sponsored links
TEDxAustin

Todd Humphreys: How to fool a GPS

February 11, 2012

Todd Humphreys forecasts the near-future of geolocation when millimeter-accurate GPS "dots" will enable you to find pin-point locations, index-search your physical possessions ... or to track people without their knowledge. And the response to the sinister side of this technology may have unintended consequences of its own. (Filmed at TEDxAustin.)

Todd Humphreys - Assistant Professor
Todd Humphreys studies GPS, its future, and how we can address some of its biggest security problems. Full bio

sponsored links
Double-click the English subtitles below to play the video.
Something happened in the early morning hours
00:16
of May 2nd, 2000, that had a profound effect
00:19
on the way our society operates.
00:23
Ironically, hardly anyone noticed at the time.
00:25
The change was silent, imperceptible,
00:28
unless you knew exactly what to look for.
00:31
On that morning, U.S. President Bill Clinton
00:34
ordered that a special switch be thrown
00:36
in the orbiting satellites of the Global Positioning System.
00:38
Instantaneously, every civilian GPS receiver
00:42
around the globe went from errors the size of a football field
00:46
to errors the size of a small room.
00:50
It's hard to overstate the effect that this change
00:57
in accuracy has had on us.
01:01
Before this switch was thrown, we didn't have
01:03
in-car navigation systems giving turn-by-turn
01:06
directions, because back then, GPS couldn't tell you
01:08
what block you were on, let alone what street.
01:11
For geolocation, accuracy matters,
01:13
and things have only improved over the last 10 years.
01:17
With more base stations, more ground stations,
01:20
better receivers and better algorithms,
01:22
GPS can now not only tell you what street you are on,
01:25
but what part of the street.
01:28
This level of accuracy
01:32
has unleashed a firestorm of innovation.
01:35
In fact, many of you navigated here today
01:38
with the help of your TomTom or your smartphone.
01:40
Paper maps are becoming obsolete.
01:44
But we now stand on the verge of another revolution
01:47
in geolocation accuracy.
01:51
What if I told you that the two-meter positioning
01:53
that our current cell phones and our TomToms give us
01:56
is pathetic compared to what we could be getting?
01:59
For some time now, it's been known that if you pay attention
02:03
to the carrier phase of the GPS signal,
02:06
and if you have an Internet connection,
02:09
then you can go from meter level to centimeter level,
02:11
even millimeter-level positioning.
02:14
So why don't we have this capability on our phones?
02:17
Only, I believe, for a lack of imagination.
02:20
Manufacturers haven't built this carrier phase technique
02:25
into their cheap GPS chips
02:28
because they're not sure what the general public would do
02:30
with geolocation so accurate that you could pinpoint
02:32
the wrinkles in the palm of your hand.
02:36
But you and I and other innovators,
02:39
we can see the potential in this next leap in accuracy.
02:42
Imagine, for example, an augmented reality app
02:46
that overlays a virtual world to millimeter-level precision
02:49
on top of the physical world.
02:52
I could build for you a structure up here in 3D,
02:54
millimeter accurate, that only you could see,
02:57
or my friends at home.
02:59
So this level of positioning, this is what we're looking for,
03:02
and I believe that, within the next few years, I predict,
03:07
that this kind of hyper-precise, carrier phase-based positioning
03:11
will become cheap and ubiquitous,
03:16
and the consequences will be fantastic.
03:19
The Holy Grail, of course, is the GPS dot.
03:21
Do you remember the movie "The Da Vinci Code?"
03:26
Here's Professor Langdon examining a GPS dot,
03:29
which his accomplice tells him is a tracking device
03:32
accurate within two feet anywhere on the globe,
03:36
but we know that in the world of nonfiction,
03:39
the GPS dot is impossible, right?
03:42
For one thing, GPS doesn't work indoors,
03:44
and for another, they don't make devices quite this small,
03:47
