CyberWire Daily - When hackers control the clock. [T-Minus: Space-Cyber Briefing]
Episode Date: September 6, 2026The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and Andy Davis..., Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services. Key sources: GPS: A backbone for critical infrastructure. Spoofing ships, jamming drones: how GPS manipulation confuses and compromises. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business.
Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation.
As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back,
automatically dismantling cross-channel attacks, building team resilience, and providing agentic email
protection. Doppel, outpacing what's next in social engineering. Learn more at doppel.com. That's D-O-P-P-P-E-L.com.
At a really high level, time's probably the most trusted input in computing and one of the least defended.
So everyone assumes that time is correct and that all,
all other inputs into software, systems, control flows may potentially be tampered with and therefore
have to be validated in some way. And often people don't realize that time A can be manipulated,
and if it is, that it's time that's being manipulated that's resulting in the behavior that they're
seeing in either their software or their systems. Welcome. I'm Maria Vermazes, and you're listening
to T-minus space cyber briefing. In this show,
we examine the evolution of cybersecurity in the global and orbital infrastructure that powers,
protects, and connects our lives.
Hi, everyone.
Thank you, as always, for joining me.
Consider the following.
A threat actor doing dastardly things to a key dependency, a single source of truth
that basically all of modern computing and infrastructure runs on.
Now, lots of you listening undoubtedly don't have to imagine it.
All I need to say is heartbleed, and I can hear a bunch of you groaning right back at me.
Sorry for that unpleasant reminder.
But for today's chat, we are not going to look at TLS.
Don't worry.
Instead, we're going to look at time.
And this is a space cyber show.
So when we talk about time, I mean the kind of thing that you get from positioning,
navigation, and timing satellites like GPS.
So if you need a brush up on all things GPS,
I highly recommend you first take a listen to our two-part GPS explainer if you haven't yet.
Those would be episodes 709 and 710, and don't worry, links are in the show notes for you.
Now, a concept that we touched on in the second episode was how positioning and navigation exploits of GPS signals are better known and appreciated,
but the timing part of it is both much more important and much less understood than it should be.
So in today's episode, we're going to dig into that in-depth with Andy Davis, Global Research Director at NCC Group.
In my discussion with him today, he posits that, yes, time is one of the most trusted yet least defended inputs in computing,
and that manipulating it can create significant security and reliability impacts.
The kinds of operational risks introduced by monkeying with time, it is not.
sci-fi. It's very real. So let's get into it. Hi, I'm Andy Davis. I'm a global research director
at NCC Group, which is a pure play cybersecurity consulting firm. I've been at NCC for around 15
years. About half of that time doing research and half of it running our transport
practice, kind of connected cars, planes, trains, that kind of thing.
I've been in this industry for more than 30 years now,
really interested in understanding how things work
and how I can get things to work in ways that they were designed.
I love that, and truly, that is what I think a lot of us
got into cybersecurity for is, how do we make it do that thing?
Yeah, Andy, thank you so much for joining me today.
You and your team got in touch about a really fascinating piece that you wrote
and let's start with maybe what that thesis is,
and then we'll get into the details.
Sure. Well, at a really high level,
time's probably the most trusted input in computing
and one of the least defended.
So everyone assumes that time is correct
and that all other inputs into software, systems, control flows
may potentially be tampered with
and therefore have to be validated in some way.
And the premise of the paper is that there are many different ways of manipulating time.
Time should be considered another input that can be manipulated,
and you can have all kinds of interesting impacts and controls over systems
by manipulating the time that's provided to them.
And often people don't realize that time A can be manipulated,
and if it is, that it's time that's being manipulated
that's resulting in the behavior that they're seeing
in either their software or systems.
Oh, okay, I want to dive into all of that.
So let's start first with timing.
You said there's a bunch of different ways
that that can essentially be an input.
What are those ways?
So if you've got a large collection of computers all connected
together in a data center, let's say,
often you will have a central source of truth for time.
Quite often GPS is used, the global positioning system,
so you're pointing an antenna about a GPS satellite.
And on all GPS satellites, they have a very accurate time source,
a clock that's based on a nuclear reaction that's very, very precise.
And timing is incredibly important in the GPS.
satellite network because if you didn't have such accurate time, their GPS wouldn't work.
The subtle differences in the signals being sent from the different GPS satellites,
if they weren't that accurate, your location wouldn't be able to be determined as accurately
as it can.
So people use the fact that GPS satellites are accessible from everywhere on Earth,
and by pointing an antenna at the sky, you can get the current accurate time.
So they tend to use that as the kind of single source of truth for a computer network
and synchronize via various network timing protocols,
all the different computers and software that's running on them,
to that single source.
