Live data from Hacker News

Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

satcom.sysnet.ucsd.edu

41–50 of 145 posts

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#41
post #32
post #16

I see no issue with the satellite backhaul itself being unencrypted; anyone using the satellite provider should assume they're hostile and encrypt+authenticate everything they send anyway. I don't trust my ISP's fiber to be snoop-resistant just because they nominally have some shitty ONT encryption. Obviously the specific examples of end-users failing to encrypt are bad, but that's not really a problem with the satel…

If someone is browsing the internet on in-flight wifi, and their DNS requests get leaked this way, I don't really think its the casual airline user's fault for not encrypting their DNS traffic. Modern cell phone data traffic (4G/5G) is all encrypted, so the same unencrypted DNS requests can't just be passively sniffed. Something similar should happen here. I'd blame the airline or their ISP provider for sending unenc…

It is the fault of the end user software not protecting them. This is why we have encrypted SNI (promoted by Cloidflare, for example).

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#42

Had a vendor offer a customer of mine a huge discount if they purchased radios without the encryption license in the year of our lord 2024. Not even WPA or WEP. Just clear across the sky. And this is terrestrial. My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. But its still incredible to see them pretend like space is impossible to get to, ultimate obscuri…

Likely no consequences to the decision-makers for data exfiltration or other shenanigans happening, so there's nothing motivating a behavior change. The reason security is so bad everywhere is that nobody gets fired when there's a breach. It's just blamed on the hackers and everyone just goes on with life singing "We take security very seriously--this happened because of someone else!"

That and h1b abuse.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#43
post #14

Earlier quoted context omitted.

End user license agreements are a huge part of the problem. Ideally users could sue if our data is leaked - and the threat of being sued would put pressure on companies to take security more seriously. Ie, it would become a business concern. Instead we're constantly asked to sign one-sided contracts ("EULAs") which forbid us from suing. If a company's incompetence results in my data being leaked on the internet, ther…

There is in at least California, the EU, and China. A lot of clauses in EULAs aren't actually legal.

On the other hand you can't sue a company for losing your data in many EU companies. You can report them to whatever data protection agency your country has, and after an investigation they can fine, and/or, in more serious cases turn the matter over to the police for a criminal investigation.

The disadvantage of this is that the local data protection agencies haven't been handing out very big fines. Sometimes that's due to company law. In my country you'd fine the owning company, which in many cases will be a holding company. Since fine sizes are linked to revenue and a holding company typically has no revenue, this means fines are often ridicilously small.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#44
post #16

I see no issue with the satellite backhaul itself being unencrypted; anyone using the satellite provider should assume they're hostile and encrypt+authenticate everything they send anyway. I don't trust my ISP's fiber to be snoop-resistant just because they nominally have some shitty ONT encryption. Obviously the specific examples of end-users failing to encrypt are bad, but that's not really a problem with the satel…

This. Bytes on every medium can be snooped. Internetworking means that your bytes go on mediums you don't know about and don't control. There's no such thing as a link where encryption is not needed, except localhost.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#45
post #33
post #5

> remarkably, nearly all the end-user consumer Internet browsing and app traffic we observed used TLS or QUIC There was a surprising amount of resistance to the push to enable TLS everywhere on the public Internet. I'm glad it was ultimately successful.

It was only successful because Google said you'd rank higher if you did it.

Which in-turn was driven by the Snowden revelations of what the NSA was doing in terms of mass surveillance.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#46
post #12

Earlier quoted context omitted.

Likely no consequences to the decision-makers for data exfiltration or other shenanigans happening, so there's nothing motivating a behavior change. The reason security is so bad everywhere is that nobody gets fired when there's a breach. It's just blamed on the hackers and everyone just goes on with life singing "We take security very seriously--this happened because of someone else!"

> nobody gets fired when there's a breach this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).

If you fire people for stuff they didn’t maliciously introduced you will end up with no people to work with.

Imagine jailing doctors for every patient that died you would be out of doctors quite soon.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#47

Is it correct to Assuming the amount of Mexican companies in this paper is because of their receiver being in the major city southwestmost corner of the country ?

Yeah that's correct. The study was conducted in San Diego which falls under the satellite beam footprint required for services in Mexico. If you were in say, Alice Springs in Australia (wink wink) for example, you'd be able to see traffic for Indonesia, Philippines, most of South East Asia, and perhaps parts of China, South Korea and Japan if the beams are right.

And if you were in Harrogate, UK (more winks), you’d be in the footprint of satellites servicing Europe.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#49
post #46
post #12

Earlier quoted context omitted.

> nobody gets fired when there's a breach this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).

If you fire people for stuff they didn’t maliciously introduced you will end up with no people to work with. Imagine jailing doctors for every patient that died you would be out of doctors quite soon.

The legal system already has sufficient cop-out: for anything that you should have been aware of, or would have been informed about.

Eg. doctors do get sued and fired for malpractice, if they did something no other skilled doctor would reasonably do ("let's just use the instruments from the previous surgery").

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#50

Does anyone remember the days when you pointed a 60cm antenna at the Hispasat 30W and connected your DVB-S2 tuner in Windows, Using Crazycat's BDADataEx, you tuned an IP data transponder. Using a technique called Satfish (with a software I don't remember), some files were reconstructed, usually vsat data from oil platforms... and porn. I'm going to dust off the TBS DVB-S2X card and try to find a data transponder to t…

[deleted]
Post reply on HN