The response from Starlink[0] was pretty amazing. I love this quote: "we want to congratulate Lennert Wouters on his security research into the Starlink user terminal – his findings are likely why you're reading this, and help us create the best product possible." A lot better than companies that would try to prosecute him.. [0]: https://api.starlink.com/public-files/StarlinkWelcomesSecuri...
Step 1: Why does Google Chrome on KDE/GNU/Linux refuse to allow me to copy text from this PDF??? So f-in annoying! That PR says: > Are these "computers" strictly controlled/owned by SpaceX? If yes, are there multiple computers per satellite? Please help me to understand this claim. In 2022, I assume when someone says "computers" they mean kernel count.
The hacking of Starlink terminals has begun
41–50 of 267 posts
Re: The hacking of Starlink terminals has begun
#42The article compares the Russian jamming of Viasat with the compromise of a Starlink UT. No, no, no... This is really wrong! > As is typically the case with any technology, the increase in use and deployment of Starlink and other satellite constellations also means that threat actors have a greater interest in finding their security holes to attack them. > Indeed, Russia saw an advantage in taking out a satellite pro…
Re: The hacking of Starlink terminals has begun
#43This reads to me like the (more complicated but ultimately) equivalent of "a user reverse engineers the website's javascript!". As in, this allows the user to mod their client but it doesn't change anything for anyone else, and wasn't meant as a real secure element. I'd assume that getting root access to the user terminal gives them no additional privileges to access the actual Starlink data & control planes.
Re: The hacking of Starlink terminals has begun
#44Earlier quoted context omitted.
> connect to the Starlink network outside of their geofence I was wondering about that but can't they determine the location "server side" by triangulation? Or maybe they could in theory but they don't in practice?
Knowing the positions of all the clients and satellites is a basic requirement for operating the network.
Re: The hacking of Starlink terminals has begun
#45Is there any mitigation against these kinds of power/timing attacks? I think the Switch was originally hacked this way.
No, not without changing microprocessors. Essentially these chips are locked by setting certain flags in memory. Various flags control various peripherals, including a flag to disable read/write access to the firmware. Obviously once you disable access, it’s permanent because you don’t have access to reenable it. This side channel attack takes advantage of a flaw in the actual silicon, where branches can be skipped i…
Re: The hacking of Starlink terminals has begun
#46Earlier quoted context omitted.
Step 1: Why does Google Chrome on KDE/GNU/Linux refuse to allow me to copy text from this PDF??? So f-in annoying! That PR says: > Are these "computers" strictly controlled/owned by SpaceX? If yes, are there multiple computers per satellite? Please help me to understand this claim. In 2022, I assume when someone says "computers" they mean kernel count.
There's 2700 satellites currently deployed, so even at 1 per satellite it's still in the "thousands".
Re: The hacking of Starlink terminals has begun
#47Earlier quoted context omitted.
Knowing the positions of all the clients and satellites is a basic requirement for operating the network.
For the satellites this is true, but it's not necessary for the clients to be geolocated when the satellite is operating as a bent pipe. Starlink will know which clients are in which footprint and can locate anybody if they want to, but it's not fundamental to the functionality of the system.
Re: The hacking of Starlink terminals has begun
#48The response from Starlink[0] was pretty amazing. I love this quote: "we want to congratulate Lennert Wouters on his security research into the Starlink user terminal – his findings are likely why you're reading this, and help us create the best product possible." A lot better than companies that would try to prosecute him.. [0]: https://api.starlink.com/public-files/StarlinkWelcomesSecuri...
Step 1: Why does Google Chrome on KDE/GNU/Linux refuse to allow me to copy text from this PDF??? So f-in annoying! That PR says: > Are these "computers" strictly controlled/owned by SpaceX? If yes, are there multiple computers per satellite? Please help me to understand this claim. In 2022, I assume when someone says "computers" they mean kernel count.
[1]: https://www.zdnet.com/article/spacex-weve-launched-32000-lin...
Re: The hacking of Starlink terminals has begun
#49This WIRED article[1] references a release of tools and information about the research on GitHub[2] however it 404s. Hope that is not being censored. [1] https://www.wired.com/story/starlink-internet-dish-hack/ [2] https://github.com/KULeuven-COSIC/Starlink-FI
Re: The hacking of Starlink terminals has begun
#50Earlier quoted context omitted.
There's 2700 satellites currently deployed, so even at 1 per satellite it's still in the "thousands".
Hmm... When I read "hundreds of thousands" I assume more than 100,000. Is that incorrect understanding of English?