CyberWire Daily - When hackers control the clock. [T-Minus: Space-Cyber Briefing]

Episode Date: September 6, 2026

The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and ⁠Andy Davis...⁠, Global Research Director at the NCC Group, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services. Key sources: GPS: A backbone for critical infrastructure. Spoofing ships, jamming drones: how GPS manipulation confuses and compromises. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠ Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business. Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back, automatically dismantling cross-channel attacks, building team resilience, and providing agentic email protection. Doppel, outpacing what's next in social engineering. Learn more at doppel.com. That's D-O-P-P-P-E-L.com. At a really high level, time's probably the most trusted input in computing and one of the least defended. So everyone assumes that time is correct and that all,
Starting point is 00:01:12 all other inputs into software, systems, control flows may potentially be tampered with and therefore have to be validated in some way. And often people don't realize that time A can be manipulated, and if it is, that it's time that's being manipulated that's resulting in the behavior that they're seeing in either their software or their systems. Welcome. I'm Maria Vermazes, and you're listening to T-minus space cyber briefing. In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects, and connects our lives. Hi, everyone.
Starting point is 00:02:17 Thank you, as always, for joining me. Consider the following. A threat actor doing dastardly things to a key dependency, a single source of truth that basically all of modern computing and infrastructure runs on. Now, lots of you listening undoubtedly don't have to imagine it. All I need to say is heartbleed, and I can hear a bunch of you groaning right back at me. Sorry for that unpleasant reminder. But for today's chat, we are not going to look at TLS.
Starting point is 00:02:46 Don't worry. Instead, we're going to look at time. And this is a space cyber show. So when we talk about time, I mean the kind of thing that you get from positioning, navigation, and timing satellites like GPS. So if you need a brush up on all things GPS, I highly recommend you first take a listen to our two-part GPS explainer if you haven't yet. Those would be episodes 709 and 710, and don't worry, links are in the show notes for you.
Starting point is 00:03:16 Now, a concept that we touched on in the second episode was how positioning and navigation exploits of GPS signals are better known and appreciated, but the timing part of it is both much more important and much less understood than it should be. So in today's episode, we're going to dig into that in-depth with Andy Davis, Global Research Director at NCC Group. In my discussion with him today, he posits that, yes, time is one of the most trusted yet least defended inputs in computing, and that manipulating it can create significant security and reliability impacts. The kinds of operational risks introduced by monkeying with time, it is not. sci-fi. It's very real. So let's get into it. Hi, I'm Andy Davis. I'm a global research director at NCC Group, which is a pure play cybersecurity consulting firm. I've been at NCC for around 15
Starting point is 00:04:23 years. About half of that time doing research and half of it running our transport practice, kind of connected cars, planes, trains, that kind of thing. I've been in this industry for more than 30 years now, really interested in understanding how things work and how I can get things to work in ways that they were designed. I love that, and truly, that is what I think a lot of us got into cybersecurity for is, how do we make it do that thing? Yeah, Andy, thank you so much for joining me today.
Starting point is 00:04:57 You and your team got in touch about a really fascinating piece that you wrote and let's start with maybe what that thesis is, and then we'll get into the details. Sure. Well, at a really high level, time's probably the most trusted input in computing and one of the least defended. So everyone assumes that time is correct and that all other inputs into software, systems, control flows
Starting point is 00:05:26 may potentially be tampered with and therefore have to be validated in some way. And the premise of the paper is that there are many different ways of manipulating time. Time should be considered another input that can be manipulated, and you can have all kinds of interesting impacts and controls over systems by manipulating the time that's provided to them. And often people don't realize that time A can be manipulated, and if it is, that it's time that's being manipulated
Starting point is 00:06:02 that's resulting in the behavior that they're seeing in either their software or systems. Oh, okay, I want to dive into all of that. So let's start first with timing. You said there's a bunch of different ways that that can essentially be an input. What are those ways? So if you've got a large collection of computers all connected
Starting point is 00:06:22 together in a data center, let's say, often you will have a central source of truth for time. Quite often GPS is used, the global positioning system, so you're pointing an antenna about a GPS satellite. And on all GPS satellites, they have a very accurate time source, a clock that's based on a nuclear reaction that's very, very precise. And timing is incredibly important in the GPS. satellite network because if you didn't have such accurate time, their GPS wouldn't work.
Starting point is 00:07:01 The subtle differences in the signals being sent from the different GPS satellites, if they weren't that accurate, your location wouldn't be able to be determined as accurately as it can. So people use the fact that GPS satellites are accessible from everywhere on Earth, and by pointing an antenna at the sky, you can get the current accurate time. So they tend to use that as the kind of single source of truth for a computer network and synchronize via various network timing protocols, all the different computers and software that's running on them,
Starting point is 00:07:39 to that single source. Because it's a radio signal, you may well have heard in military contexts, sometimes adversaries will block the GPS signal. Yes, yep. to prevent people accurately knowing where they are. But you can be more creative than that. You can actually spoof GPS signals.
Starting point is 00:08:03 So if I had a software defarine radio, which is a piece of kit that you can buy for less than a thousand dollars, probably significantly less than a thousand dollars, and pointed my antenna at the receiving antenna on the roof of a data center, I could pretend to be the GPS software network. and I could inject my own time that could be subtly different or wildly different to the real time.
Starting point is 00:08:30 And of course, because all of the computers are trusting that time signal, that information would get propagated and reflected through the network. And so that's a kind of a central place where time could be manipulated. But as I said, where the information is propagated
Starting point is 00:08:49 from one computer to another using a network time protocol, if somebody has got some kind of level of access to that network and has the ability to spoof their own network time protocol or inject protocol data into that network, they can manipulate the time on the network itself. Now, that's not quite so satisfactory, because if you're not manipulating the original kind of source of truth coming from a satellite, it might continue to kind of override any changes you try and make within the network. But that's just two kind of ways where people can manipulate that time.
Starting point is 00:09:32 Another place just quickly to think about is as our computing infrastructure is becoming more and more virtualized, so instead of lots of physical computers, you've got lots of computers that are running hypervisors, that are running virtual computers inside of them. Every layer of virtualization you've got within computing is essentially its own little universe that can run its own time. So if you can manipulate how time is propagated
Starting point is 00:10:05 to these different virtual worlds where virtual computers are running on, then it's another way of manipulating their understanding of what the current time is. Yeah, and that's really the question. question that comes up for me is I think in the very abstract I have a little bit of a sense of you know you start manipulating time bad things will will happen what does happen if you mess with timing because that is such a very very basic you know layer of understanding that everything operates on
Starting point is 00:10:34 so is it just things don't work correctly or things just don't work or does it depend there are some very targeted attacks that you can do expiry of things like security certificates is it is a great example I mean, just to make it kind of really simple to understand, if you imagine a cinema ticket that expires at midnight tonight, the ticket itself, maybe genuine, but if somebody changes the clock that checks the ticket, then yesterday's ticket suddenly becomes valid again.
Starting point is 00:11:07 And instead of a cinema ticket, it's a security certificate that's providing one system access to another system. And, you know, somebody's decided that on a certain date that expires and should be revoked or should be reset for whatever reason. That's an example of where access control could be bypassed. Well, time is on our side. Time is the enemy. One thing's for sure. Time is. And it is time for us to take a quick break. We'll be right back. Today's cybercriminals aren't just launching attacks, they're building businesses around them. They have subscription models, they have a marketplace, they have affiliate program.
Starting point is 00:12:14 If you want to do referrals, you can get credits. They make it really easy. It really looks like a legitimate SaaS product that somebody might use. I sat down with Mike Britton, CIO at Abnormal AI to explore how AI is lowering the barrier to cybercrime and what security leaders need to change in response. Here are full conversation at explore. TheCyberwire.com slash abnormal AI. We return now to my discussion with Andy Davis,
Starting point is 00:12:50 global research director at NCC Group, about why timing is a crucial but underappreciated dependency in modern computing. My next question to him was on the manipulation of timing in attacks against crucial infrastructure, like power grids. What would those kinds of? attacks look like? Synchronization of systems is often very important, and the way that power generation
Starting point is 00:13:15 systems operate sometimes rely on very accurate synchronization between one system and another. And if you can desynchronize those, you can have a massive impact on the way that the systems operate and can negatively impact the generation of the power. or could potentially, you know, cause outages or even, you know, fires and, you know, really nasty events. If systems go out of synchronization that are controlling safety critical elements, critical after infrastructure. Wow. Yeah. I think I really, it's something I really didn't appreciate at all. And I'm still, as I've said, I'm learning so much about this. I guess what do we, what do we do from here? How do we make systems more resilient, perhaps incorrect?
