How to fool a GPS Todd Humphreys

something happened in the early morning

hours of May 2nd 2000 that had a

profound effect on the way our society

operates ironically hardly anyone

noticed at the time the change was

silent imperceptible unless you knew

exactly what to look for on that morning

US President Bill Clinton ordered that a

special switch be thrown in the orbiting

satellites of the global positioning

system instantaneously every civilian

GPS receiver around the globe went from

errors the size of a football field the

errors the size of a small room it’s

hard to overstate the effect that this

change in accuracy has had on us before

this switch was thrown we didn’t have in

car navigation systems giving

turn-by-turn directions because back

then gps couldn’t tell you what block

you are on let alone what street for

geolocation accuracy matters and things

have only improved over the last 10

years with more base stations or ground

stations better receivers and better

algorithms GPS can now not only tell you

what street you were on but what part of

the street this level of accuracy has

unleashed a firestorm of innovation in

fact many of you navigated here today

with the help of your TomTom or your

smartphone paper maps are becoming

obsolete Boystown now stand on the verge

of another revolution in geolocation

accuracy what if I told you that the 2

meter positioning that our current cell

phones and our our tom-toms give us is

pathetic compared to what we could be

getting for dump sometime now it’s been

known that if you pay attention to the

carrier phase of the GPS signal and if

you have an internet connection then you

can go from meter love

2-centimeter level even millimeter level

positioning so why don’t we have this

capability on our on our phones only I

believe for a lack of imagination

manufacturers haven’t built this carrier

phase technique into their cheap GPS

chips because they’re not sure what the

general public would do with geolocation

so accurate that you could pinpoint the

wrinkles in the palm of your hand but

you and I and other innovators we can

see the potential in this next leap in

accuracy imagine for example an

augmented reality app that overlays a

virtual world 2 millimeter level

precision on top of the physical world I

could build for you a structure up here

in 3d millimeter accurate that only you

could see or my friends at home so this

level of positioning this is what we’re

looking for and I believe that within

the next few years I predict that this

kind of hyper precise scarrier phase

based positioning will become cheap and

ubiquitous and the consequences will be

fantastic

the Holy Grail of course is the GPS dot

do you remember the the movie The Da

Vinci Code here’s professor Langdon

examining a GPS dot which his accomplice

tells him is a tracking device accurate

within 2 feet anywhere on the globe but

we know that in the world of nonfiction

the GPS dot is impossible right

for one thing GPS doesn’t work indoors

and for another they don’t make devices

quite this small especially when those

devices have to relay their measurements

back over a network

well these objections were perfectly

reasonable a few years ago but things

have changed there’s been a strong trend

toward miniaturization better

sensitivity so much so that a few years

ago a GPS tracking device looked like

this clunky box to the left of the keys

compare that with the device released

just months ago that’s now packaged into

something the size of a key fob and if

you take a look at the state-of-the-art

for a complete GPS receiver which is

only a centimeter on a side and more

sensitive than ever

you realize that the GPS dot will soon

move from fiction to nonfiction imagine

what we could do with a world full of

GPS dots it’s not just that you’ll never

lose your wallet or your keys anymore or

your child when you’re at Disneyland

you’ll buy gps dots in bulk and you’ll

stick them on everything you own worth

more than a few tens of dollars I

couldn’t find my shoes one recent

morning and as usual I had to ask my

wife if she had seen them but I

shouldn’t have to bother my wife with

that kind of triviality I should be able

to ask my house where my shoes are those

of you who have made the switch to Gmail

remember how refreshing it was to go

from organizing all of your email to

simply searching it the GPS dot will do

the same for our possessions now of

course there is a flip side to the GPS

dot I was in my office some months back

and got a telephone call the woman on

the other end of the line we’ll call her

Carol was panicked apparently an

ex-boyfriend of Carol’s from California

had found her in Texas and was following

her around so you might ask at this

point why she’s calling you well so did

I but it turned out there was a

technical twist to Carol’s case every

time her ex-boyfriend would show up at

the most improbable times in the most

improbable locations he was carrying an

open laptop and over time Carol realized

that he had planted a GPS tracking

device on her car so she was calling me

for help

to disable it well you should go to a

good mechanic and have him take him look

