While this seems legit, it's worth noting that ADSB, the RF message protocol used for most 'live' location stats in FlightRadar24, has no form of authentication. Nevermind the network protocol weaknesses, trolling FR24 would require little more than a $300 radio and some free software.
If anyone does that, some very professional people who love hunting radio emitters (so much that they've made it their life's work) will start triangulating him. They'll have a blast, and they're very good at it. And they'll come accompanied by some plentifully armed people who like to use force, and they're very good at it.
Yes, and it’s not just for these sites but ATC too... although that’s been true of all aviation coms and nav technologies. Someone with some radio gear and a basic understanding of how these systems work could mess things up big time. That’s why, at least in the US, unauthorized broadcasting on aviation Nav or Com frequencies is a deadly serious thing that the Feds don’t take lightly.
For a much simpler threat model, the FAA is also deadly serious about laser illumination of aircraft and will involve local law enforcement and the FBI. Don’t let your buddy who got some crazy powerful laser pointer be stupid and point it toward an airplane or helicopter.
You'd also be trolling the air traffic control system
The safe way of avoiding that is to inject it directly into the FR24 feed, rather than broadcasting it as ADS-B.
A considerable proportion of their data is receiving from end-users running their own receivers, rather than the FR24-branded receiver. They do reject spurious data from one receiver but genuine-looking data would be hard to detect and discard.
It's certainly real, the flight path is being tracked in real time by thousands of receivers. You'd need to fly around your transponder to make that, at which point it's not illegal any longer. But if you started DDoS'ing a single point in airspace you're going to go to jail very quickly.
That's already been demonstrated at defcon. Here's Brad Haines tricking open source flight tracking software into displaying YOURMOM, a connecting flight with the San Francisco International air control tower. Demonstrated in safe conditions in a faraday cage, of course.
I was thinking of this exact talk. IIRC, He never gets a hold of the more expensive plane-to-plane transmitters and of course, he wouldn't transmit anything on them if he did, but he does bring up a lot of concerns and I'm wondering what the FAA and other countries orgs have in place to detect malicious signals, track them and stop/arrest them.
"the RF message protocol used for most 'live' location stats in FlightRadar24, has no form of authentication."
I wonder if this is a potential security risk, considering ADS-B is not only used for flight tracking but also air traffic control and collision avoidance?
Could a bad actor (using a drone, perhaps) broadcast a false signal and trick aircraft into performing collision avoidance manoeuvres? Or flood the ADS-B bandwidth with false signals to confuse ATC?
Yes. At which point, the pilots will see what is going on, take manual control, gather data for ATC's inevitable response, and use traditional instruments to navigate the airplane to a safe landing. Passengers would likely be unaware. In the United States, a report would subsequently be filed with the ASRS.
They could be employing some verification by using multilateration (time (difference) of arrival) between their receivers, which would make it a lot more resistant to spoofing.
Yeah, ADSB is a position reporting system that has to work between aircraft with no prearrangement. Such a thing is inherently insecure by the nature of what it is.
Not so. A PKI could have been put in place and would have allowed "strangers" to securely authenticate and set up a secure session, but I suppose the expense was not deemed worthwhile. Also possible is that such a session would be point-to-point, and an area handshake, while possible, would have been less reliable and more complex, while also loading the bandwidth with more radio traffic and thus increasing the noise floor overall. ATC running costs would have increased as well.
So it's not that it couldn't be done or is inherently insecure, it's that a choice was made (either by omission or by intent) to not do it.
It's a one way protocol. Pure broadcast. No session.
Note that anyone with a hundred bucks can buy a used aviation voice radio and do all the spoofing they want. It just isn't a problem because people don't like jail. The problem of getting acceptable reliability in an aviation electronics environment is tough enough that deliberate attacks fall below the noise.
Comments
While this seems legit, it's worth noting that ADSB, the RF message protocol used for most 'live' location stats in FlightRadar24, has no form of authentication. Nevermind the network protocol weaknesses, trolling FR24 would require little more than a $300 radio and some free software.
