: GPS Spoofing (Score:4, Informative)
Re: (Score:2)
NATO grants itself that right.
Re: (Score:2)
Just because there is a treaty doesn't mean you can guess the contents of it to further your argument. The North Atlantic Treaty doesn't agree with your appraisal of its contents.
Re: GPS Spoofing (Score:4, Informative)
Incorrect, the ottoman Empire handed Crimea over in 1783, and Crimea was a separate SSR from 21 to 45, then part of the Russian SSR from 45 to 54, then a part of the Ukrainian SSR from 54 to 91, and then a part of an independent Ukraine from 91 to 2014.
So. Try to keep up!
Re: (Score:2)
Re: (Score:2, Funny)
what is more democratic than 99%.
letting the other 80% vote too?
Re: (Score:3)
99% of their population voted to stay with Russia. So now you can just fuck off, if you aren't a Crimean resident. Democratic election is what American regime claims it is spreading throughout the world, what is more democratic than 99%.
00% of Chechnya's population wants independence - and Russia gives a shit about that. Fuck Putin.
Re: (Score:2)
It's all fun and games until a ship runs aground or collides with something, and an eye gets poked out
Don't some weapons use GPS for, at least, some navigation? If so, then now there's now an exclusion area.
Re:GPS Spoofing (Score:4, Funny)
Given that the first thing the Russians would do in an actual war would be to take out the GPS satellites I suspect there's an inertial and possibly a visual b@7;'[[*&)>..
no carrier
Re: (Score:2)
Oh, come on, comrades, this is a funny old tech meme! Lighten up a bit on the mods.
Re: (Score:2)
Yeah, because we all need global positioning satellites, when we are either dead or hiding underground when the nuclear missiles fly. All I see is a propaganda scam to cover US naval officers illegally forcing right of even when those ships they are targeting with the US navies ego, can not make the manoeuvres they to force of them.
Reality for a military vessel like a destroyer, if the captain of that vessel, ever allows a slow barely manoeuvrable merchant vessel, even on purpose, to ram it, they should be
Re: GPS Spoofing (Score:2)
Probably those destroyers were way, way, way too dependent on networked computer systems for situational awareness. Most likely the captain had no idea anything was amiss until he felt the collision.
It seems like American military doctrine is too focused on using hyper-modern technology to suppress civilian and paramilitary resistance to an occupation. Glitzy, unproven, unreliable high tech toys are are just great when you're fighting against goatherds with AK-47s.
But we appear to have lost focus on fighti
Re: (Score:2)
But we appear to have lost focus on fighting an a "real" war against an evenly matched opponent.
I believe the opposite is true. We are seeing a military built in a way to fight World War 2 all over again that cannot deal well with "goatherds carrying AK-47s". I recall a US Navy exercise where someone brought in to command the simulated opposition force developed a plan that "sunk" nearly the entire flotilla. Despite the success of the opposition force in the simulation the US Navy tossed out anything that they may have learned and just called the simulation "unrealistic".
I'm not saying that having
Re: GPS Spoofing (Score:4, Informative)
Source: Conversations with a participant of MC02.
Re: (Score:2)
What a crock, you have sonar, radar, lookouts, officers on the bridge, coxswain in at the con. Only arrogance could have caused those crashes and forcing right of way. The, 'er', we didn't see the merchant vessel that anyone else could see from several kilometres away is no bloody excuse. No matter which way you look at it, a professional crew that could not fail to miss a major merchant vessel is either drunk, wildly incompetent or driven by massive erections. How incompetent, how egoistic https://www.yout [youtube.com]
Re: (Score:2)
Eh... just doesn't seem very likely. Sorry.
Re: (Score:2)
Where did, you learn to, write like William, Shatner, talks?
Re: GPS Spoofing (Score:2)
That would be a no.
Modern weapons can use GPS as one method of in flight guidance, but rarely is it the only method available to it.
In addition, those same modern weapons can use encrypted versions of said GPS making modifying the data just a wee bit more difficult.
Have to go with all out jamming for that.
Re: (Score:2)
It seems a small crisis is brewing in the South China Sea. Or thereabouts.
Re: (Score:2)
It seems a small crisis is brewing in the South China Sea. Or thereabouts.
Right, it sure is hard to know where the crisis is brewing when someone is spoofing GPS.
Re: (Score:2)
maybe they aren't islands, the GPS spoofing just makes them seem to sit still
Re: (Score:2)
Hormel has regional SPAM?
Yes. "By 2003, Spam was sold in 41 countries on six continents and trademarked in over 100 countries (except in the Middle East and North Africa)." - wikipedia
Re: (Score:2)
The US Navy seems to be doing a pretty good job at colliding with things without any help from the Russians.
Or...are they?! (Cue Twilight Zone riff)
Time to add encryption to civilian GPS? (Score:5, Insightful)
The US military already encrypts GPS for themselves - it can still be jammed, but it can't be spoofed.
Maybe it's time encryption was applied to civilian GPS as well. It's not like consumer electronics don't have the capability to handle the decryption, and it's not like you'd have to use the same keys as military GPS.
Re:Time to add encryption to civilian GPS? (Score:4, Informative)
it can still be jammed
That's why the USN has started teaching Old School navigation methods again.
Re: (Score:3)
Welcome to the age of electronic warfare, where sextants and typewriters may be brought out of mothballs before it's all said and done.
Re:Time to add encryption to civilian GPS? (Score:5, Insightful)
where sextants and typewriters may be brought out of mothballs before it's all said and done.
I think the Russians have already done that. [telegraph.co.uk]
Re: (Score:2)
Interesting. And they can track the exact machine used by its keystrokes, a nice little side benefit.
Re: (Score:2)
I know that was the case with "pivoting arm" typewriters (at least according to crime fiction) but am not sure that's valid with ball and daisy wheel machines.
Re: (Score:2)
Old fart who actually remembers this crap here.
Daisywheel with a fresh wheel is your best bet for covering your tracks. Over time identifiable damage occurs to the plastic coating of the daisywheel, so changing your daisy wheel every couple of weeks will effectively cover your tracks.
Typeballs aren't a panacea. While they more uniformly manufactured than type elements in a conventional typewriter, damage through mishandling can occur. Swapping typeballs helps, but over time Selectric type machines develo
Re: (Score:2)
Most HP Laser Jets didn't have PostScript interpreters. That the reasons host-based PS interpreters were created.
Also, flaws in drums will be transmitted to the printed page, allowing them to be traced.
Re: (Score:3)
it can still be jammed
That's why the USN has started teaching Old School navigation methods again.
How old school? Sextants, paper and pencil or "Alexa? ..."
Re: (Score:2)
it can still be jammed
That's why the USN has started teaching Old School navigation methods again.
Unfortunately, as recent incidents have shown, the lessons aren't going well!
Re: (Score:2)
You refer to bumping into other ships?
Re: (Score:3)
Encryption wouldn't be needed, but signing would be important. However, how does one offer this? An encrypted stream takes very little overhead to keep going with, because block and stream ciphers are very efficient. However, plaintext signing is a different ball game together. How do you sign a stream?
Re: (Score:2, Informative)
How do you sign a stream?
Break the stream into blocks (it probably already has blocks), get a checksum for each block, and sign the checksum. Send them on a separate channel if you don't want to modify the original stream.
Re: (Score:2)
Re: (Score:2)
>Encryption wouldn't be needed, but signing would be important.
Encryption's not my strong suit. Is that significantly different from using a private key to encrypt and publishing the decryption key? It's not like you're trying to protect the stream against decryption, you're just trying to prove who is sending the data.
Re:Time to add encryption to civilian GPS? (Score:5, Interesting)
The US military already encrypts GPS for themselves - it can still be jammed, but it can't be spoofed.
Of course it can be spoofed ("meaconned"), even if you assume that the encryption cannot be cracked. An attacker can receive the satellite signal and retransmit it. This signal will arrive at the target late, but it will still be valid - of course the attacker has to manipulate power / jamming etc to convince the receiver that the meacon signal is the valid one. You can be sure much thought has been given to this topic.
The particular attacks in the original post appear to be related to protecting Putin [nrkbeta.no]. I doubt the military attacks get rolled out for such a simple purpose.
Re: (Score:2)
An attacker can receive the satellite signal and retransmit it.
