I see no issue with the satellite backhaul itself being unencrypted; anyone using the satellite provider should assume they're hostile and encrypt+authenticate everything they send anyway. I don't trust my ISP's fiber to be snoop-resistant just because they nominally have some shitty ONT encryption. Obviously the specific examples of end-users failing to encrypt are bad, but that's not really a problem with the satel…
If someone is browsing the internet on in-flight wifi, and their DNS requests get leaked this way, I don't really think its the casual airline user's fault for not encrypting their DNS traffic. Modern cell phone data traffic (4G/5G) is all encrypted, so the same unencrypted DNS requests can't just be passively sniffed. Something similar should happen here. I'd blame the airline or their ISP provider for sending unenc…
Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
41–50 of 145 posts
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#42Had a vendor offer a customer of mine a huge discount if they purchased radios without the encryption license in the year of our lord 2024. Not even WPA or WEP. Just clear across the sky. And this is terrestrial. My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. But its still incredible to see them pretend like space is impossible to get to, ultimate obscuri…
Likely no consequences to the decision-makers for data exfiltration or other shenanigans happening, so there's nothing motivating a behavior change. The reason security is so bad everywhere is that nobody gets fired when there's a breach. It's just blamed on the hackers and everyone just goes on with life singing "We take security very seriously--this happened because of someone else!"
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#43Earlier quoted context omitted.
End user license agreements are a huge part of the problem. Ideally users could sue if our data is leaked - and the threat of being sued would put pressure on companies to take security more seriously. Ie, it would become a business concern. Instead we're constantly asked to sign one-sided contracts ("EULAs") which forbid us from suing. If a company's incompetence results in my data being leaked on the internet, ther…
There is in at least California, the EU, and China. A lot of clauses in EULAs aren't actually legal.
The disadvantage of this is that the local data protection agencies haven't been handing out very big fines. Sometimes that's due to company law. In my country you'd fine the owning company, which in many cases will be a holding company. Since fine sizes are linked to revenue and a holding company typically has no revenue, this means fines are often ridicilously small.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#44I see no issue with the satellite backhaul itself being unencrypted; anyone using the satellite provider should assume they're hostile and encrypt+authenticate everything they send anyway. I don't trust my ISP's fiber to be snoop-resistant just because they nominally have some shitty ONT encryption. Obviously the specific examples of end-users failing to encrypt are bad, but that's not really a problem with the satel…
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#45> remarkably, nearly all the end-user consumer Internet browsing and app traffic we observed used TLS or QUIC There was a surprising amount of resistance to the push to enable TLS everywhere on the public Internet. I'm glad it was ultimately successful.
It was only successful because Google said you'd rank higher if you did it.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#46Earlier quoted context omitted.
Likely no consequences to the decision-makers for data exfiltration or other shenanigans happening, so there's nothing motivating a behavior change. The reason security is so bad everywhere is that nobody gets fired when there's a breach. It's just blamed on the hackers and everyone just goes on with life singing "We take security very seriously--this happened because of someone else!"
> nobody gets fired when there's a breach this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).
Imagine jailing doctors for every patient that died you would be out of doctors quite soon.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#47Is it correct to Assuming the amount of Mexican companies in this paper is because of their receiver being in the major city southwestmost corner of the country ?
Yeah that's correct. The study was conducted in San Diego which falls under the satellite beam footprint required for services in Mexico. If you were in say, Alice Springs in Australia (wink wink) for example, you'd be able to see traffic for Indonesia, Philippines, most of South East Asia, and perhaps parts of China, South Korea and Japan if the beams are right.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#48Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#49Earlier quoted context omitted.
> nobody gets fired when there's a breach this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).
If you fire people for stuff they didn’t maliciously introduced you will end up with no people to work with. Imagine jailing doctors for every patient that died you would be out of doctors quite soon.
Eg. doctors do get sued and fired for malpractice, if they did something no other skilled doctor would reasonably do ("let's just use the instruments from the previous surgery").
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#50Does anyone remember the days when you pointed a 60cm antenna at the Hispasat 30W and connected your DVB-S2 tuner in Windows, Using Crazycat's BDADataEx, you tuned an IP data transponder. Using a technique called Satfish (with a software I don't remember), some files were reconstructed, usually vsat data from oil platforms... and porn. I'm going to dust off the TBS DVB-S2X card and try to find a data transponder to t…