at your car I said I already have she

told me he didn’t see anything obvious

and he said he’d have to take the car

apart piece by piece well then uh you

better go to the police I said I already

have she replied they’re not sure this

rises to the level of harassment and

they’re not set up technically to find

the device

okay what about the FBI I’ve talked to

them too and same story we then talked

about her coming to my lab and us

performing a radio sweep of her car but

I wasn’t even sure that would work given

that some of these devices are

configured to only transmit when they’re

inside safe zones or when the car is

moving so there we were Carol isn’t the

first and certainly won’t be the last to

find herself in this kind of fearsome

environment worrisome situation caused

by GPS tracking in fact as I looked into

her case I discovered to my surprise

that it’s not clearly illegal for you or

me to put a tracking device on someone

else’s car the Supreme Court ruled last

month that a policeman has to get a

warrant if he wants to do prolonged

tracking but the law isn’t clear about

civilians doing this to one another so

it’s not just big brother we have to

worry about but big neighbor

there is one alternative the Carroll

could have taken very effective it’s

called the wave bubble it’s a an open

source GPS jammer developed by L’Amour

freed a graduate student at MIT and

L’Amour calls it a tool for reclaiming

our personal space with a flip of the

switch you create a bubble around you

within which GPS signals can’t reside

they get drowned out by the bubble and

L’Amour designed this in part because

like Carol she felt threatened by GPS

tracking then she posted her design to

the web and if you don’t have time to

build your own you can buy one Chinese

manufacturers now sell thousands of

nearly identical devices on the Internet

so you might be thinking the way bubble

sounds great I should have one might

come in handy if somebody ever puts a

tracking device on my car but you should

be aware that its use is very much

illegal in the United States and why is

that well because it’s not a bubble at

all it’s jamming signals don’t stop at

the edge of your personal space or at

the edge

car they go on to jam innocent GPS

receivers for miles around you now if

you’re Carol or L’Amour or someone who

feels threatened by GPS tracking it

might not feel wrong to turn on a wave

bubble but in fact the results can be

disastrous imagine for example you’re

the captain of a cruise ship trying to

make your way through a thick fog and

some passenger in the back turns on a

wave bubble all of a sudden your GPS

readout goes blank and now it’s just you

and the fog and whatever you can pull

off the radar system if you remember how

to work it

they in fact they don’t update or upkeep

lighthouses anymore and Loran the only

backup to GPS was discontinued last year

our modern society has a special

relationship with GPS we’re almost

blindly reliant on it it’s built deeply

into our systems and infrastructure some

call it the invisible utility so turning

on a wave bubble might not just cause

inconvenience it might be deadly but as

it turns out for purposes of protecting

your privacy at the expense of general

GPS reliability there’s something even

more potent and more subversive than a

wave bubble and that is a GPS spoofer

the idea behind the GPS spoofer is

simple instead of jamming the GPS

signals you fake them you imitate them

and if you do it right the device you’re

attacking doesn’t even know it’s being

spoofed so let me show you how this

works in any GPS receiver there’s a peak

inside that corresponds to the authentic

signals these three red dots represent

the tracking points that try to keep

themselves centered on that peak but if

you send in a fake GPS signal another

peak pops up and if you can get these

two peaks perfectly aligned the tracking

points can’t tell the difference and

they get hijacked by the stronger

counter

signal with the authentic peak getting

forced off at this point the game is

over the fake signals now completely

control this GPS receiver so is this

really possible can someone really

manipulate the timing and positioning of

a GPS receiver just like that with a

spoofer well the short answer is yes the

key is that civil GPS signals are

completely open

they have no encryption they have no

intent ocation they’re wide open

vulnerable to a kind of spoofing attack

even so up until very recently nobody

worried about GPS spoofer x' people

figured that it would be too complex or

too expensive for some hacker to build

one but I and a friend of mine from

graduate school we didn’t see it that

way we knew it wasn’t going to be so

hard and we wanted to be the first to

build one so we could get out in front

of the problem and help protect against

GPS spoofing I remember vividly the week

it all came together we built it at my

home which means that I got a little

extra help from my three-year-old son

Ramon here’s Ramon looking for a little

attention from dad that week at first

the spoof it was just a jumble of cables

and computers though we eventually got

it packaged into a small box now the dr.

Frankenstein moment when the spoofer

finally came alive and I glimpsed its

awfull potential came late one night

when I tested the spoofer against my

iPhone

let me show you some actual footage from

that very first experiment I had come to

completely trust this little blue dot

and it’s reassuring blue halo they seem

to speak to me they say here you are

here you are

and you can trust us so something felt

very wrong about the world it was a

sense almost of betrayal when this

little blue dot started at my house and

went running off toward the north

leaving me behind I wasn’t moving what I

then saw in this little moving blue dot

was the potential for chaos I saw

airplanes and ships veering off course

with the captain learning only too late

that something was wrong

I saw the GPS derived timing of the New

York Stock Exchange being manipulated by

hackers you can scarcely imagine the

kind of havoc you could cause if you

knew what you were doing with a GPS

spoofer there is though one redeeming

feature of the GPS spoofer it’s the

ultimate weapon against an invasion of

GPS dots imagine for example you’re

being tracked but you can play the

tracker for a fool pretending to be at

work when you’re really on vacation or

if you’re Carol you could lure your

ex-boyfriend into some empty parking lot

where the police are waiting for him so

I’m fascinated by this conflict a

looming conflict between privacy on the

one hand and the need for a clean radio

spectrum on the other we simply cannot

tolerate GPS jammers and spoof errs and

yet given the lack of effective legal

means for protecting our privacy from

the GPS dot can you really blame people

from wanting to turn them on for wanting

to use them I hold out hope that we’ll

be able to reconcile this conflict with

some sort of some yet uh uninventive

technology but meanwhile grab some

popcorn because things are going to get

interesting within the next few years

many of you will be the proud owner of a

GPS dot maybe you’ll have a whole bag

full of them

you’ll never lose track of your things

again

the GPS dot will fundamentally reorder

your life but will you be able to resist

the temptation to track your fellow man

or will you be able to resist the

temptation to turn on a GPS spoofer or a