In case the attacker only wants to shift the time a bit -which could be important for communication networks- this would not be too hard indeed. If, on the other hand, he wanted to do a spoofing of the position, that would require capturing the satellite signals and delaying them individually. For the civilian code, the separation of the satellite signals can be done easily by digital correlation. However, because the military code is not publicly known, the isolation of the signals can only be done using l
Re:Time to add encryption to civilian GPS? (Score:5, Informative)
Re: (Score:3)
Re: (Score:2)
Re: (Score:2)
That was not my impression on how GPS worked. The military GPS is the same GPS that everyone else uses. The difference is that the military can predict the noise that was added to the GPS signal - because they added it. Once you know the noise you can subtract it from the observed signal to get the ideal signal with optimal accuracy. So there is no encryption / decryption involved when observing a GPS signal. The encryption / decryption occurs when transferring / calculating the added noise - a comple
Re: (Score:3)
What you're describing was Selective Availability and is no longer in use. What the GP was describing is the P(Y)-code [wikipedia.org], which is an encrypted PRN. All of this information is readily available these days and there's no need to rely on impressions.
Re: (Score:2)
The US military already encrypts GPS for themselves - it can still be jammed, but it can't be spoofed.
All GPS receivers do is measure aspects of delay. These measurements become the basis for determining location.
It is not necessary for an adversary to understand a signal to alter time of receipt and therefore modify calculated position.
Maybe it's time encryption was applied to civilian GPS as well. It's not like consumer electronics don't have the capability to handle the decryption, and it's not like you'd have to use the same keys as military GPS.
I would opt for better internal clocks within receivers and schemes such as RAIM to allow meddling to be flagged with high level of confidence.
Re: (Score:2)
Re: Time to add encryption to civilian GPS? (Score:4, Informative)
Wrong. Russia already spoofs GPS signals around Moscow to make it look like you're at the airport - sounds a lot like this. You can google the Moscow GPS events if you want.
Re: (Score:2)
It is probably easier to spoof GPS around Moscow than it is to spoof GPS out in the sea.
Wrong (Score:2)
GPS signals are weak and easy to overpower. The protocol is 100% open and anyone can easily spoof positions with a HackRF and decent amplifier. The old positioning system (which name escapes) me was retired but was again re-activated for reasons exactly like this.
Re: (Score:3)
So, you'd need something more powerful than the 26 W a GPS satellite transmitter puts out from 21000 km away? Wow, that's a lot. <rolleyes>
corrections (Score:2)
If you are spoofing the processing gain from the spreading code will apply to you too so that cancels. The marine GPS antennas are about 10dbi straight up and 0dbi at the horizon. They are tuned to be as close to a half sphere as possible because you get mist if your horizontal position accuracy from the satellites on the horizon so you need to hear those. So 26w plus 13dbi antenna minus 182 path loss is -155db at the ship antenna. Since you are really trying to spoof the horizon birds anyway the antenna ga
Re: (Score:3)
Eh? The point of spoofing it is to deny the enemy the use of it.
It makes as much sense to say "Russians have their own submarines/bombers and thus no need to sink/shoot down the US ones".
Re: (Score:2)
If you did with a spoofed signal, you'd need a rather powerful antenna
Satellite signals for GPS are so piss weak that there's enough concern about harmonics from other frequency transmitters causing outages, let alone on the fundamental.
If you want to spoof a GPS signal you can do it with a couple of hundred dollar SDR without an antenna attached and still affect every device in the vicinity of your house.
Re: (Score:2)
We're talking several ships in the ocean simultaneously, not sure if you've noticed but that's not the vicinity of your house, one of the boats is probably the length of your entire street and the boats probably can't see each other (distance of at least 14km between them).
You need at least 2 antenna's, one for each frequency GPS uses (1.2 and 1.5GHz).
How will you reposition a GPS signal for the area of a small city with the SDR? GPS has fairly decent signal discrimination (it kind of has to) and you need t
Re: (Score:2)
We're talking several ships in the ocean simultaneously, not sure if you've noticed but that's not the vicinity of your house
Re-read my post. Specifically about a system with the antenna disconnected being enough to play around in your local house. I don't think you really appreciate just how weak the GPS signal is when it hits the ground. It's somewhere in the order of -130dBm everywhere. To put that in perspective it's about 1000 times weaker than the point where your phone goes from showing no bars to showing no service.
