Earlier this month I wrote about how police have been seizing hundreds of drones around the country for alleged violations of no-fly rules. The counter-drone business is hopping today, with law enforcement around the country highlyfocused on gaining the ability to deal with drones flying places they’re not supposed to be, as well as the so-far-nonexistent but probably eventually inevitable prospect of a violent attack via drone. Often called counter-UAS (for “uncrewed aerial system,” a bureaucratic term for drone), the field is dedicated to the difficult problem of how to ground, capture, destroy, or otherwise “mitigate” a rogue drone. Within the counter-UAS field lurks a significant public policy issue that has not been discussed enough: the hacking of drones.
It’s not easy to defend against drones. Techniques for mitigating them include shooting at them with projectiles, lasers, or microwaves, jamming GPS or other radio signals, and sending up defensive drones with big nets. US law enforcement officers don’t operate on a battlefield, however (despite how many of them dress and sometimes behave). In a civilian environment, massive interference with the radio spectrum, shooting dangerous lasers into our crowded skies, and aerial shoot-outs that send wreckage crashing down on civilians’ heads just won’t do.
There is another counter-drone technique that supposedly avoids all these problems: hacking into a drone to take it over and steer it safely away. But that raises one of the longest-running issues in cybersecurity: the creation or hoarding of software vulnerabilities that can be used by the authorities to break into software, but which also leave the door open for malevolent hackers to do so as well
Those vulnerabilities can take the form of software bugs that make devices vulnerable to takeover or other hacking, known in the cybersecurity field as “zero days.” Also possible but currently unlikely (because of the amount of coordination and secrecy that would be required) is that manufacturers are building intentional backdoors into their devices for officials to use. Either way, exploitation of vulnerabilities in drones implicates a serious problem that has arisen in many different contexts: there is no way you can have a vulnerability in a technology that can be used only for good purposes.
This has been central to perennial debates over government encryption backdoors, in which law enforcement officials push for laws to require the writers of encrypted communications software to introduce intentional vulnerabilities so that the police can eavesdrop. It also arises in the conflict between the NSA’s offensive and defensive missions (“we’ve discovered a way to break into a Windows computer; do we keep it to ourself so we can spy on our enemies, or do we tell Microsoft so they can fix the bug and protect Americans?”). At the ACLU we’ve called for prioritizing public security over secret private power.
Here the same issue is repeating itself: if the government knows of a bug that allows an attacker to hijack a drone, but doesn’t inform the manufacturer, it’s a betrayal of the public interest that leaves every drone that uses that software vulnerable to takeover by malevolent actors
It doesn’t help that consumer drones generally have terriblesecurity. Many protocols that govern communications between ground controllers and drones are weak — many still transmit data over unencrypted channels, and lack strong authentication measures that would ensure the drone only accepts commands from the controller being operated by its owner and not from anyone else
It’s surprising to me that, amidst the enormous amount of hype about the threat of drone terrorism and the like, drone protocols remain so weak. I can’t help wondering why we haven’t seen a stronger push for security reforms — and whether it’s because too many shortsighted people in authority would rather drones stay vulnerable
An approach that is already being tappedThe hacking of drones is very real, however, and has happened in both defense and commercial contexts, including to smuggle contraband into prisonsreporting on efforts to combat drone flights near World Cup soccer games, the LA Times reported that
More than once, drones have gotten close enough to the massive stadium in Inglewood to be taken over and brought to the ground by the FBI. That ability, according to a white paper by one of the manufacturers, is possible through technology that allows an agent to communicate with the drone and substitute themselves as the operator, take it over and ground it
It’s not clear what white paper the Times is referring to, but some companies are certainly marketing their ability to hijack drones. A company called D-Fend Solutions sells a product that it says provides advanced radio frequency (RF) “cyber takeover technology.”
The system detects, locates and identifies rogue drones in protected airspace, then neutralizes threats by executing RF cyber-takeovers — whether as a standalone, multilayer, or integrated system — for safe landings and controlled outcomes
D-Fend (which just reached an agreement to be acquired by police technology vendor Motorola Solutions) offers little detail about how it executes these “cyber takeovers,” but it seems clear that whether the vulnerabilities are exotic zero days or run-of-the-mill protocol flaws, the company’s business model is to stay ahead of efforts to secure drones by identifying vulnerabilities and monetizing them on behalf of security agencies rather than fixing them so that all drones can be more secure against hijacking. A company blog post on “How to Control a Drone” warns that threat actors are “evolving rapidly, using increasingly complex tactics” to “bypass detection and mitigation.”
By “bypass mitigation,” the company means “protect their drones against takeover by others.” But again, if threat actors can’t protect their drones against takeover by others, neither can anyone else. Still, the company writes,
To stay ahead, counter-drone technology must… execute protocol-based takeovers that can adapt to diverse manufacturer-specific protocols
With modern drone threats, control is the central vulnerability, and understanding the concept of control allows defenders to respond with precision. The best C-UAS solutions are focused on giving control back to the defenders
The myth that vulnerabilities can be reserved for defenders and won’t be seized upon by bad actors appears to be a zombie idea — one that never dies
In 2023 I represented the ACLU on an FAA Agency on counter-UAS, and I raised this issue. I notedthat the committee’s final report “incorporates the concept of mitigating drones through ‘takeover’ of a targeted aircraft” and recommended that
the FAA work to require that discovery of any security vulnerabilities in drones be immediately shared with drone manufacturers so they can be patched, and not kept secret for C-UAS purposes
We also recommended “a ban on the creation of backdoors in drone security systems.”
But as far as I can tell this misguided approach to drone security seems to be continuing along its merry way largely unquestioned. Hopefully the lack of wisdom in that strategy won’t be revealed in tragic ways

