Live data from Hacker News

SATCOM terminals under attack in Europe: a plausible analysis

reversemode.com

31–40 of 79 posts

Re: SATCOM terminals under attack in Europe: a plausible analysis

#31

Earlier quoted context omitted.

The purpose of a false flag is to drive a certain narrative, so it's always accompanied by incessant media coverage. That is not the case here, the attack is likely for genuine tactical purposes.

> That is not the case here Are you sure that false-flag attacks always involve a media blitz? Just thinking that if I were planning a false flag, and I know that people would recognize it as such because of the media blitz, then I'd look for a workaround. That seems consistent with what we have here.

Do you have an example of a false flag without a media circus around it?

Re: SATCOM terminals under attack in Europe: a plausible analysis

#32
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

> why waste that access on breaking everything in a highly-visible way when you're better off silently sitting there and using the access to eavesdrop on everything The subtle approach takes more time. Take the PoV of the hypothetical Russian decision maker.. you can either take all them down now with something quick & dirty while the tanks are rolling, or inject a stealthy targeted piece of malware you haven't finis…

Yes, this was my point. I don’t believe they’ve attacked anything satellite-specific and instead just pushed an intentionally-bad configuration or firmware update to terminals in the field.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#33

Earlier quoted context omitted.

The purpose of a false flag is to drive a certain narrative, so it's always accompanied by incessant media coverage. That is not the case here, the attack is likely for genuine tactical purposes.

> That is not the case here Are you sure that false-flag attacks always involve a media blitz? Just thinking that if I were planning a false flag, and I know that people would recognize it as such because of the media blitz, then I'd look for a workaround. That seems consistent with what we have here.

> What’s the point of a false flag if nobody knows about it?

I agree. A false-flag attack is all about optics.

But IIUC the GP, they're saying the SATCOM failure isn't widely known, so it wouldn't make sense as a false-flag attack.

That's where GP loses me. Because we are discussing it here, as members of the general public. And the discussion isn't limited to a small nerdy site like HN; it's also being covered by Reuters [0].

[0] https://www.reuters.com/business/energy/satellite-outage-kno...

Re: SATCOM terminals under attack in Europe: a plausible analysis

#34

Can someone versed in military doctrine / strategy talk about dealing with the uncertainty of a false-flag attack? Does the best-known approach just boil down to weighing the cost/benefit of (acting | not acting) x P(most likely aggressor | some other cause)? Or has someone figured out a better approach?

I usually use a 'what are either side saying about it' and then apply a 'there are always three sides to things ' heuristic transform filter.

Unfortunately with all the censorship, service withdrawals, disconnections etc (from both sides) makes this approach .... difficult ....

My opinion is, let all the information flow. People are not sheep that need herding by the powers that be (again, I refer to both 'sides' here).

Re: SATCOM terminals under attack in Europe: a plausible analysis

#35
I have personally seen that a lot of "cheap" point to multipoint contended access VSAT modems have very little security on them.

Would not be surprised in the slightest if something like a new firmware load or configuration push coming from the hub of the network was not properly validated by the modems using a secure crypto key/signature method.

Keep in mind that what we're talking about here is the European equivalent of the viasat/hughesnet/wildblue low cost, highly contended access geostationary vsat modem service. It's about the cheapest possible thing you can buy that is two way IP data via geostationary at 64:1 oversubscription ratio or more. There are very demanding economics factors in play that require the company to make the end user terminal hardware as absolutely cheap as possible, for all of the sub components (physical dish/mounting, LNB, Tx/BUC/SSPA, cabling, and modem).

Re: SATCOM terminals under attack in Europe: a plausible analysis

#36
post #21

Earlier quoted context omitted.

Sure, I'd hope for a heavily decentralized system to have some capability of autonomous operation. But in the medium and long term, it can't be good to not be able to remotely monitor for failures requiring manual intervention or on-site mechanical servicing.

Having to visit every turbine to replace a satellite modem doesn't sound like a super large challenge at nation-state scale.

The problem is once again our godawful prior government. Many tens of thousands of jobs in the wind industry have vanished over the last years [1] because the Conservatives oppose renewable power and impeded it wherever possible - if it is because of corruption, incompetence, fear of the far-right that outright demonizes anything not fossil or nuclear I don't know. In any case, we simply don't have the staff to visit literally thousands of wind turbines, a lot of which are actually offshore, simply to replace routers.

This situation is an unbelievable clusterfuck.

[1]: https://www.zdf.de/nachrichten/wirtschaft/windkraft-industri...

Re: SATCOM terminals under attack in Europe: a plausible analysis

#37
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

> "Cyberattack on satellite network" sounds so serious

yes agree -- third hand witness to actual ground station management of Small SATs here.. even internal engineers are locked out; multiple keys required to perform actions; closely monitored change-of-behavior networks, etc etc

beware of REALLY LARGE CLAIMS at this time -- peace out

Re: SATCOM terminals under attack in Europe: a plausible analysis

#38
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

This sort of what virtual networking devices are trying to solve, no?

Going to a full on box also increases your attack surface by adding a lot of unnecessary stuff.

Plus even with something completely in software you still need the physical hardware in there at some point - and those individual pieces will be running their own firmware and microcontroller software.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#39

Can someone versed in military doctrine / strategy talk about dealing with the uncertainty of a false-flag attack? Does the best-known approach just boil down to weighing the cost/benefit of (acting | not acting) x P(most likely aggressor | some other cause)? Or has someone figured out a better approach?

The purpose of a false flag is to drive a certain narrative, so it's always accompanied by incessant media coverage. That is not the case here, the attack is likely for genuine tactical purposes.

Everything you are describing would still have an intended audience - the audience may be smaller, or niche, but they still exist.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#40
post #24
post #14

Earlier quoted context omitted.

> Sure, but can you prove it to the public in enough certainty to declare war? This is not a court of law, proof is not what is missing to declare a war against Russia. They have a credible nuclear deterent, that is why war is not declared against them by other countries. It is in fact a very sweet idea to think that a war declaration depends on meeting or not meeting some evidentiary standard.

You misunderstood, or simply ignored the word “public”. In free press societies, you need the will of the people to go to war. You need a 9/11 moment. A casus belli.

> In free press societies, you need the will of the people to go to war.

Sure. And this consent can be produced when there is a need for it. “Proof” is not the missing component.

That American basketball player who the Russians detained? Casus belli. The cyber attacks? Casus belli. Shelled civilians? Casus belli. The NATO country cargo ships which got hit and sunk? Casus belli.

These are just the ones I can think of. A proper state aparatus can come up with many more and probably even better ones. Government officials will leak the background, solemn faced politicians will demand justice while friendly journalist will write up the whole thing in the most hearth wrenching way. If they want to they can.

So why do they don’t want to? Is it because the Russian army is so powerfull that we think we can’t overpower them? No. Is it because the Russian air defences are so advanced that they cannot be picked apart? No. So what is it which makes the west avoid a direct confrontation with Russia? Why are they doing this strange dance of supplying weapons to Ukraine and hurting Russia with sanctions, but not directly engaging with them troop-to-troop? It’s the Russian nukes.

> You misunderstood, or simply ignored the word “public”.

I don’t think so. You won’t “prove” anything to the public through detailed technological explanations. A fig leaf of deniability might be an interesting roadblock in a criminal prosecution where things have to be proven “beyond a reasonable doubt”. In a situation where there is a governmental will to engage in a peacekeeping mission (read: send troops to fck the Russians up) the evidentiary level is “can we find an authorative sounding voice in the whole government who can tell the right sod story to enough guilable journalist to sell the people on it”. That is such a low level of “proof” that one might as well assume it can be met nearly always.

Journalist won’t pour over the attack binaries using Ghidra to make an assesment about the relative probabilities that it has the signatures of being created by this or that advanced persistent threat group. The ones who would demand that level of rigour before publishing won’t get the scoop. The ones who are selected to spread the message will have a lovely hour with a very charismatic “expert” who will walk them through just enough of the detail to sound right but not to get bogged down in unnecesary complications. This chat will get translated into a single line in their article, maybe something like “experts at the National Security Agency matched the unique signatures of the cyberweapon to the advanced persistent threat group Tippsy Bears, a known front of the Russian Federation.” Followed by two pages of hearth wrenching human angle story about innocents suffering needlesly. That is the “proof” the public might get.

Post reply on HN