craig mathias
Principal

Hacking the Predator Drone – Piece of Cake

Opinion
Dec 17, 20093 mins

I often wonder how idiots get into positions of authority

So I’m flipping on the news at zero dark thirty this morning, and, to my surprise, I discover that the video feeds from the Air Force’s super-duper unmanned Predator intelligence-gathering-and-Hellfire-missile-launching aircraft are unencrypted. This means that anyone with a little technical knowledge, a satellite receiver, and a little software can watch, in real time, the video sent from the Predator during operational missions. I don’t suppose it occurred to the designers (note that I’m not referring here to the engineers involved in building the solution, usually the targets of my wrath, especially if they work for Microsoft) of this system that this might be a possibility. That’s why they’re idiots, after all. And, of course, it appears that no one up the chain of command thought to inquire as to the security of this rather sensitive video, perhaps assuming, as I did, that all transmissions to and from an armed military aircraft would be encrypted. Silly me. Shame on them.The problem (among many other related breeches of wireless security, in fact), according to the CBS News report, has been around for a long time. There is now hard evidence that unauthorized entities have in fact gained access to the feeds. There is no quick fix here, but this should never have been a problem in the first place. I lecture frequently on the importance of building a culture of security, on the requirements for basic security elements (a security policy, encryption of the file and VPN varieties, strong authentication, etc.), and on how, when it comes to security, one is never “done”. And here we have a vital national-security system where apparently the job never got started.I occasionally work on government programs. I have no moral or ethical qualms about such, and I am proud to be able to contribute to national security programs whenever I can. I may not agree with the mission (I’ve always been against the “wars” in Iraq and Afghanistan, for example), but I think it’s important to have the capabilities should they ever be required (or for their value as a deterrent). But if the system is fundamentally insecure or otherwise compromised, what’s the point?In the private sector, we fire idiots. I think it’s time to do the same here, well up the management chain, and not just at the contractor responsible for this nonsense. There are plenty of secured satellite systems available; it’s obvious these should be used in situations like this. Obvious to non-idiots, anyway.

craig mathias

Craig J. Mathias is a principal with Farpoint Group, an advisory firm specializing in wireless networking and mobile computing. Founded in 1991, Farpoint Group works with technology developers, manufacturers, carriers and operators, enterprises, and the financial community. Craig is an internationally-recognized industry and technology analyst, consultant, conference speaker, author, columnist, and blogger. He regularly writes for Network World, CIO.com, and TechTarget. Craig holds an Sc.B. degree in Computer Science from Brown University, and is a member of the Society of Sigma Xi and the IEEE.

More from this author