Hacker News new | ask | show | jobs
by sneak 144 days ago
ADS-B is packet data telemetry broadcast unencrypted and unauthenticated by aircraft on 1090MHz.

Anyone can receive it, and many do. FlightRadar and others have networks of people with receivers that forward all received packets to central servers.

The aircraft self-report location, heading, altitude, etc, so anyone can transmit packets making ghost planes.

I am somewhat surprised nobody has stashed an ADS-B spoofer near ATL or AMS that just broadcasts tracks of A380 tail numbers crossing the runways perpendicular at 500 ft AGL or something. They have primary radar, sure, but I imagine there would still be a temporary disruption until people figured out what was going on.

I think this is the first case I’ve seen of ADS-B spoofing in the wild.

EDIT: this was spoofed reports to the data aggregators via the internet, not broadcast on radio waves. I’ve still never seen or heard tell of RF ADS-B spoofing.

3 comments

> I’ve still never seen or heard tell of RF ADS-B spoofing.

Probably because the required expertise, effort, risk, and reward ratios don't work out. You can cause a minor disturbance that isn't particularly visible and in exchange get investigated by the FBI. Seems about as wise as attempting to graffiti the front gate of a military base.

Fake signals are not uncommon, but mostly accidental. They are dealt with very quickly when causing traffic control problems
Sure, but traffic control problems can still be caused (temporarily) by abuse of the frequency/protocol by those intending to cause disruption.

Can you tell me more about the fake signals? Who sends them? Why? How often?

I'm guessing this doesn't cause traffic control problems due to the no-fly zone over that area?
Probably is not causing traffic issues. With that said I'm sure a number of TLA's are looking into it already, so whoever did it has hopefully took a number of infosec steps not to get caught and questioned.
There was this proof of concept in 2012: https://youtu.be/CXv1j3GbgLk?t=2483

(IIUC they did not actually transmit data, just fed it directly into an ADS-B receiver, but transmitting would've been trivial at this point)