Being able to fool multiple ships is not a case of any technical feat. Throw up a dipole and put a few watts
37-ton tanker ? (Score:3)
Re:37-ton tanker ? (Score:4, Funny)
TFA says "tonnes". Maybe we should just use gigagrammes for clarity.
Re: (Score:2)
TFA says "tonnes". Maybe we should just use gigagrammes for clarity.
That's a great idea. Seriously. We already use the kilogram and milligram for indicating mass, why not a gigagram? Although I think you spell it funny.
sophistication (Score:5, Interesting)
Wikipedia suggests that Russia spoofs GPS whenever Putin is in the area.
Re:sophistication (Score:5, Funny)
Wikipedia suggests that Russia spoofs GPS whenever Putin is in the area.
No! No hack, no spoof. Putin Strong, like bull. Forceful personality warps space around him. West just jealous they not have such leader.
Re: (Score:2)
Wikipedia suggests that Russia spoofs GPS whenever Putin is in the area.
No! No hack, no spoof. Putin Strong, like bull. Forceful personality warps space around him. West just jealous they not have such leader.
That's nothing! Our great leader has a furry alien parasite on his head that makes him hyper intelligent, the greatest negotiator of all time, a business genius without peer and he has good genes... good genes, great genes, absolutely amazing, wonderful genes, he is always a winner and his eloquence warps reality itself into ... an alternate reality, of ... alternative facts... and he gets two scoops of ice cream because he's an alpha male, not a one scoop pyjama boy.
Re: (Score:3)
"Our great leader has a furry alien parasite on his head"
That's the trouble with Tribbles.
Re: (Score:2)
No! No hack, no spoof. Putin Strong, like bull. Forceful personality warps space around him. West just jealous they not have such leader.
For some reason I read that aloud in the voice of a North Korean news reporter.
Want an overview of Russian government? (Score:3)
If you want an overview of the degradation of the Russian government, I suggest this book: The New Tsar: The Rise and Reign of Vladimir Putin [amazon.com], by Steven Lee Myers (2015)
For those who want an overview of the degradation of the U.S. government, can you recommend a book?
Re: Want an overview of Russian government? (Score:2)
That's gonna be a tough one, seeing as how there are maybe 1000 total antifa goons nationwide. And also seeing how they are just a much of anti-'s, grievance mongers without any real Ideology or positive goals.
bug (Score:2)
Re: bug (Score:2)
To its author, that bug might be a feature...
About a year ago (Score:2)
About a year ago, this same thing was reported on land as well in Russia
https://news.slashdot.org/stor... [slashdot.org]
Re: (Score:2)
You might want to, you know, at least look at the first sentence from darkain's link before commenting.
The linked story was about Russians noticing their GPS not working in the vicinity of the Kremlin. It's quite easy to see why the Russian Government would want that; but it's rather more difficult to argue why Ukrainians or Muslims would be involved.
Vanish from GPS, eh? (Score:2)
I thought all the satellites were too old to receive anything from earth, let alone from puny handheld units like as early smartphones were. Maybe that's why it's not called Wireless magazine?
AIS or GPS? (Score:5, Insightful)
Keep in mind that AIS is just one of several redundant systems which ships use to navigate waterways and track positions of nearby vessels.
No investigation has indicated suspicions that Russia did anything. The only one who suspects Russia is one captain of a tanker ship.
Re:AIS or GPS? (Score:5, Interesting)
Re:AIS or GPS? (Score:4, Informative)
Re: (Score:2)
Are we spoofing GPS here, or are we spoofing AIS? Just so we're clear... GPS is obviously GPS, but the summary seems to conflate GPS and AIS. AIS is a terrestrial based VHF system which takes GPS data from individual ships adds identifiers and transmits it to anyone who cares to listen, which usually means other ships and shore-side receivers. It sounds to me like it is AIS that is being spoofed -- which would be trivial compared to GPS.
It's talking about GPS spoofing where bad AIS data flows from bad GPS data.
Quoting TFA:
"Instead of displaying Atria's actual position, the ship's systems located it 25 to 30 miles away â" at Gelendzhik airport"
Re: (Score:2)
AIS is not used by the ship to navigate, and the ships navigation is broken by this spoof. So it can't be AIS.
