Hacking the Nautical Rules of the Road Turn Left for Global Pwnage
Amp, Data
DEF CON 33 · Day 1 · Main Stage
Overview
In an era where cyber warfare often focuses on digital infrastructure, the DEF CON talk "Hacking the Nautical Rules of the Road Turn Left for Global Pwnage" by Amp and Data pivoted the conversation to a profound, yet often overlooked, domain: maritime operations and the critical role of human trust. This presentation meticulously dissects the systemic fragility within global shipping, arguing that the most impactful attacks aren't necessarily highly sophisticated technical exploits, but rather those that undermine the foundational trust upon which maritime safety and global trade depend. The speakers' unique blend of military cyber operations expertise and seasoned maritime experience provided a compelling framework for understanding how seemingly simple deviations from established norms, like turning a ship to port at the wrong time, can cascade into catastrophic economic and societal disruption.

Key moments
- 0:00 Talk introduction and speaker backgrounds
- 2:00 Why maritime matters: global trade impact
- 2:25 Exposing systemic fragility in maritime operations
- 3:20 Importance of knowing collision regulations (Colregs)
- 4:15 Vulnerabilities of modern super container ships
- 6:30 The 'turn to port' attack strategy
- 7:00 Impact on mariners and system confidence
Hacking the Nautical Rules of the Road Turn Left for Global Pwnage
Speakers: Amp; Data
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=WDPOk0GxxEo
Overview
In an era where cyber warfare often focuses on digital infrastructure, the DEF CON talk "Hacking the Nautical Rules of the Road Turn Left for Global Pwnage" by Amp and Data pivoted the conversation to a profound, yet often overlooked, domain: maritime operations and the critical role of human trust. This presentation meticulously dissects the systemic fragility within global shipping, arguing that the most impactful attacks aren't necessarily highly sophisticated technical exploits, but rather those that undermine the foundational trust upon which maritime safety and global trade depend. The speakers' unique blend of military cyber operations expertise and seasoned maritime experience provided a compelling framework for understanding how seemingly simple deviations from established norms, like turning a ship to port at the wrong time, can cascade into catastrophic economic and societal disruption.
The core thesis of the talk is that the true vulnerability lies not just in technology, but in "Layer 9" – people's confidence in the system. By exploiting this layer, adversaries can achieve "global pwnage" not through direct control of every vessel, but by creating widespread fear, uncertainty, and doubt that paralyzes an entire industry. The talk serves as a stark warning about the potential for low-tech, high-impact attacks that leverage human psychology and institutional reliance on trust, urging the cybersecurity community to look beyond traditional technical defenses and consider the broader socio-economic implications of maritime insecurity.
Background
▶ Watch: Talk introduction and speaker backgrounds (0:00)
The maritime sector forms the indispensable backbone of the global economy, facilitating the movement of an astonishing 90% of the world's cargo and approximately $17 trillion – or 70% – of its annual trade. This immense scale, however, belies a profound systemic fragility. As the speakers succinctly put it, "when vessels stall, markets fall." Despite its critical importance, the maritime industry operates under a unique set of circumstances that make it particularly susceptible to both physical and cyber threats.
At the heart of maritime safety are the International Regulations for Preventing Collisions at Sea (COLREGs), often referred to as the "nautical rules of the road." These regulations, along with additional national and international codes (totaling over 4,000 pages), dictate how vessels interact to prevent collisions. Mariners are extensively trained in these rules, fostering a deep-seated expectation of adherence among all operators. This expectation of predictable behavior is a cornerstone of maritime trust. However, ships themselves, despite their imposing physical presence, are described as having a "hard outside and a soft gooey inside." They function as miniature cities, complete with their own Industrial Control Systems (ICS), SCADA environments, and often wildly outdated IT infrastructure. Many of these systems run on protocols developed in the 1960s, lacking fundamental security features like authentication or encryption. Open Wi-Fi networks are common, and the operational technology (OT) aboard these vessels prioritizes reliability and uptime above all else, often at the expense of robust cybersecurity.
The threat landscape is far from theoretical. The Maritime Cyber Attack Database, maintained by NHL Stenden University of Applied Sciences, has recorded over 200 reported cyber attacks against maritime companies and ships since 2020 – roughly one per week. The speakers suggest that, factoring in normal underreporting rates, the actual number of successful attacks could be as high as one every four to eight hours. Compounding this vulnerability is the human element: even the largest ships typically have only 20 to 30 crew members, none of whom are usually dedicated cybersecurity professionals. These crews are often "pretty much blind" to the cyber security posture of many onboard systems, making them unwitting participants in potential attack paths. The entire industry, therefore, presents a target-rich environment where deeply embedded trust, outdated technology, and limited cyber awareness converge to create significant risk.
Key Findings
▶ Watch: Exposing systemic fragility in maritime operations (2:25)
The central discovery presented in the talk is the concept of "Layer 9" vulnerability – the inherent systemic fragility rooted in people's confidence in maritime operations. This layer, distinct from technical or operational layers (Layers 1-8), represents the collective trust that underpins the entire global shipping ecosystem. The speakers argue that true "global pwnage" is achieved not by directly controlling every vessel, but by systematically eroding this trust, leading to widespread fear and paralyzing economic activity.
A core finding is the statistical predisposition of mariners to avoid turning to port (left) in collision avoidance scenarios. The speakers highlight that, statistically, a mariner has a 75% chance of doing the "right thing" by not turning to port when encountering another vessel. This implies that deliberately turning to port, or manipulating a ship to do so, constitutes the "wrong thing" and creates immediate alarm and disruption. This action abuses established norms and expectations, forcing other vessels to take evasive action, regardless of who is technically "at fault." Such maneuvers incur costs: increased fuel consumption, deviation from course, and potential accountability for the parent company. More critically, it creates a "deer in the headlights" effect, inducing panic, freezing, or incorrect responses from the crew, thereby increasing the likelihood of accidents.
The talk provided compelling real-world examples to illustrate the devastating consequences of errors, both accidental and potentially malicious, that impact this Layer 9 trust:
- Costa Concordia (2012): This cruise liner ran aground after sailing too close to shore, resulting in 32 deaths, 64 injuries, and over $2 billion in costs. The incident dramatically impacted the entire cruise line industry, causing an estimated $5-6 billion in lost revenue in the subsequent year, demonstrating how a single accident can have systemic economic ripple effects.
- USS John S. McCain (2017): This US Navy destroyer collided with a Liberian tanker after turning to port. The incident claimed 10 sailors' lives and caused over $100 million in damages, despite both ships moving at slow speeds (under 11 mph). This was attributed to a loss of control, not sabotage, yet highlights the vulnerability of critical maneuvers.
- Iranian Tankers (Earlier this year): A significant incident where 116 Iranian tankers and cargo ships were simultaneously and remotely hacked. While attackers did not gain control of the operational systems, they successfully isolated communication systems, cutting off crews from each other, from shore, and from other vessels. This demonstrated the power of creating isolation and uncertainty, even without direct physical damage.
These incidents, ranging from accidents to cyber attacks targeting communications, underscore the fragility of maritime operations and the profound impact when the predictable "rules of the road" are broken or trust is undermined. The speakers' key finding is that by intentionally introducing unpredictable behavior, such as a "turn left" scenario, an attacker can exploit the human element and the inherent reliance on trust to create widespread disruption that scales far beyond the initial technical compromise.
Technical Deep Dive
▶ Watch: Importance of knowing collision regulations (Colregs) (3:20)
While the core message of the talk emphasizes the human element and trust ("Layer 9"), the speakers also detailed numerous technical vulnerabilities that could be exploited to initiate the "turn left" scenario or achieve broader disruption. These vulnerabilities are endemic across the maritime sector, largely due to a historical prioritization of reliability and uptime over cybersecurity, coupled with the use of outdated technologies.
The operational technology (OT) environments on modern vessels and in ports present a significant attack surface. Ships are essentially floating cities with their own Industrial Control Systems (ICS) and SCADA systems. These often run on legacy protocols developed in the 1960s, which were never designed with security in mind. Consequently, they frequently lack basic security measures such as authentication and encryption. This makes them highly susceptible to direct manipulation if an attacker gains network access. Furthermore, many vessels still operate open Wi-Fi networks, providing an easy entry point for proximity-based attacks.
The talk highlighted several specific technical vectors:
- AIS (Automatic Identification System): This system, mandatory for most large vessels, broadcasts a ship's identity, position, course, and speed to other ships and shore stations. Critically, AIS is an unauthenticated, unencrypted, VHF-based technology originating from the 1960s. This makes it inherently vulnerable to spoofing and jamming. An attacker can easily broadcast false AIS signals, making phantom ships appear on navigation screens or misrepresenting the position of real vessels. This can cause confusion, misdirection, and trigger unnecessary or incorrect collision avoidance maneuvers, directly enabling the "turn left" attack concept by creating a perceived threat.
- GPS Spoofing and Jamming: A widely recognized vulnerability, GPS systems are crucial for modern navigation. GPS spoofing involves broadcasting false GPS signals to make a ship's navigation system report an incorrect position, course, or speed. GPS jamming involves overwhelming legitimate GPS signals, effectively blinding a ship's navigation. Both can lead to vessels veering off course, entering restricted areas, or initiating dangerous maneuvers. The speakers noted that the body of work on GPS attacks continues to grow at conferences like DEF CON, indicating a persistent and evolving threat.
- Digital Charts: Modern ships increasingly rely on digital charts rather than traditional paper versions for navigation. While more convenient and often more accurate, these digital systems present a "delicious attack surface." Malicious actors could modify these charts to either conceal real navigation hazards (e.g., reefs, shallow water) or, conversely, create phantom hazards where none exist. This could lead ships to strike real obstacles or force them into sudden, dangerous evasive actions, including an unexpected "turn to port."
- Ransomware: Given the prevalence of aging and often undefended systems in maritime IT and OT, ransomware poses a significant threat. A successful ransomware attack could cripple port operations, halt cargo movement, or disable critical ship systems, leading to massive delays and economic losses.
- Targeted Malware: Beyond ransomware, highly targeted malware could be deployed to directly manipulate specific ship systems. Examples given include malware designed to capsize a ship, interfere with ballast pumps (critical for stability), or disrupt fire suppression systems. Such attacks could create physical hazards or even lead to the deliberate destruction of a vessel, with profound implications for safety and trust.
- Cloud Databases: The increasing interconnectedness of maritime logistics means that various systems—from inventory tracking to customs and port operations—rely on cloud databases. These databases, linking disparate parts of the global supply chain, present "terrific opportunities to do all sorts of nefarious things" if compromised, enabling widespread disruption of port efficiency and data integrity.
The speakers emphasized that these are not entirely new attack vectors in the broader cybersecurity landscape. However, their application "in this domain with this broad a target at this scale" is what makes them particularly potent in the maritime context. The lack of basic cyber hygiene, network segmentation, and modern security protocols across much of the industry means that even well-known attack techniques can have disproportionately severe consequences.
Demo / Proof of Concept
▶ Watch: The 'turn to port' attack strategy (6:30)
While the talk meticulously outlined the theoretical attack vectors and demonstrated the potential for catastrophic outcomes through historical examples, it did not feature a live, real-time demonstration or a technical proof-of-concept of a ship being manipulated to turn to port. Instead, the speakers focused on building a conceptual framework for how such an attack would unfold and scale, leveraging existing vulnerabilities and human psychology.
The "demo" of the talk was primarily conceptual, illustrating how manipulating perceived reality or system behavior could lead to the desired outcome. For instance, the discussion around AIS spoofing and GPS jamming served as a conceptual demonstration of how an attacker could make a ship's crew believe they needed to "turn to port" by presenting false navigational data or creating phantom collision threats. Similarly, the explanation of how digital charts could be altered to show non-existent hazards or conceal real ones demonstrated how an attacker could engineer a scenario where a ship would be forced into a dangerous maneuver.
The speakers also used the analogy of a driver encountering a vehicle coming directly at them on a highway to illustrate the visceral "feeling in your chest" that licensed mariners would experience when confronted with a ship violating the rules of the road. This served to "demonstrate" the human psychological impact that is central to the "Layer 9" attack. The examples of the Costa Concordia, USS John S. McCain, and the Iranian tanker hacks served as real-world precedents of how accidents, errors, or communication disruptions have already created the kind of chaos and loss of trust that an intentional "turn left" attack aims to achieve. The talk, therefore, presented a compelling case for the feasibility and impact of such attacks by drawing on established security principles and real-world incidents, rather than a novel technical demonstration.
Defensive Implications
▶ Watch: Impact on mariners and system confidence (7:00)
The talk concluded with a powerful call to action for the cybersecurity community, emphasizing that defending against "global pwnage" in the maritime sector requires a multi-faceted approach that extends beyond traditional technical fixes. The speakers stressed that many of the fundamental security practices common in other industries are still nascent or entirely absent in maritime operations, making basic cyber hygiene and network segmentation paramount.
Key defensive implications and recommendations for defenders include:
- Stress Test Equipment: Maritime equipment, from navigation systems to ICS/SCADA, needs rigorous security testing. Defenders should actively engage in stress testing these systems to identify vulnerabilities before adversaries do. This includes not just the software, but also the hardware and communication protocols.
- Demand More from Manufacturers: A significant portion of the vulnerability stems from manufacturers prioritizing reliability and cost over security. Defenders, as stakeholders, need to demand more robust security features from maritime equipment manufacturers. This includes built-in authentication, encryption, secure-by-design principles, and regular security updates.
- Implement Basic Cyber Hygiene: For many maritime organizations, even foundational cybersecurity practices are lacking. Defenders must advocate for and implement essential cyber hygiene measures, such as strong password policies, multi-factor authentication, regular patching, and employee security awareness training.
- Network Segmentation: The "soft gooey inside" of ships and ports, characterized by flat networks connecting IT and OT, is a critical vulnerability. Implementing network segmentation can significantly limit the lateral movement of attackers, isolating critical operational technology from less secure IT systems and external networks.
- Participate in Maritime Cybersecurity Initiatives: The speakers encouraged involvement in communities like the Maritime Hacking Village at DEF CON and participating in Capture The Flag (CTF) events focused on maritime systems. Such engagement helps build expertise, foster collaboration, and develop innovative defensive strategies.
- Reinforce Trust in Systems: The ultimate goal of the "turn left" attack is to erode trust. Defenders must actively work to reinforce public and operational trust in maritime systems. This involves transparent communication about security incidents, visible efforts to improve security, and fostering a culture of security awareness among all stakeholders, from crew members to executives and even the public.
- Educate and Empower Mariners: Given that crew members are often "blind" to cyber security issues, it is crucial to provide them with basic cyber awareness training. While they are not expected to be incident responders, understanding common threats and reporting suspicious activities can be a vital first line of defense.
- Advocate for Policy Changes: Beyond technical and organizational measures, there's a need for policy and regulatory bodies to mandate higher cybersecurity standards for the maritime industry, driving widespread adoption of best practices.
The speakers highlighted that these recommendations, while "nothing new" to the cybersecurity community, are revolutionary for many in the maritime sector. The overarching message for defenders is to recognize the unique threat landscape of the maritime domain, understand the profound impact of attacks on "Layer 9" trust, and proactively implement both technical and human-centric defenses to protect the global economy.
Key Takeaways
- Maritime is Critical but Fragile: The global economy relies heavily on maritime trade, yet the sector exhibits systemic fragility, particularly in its reliance on outdated technology and human trust.
- "Layer 9" is the Ultimate Target: The most impactful attacks target "Layer 9" – people's confidence in the system. Undermining this trust can lead to widespread fear and economic paralysis.
- "Turn Left" as an Exploit: Deliberately causing a ship to turn to port (left) exploits established nautical norms, forcing dangerous reactions and creating chaos, even without direct collision.
- Vulnerable Technology, Outdated Security: Ships and ports utilize many unauthenticated, unencrypted, legacy systems (e.g., AIS, GPS, digital charts) that are ripe for technical exploitation, often lacking basic cyber hygiene and network segmentation.
- Scaling Impact Through Trust Erosion: Incidents like the Suez Canal grounding or the Costa Concordia disaster demonstrate how single events, whether accidental or intentional, can scale to billions in economic damage and permanently alter societal behavior by eroding trust.
- Call to Action for Defenders: The cybersecurity community must engage with the maritime sector to stress test equipment, demand better security from manufacturers, implement basic cyber hygiene, and actively reinforce trust in these critical systems.
About the Speaker(s)
The talk was presented by Amp and Data.
Amp brings a robust background in real-world cyber operations, having conducted missions against targets across all five domains—airlines, sea, space, cyberspace, and land—with all five of the Five Eyes partners. This extensive experience provides Amp with a unique, holistic perspective on systemic vulnerabilities across critical infrastructure. Amp also proudly noted being the parent of the child who designed the cool space badge for the conference.
Data (also known as Guan) has a deep and practical understanding of maritime operations, having spent the last decade traveling the globe on ships in various capacities. Data's roles have included engineer, ship driver, mentor, and captain (though not simultaneously), all of which involved teaching, learning, or practicing the nautical rules of the road. Currently, Data also captains CTF teams and speaks at DEF CON, bridging the gap between traditional maritime expertise and cutting-edge cybersecurity.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent maritime security awareness talk with a genuinely interesting thesis — the 'Layer 9' trust-erosion framing is conceptually sharp and the speaker pairing (cyber ops + actual ship captain) is the right credential stack for this topic. But it doesn't go deep enough technically to be a research talk, and it doesn't go wide enough strategically to move the needle on policy — it lands in the respectable middle ground of 'informed practitioners explaining a neglected domain to a general DEF CON audience.'
Heather Calloway (CISO) — SOLID
A competent, well-framed awareness talk that correctly identifies maritime critical infrastructure as an underserved risk domain and makes a credible case that the attack surface is wide open. The 'Layer 9' framing is memorable and the real-world incident grounding is effective, but the defensive recommendations are thin and the institutional accountability question — who owns this risk, and who can actually act — never gets answered.