If anyone does that, some very professional people who love hunting radio emitters (so much that they've made it their life's work) will start triangulating him. They'll have a blast, and they're very good at it. And they'll come accompanied by some plentifully armed people who like to use force, and they're very good at it.
Not true. Done this. Never have been found.
Yes, and it’s not just for these sites but ATC too... although that’s been true of all aviation coms and nav technologies. Someone with some radio gear and a basic understanding of how these systems work could mess things up big time. That’s why, at least in the US, unauthorized broadcasting on aviation Nav or Com frequencies is a deadly serious thing that the Feds don’t take lightly.
I think in Germany it's just as serious.
It's serious everywhere.
For a much simpler threat model, the FAA is also deadly serious about laser illumination of aircraft and will involve local law enforcement and the FBI. Don’t let your buddy who got some crazy powerful laser pointer be stupid and point it toward an airplane or helicopter.
You'd also be trolling the air traffic control system, which would get the attention of people you'd much rather not notice you.
That doesn't prove that this is real, but think twice before trying it out....
The safe way of avoiding that is to inject it directly into the FR24 feed, rather than broadcasting it as ADS-B.
A considerable proportion of their data is receiving from end-users running their own receivers, rather than the FR24-branded receiver. They do reject spurious data from one receiver but genuine-looking data would be hard to detect and discard.
It's certainly real, the flight path is being tracked in real time by thousands of receivers. You'd need to fly around your transponder to make that, at which point it's not illegal any longer. But if you started DDoS'ing a single point in airspace you're going to go to jail very quickly.
That's already been demonstrated at defcon. Here's Brad Haines tricking open source flight tracking software into displaying YOURMOM, a connecting flight with the San Francisco International air control tower. Demonstrated in safe conditions in a faraday cage, of course.
https://www.youtube.com/watch?v=CXv1j3GbgLk
I was thinking of this exact talk. IIRC, He never gets a hold of the more expensive plane-to-plane transmitters and of course, he wouldn't transmit anything on them if he did, but he does bring up a lot of concerns and I'm wondering what the FAA and other countries orgs have in place to detect malicious signals, track them and stop/arrest them.
"the RF message protocol used for most 'live' location stats in FlightRadar24, has no form of authentication."
I wonder if this is a potential security risk, considering ADS-B is not only used for flight tracking but also air traffic control and collision avoidance?
Could a bad actor (using a drone, perhaps) broadcast a false signal and trick aircraft into performing collision avoidance manoeuvres? Or flood the ADS-B bandwidth with false signals to confuse ATC?
Yes. At which point, the pilots will see what is going on, take manual control, gather data for ATC's inevitable response, and use traditional instruments to navigate the airplane to a safe landing. Passengers would likely be unaware. In the United States, a report would subsequently be filed with the ASRS.
They could be employing some verification by using multilateration (time (difference) of arrival) between their receivers, which would make it a lot more resistant to spoofing.
EDIT: https://www.flightradar24.com/how-it-works#mlat
Definitely plausible for ATC installs.
It's legit https://twitter.com/flightradar24/status/940976806638899201
Yeah, ADSB is a position reporting system that has to work between aircraft with no prearrangement. Such a thing is inherently insecure by the nature of what it is.
Not so. A PKI could have been put in place and would have allowed "strangers" to securely authenticate and set up a secure session, but I suppose the expense was not deemed worthwhile. Also possible is that such a session would be point-to-point, and an area handshake, while possible, would have been less reliable and more complex, while also loading the bandwidth with more radio traffic and thus increasing the noise floor overall. ATC running costs would have increased as well.
So it's not that it couldn't be done or is inherently insecure, it's that a choice was made (either by omission or by intent) to not do it.
It's a one way protocol. Pure broadcast. No session.
Note that anyone with a hundred bucks can buy a used aviation voice radio and do all the spoofing they want. It just isn't a problem because people don't like jail. The problem of getting acceptable reliability in an aviation electronics environment is tough enough that deliberate attacks fall below the noise.
Yes, at least put a signature block in the protocol.
I guess it's similar to the AIS signals used by ships.