especially when those devices have to relay
03:50
their measurements back over a network.
03:53
Well, these objections were perfectly reasonable
03:56
a few years ago, but things have changed.
03:58
There's been a strong trend toward miniaturization,
04:01
better sensitivity, so much so that, a few years ago,
04:04
a GPS tracking device looked like this clunky box
04:07
to the left of the keys.
04:10
Compare that with the device released just months ago
04:12
that's now packaged into something the size of a key fob,
04:15
and if you take a look at the state of the art
04:19
for a complete GPS receiver, which is only a centimeter
04:21
on a side and more sensitive than ever,
04:24
you realize that the GPS dot will soon move
04:26
from fiction to nonfiction.
04:30
Imagine what we could do with a world full of GPS dots.
04:34
It's not just that you'll never lose your wallet or your keys
04:38
anymore, or your child when you're at Disneyland.
04:41
You'll buy GPS dots in bulk, and you'll stick them on
04:46
everything you own worth more than a few tens of dollars.
04:50
I couldn't find my shoes one recent morning,
04:54
and, as usual, had to ask my wife if she had seen them.
04:56
But I shouldn't have to bother my wife with that kind of triviality.
04:59
I should be able to ask my house where my shoes are.
05:03
(Laughter)
05:06
Those of you who have made the switch to Gmail,
05:08
remember how refreshing it was to go from
05:11
organizing all of your email to simply searching it.
05:14
The GPS dot will do the same for our possessions.
05:18
Now, of course, there is a flip side to the GPS dot.
05:23
I was in my office some months back
05:28
and got a telephone call.
05:30
The woman on the other end of the line, we'll call her Carol,
05:33
was panicked.
05:36
Apparently, an ex-boyfriend of Carol's from California
05:38
had found her in Texas and was following her around.
05:41
So you might ask at this point why she's calling you.
05:44
Well, so did I.
05:48
But it turned out there was a technical twist to Carol's case.
05:50
Every time her ex-boyfriend would show up,
05:54
at the most improbable times and the most improbable locations,
05:56
he was carrying an open laptop,
06:01
and over time Carol realized that he had planted
06:03
a GPS tracking device on her car,
06:06
so she was calling me for help to disable it.
06:09
"Well, you should go to a good mechanic
06:12
and have him look at your car," I said.
06:14
"I already have," she told me.
06:17
"He didn't see anything obvious,
06:20
and he said he'd have to take the car apart piece by piece."
06:22
"Well then, you'd better go to the police," I said.
06:25
"I already have," she replied.
06:29
"They're not sure this rises to the level of harassment,
06:32
and they're not set up technically to find the device."
06:34
"Okay, what about the FBI?"
06:38
"I've talked to them too, and same story."
06:39
We then talked about her coming to my lab
06:44
and us performing a radio sweep of her car,
06:45
but I wasn't even sure that would work,
06:48
given that some of these devices are configured
06:50
to only transmit when they're inside safe zones
06:52
or when the car is moving.
06:55
So, there we were.
06:58
Carol isn't the first, and certainly won't be the last,
06:59
to find herself in this kind of fearsome environment,
07:02
worrisome situation caused by GPS tracking.
07:07
In fact, as I looked into her case,
07:13
I discovered to my surprise that it's not clearly illegal
07:15
for you or me to put a tracking device on someone else's car.
07:19
The Supreme Court ruled last month that a policeman
07:23
has to get a warrant if he wants to do prolonged tracking,
07:27
but the law isn't clear about civilians doing this to one another,
07:31
so it's not just Big Brother we have to worry about,
07:35
but Big Neighbor. (Laughter)
07:37
There is one alternative that Carol could have taken,
07:41
very effective. It's called the Wave Bubble.
07:45
It's an open-source GPS jammer,
07:51
developed by Limor Fried,
07:54
a graduate student at MIT, and Limor calls it
07:56
"a tool for reclaiming our personal space."
08:00