Also, as mentioned above, it is clearly stated that GPS is spoofed and nothing else.
Vanish from GPS? (Score:2)
What does this even mean? It seem to indicate that the poster thinks GPS is some sort of tracking system.
Oblig. (Score:2)
In Soviet Russia GPS spoofs you!
I mention this in tribute to our favorite russkiy komik, a funny guy from the Cold War. It occurs to me, there must have been some expat Americans over in the USSR doing the comedy circuit. Is anyone aware of anyone?
wikipedia: His humor combined a mockery of life under Communism and of consumerism in the United States, as well as word play caused by misunderstanding of American phrases and culture, all punctuated by the catchphrase, "And I thought, 'What a country!'"
What a
37-ton tanker? (Score:2)
(It's only Monday, but I've already met my internet pedantry quota for the week.)
So what about GLONASS? (Score:2)
Why airports? (Score:3)
Anyone else notice a pattern? It seems that when the signals are spoofed the reported location is at an airport. Why would that be?
Is this to protect the airport? For example, a GPS guided bomb dropped on the airport would think it is on target when in fact it is 30 miles out from shore. Is it to protect other targets? They'd be willing to go sacrificing the airport (presumably a low occupancy area with few buildings, most of the area being runways and such) instead of a higher value target.
Maybe it's just that an airport is a convenient place to hide the equipment and the device is re-transmitting it's own location to get around the problems of having to decode and re-encode the GPS signals.
Maybe I'm seeing a pattern that isn't there.
Re: (Score:2)
Maybe it's just that an airport is a convenient place to hide the equipment and the device is re-transmitting it's own location to get around the problems of having to decode and re-encode the GPS signals.
You don't need to decode and recode. Other than for the military GPS signals aren't complicated or encrypted. They are well described and open. Also there are freely available tools to create fake GPS signals. All you need to do is pump them through a transmitter, not even a very strong one.
Re: (Score:2)
Re: (Score:2)
Just another example of terrible headline writing, with the added bonus of uninformed authorship, and a dose of failure-to-consult-experts, though in this case a minute with Wikipedia would have sufficed for an author of average intelligence.
I know, big assumption there.
Sources of AIS errors (Score:2)
GPS spoofing possibly seen in AIS data: http://schwehr.blogspot.com/20... [blogspot.com]
And before that I've written quite a bit on the insanity that is AIS:
AIS Integrity and Security - Part 0: http://schwehr.blogspot.com/20... [blogspot.com]
Interesting theory. GPS problems. (Score:2)
Why pseudolites are used: Pseudolites preserve position information during GPS-denied conditions [army.mil] (June 2, 2016)
More info about the development of radio frequency position information:
Opening Up Indoors: Japan's Indoor Messaging System, IMES [gpsworld.com] (May 1, 2011)
There are, of course, probl
Link (Score:2)
Re: (Score:2)
To successfully meacon a GPS signal, you need a very powerful transmitter, and an antenna which transmits circularly-polarised photons. That bumps the cost up a bit. We're talking a few thousand dollars rather than hundreds, but still, it's not quite as simple as you make out.
Re: (Score:2)
https://www.fleetmon.com/maritime-news/2017/19867/gps-spoofing-preps-worldwide-sabotage/
You can also look up the Altria and find its true size. (in the photo section).
I'm not sure I want to follow the link, but googling it let to this interesting tidbit from the Army's OPFOR guide http://www.apd.army.mil/epubs/... [army.mil]
"Note: A GPS jammer the size of cigarette pack transmitting 4 Watts, can effectively deny use of GPS in an area ranging as far as 150-200 km. It is extremely simple to install one of these lightweight GPS jammers into a small UAV. Off-the-shelf remote controlled aircraft can also be modified to provide this capability. "
Re: ofc (Score:2)
Senator McCarthy, so nice to see you again.
Re: (Score:2)
I suppose you get all of your news from websites with anonymous domain registration that claim to be American. You wouldn't know fake news if it bit your dick off.
Re: (Score:2)
Much more likely that the Russians are trying to thwart a much more serious threat. They are trying to keep Uber out.