wave bubble to protect your own privacy

so as usual what we see just beyond the

horizon is full of promise and peril

it’ll be fascinating to see how this all

turns out thanks

2000 年 5 月 2 日凌晨发生的一件事,对

我们社会的运作方式产生了深远的影响

全球定位系统的轨道卫星上的一个特殊开关会立即在全球

每个民用

GPS 接收器

中出现错误 足球场

大小 错误 小房间大小

很难夸大这种

变化的影响 在抛出此开关之前,我们的准确性已经存在,

我们在

汽车导航系统中没有提供

转弯指示,因为

当时 gps 无法告诉您您在哪个街区

,更不用说在哪条街道上对

地理定位准确性很重要了

在过去的 10

年中,只有更多的基站或地面站有了

更好的接收器和更好的

算法 GPS 现在不能 只告诉你

你在哪条街上,但这条街的哪一部分

这种精确程度

引发了一场创新风暴

事实上,你们中的许多人今天

在 TomTom 或

智能手机纸质地图的帮助下导航到这里

已经过时 Boystown 现在站在

地理定位精度的另一场革命的边缘

如果我告诉你

,我们目前的

手机和我们的 tom-toms 给我们的 2 米定位与我们

现在某个时候可能得到的倾销相比是可悲的,

众所周知,如果你 注意

GPS 信号的载波相位,如果

你有互联网连接,那么你

可以从米爱

2 厘米级甚至毫米级

定位,所以我们为什么

不在我们的手机上拥有这个功能,我

相信 缺乏想象力

制造商还没有将这种载波

相位技术内置到他们廉价的 GPS

芯片中,因为他们不确定

公众会如何处理地理定位,

所以 ac 策展人说您可以查明

手掌上的皱纹,但是

您和我以及其他创新者可以

看到下一次

准确度飞跃的潜力,例如,

增强现实应用程序将

虚拟世界覆盖在 2 毫米级

精度之上 物理世界 我

可以为你建造一个

3d 毫米精确的结构,只有你

或我家里的朋友才能看到,所以这种

水平的定位这就是我们正在

寻找的,我相信

在接下来的几年内,我预测

这种基于 scarrier 相位的超精确

定位将变得便宜且

无处不在,其后果将是

奇妙

的圣杯当然是 GPS 点

你还记得电影

达芬奇密码这里是兰登教授

检查他的同伙的 GPS 点

告诉他是一个跟踪设备

,在全球任何地方都可以精确到 2 英尺,但

我们知道,在非小说世界中

,GPS 点

不可能一秒 GPS 不能在室内工作

,另一方面,他们不会让设备

变得这么小,尤其是当这些

设备必须通过网络很好地转发他们的测量值时

这些反对意见在

几年前是完全合理的,但情况

已经发生了变化,有一个强大的

小型化的趋势 灵敏度更高,

以至于几年

前 GPS 跟踪设备看起来像

按键左侧的这个笨重的盒子

与几个月前发布的设备相比

,现在包装

成钥匙扣大小的东西,如果

你看看最

先进的完整 GPS 接收器,它的边长

只有一厘米,而且

比以往任何时候都更灵敏

你意识到 GPS 点很快就会

从小说变成非

小说 一个充满

GPS 点的世界 不仅仅是你永远不会

丢失你的钱包或钥匙或

你的孩子 当你在迪士尼乐园时

,你会大量购买 gps 点并

贴在上面 你拥有的所有东西都值

几十美元 我

最近一个早上找不到我的鞋子

,像往常一样,我不得不问我

妻子是否看到了它们,但我

不应该用那种琐碎的事情来打扰我的妻子

我应该

可以问我的房子我的鞋子在

哪里 那些已经切换到 Gmail 的人

记得

从整理所有电子邮件到

简单地搜索它是多么令人耳目一新 GPS 点

现在对我们的财产也有同样的作用

当然,GPS 点也有另一面,

几个月前我在办公室

接到一个电话,电话

那头的女人我们会称她为

Carol,她很惊慌,显然是

来自加利福尼亚的 Carol 的前男友

在得克萨斯州找到了她,并且一直在跟踪

她,所以此时你可能会问

为什么她会打电话给你,

我也是,但事实证明,

每次卡罗尔的前男友出现在最不可能的情况下,她的案子都会出现技术上的转折

不可能的时候 他带着一台

打开的笔记本电脑,随着时间的推移,卡罗尔

意识到他

在她的车上安装了一个 GPS 跟踪设备,所以她打电话给我

寻求帮助

以禁用它,你应该去找一个

好的机械师,让他带他

看看你的 车我说我已经有了她

告诉我他没有看到任何明显的

东西他说他必须把车

一块块拆开然后呃你

最好去警察我说我已经

有了她回答他们是 不确定这

会上升到骚扰的程度,而且

他们在技术上没有设置来

找到设备,

好吧,联邦调查局呢?我也和他们谈过

,同样的故事,然后我们

谈到了她来到我的实验室,我们

正在播放收音机 扫了她的车,但

我什至不确定这会起作用,因为

其中一些设备被

配置为仅在它们处于

安全区域内或汽车

移动时传输,所以我们在那里卡罗尔不是

第一个,当然 不会是最后一个

发现自己处于这种恐惧中的人 GPS跟踪

造成的一些环境令人担忧的情况

事实上,当我调查

她的案件时,我惊讶地

发现,你或

我在别人的车上安装跟踪设备显然不是违法