With a flip of the switch you create a bubble around you
08:04
within which GPS signals can't reside.
08:06
They get drowned out by the bubble.
08:09
And Limor designed this, in part, because, like Carol,
08:11
she felt threatened by GPS tracking.
08:15
Then she posted her design to the web,
08:17
and if you don't have time to build your own,
08:20
you can buy one.
08:24
Chinese manufacturers now sell thousands
08:24
of nearly identical devices on the Internet.
08:26
So you might be thinking, the Wave Bubble sounds great.
08:30
I should have one. Might come in handy if somebody ever puts a tracking device on my car.
08:34
But you should be aware that its use is very much illegal
08:38
in the United States.
08:42
And why is that?
08:44
Well, because it's not a bubble at all.
08:44
Its jamming signals don't stop at the edge
08:47
of your personal space or at the edge of your car.
08:50
They go on to jam innocent GPS receivers for miles around you. (Laughter)
08:52
Now, if you're Carol or Limor,
08:59
or someone who feels threatened by GPS tracking,
09:01
it might not feel wrong to turn on a Wave Bubble,
09:04
but in fact, the results can be disastrous.
09:08
Imagine, for example, you're the captain of a cruise ship
09:12
trying to make your way through a thick fog
09:14
and some passenger in the back turns on a Wave Bubble.
09:17
All of a sudden your GPS readout goes blank,
09:21
and now it's just you and the fog
09:23
and whatever you can pull off the radar system
09:27
if you remember how to work it.
09:29
They -- in fact, they don't update or upkeep lighthouses
09:32
anymore, and LORAN, the only backup to GPS,
09:38
was discontinued last year.
09:43
Our modern society has a special relationship with GPS.
09:45
We're almost blindly reliant on it.
09:50
It's built deeply into our systems and infrastructure.
09:53
Some call it "the invisible utility."
09:56
So, turning on a Wave Bubble might not just cause inconvenience.
10:00
It might be deadly.
10:04
But as it turns out, for purposes of protecting your privacy
10:08
at the expense of general GPS reliability,
10:12
there's something even more potent
10:16
and more subversive than a Wave Bubble,
10:18
and that is a GPS spoofer.
10:22
The idea behind the GPS spoofer is simple.
10:25
Instead of jamming the GPS signals, you fake them.
10:28
You imitate them, and if you do it right, the device
10:32
you're attacking doesn't even know it's being spoofed.
10:35
So let me show you how this works.
10:38
In any GPS receiver, there's a peak inside
10:40
that corresponds to the authentic signals.
10:42
These three red dots represent the tracking points
10:45
that try to keep themselves centered on that peak.
10:48
But if you send in a fake GPS signal,
10:51
another peak pops up, and if you can get these two peaks
10:54
perfectly aligned, the tracking points can't tell the difference,
10:58
and they get hijacked by the stronger counterfeit signal,
11:03
with the authentic peak getting forced off.
11:06
At this point, the game is over.
11:10
The fake signals now completely control this GPS receiver.
11:12
So is this really possible?
11:16
Can someone really manipulate
11:18
the timing and positioning of a GPS receiver
11:19
just like that, with a spoofer?
11:21
Well, the short answer is yes.
11:24
The key is that civil GPS signals
11:26
are completely open.
11:29
They have no encryption. They have no authentication.
11:30
They're wide open, vulnerable to a kind of spoofing attack.
11:34
Even so, up until very recently,
11:38
nobody worried about GPS spoofers.
11:40
People figured that it would be too complex
11:43
or too expensive for some hacker to build one.
11:45
But I, and a friend of mine from graduate school,
11:47
we didn't see it that way.
11:51
We knew it wasn't going to be so hard,
11:54
and we wanted to be the first to build one
11:56
so we could get out in front of the problem
11:58
and help protect against GPS spoofing.
12:00
I remember vividly the week it all came together.
12:04
We built it at my home, which means that
12:08
I got a little extra help from my three-year-old son Ramon.
12:11
Here's Ramon — (Laughter) —
12:15
looking for a little attention from Dad that week.
12:18
At first, the spoofer was just a jumble of cables
12:21
and computers, though we eventually got it packaged
12:24
into a small box.
12:27
Now, the Dr. Frankenstein moment,
12:28
when the spoofer finally came alive
12:31
and I glimpsed its awful potential,
12:34
came late one night when I tested the spoofer
12:36
against my iPhone.
12:39
Let me show you some actual footage from that
12:41
very first experiment.
12:43
I had come to completely trust this little blue dot
12:45
and its reassuring blue halo.
12:48
They seemed to speak to me.
12:50
They'd say, "Here you are. Here you are." (Laughter)
12:51
And "you can trust us."
12:56
So something felt very wrong about the world.
12:59
It was a sense, almost, of betrayal,
13:04
when this little blue dot started at my house,
13:06
and went running off toward the north
13:11
leaving me behind. I wasn't moving.
13:12
What I then saw in this little moving blue dot
13:16
was the potential for chaos.
13:20
I saw airplanes and ships veering off course, with the captain
13:23
learning only too late that something was wrong.
13:27
I saw the GPS-derived timing
13:31
of the New York Stock Exchange
13:34
being manipulated by hackers.
13:36
You can scarcely imagine the kind of havoc
13:38
you could cause if you knew what you were doing
13:41
with a GPS spoofer.
13:43
There is, though, one redeeming feature
13:47
of the GPS spoofer.
13:52
It's the ultimate weapon against an invasion of GPS dots.
13:54
Imagine, for example, you're being tracked.
13:59
Well, you can play the tracker for a fool,
14:02
pretending to be at work when you're really on vacation.
14:04
Or, if you're Carol, you could lure your ex-boyfriend
14:07
into some empty parking lot
14:10
where the police are waiting for him.
14:11
So I'm fascinated by this conflict, a looming conflict,
14:14
between privacy on the one hand
14:19
and the need for a clean radio spectrum on the other.
14:22
We simply cannot tolerate GPS jammers and spoofers,
14:26
and yet, given the lack of effective legal means
14:29
for protecting our privacy from the GPS dot,
14:33
can you really blame people for wanting to turn them on,
14:37
for wanting to use them?
14:38
I hold out hope that we'll be able to reconcile
14:41
this conflict with some sort of,
14:44
some yet uninvented technology.
14:47
But meanwhile, grab some popcorn,
14:53
because things are going to get interesting.
14:56
Within the next few years,
14:58
many of you will be the proud owner of a GPS dot.
14:59
Maybe you'll have a whole bag full of them.
15:03
You'll never lose track of your things again.
15:06
The GPS dot will fundamentally reorder your life.
15:09
But will you be able to resist the temptation
15:13
to track your fellow man?
15:16
Or will you be able to resist the temptation
15:19
to turn on a GPS spoofer or a Wave Bubble
15:21
to protect your own privacy?
15:24
So, as usual, what we see just beyond the horizon
15:27
is full of promise and peril.
15:30
It'll be fascinating to see how this all turns out.
15:34
Thanks. (Applause)
15:37
Translator:Joseph Geni
Reviewer:Morton Bast

sponsored links

Todd Humphreys - Assistant Professor
Todd Humphreys studies GPS, its future, and how we can address some of its biggest security problems.

Why you should listen

Todd Humphreys is director of the University of Texas at Austin's Radionavigation Laboratory -- where he works as an assistant professor in the Department of Aerospace Engineering and Engineering Mechanics. His research into orbital mechanics has made him one of the world's leading experts on GPS technology and the security concerns that arise from its ubiquitous use.  In 2008 he co-founded Coherent Navigation, a startup dedicated to creating more secure GPS systems.

The original video is available on TED.com
sponsored links

If you need translations, you can install "Google Translate" extension into your Chrome Browser.
Furthermore, you can change playback rate by installing "Video Speed Controller" extension.

Data provided by TED.

This website is owned and operated by Tokyo English Network.
The developer's blog is here.