Skip to content

Comment on Iranian Hackers Post Images Over JFK Airport From UAV That Was Hijacked In March

Comments

This thread seems to be pretty chock full of some tinfoil hats.

1) You're not going to be added to "a list" because you clicked a link on hacker news. Remember that the NSA employs some of the smartest people in the world. Would it be meaningful to add a bunch of curious silicon valleyists to a list of "possible terrorists"? Probably not.

2) If you think that an aircraft that is anything bigger than a small pigeon could get anywhere near a major airport without getting itself a nice escort, then you're nuts.

Here is a map of the airspace near JFK: http://www.aeroplanner.com/notams/airspace.cfm?apt=jfk

This is all "Class b" or "bravo" airspace. It's all heavily controlled, heavily monitored with radar, and you have to ask permission to enter it.

It's incredibly unlikely that there was a "drone" in bravo airspace. Possibly a UAV, definitely not the boogey man Iranians.

3) This website doesn't even say anything. It's some pictures that could have easily been photoshopped together. Google translate isn't giving me anything interesting, and unless HN is a LOT more diverse than I realized, you're all going nuts over a couple of grainy photos.

Finally, here is what the drone that Iran supposedly "captured" last year looks like: http://i.imgur.com/ALveZWi.jpg

It isn't a toy. It's huge. There is no way that is getting anywhere near a RADAR without everybody knowing about it. Yes, it is [possibly...meant to be, rumored to be] stealth. That doesn't mean it's going to go undetected into a major airport like that.

Relax. Go have a beer.

1. You have a lot more confidence in our government's ability to accurately compile lists than I do, particularly in light of the failures of the no-fly list: https://en.wikipedia.org/wiki/No_Fly_List#False_positives

2. Based on commentary from native Persian speakers on this thread, it would appear that no one is claiming that the drone was remotely piloted by Iranians into US Airspace, but rather the one that was shot down in Iran several months ago (confirmed by the US Government) had these photos on it.

3. See above, there are at least 2 Persian speakers on this thread. HN is a LOT more diverse than you realize.

https://en.wikipedia.org/wiki/Iran–U.S._RQ-170_incident‎

"2. Based on commentary from native Persian speakers on this thread, it would appear that no one is claiming that the drone was remotely piloted by Iranians into US Airspace, but rather the one that was shot down in Iran several months ago (confirmed by the US Government) had these photos on it."

If this is true it means the Iranians compromised the encryption on the UAV's drive, which would be seriously not good.

The Iranians outsmarting NSA encryption? Not likely. Possible in theory and a huge deal, but not likely. If they decrpyted something from a military aircraft, it's much more likely that shoddy engineering work was done on that aspect of said aircraft because it was decided that security wasn't a top concern. (And, indeed, having pictures of JFK _isn't_ a big deal.)

Totally possible the imaging equipment retains data in an insecure fashion.

However, milspec != NSA, and its highly likely the Russians would help the Iranians in such an endeavor in exchange for intelligence sharing.

milspec != NSA

What exactly is "milspec"? I was under the impression that military security standards in the US _are_ produced by the NSA.

highly likely the Russians would help the Iranians in such an endeavor in exchange for intelligence sharing.

I must be missing something... yes, but what do Russians have to do with it? I thought this was a US drone captured by Iranians. Genuine question here.

MIL-SPEC means encryption built to military specifications. It includes, but does not equate to, NSA Suite B cryptography. As you can imagine, using crypto designed by a paranoid spook agency would not be appropriate for all military applications, for example a near-real-time flight application. As a result, there are a variety of encryption standards used by the military, some of which would be approved by the NSA, others which wouldn't.

It's a good question about the Russians. The ties between Russia and Iran are much tighter than most in the US realize, especially when it comes to national security, and particularly with regard to US-related issues. If we used industrial grade crypto on a system, it would be in line with past behaviors for the Russians to help the Iranians with it.

Thanks.

Regarding the Russians: Oh, I see, now. Yes, you're right that if country X cracks our encryption, we can't assume that they didn't get help from <insert China or Russia here>.

for example a near-real-time flight application.

Wait, why do you say such a system wouldn't use NSA-grade encryption?

for example a near-real-time flight application.

Primarily latency. Now, ideally you'd like the entire subsystem moved off disk into volatile memory, but for some things you're going to have to read from disk. I can imagine cases where that wouldn't be easily feasible if the drive had NSA crypto.

