Live data from Hacker News

The hacking of Starlink terminals has begun

wired.com

201–210 of 267 posts

Re: The hacking of Starlink terminals has begun

#201

This WIRED article[1] references a release of tools and information about the research on GitHub[2] however it 404s. Hope that is not being censored. [1] https://www.wired.com/story/starlink-internet-dish-hack/ [2] https://github.com/KULeuven-COSIC/Starlink-FI

DEF CON goon here. Sometimes our presenters provide the link to a private GitHub repo to the press in advance of their presentation. After the presentation they make the repo public.

:-)

Might be better to encourage placeholder repository to avoid concerns from the public such as this but as long as the presenter ultimately controls the namespace it is not really at issue.

Re: The hacking of Starlink terminals has begun

#202

Eh low threat hack. Requires physical access to dish and installs piece of easily identifiable hardware. Tbh give unfettered access to most hardware and you can hack it.

The terminal is used to contact the constellation as well as Starlink's backend servers.

If the remote machines have the assumption of trustworthy terminals baked in, then this isn't a low threat hack.

Re: The hacking of Starlink terminals has begun

#203
post #196

Earlier quoted context omitted.

Using this table for reference and the fact that proper smartcards like banking cards and SIM cards are secure I'm pretty confident calling modern CA systems secure too. If some providers don't have one of those, then it's probably because it's not worth it for them to switch or upgrade. https://en.wikipedia.org/wiki/Conditional_access#Digital_sys... EDIT: More than that, some recent ones even solved so called 'card…

I'm not saying the modern CAMs have been compromised, just saying the profit incentive has dwindled. For a while, entirely non-OEM receivers were being used with key distribution over the internet. But at that point, just get a black market IPTV subscription. Compromising the cards has a fraction of the value it used to, and there's more 'locked down' targets in other devices to focus one's skills at.

Handwave all you want, but the topic at hand is a possibility of securing devices against physical access attacks. And it's not only possible, it's pretty straightforward if you don't suffer from NIH syndrome.

And as an example satellite TV providers did it (or acquired a license for it). If you're saying that incentives to hack them aren't there anymore, then that's just wrong because the foundation on which such security is based on affects many things.

Declining popularity of SatTV as a whole in a particular country is neither here, nor there. If a hacker mentioned in the article could hack a CA system, he would've.

Re: The hacking of Starlink terminals has begun

#204

Eh low threat hack. Requires physical access to dish and installs piece of easily identifiable hardware. Tbh give unfettered access to most hardware and you can hack it.

The value of this attack isn't breaking into the terminal itself, but that it allows the end user to modify the control channel to the satellite. It allows internal inspection of the protocols, authentication, data formats, etc between the terminal and the satellite itself.

I assume that the actual received and transmitted packets from the terminal are encrypted so "outside in" inspection is very very difficult.

Re: The hacking of Starlink terminals has begun

#205

I wonder when the first hacker will hack a satelite, fire it's retro-rockets to make it crash and cause the Kessler Syndrome, intentionally or not https://en.wikipedia.org/wiki/Kessler_syndrome Of course that could also happen with random bugs and no hacking I guess?

Hackers damaged/destroyed the ROSAT satellite in the late 90s

https://en.wikipedia.org/wiki/ROSAT#End_of_operations

Re: The hacking of Starlink terminals has begun

#206

Earlier quoted context omitted.

> connect to the Starlink network outside of their geofence I was wondering about that but can't they determine the location "server side" by triangulation? Or maybe they could in theory but they don't in practice?

Knowing the positions of all the clients and satellites is a basic requirement for operating the network.

[deleted]

Re: The hacking of Starlink terminals has begun

#208

Earlier quoted context omitted.

I'm not too familar with the low-level details of the Starlink network, but in the slides of the talk it's shown that the dish contains a GPS receiver, so isn't it possible that the client tells the satellite its location on first contact?

If you trick the satellite into thinking you're somewhere you're not, then it won't point the beam at you and you won't get any service.

How accurate does the location have to be in terms of radius? A few centimeters? A few meters?

Re: The hacking of Starlink terminals has begun

#209

Earlier quoted context omitted.

If you trick the satellite into thinking you're somewhere you're not, then it won't point the beam at you and you won't get any service.

How accurate does the location have to be in terms of radius? A few centimeters? A few meters?

If you trick it into thinking you're a few metres away from your true location then you're not evading any geofence that you couldn't trivially evade simply by moving a few metres.

Re: The hacking of Starlink terminals has begun

#210

Earlier quoted context omitted.

What are you on about. This has nothing to do with the satellites, not can this hardware mod ever be used to affects the hardware in orbit.

That's not necessarily true. Hacking the ground station means in all likelihood getting access to low level protocols between the ground station and satellite, which potentially means getting the ability to affect the satellites. Not a sure thing, but if I wanted to attack a StarLink satellite, this would be a solid first step in doing so.

The researcher mentions that in the article.
Post reply on HN