This reads to me like the (more complicated but ultimately) equivalent of "a user reverse engineers the website's javascript!". As in, this allows the user to mod their client but it doesn't change anything for anyone else, and wasn't meant as a real secure element. I'd assume that getting root access to the user terminal gives them no additional privileges to access the actual Starlink data & control planes.
If it gives you direct/raw access to the control plane, you then may be able to launch denial of service and other attacks that would negatively impact the network and other terminals. I don't know anything about the Starlink protocol, but a rough Ethernet analog might be an ARP attack/flood.
The hacking of Starlink terminals has begun
141–150 of 267 posts
Re: The hacking of Starlink terminals has begun
#142Hacking in the older "using a device in an unexpected/unsupported way," not "black-hat hacking" I guess. Typical over-dramatic Wired. Hats off to this guy, hardware hacks always impress.
Re: The hacking of Starlink terminals has begun
#143Earlier quoted context omitted.
If you root your ISP provided modem, aren’t you one step closer to exploiting some bug in DOCSIS? Similarly here wouldn’t you be one step closer to exploiting the “network itself?” (Air-quotes because I’m not actually sure what that means in this context.)
If you root your Android, are you one step closer to hacking the 5G network?
Re: The hacking of Starlink terminals has begun
#144I see a lot of articles that quote the cost for hacking a product or service. I feel like these type of titles undermine the effort that took place. Surely the lab Wouters used had tools and processes that aren't cheap, nor would you consider his expertise inexpensive. I'm not impressed by a PCB board being cheap. Does anyone else feel this way about similar headlines?
"Twitter hack compromising 5.4 million accounts accomplished using $12 keyboard"
Re: The hacking of Starlink terminals has begun
#145Relevant presentation on DEFCON Media server: https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre... https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre...
[flagged]
This demonstrates that a determined attacker can get access to the software running on their own personal terminal. That's like a determined attacker being able to get access to their own personal router. It sounds like strictly a good thing and with how many satellite internet companies are coming online we will hopefully see some common hardware devices that users have full access to along with some custom firmware that folks can run on them.
This has almost nothing to do with the security of the satellite constellation itself.
Re: The hacking of Starlink terminals has begun
#146Hacking in the older "using a device in an unexpected/unsupported way," not "black-hat hacking" I guess. Typical over-dramatic Wired. Hats off to this guy, hardware hacks always impress.
Complaining about hacking being used correctly on Hacker News? Now I've seen everything.
Re: The hacking of Starlink terminals has begun
#147Earlier quoted context omitted.
Both the client and the satellite use beam forming. The signal is pointed at you in a relatively narrow beam not broadcast spherically. They have to know where you are to point at you (phased array antennas so electronic not physical pointing)
I'm not too familar with the low-level details of the Starlink network, but in the slides of the talk it's shown that the dish contains a GPS receiver, so isn't it possible that the client tells the satellite its location on first contact?
Re: The hacking of Starlink terminals has begun
#148Earlier quoted context omitted.
Isn't the literal name of this website using the same definition, as in tinkering with something?
IIRC this website was born of a novel use of the term 'hacking' in the startup space- hacking business growth. Here, hacking is a more well established term- hacking networking hardware is something I suspect most people would associate with black-hat type hacking.
Re: The hacking of Starlink terminals has begun
#149Earlier quoted context omitted.
Isn't the literal name of this website using the same definition, as in tinkering with something?
True! To my reading, "the hacking of Starlink terminals has begun" is a little bit ominous looking, but maybe the error is on my side.