的,最高法院

上个月裁定警察必须

如果他想进行长时间跟踪,请获得搜查令,

但法律并不清楚

平民互相这样做,

所以我们不仅要担心老大哥,而且要

担心大邻居

,卡罗尔本可以采取另一种选择,

非常有效

所谓的波浪泡沫它是

由 L’Amour 开发的开源 GPS 干扰器,它

释放了麻省理工学院的一名研究生,

L’Amour 称之为回收

我们个人空间的工具

信号无法驻留,

它们会被泡沫淹没,而

L’Amour 设计了这个部分是因为

像 Carol 一样,她感到受到 GPS

跟踪的威胁,然后她将她的设计发布到

了网络上,如果你不这样做 没有时间

建立自己的你可以买一个中国

制造商现在

在互联网上销售数千个几乎相同的设备

所以你可能会想泡沫

听起来很棒如果有人放了跟踪设备我应该有一个可能

会派上用场

我的车,但你

应该知道,它的使用

在美国是非常非法的,为什么

这么好,因为它根本不是泡沫

,它的干扰信号不会停在

你个人空间的边缘或他们

的边缘

汽车

如果

您是 Carol 或 L’Amour 或

感到受到 GPS 跟踪威胁的人,那么现在继续干扰您周围数英里内的无辜 GPS 接收

器 例如,您

是一艘游轮的船长,

试图穿过浓雾,

而后面的一些乘客

突然打开了一个波浪泡,您的 GPS

读数变为空白,现在只有您

和雾以及任何您 C

如果您记得如何工作,请关闭雷达系统

,实际上他们不再更新或维护

灯塔,而 Loran

去年停止了 GPS 的唯一备份

我们的现代社会与 GPS 有着特殊的

关系,我们几乎是

盲目的 依赖于它,它深深地

内置在我们的系统和基础设施中,有些人

称它为隐形实用程序,因此

打开波浪气泡可能不仅会造成

不便,而且可能是致命的,

但事实证明,它是为了保护

您的隐私而牺牲了 GPS 的一般

可靠性 有

比气泡更有效和更具颠覆性的东西

,那就是 GPS 欺骗器

GPS 欺骗器背后的想法很

简单,而不是干扰 GPS

信号,你伪造它们,你模仿它们

,如果你做得对,你正在攻击的设备

甚至不知道它被

欺骗了所以让我告诉你它是

如何在任何 GPS 接收器中工作的,内部有一个峰值

对应于

这三个红色的真实信号 点代表

试图将

自己保持在该峰值中心的跟踪点,但是如果

您发送虚假 GPS 信号

,则会弹出另一个峰值,如果您可以使这

两个峰值完全对齐,则跟踪

点无法区分

它们并被劫持 通过更强的

计数器

信号,此时正宗峰值被

强制关闭,游戏

结束了假信号现在完全

控制这个 GPS 接收器,所以这

真的有可能有人真的可以

操纵 GPS 接收器的时间和定位,

就像用

欺骗者很好 简短的回答是肯定的

关键是民用 GPS 信号是

完全开放的

他们没有加密 他们没有

意图的位置 他们是完全开放的

容易受到一种欺骗攻击

直到最近没有人

担心 GPS 欺骗者 x ‘人们

认为

对于某些黑客来说构建一个太复杂或太昂贵,

但我和我

研究生院的朋友我们没有看到

这样我们就知道它不会那么

难,我们想成为第一个

建造一个这样我们就可以

解决问题并帮助防止

GPS 欺骗我清楚地记得

我们建造的那一周。 它在我

家,这意味着我

从我三岁的儿子拉蒙那里得到了一些额外的帮助,

这是拉蒙

那一周开始寻求爸爸的一点关注,

虽然我们最终得到了恶搞,但它只是一堆杂乱的电缆和电脑

它现在包装成一个小盒子,博士。

科学怪人的那一刻,

当我在我的 iPhone 上测试了这个欺骗器时,

瞥见了它可怕的潜力。 令人安心的蓝色光环他们似乎

在跟我说话他们说在这里你在这里你在

这里你可以相信我们所以

感觉世界有些不对劲

当这个

小蓝点从我家开始

并跑掉时,这几乎是一种背叛的感觉 向北

把我留在身后 我没有移动 我

在这个移动的小蓝点中看到的东西

是潜在的混乱 我看到

飞机和船只偏离航线

而船长才知道有什么问题为时已晚

我看到了 GPS 衍生

纽约证券交易所被黑客操纵的时间

你几乎无法想象

如果你

知道你在那里用 GPS 欺骗器做什么会造成什么样的破坏

虽然

是 GPS 欺骗器的一个可取之处,但它是

抵御 GPS 点入侵的终极武器

想象一下,例如,您正在

被跟踪,但是当您真正在度假时,您可以

为一个假装在工作的傻瓜玩跟踪器,

或者

如果 你是卡罗尔,你可以把你的

前男友引诱到

警察正在等他的空旷停车场,所以

我对这种冲突着迷,

一方面是隐私,

另一方面是需要干净的无线电

频谱。 其他我们根本

不能容忍 GPS 干扰器和欺骗错误,

但鉴于缺乏有效的法律

手段来保护我们的隐私

免受 GPS 点的影响,你真的可以责怪人们

因为想要使用它们而想要打开它们吗?

我希望我们 将

能够用

某种尚未发明的

技术来调和这种冲突,但同时抓住一些

爆米花,因为

在接下来的几年内事情会变得有趣

,你们中的许多人都会感到自豪

GPS 点的拥有者也许你会装满一整袋

你永远不会再忘记你的

东西 GPS 点将从根本上重新安排

你的生活,但你是否能够

抵制追踪你的同胞的诱惑,

或者将会 您能够

抵制打开 GPS 欺骗器或

波浪气泡以保护您自己的隐私的诱惑,

所以像往常一样,我们在地平线之外看到的东西

充满希望和危险

谢谢