HomeSecurityPolice drones can be hacked from a mile away!

Police drones can be hacked from a mile away!

drone-police

A $35,000 police drone can be captured by hackers from over a mile away, a security researcher says.

Drones are in the spotlight once again, thanks to a security researcher who revealed that one of the government's flying machine models has critical vulnerabilities that could allow them to be hacked from more than a mile away.

Security researcher Nils Rodday demonstrated at the RSA Security Conference in San Francisco on Wednesday how flaws in the wireless connection of a $35,000 drone allowed him to take complete control of the quadcopter with the help of just a laptop and a cheap radio chip connected via USB.

Any hacker who can reverse engineer a drone's flight software can engineer this controller to send navigation commands, taking advantage of the lack of encryption between the drone and the control unit, known as the "telemetry box." Rodday says, "You can go into the packets and change waypoints, things in the flight computer, set a different home point. Anything a normal pilot can do, you can do."

Rodday, who now works at IBM, discovered it while working on a research drone while working as a graduate researcher at the University of Twente in the Netherlands before working with IBM on the subject. He does not provide any information about the drone he tested or the name of its vendor.

The unnamed UAV manufacturer signed a non-disclosure agreement in exchange for lending him its expensive quadcopter for testing. However, he did hint that the roughly 3-foot quadcopter has a flight time of about 40 minutes and has been developed by police and fire departments, though it is also marketed for use in industrial applications such as professional photography, power line inspections and windmill inspection.

The UAV studied by Roddy has two serious security flaws: The Wi-Fi connection between the telemetry module and the user’s tablet uses weak “WEP” or “Wired-Equivalent Privacy” as encryption, and even worse, it has incredibly insecure encryption (or lack thereof) connecting the telemetry module to the UAV itself. This would allow any attacker to “crack” this frame and send a so-called “kill” command initiated by the drone owner over the network. That’s not all though, as this vulnerability would also block any command from the legitimate operator of their drone.

Existing police drones are often equipped with cameras, and can be used in rescue and emergency situations to search locations that would be difficult to access, so it's very critical if someone takes control of such a drone, as Rodday did.

“If you think about it, someone could do this just for fun, or also to cause damage or create chaos in a routine surveillance process,” Rodday told Wired. “You could send a command to the camera to point it in the wrong direction so that the desired information is not being received … or you could steal the drone, all the equipment that’s attached to it, and its information.”

Rodday has since notified drone manufacturers of the breaches he uncovered, and tells Wired that the company plans to address the issue when it updates its new drones. But that means UAVs already on the market are easy targets for hacking.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS