This entry survives from CORALog, the lab's original weblog. It is republished here because the point it made in 2006 is now a procurement question, not an academic one.
What the original post said
The post discussed reporting that the video downlink from Predator unmanned aircraft was transmitted without encryption, and that the signal could be received with commodity equipment. The interesting part was not the interception itself but the reasoning behind it: the link was treated as a sensor feed rather than as a communications channel, so it was never given a communications-grade threat model.
The lab's argument at the time was that autonomy raises the stakes on every link a machine depends on. A remote-operated system fails visibly when its link is attacked. An autonomous one may keep acting on data it should not trust.
Why it still matters when you buy a robot
Every platform in the Coral Labs catalogue is a networked computer with actuators. It streams video, accepts mission updates and often phones home to a vendor cloud. The 2006 failure mode - an unauthenticated channel treated as harmless telemetry - has not disappeared, it has been re-implemented on newer radios.
Three questions cover most of the exposure. Where is video and telemetry processed, and is it encrypted in transit and at rest? Can the robot be commanded from outside your network, and by whom? What happens to autonomy when the link drops - does it stop, hold, or continue on stale data?
The practical test
Ask a vendor to demonstrate the failure, not to describe it. Pull the network during a demonstration and watch the robot's behaviour. A platform that comes to a controlled stop and reports the fault is engineered for deployment. One that keeps moving on a stale plan is a pilot risk you will discover later, on your own site.
Tags: Archive · Security · Autonomy