Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The signals aren't for a specific location, they are world-wide. So the "for Las Vegas" part doesn't work.

The whole point of GPS is that the differential in signal timing between the signals from the transmitters on different satellites tells you how far you are from those satellites, and thus if you know where the satellites are supposed to be, that tells you where you must be.

As a result, recording the signals in a desert outside Las Vegas three weeks ago is by far the easiest way to get... drum roll... the signals which when received by your GPS receiver right now will convince it that right now it's three weeks ago and it is just outside Las Vegas.

> Replay attacks are just a kind of denial of service

Nope, as explained they're actually a very common and effective spoofing tactic. The receiver doesn't say "No service" it will tell you that you're outside Las Vegas three weeks ago.

> Spoofing attacks are far more dangerous, and cryptographic signing defeats them effectively.

Spoofing attacks use the same principle (although of course they'll tell your receiver it's a few milli-seconds ago and it is somewhere nearby, not outside Las Vegas three weeks ago).

Signatures make no major difference, this data is authentic it's just second hand. Everything checks out, that's why they do it.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: