Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm wondering how comprehensive the research is that says it's just those 3 vendors and ~7 devices. Given that it's more than one vendor, it feels like a pattern that's a common mistake or design compromise. I wouldn't be surprised if the impact is broader than expected.


All GPS receivers(1) have this issue but the date they experience it on differs from device to device because to fix the rollover issue they adjust the wrap point in their firmware based on when the firmware was made.

(1) Technically the modernized L2C/L1C/L5 signals use a 13-bit week number, but because the deployment of these signals was massively delayed receivers using them are basically non-existent today. (I also have no idea if the current receivers supporting them successfully use the 13-bit week number, given that they're not guaranteed to be able to receive the modernized signals as they're still less available than L1)


Wouldn't some of them have rollover counters or adjustable epochs, etc?


The epoch is adjustable by updating the firmware... if there is an updated firmware. That's the reason for the current batch of devices dying now: it's based on a date set in their firmware. Unfortunately these are embedded receivers so making anything adjustable isn't necessarily easy.

I'm not aware of any devices that implement a rollover counter but there may be some, though a rollover counter needs to figure out how to deal with corrupted or spoofed signals and will have issues like spares off the shelf not working like the device they're replacing.


Ah, re-reading, it sounds like these are all from one vendor that's known by two names..."Microsemi" and "Symmetricom" (acquisition, etc). So perhaps that risk is low.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: