Live data from Hacker News

SATCOM terminals under attack in Europe: a plausible analysis

reversemode.com

51–60 of 79 posts

Re: SATCOM terminals under attack in Europe: a plausible analysis

#51
post #21

Earlier quoted context omitted.

Sure, I'd hope for a heavily decentralized system to have some capability of autonomous operation. But in the medium and long term, it can't be good to not be able to remotely monitor for failures requiring manual intervention or on-site mechanical servicing.

Having to visit every turbine to replace a satellite modem doesn't sound like a super large challenge at nation-state scale.

That's assuming that there is enough personnel and spare hardware available, which is not a given even outside of an ongoing supply chain crisis.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#52

Earlier quoted context omitted.

A satellite data system used by the Ukrainian military was knocked out at the same time as the invasion, the outage started in Ukraine before spreading outward, and the damage is permanent - which would not happen in a botched firmware upgrade, where units would load a backup firmware image or get an image OTA, or be fixable via site visit. Not exactly a 'really large claim' that this was an attack.

I think GP is saying that an attack that impacted the satellites flying around in space is a large claim, on account of their systems have better security. I imagine the idea of a many millions of $ satellite burning up because someone left a telnet server open is enough to make executives take sat security a little more seriously than say terminal security. Don’t think anyone is really refuting the idea that satelli…

My argument in my original post was that the fact that this is a satellite network is likely to be completely irrelevant to the actual attack and that the parts that were compromised exist just as well in a terrestrial-based network. However, "satellite network suffers cyber-attack" is a better headline than "local ISP was stupid and got their management network pwned" - the former implies extra complexity which works well for ass-covering and swaying public opinion, something they very much need if it turns out the vulnerability was very stupid & mundane.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#53

Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…

> Is there a plausible explanation for who would do this, besides Russia? Any engineer could accidentally do it... I can totally imagine the release engineer accidentally pushing the dev version, only to realise later that the dev version doesn't have quite the right config to connect for example. Blaming it on a cyber attack is a lot less bad than saying "whoops, we bricked everyone's modems".

It should be pretty easy to figure out which one it is, except if the deployment vector was actually a malicious firmware update.

A plausibly deniable exploit like that is probably orders of magnitude more expensive, and the timing is suspicious enough that it's probably not even worth trying. In any case, it's not like it's trivial to attribute (beyond reasonable doubt) a "transparent" cyber attack either.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#54
post #23
post #20

Earlier quoted context omitted.

With the right commands, you could flip the satellite by 180 degrees, move it from Europe to the pacific ocean, or crash it into one of its neighbors. All geostationary satellites need to be capable of at least some station-keeping to correct for drift, move them to other service areas, or move them to a graveyard orbit at their end of life. (Unlike LEO, GEO satellites don't carry enough fuel for de-orbiting, and fri…

> That layer of commands is hopefully very well protected. Typically some form of HMAC authentication. You can read about it in the CCSDS Blue Book.

What a fascinating rabbit hole. Thank you!

Re: SATCOM terminals under attack in Europe: a plausible analysis

#56
post #9
post #7

Earlier quoted context omitted.

Taking a country's infrastructure through a cyberattack is considered an act of war. Same as if you bombed the power generation infrastructure.

Sure, but can you prove it to the public in enough certainty to declare war? No. Suppose it was Russian flag, they could very easily just claim they were framed - and they very likely could’ve been.

I was with you until you said prove it "to the public"

After the WMDs and 17 intelligence agencies agree fiascos, among countless others, I'm beginning to lean on the side of the media being able to sell snow to an eskimo.

I know this is US-centric and lots of europe/other parts of the world were much more skeptical of the WMD claims at the time.

Before people politically flame me, I mention the "17 intelligence agencies" for 2 reasons 1) getting 17 people to agree on anything is impossible, getting 17 gigantic bureaucracies larger each than most governments to agree on anything is asinine. 2) most of the evidence, if you read the redacted report, was trivially forgeable so as to be pointless in determining actual responsibility. "we found cyrillic characters in the code, only could have come from russia!"

Re: SATCOM terminals under attack in Europe: a plausible analysis

#57
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

> (and the impossibility to obtain said equipment for the average Joe). when I worked on similar problems some years ago, we found out that certain radios were used across sectors with basically the same ucLinux kernels and toolchains, bootloaders, and SoCs. I agree with the "internal VLAN" assessment to a point, as these networks tend to backhaul their admin channel / control plane messaging back to their vendor. Th…

> With this (speculative) radio packet of death, you could fly a spyplane over the region at super sonic speeds

That could work in Ukraine, but a spy plane above Germany would have made national news.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#58
Simultaneously, Russian ground forces have had a hell of a time using their encrypted radios, resulting in the logistical and tactical omnishambles observed by many, and fallback transmitting in the clear using civilian ham radios or cell phones.

Some have attributed this to difficulty in distributing encryption keys to forward units or just general incompetence, but one fun theory I saw on twitter is that Russia uses SDRs somewhere in their radio net and a similar poison packet bricked them all.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#59
post #9
post #7

Earlier quoted context omitted.

Taking a country's infrastructure through a cyberattack is considered an act of war. Same as if you bombed the power generation infrastructure.

Sure, but can you prove it to the public in enough certainty to declare war? No. Suppose it was Russian flag, they could very easily just claim they were framed - and they very likely could’ve been.

Probably not, which is why you probably wouldn't want to openly send the military. But you might, e.g., perform cyberattacks yourself.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#60

Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…

Dumb Question here but my thoughts were - why not push the corrupted update to the sats? AKA hack the sat firmware? I'm fairly certain that they aren't wide open doors but still - I would guess that it would be a lot easier doing it that way. Perhaps it was both, or someting else entirely. It will make for an interesting read one day.

Because it's one thing to attack hardware in Ukraine and have some collateral damage in other parts of the world, and an entirely different thing to directly attack an expensive space asset of another country just because it is used to provide service to Ukraine.

Also, the affected ground stations are in Germany, the satellite belongs to a US company.

Post reply on HN