Live data from Hacker News

The hacking of Starlink terminals has begun

wired.com

101–110 of 267 posts

Re: The hacking of Starlink terminals has begun

#101

This WIRED article[1] references a release of tools and information about the research on GitHub[2] however it 404s. Hope that is not being censored. [1] https://www.wired.com/story/starlink-internet-dish-hack/ [2] https://github.com/KULeuven-COSIC/Starlink-FI

Quoted post unavailable.

> looks like Starlinks legal dept got to the github repo first :(

If true than it was not through the normal DMCA process of GitHub that would result in a public[1] take-down notice being filed for transparency.

[1] https://github.com/github/dmca

Re: The hacking of Starlink terminals has begun

#102

Earlier quoted context omitted.

If a system is designed to not allow that access, and you can compromise that design, it is most definitely a vulnerability.

I'm convinced that it's impossible to prevent anyone that can physically tamper with a system from having full privileges on that system, as a result of physics. The only way to truly protect information is to make use of quantum effects, and we've only just started doing that in labs. Everything else is just making it harder. So, if you make things harder and someone comes along that invests more effort to overcome,…

> Everything else is just making it harder.

If it's hard enough that only state actors can potentially do it, then what does it matter in real life that it's theoretically vulnerable?

Re: The hacking of Starlink terminals has begun

#103
post #83

I'm sure it will never happen but it would be awesome if they would release an 'open' terminal under the same auspices of commercial SDR transceivers. I'm curious if these could be used for very localized doppler radar.

You can build a simple Doppler radar yourself today using a couple of SDRs, but sophisticated phased arrays are the kind of thing that makes for pretty good military equipment. I doubt an open one will come on the market (legally) soon.

Just say you’re doing high resolution of metamaterials for science. Materials resonant at the target radar band, because that wavelength is easier to manufacture/economically useful/etc.

I think you’re more likely to find a job than trouble — SBIR has a bunch of grants in that area. (Last I looked.)

Re: The hacking of Starlink terminals has begun

#104
post #23

The article compares the Russian jamming of Viasat with the compromise of a Starlink UT. No, no, no... This is really wrong! > As is typically the case with any technology, the increase in use and deployment of Starlink and other satellite constellations also means that threat actors have a greater interest in finding their security holes to attack them. > Indeed, Russia saw an advantage in taking out a satellite pro…

> The article compares the Russian jamming of Viasat with the compromise of a Starlink UT. No, no, no... This is really wrong!

This is a bit misleading. The article mentions the Viasat hack in the next-to-last paragraph of the article before the update in the context of satellite security more broadly:

> "As an increasing amount of satellites are launched—Amazon, OneWeb, Boeing, Telesat, and SpaceX are creating their own constellations—their security will come under greater scrutiny. In addition to providing homes with internet connections, the systems can also help to get ships online, and play a role in critical infrastructure. Malicious hackers have already shown that satellite internet systems are a target. As Russian troops invaded Ukraine, alleged Russian military hackers targeted the Via-Sat satellite system, deploying wiper malware that bricked people’s routers and knocked them offline. Around 30,000 internet connections in Europe were disrupted, including more than 5,000 wind turbines."

Re: The hacking of Starlink terminals has begun

#105
post #69

I never understand why the dollar amount is always included in these headlines. Like affording the $25 worth of hardware is really the most difficult obstacle to overcome here.

It's a sign of the hackers skill that they can take the same difficult problem and make it so anyone with $25 can duplicate it.

Making something accessible to the masses makes it a more impressive achievement.

Re: The hacking of Starlink terminals has begun

#106
post #5

Relevant presentation on DEFCON Media server: https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre... https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre...

[flagged]

> meaning everyone of those floating satellites needs to be brought back down and modified

Don’t they have a fairly short operational lifetime, thanks to increased drag from being in LEO? IIRC it’s around 5 years. I believe that’s part of the reason for the high launch cadence. Worst case they just limp along with what they’ve got until they’re all replaced with new satellites.

Re: The hacking of Starlink terminals has begun

#107
post #62

Earlier quoted context omitted.

If a system is designed to not allow that access, and you can compromise that design, it is most definitely a vulnerability.

If a system is not resilient against rooting a terminal which is in user's physical possession, it's a design flaw. Or, rather, the more resilient the system as a whole is to compromises of individual terminals, the better the design is. Assuming such compromise never happens would be outright incompetent.

You might very well want both

E.g.

You may want to protect end users against implants and other attacks from physical tampering with their terminals.

You might not want hostile parties to have an easy time reverse engineering terminals so they can more easily search for remote vulnerabilities in the terminals.

You may not want to hand hostile parties a phased array optimized to transmit to Starlink running arbitrary software of their choice, along with keys identifying the terminal, because even though you think the satellites and authentication mechanisms are robust, making it hard to get this information adds defense in depth.

Re: The hacking of Starlink terminals has begun

#108

Earlier quoted context omitted.

You'd also have to do it, though. Build it, maintain it, rely on it. Alternatively you could just embed a cheap GNSS chip and let other people build and maintain it. > I misrecalled. StarLink can provide 10x more precise positioning than GPS. GPS can also provide much more precise positioning than it does for consumers. There are encrypted bands used for military, etc with significantly better specs.

I don't think that's true anymore. iirc, the accurate bands were made public in the 80s

You might be thinking of Selective Availability (which limited accuracy on purpose) being turned off in 2000.

Re: The hacking of Starlink terminals has begun

#109

Earlier quoted context omitted.

[flagged]

In the same way that me turning off secure boot on my desktop means free Netflix for everyone and we should shut down Comcast until there's a fix. This is a cool attack, but (so far) no more than that. I'd expect that the SpaceX security team is over there putting in some glitch resistant compares at the moment, assuming they haven't already.

Yeah it's quite the opposite actually. Taken from the excellent preso linked above:

"""

• This is a well-designed product (from a security standpoint)

• No obvious (to me) low-hanging fruit

• In contrast to many other devices getting a root shell was challenging

• And a root shell does not immediately lead to an attack that scales

"""

Re: The hacking of Starlink terminals has begun

#110
post #60

Pretty sure Russia has physical satellite killer missiles just like US does? Would a nuke in space even work to take out a group of them, maybe even via an EMP surge or are they hardened? Sometimes I wonder if the world would be more peaceful if cellphone networks couldn't work anymore but there would be so much other chaos so guess not.

Quoted post unavailable.

> The PLA has literally robots that can obscure and destroy US satellites without launching missiles at it

This is 100% speculation.

The only thing that China has demonstrably done is blow up satellites. It would be unsurprising if this tech was in development, but nobody has any clue whether there are non-kinetic satellite neutralization weapons deployed.

Post reply on HN