"Regarding the Russians: Oh, I see, now. Yes, you're right that if country X cracks our encryption, we can't assume that they didn't get help from <insert China or Russia here>."

Right, but its more than that in the case of the Iranians. The Russians have a long and documented history of assistance to the Iranians and the Syrians.

for some things you're going to have to read from disk.

I'm not sure I follow. For some things you're going to have to _write_ to disk... like captured video. (I wouldn't consider that to be the "real-time" part of the software, though.) And you might have to read from disk occasionally... maybe you have map information stored there... but that probably doesn't need to be real-time. Can you tell me an example where you would need to read from disk in real-time? (Which I think should anyway be impossible, regardless of whether or not heavy crypto is being used.)

The Russians have a long and documented history of assistance to the Iranians and the Syrians.

Yeah, very true, I have noticed that, too.

Sure! Man I love when people on hn ask genuine questions rather than trying to one up one another. It's one of the reasons I was so reluctant to stop lurking for so long.

Much like the Mars rovers, the navigation system is loaded in a modular fashion, with complex algorithms for each scenario loaded on the fly. So for example, imagine a UAV goes into a stall. Likely the aircraft needs a whole new set of algorithms to recover. It's very likely I this case you'd need low latency disk reads. Now again, this is just a guess based upon my experience with similar systems. I've never developed a UAV system.

Man I love when people on hn ask genuine questions rather than trying to one up one another. It's one of the reasons I was so reluctant to stop lurking for so long.

Well then, you're exactly the kind of person we need to stop lurking and start participating, so welcome aboard. But yeah, I totally understand you.

this is just a guess based upon my experience with similar systems

You mean planetary rovers? If not, can you be more specific? I realize it's not necessarily wise to divulge too much industrial information. I actually have worked on UAVs... not to the point that I can say the scenario you're presenting is incorrect (I wasn't involved in that kind of stuff), but I don't think it's very plausible. I could see that strategy being more reasonable on a super memory-constrained device where the system is radiation hardened, like space equipment. I would think for a normal UAV, you'd just keep all the code (algorithms) you might need in memory.

Its possible I'm wrong. I've never designed a UAV flight system, so I was speculating as to reasons why a lower level of encryption might be needed. Its possible that's not a realistic constraint for atmospheric craft.

If this is anything, it's probably a redux of the Taliban accessing the unencrypted video feed of Predator drones. For a long time, most video (not control) feeds were sent in the open. The Taliban realized this and were able to grab those feeds using a $30 antenna and a laptop. A compromise in operational security? Sure. A method of "hijacking" UAVs? No way.

I'm not convinced this shows anything at all. But even if it did, remember, the Iranian government has a history of photoshopping images for propaganda purposes. See e.g. http://thelede.blogs.nytimes.com/2008/07/10/in-an-iranian-im...

Agree with OP. Very little here. Keep calm and carry on.

EDIT: Turns out they're claiming these were pulled off the RQ-170 Sentinel that crash landed in Iran. If that's true, it would mean the drive was salvaged and decrypted, which is a potentially big deal.

"If you think that an aircraft that is anything bigger than a small pigeon could get anywhere near a major airport without getting itself a nice escort, then you're nuts."

I'm reasonably sure I've got several "aircraft" in my shed which I could easily use to overfly "a major airport" if I chose to do so.

This one, for example, is at least medium or large pidgeon sized (610mm wingspan): http://www.flickr.com/photos/bigiain/5228554566/ - the flight in that video was around 2.5km from the intersection of the runways at Sydney Airport. That plane (with the camera on board) can fly for ~23 minutes doing 20m/s. That'd give me a comfortable 10mins loiter time over the airport while still being comfortably able to retrieve the camera and it's SD card.

Note - that's barely more that $100 worth of stuff, it's less than 150g all up flying weight, and it's got so little metal in it that I'd be astounded if the regular airport radar could distinguish it under ideal conditions, never mind while it's only a few tens of meters up and buried in the ground clutter.

Note2 - that plane would require retrieval to get the images back, someone actually interested in getting airport pictures without getting caught could use a slightly larger plane carrying a video transmitter sending pictures, never intending to get the plane back (ideally, I guess, ditching the plane at sea to avoid anyone seeing it - a hollow balsa/film construction that'd sink easily might be better than a foam "floating" construction.)

Note3 - that plane as it's configured now isn't flyable at 2.5km range, but there's lots of hobbyists who've worked around the problems there.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.