Starting point is 00:14:05 had assumed there was a lot of redundancy to protect from this sort of thing, or perhaps that these kinds of risks were so maybe military focus that perhaps the rest of us don't need to worry about this as much, but it sounds like those are false assumptions. So with regard to redundancy, people think about the redundancy of their systems rather than necessarily the redundancy of their alternate time sources. When people think about time, they're normally more concerned about how accurate that time is, rather than being concerned about what happens if that time is wrong. So it's kind of a shifting mindset, really, that we're talking about from an accuracy mindset to an integrity mindset. Because
Starting point is 00:14:53 people don't often think about the fact that time could be wrong, and if it was wrong, what impact it might have on their systems. It's all about having multiple time sources that you can compare against. So for example, I talked about accurate time sources being on board satellites. In the situation where you've got a large data center with lots of expensive servers in it, it's not that much more expensive to get an accurate time source independent of the satellite network that you have within your network. So, you know, one of those cesium clocks, that kind of thing, the kind of thing that was actually based on all the satellites. So you can have multiple time sources and constantly compare between the two and make sure that one isn't being
Starting point is 00:15:40 manipulated. If you look at mobile phones, for example, one of the things that they do in this sense is they're constantly getting the accurate time information from the GPS satellites because all smartphones these days have got GPS in them. But they also have accurate time source that's sent via the cellular network, and therefore they're able to cross-reference between those two. And if, for example, they suddenly see that the GPS time source changes, they can see that either there's been a problem, you know, some kind of reception problem,
Starting point is 00:16:19 or it's being spoofed or manipulated. Okay. All right, so for an Infosec practitioner who's listening to our chat right now, I'm wondering if there's anything, any base assumption that we should be challenging or anything that might surprise them to learn that you want to highlight. I think that the most surprising thing is that when time is either manipulated or strays, you know, it changes as a result of some kind of non-malicious reason. the way that that can be exhibited in behavior of the systems doesn't immediately make you think that something external is affecting it. People wouldn't necessarily jump to the conclusion that, oh, it's time that's caused this.
Starting point is 00:17:13 Because, you know, apart from the targeted type attacks that I talked about where you need to get time and bypass the security control, if time drifts, it can have, have very subtle effects on control systems, that's saying, and they could be seen as an intermittent failure. Well, yeah, they could be seen as maybe a component within the system that's just degraded over time the way that it's behaving. So people might jump to the conclusion that, oh, well, that system might have failed, and that's why it's behaving that way, rather than the time source that it's relying on has strayed or stopped or changed, and that's the result.
Starting point is 00:18:04 So, again, it's a kind of a mindset of don't assume that when you see anomalous behavior in your systems, that it's actually the fault of the system. It might be, you know, the time source that's being provided to it. that can have those effects. I'd just like to mention an incident that happened back in 2012 called the Leap Second incident. Now, a leap second is an extra second that occasionally needs to be added to universal coordinated time,
Starting point is 00:18:39 UTC, in a coordinated way globally, because of the way that the Earth's rotation changes over time compared to our universal time. It's basically a correcting factor that every number of years, they need to add an extra second, which is called a leap second. And back in 2012, when they inserted this leap second, it had a huge amount of effect on major internet services. People like LinkedIn, Mozilla, Reddit, all these big systems that have some reliance on time. just the manipulation of that time by one second that was done in a controlled way
Starting point is 00:19:22 had all kinds of unintended consequences on these systems and really kind of raised the issue as something that people should be more concerned about. Now, when I've mentioned this to people, they can't remember the 2012 leap second incident so people forget this stuff quickly. Yeah, I was going to say,
Starting point is 00:19:42 I'm trying to remember that as well and I'm struggling. Can you refresh my memory? little bit on that one. So, I mean, the kind of experiences that the servers had were CPU, spikes, lockups, crashes, service outages, because the different ways that software components within them handle the extra second incorrectly. So that basically goes back to your question earlier about, you know,
Starting point is 00:20:09 how should system designers cater for these things, that they need to consider time being, either actively manipulated or, you know, drifting as an input that needs to be checked and ensure that the robustness of their system when time does change. That's fascinating. Honestly, this has been such a really interesting chat. Andy, thank you so much for sharing your expertise with us today. It feels kind of metaphysical to be talking about time in such an abstract and also concrete way at the same time. So this is super neat.
Starting point is 00:20:45 Andy, thank you so much for joining me today. I really appreciate it. And that is T-minus Space Cyber Briefing, brought to you by N2K CyberWire. If you like what you heard today, you will also enjoy our newsletter, Signals in Space. You'll get research and notes pulled together by our producer Ethan Cook and me,
Starting point is 00:21:12 along with this week's top space cyber news stories. Subscribe by visiting thecyberwire.com slash newsletters. We'd love to know what you think of our podcast, your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like our show, and we always hope that you do, please share a rating and review in your podcast app. You could also fill out the survey in the show notes or send an email to us at space at n2K.com. We're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector,
Starting point is 00:21:49 from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation. Learn how at N2K.com. Thank you again for listening to T-Minus. I am your host, Maria Vermazas. The show is produced by Ethan Cook and Liz.
Starting point is 00:22:19 Stokes. We're mixed by Elliot Peltzman and Trey Hester with original music by Elliot Peltzman. Our executive producer is Jennifer Iben with Content Strategy by Mayon Plout. Peter Kilpy is our publisher. See you next week.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.