Because it's a radio signal,
you may well have heard in military contexts,
sometimes adversaries will block the GPS signal.
Yes, yep.
to prevent people accurately knowing where they are.
But you can be more creative than that.
You can actually spoof GPS signals.
So if I had a software defarine radio,
which is a piece of kit that you can buy for less than a thousand dollars,
probably significantly less than a thousand dollars,
and pointed my antenna at the receiving antenna on the roof of a data center,
I could pretend to be the GPS software network.
and I could inject my own time
that could be subtly different
or wildly different to the real time.
And of course, because all of the computers
are trusting that time signal,
that information would get propagated
and reflected through the network.
And so that's a kind of a central place
where time could be manipulated.
But as I said,
where the information is propagated
from one computer to another
using a network time protocol, if somebody has got some kind of level of access to that
network and has the ability to spoof their own network time protocol or inject protocol
data into that network, they can manipulate the time on the network itself.
Now, that's not quite so satisfactory, because if you're not manipulating the original
kind of source of truth coming from a satellite,
it might continue to kind of override any changes you try and make within the network.
But that's just two kind of ways where people can manipulate that time.
Another place just quickly to think about is as our computing infrastructure is becoming
more and more virtualized, so instead of lots of physical computers,
you've got lots of computers that are running hypervisors,
that are running virtual computers inside of them.
Every layer of virtualization you've got within computing
is essentially its own little universe
that can run its own time.
So if you can manipulate how time is propagated
to these different virtual worlds
where virtual computers are running on,
then it's another way of manipulating their understanding
of what the current time is.
Yeah, and that's really the question.
question that comes up for me is I think in the very abstract I have a little bit of a sense of
you know you start manipulating time bad things will will happen what does happen if you mess with
timing because that is such a very very basic you know layer of understanding that everything operates on
so is it just things don't work correctly or things just don't work or does it depend
there are some very targeted attacks that you can do expiry of things like security
certificates is it is a great example
I mean, just to make it kind of really simple to understand,
if you imagine a cinema ticket that expires at midnight tonight,
the ticket itself, maybe genuine,
but if somebody changes the clock that checks the ticket,
then yesterday's ticket suddenly becomes valid again.
And instead of a cinema ticket,
it's a security certificate that's providing one system access
to another system.
And, you know, somebody's decided that on a certain date that expires and should be revoked or should be reset for whatever reason.
That's an example of where access control could be bypassed.
Well, time is on our side. Time is the enemy. One thing's for sure. Time is. And it is time for us to take a quick break. We'll be right back.
Today's cybercriminals aren't just launching attacks, they're building businesses around them.
They have subscription models, they have a marketplace, they have affiliate program.
If you want to do referrals, you can get credits.
They make it really easy.
It really looks like a legitimate SaaS product that somebody might use.
I sat down with Mike Britton, CIO at Abnormal AI to explore how AI is lowering the barrier to cybercrime
and what security leaders need to change in response.
Here are full conversation at explore.
TheCyberwire.com slash abnormal AI.
We return now to my discussion with Andy Davis,
global research director at NCC Group,
about why timing is a crucial
but underappreciated dependency in modern computing.
My next question to him was on the manipulation of timing
in attacks against crucial infrastructure, like power grids.
What would those kinds of?
attacks look like?
Synchronization of systems is often very important, and the way that power generation
systems operate sometimes rely on very accurate synchronization between one system and another.
And if you can desynchronize those, you can have a massive impact on the way that the systems
operate and can negatively impact the generation of the power.
or could potentially, you know, cause outages or even, you know, fires and, you know, really nasty events.
If systems go out of synchronization that are controlling safety critical elements, critical after infrastructure.
Wow. Yeah. I think I really, it's something I really didn't appreciate at all.
And I'm still, as I've said, I'm learning so much about this.
I guess what do we, what do we do from here? How do we make systems more resilient, perhaps incorrect?
had assumed there was a lot of redundancy to protect from this sort of thing, or perhaps that
these kinds of risks were so maybe military focus that perhaps the rest of us don't need to
worry about this as much, but it sounds like those are false assumptions.
So with regard to redundancy, people think about the redundancy of their systems rather
than necessarily the redundancy of their alternate time sources. When people think
about time, they're normally more concerned about how accurate that time is, rather than being
concerned about what happens if that time is wrong. So it's kind of a shifting mindset,
really, that we're talking about from an accuracy mindset to an integrity mindset. Because
people don't often think about the fact that time could be wrong, and if it was wrong, what
impact it might have on their systems. It's all about having multiple time sources that you can
compare against. So for example, I talked about accurate time sources being on board satellites.
In the situation where you've got a large data center with lots of expensive servers in it,
it's not that much more expensive to get an accurate time source independent of the satellite network
that you have within your network. So, you know, one of those cesium clocks, that kind of thing,
the kind of thing that was actually based on all the satellites. So you can have multiple
time sources and constantly compare between the two and make sure that one isn't being
manipulated. If you look at mobile phones, for example, one of the things that they do in this
sense is they're constantly getting the accurate time information from the GPS satellites
because all smartphones these days have got GPS in them. But they also have accurate time source
that's sent via the cellular network,
and therefore they're able to cross-reference between those two.
And if, for example, they suddenly see that the GPS time source changes,
they can see that either there's been a problem,
you know, some kind of reception problem,
or it's being spoofed or manipulated.
Okay.
All right, so for an Infosec practitioner who's listening to our chat right now,
I'm wondering if there's anything, any base assumption that we should be challenging or anything that might surprise them to learn that you want to highlight.
I think that the most surprising thing is that when time is either manipulated or strays, you know, it changes as a result of some kind of non-malicious reason.
the way that that can be exhibited in behavior of the systems
doesn't immediately make you think that something external is affecting it.
People wouldn't necessarily jump to the conclusion that, oh, it's time that's caused this.
Because, you know, apart from the targeted type attacks that I talked about where you
need to get time and bypass the security control, if time drifts, it can have,
have very subtle effects on control systems, that's saying, and they could be seen as an
intermittent failure. Well, yeah, they could be seen as maybe a component within the system that's
just degraded over time the way that it's behaving. So people might jump to the conclusion that,
oh, well, that system might have failed, and that's why it's behaving that way, rather than
the time source that it's relying on has strayed or stopped or changed, and that's the
result.
So, again, it's a kind of a mindset of don't assume that when you see anomalous behavior in
your systems, that it's actually the fault of the system.
It might be, you know, the time source that's being provided to it.
that can have those effects.
I'd just like to mention an incident that happened back in 2012
called the Leap Second incident.
Now, a leap second is an extra second
that occasionally needs to be added to universal coordinated time,
UTC, in a coordinated way globally,
because of the way that the Earth's rotation changes over time
compared to our universal time.
It's basically a correcting factor that every number of years, they need to add an extra second, which is called a leap second.
And back in 2012, when they inserted this leap second, it had a huge amount of effect on major internet services.
People like LinkedIn, Mozilla, Reddit, all these big systems that have some reliance on time.
just the manipulation of that time by one second
that was done in a controlled way
had all kinds of unintended consequences
on these systems
and really kind of raised the issue
as something that people should be more concerned about.
Now, when I've mentioned this to people,
they can't remember the 2012 leap second incident
so people forget this stuff quickly.
Yeah, I was going to say,
I'm trying to remember that as well
and I'm struggling.
Can you refresh my memory?
little bit on that one.
So, I mean, the kind of experiences that the servers had were CPU, spikes, lockups,
crashes, service outages, because the different ways that software components within them
handle the extra second incorrectly.
So that basically goes back to your question earlier about, you know,
how should system designers cater for these things, that they need to consider time being,
either actively manipulated or, you know, drifting as an input that needs to be checked
and ensure that the robustness of their system when time does change.
That's fascinating.
Honestly, this has been such a really interesting chat.
Andy, thank you so much for sharing your expertise with us today.
It feels kind of metaphysical to be talking about time in such an abstract and also concrete way at the same time.
So this is super neat.
Andy, thank you so much for joining me today.
I really appreciate it.
And that is T-minus Space Cyber Briefing,
brought to you by N2K CyberWire.
If you like what you heard today,
you will also enjoy our newsletter, Signals in Space.
You'll get research and notes pulled together
by our producer Ethan Cook and me,
along with this week's top space cyber news stories.
Subscribe by visiting
thecyberwire.com slash newsletters.
We'd love to know what you think of our podcast,
your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape.
If you like our show, and we always hope that you do, please share a rating and review in your podcast app.
You could also fill out the survey in the show notes or send an email to us at space at n2K.com.
We're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector,
from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals grow, learn, and stay informed.
As the nexus for discovery and connection, we bring you the people, the technology,
and the ideas shaping the future of secure innovation.
Learn how at N2K.com.
Thank you again for listening to T-Minus.
I am your host, Maria Vermazas.
The show is produced by Ethan Cook and Liz.
Stokes. We're mixed by Elliot Peltzman and Trey Hester with original music by Elliot Peltzman.
Our executive producer is Jennifer Iben with Content Strategy by Mayon Plout.
Peter Kilpy is our publisher. See you next week.
