lol i just got my daily SANS email and it has the drone thing as the top story. i like the editor's op/ed at the end.
TOP OF THE NEWS
--US Military Drone Surveillance Video Intercepted
(December 17, 2009)
With the help of hackers and USD 26 piece of software, Iraqi militants
have reportedly managed to intercept live video feeds from US Predator
drones. There is no evidence to indicate that the hackers or militants
gained control of the unmanned aircraft, but the attack does provide
them with information about where the US military is conducting
surveillance. The issue was discovered in late 2008 when US military
personnel found files of the intercepted surveillance on the laptop of
a Shiite militant who had been apprehended. The US is reportedly
working on encrypting its drone video feeds from Iran, Pakistan and
Afghanistan. The vulnerability being exploited is in an unencrypted
download link. The US military has known about the vulnerability for
more than a decade, but assumed its adversaries would not be able to
exploit it.
http://online.wsj.com/article/SB1261022 … lenews_wsjhttp://www.wired.com/dangerroom/2009/12 … ty-breach/http://www.msnbc.msn.com/id/34465420/ns … -security/Reuter's reports the problem was fixed after being discovered a year ago:
http://www.reuters.com/article/idUSTRE5BG3RM20091217In a separate story, the US military plans to purchase additional
unmanned aircraft to bolster the planned troop surge in Afghanistan.
http://www.nextgov.com/nextgov/ng_20091 … f=topstory[Editor's Note (Pescatore): There will join the Hall of Shame with many
similar bad decisions about not encrypting, or weakly encrypting in
mobile environments. Back in 2006, Visa, Mastercard and Amex issued
credit cards with RFID chips for "no swipe" use - and University of
Massachusetts researchers found they hadn't turned on the advertised
encryption. In 1999 it came out that in Windows CE Microsoft was
"encrypting" the user password by simply XORing it with the word PEGASUS
spelled backwards. As the talking Barbie doll said "Encryption is
*hard*..."]