Live data from Hacker News

Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

satcom.sysnet.ucsd.edu

51–60 of 145 posts

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#51
post #48

I wonder why the DOI link on the bottom left of the first page does not work: https://doi.org/10.1145/3719027.3765198

It’s quite common for a DOI to be assigned to a paper after it’s accepted during camera ready. However, the DOI won’t work until the conference or journal version is published on the official website (ACM in this case). The version you’re viewing now is simply a preprint directly from the authors.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#52
post #20

Had a vendor offer a customer of mine a huge discount if they purchased radios without the encryption license in the year of our lord 2024. Not even WPA or WEP. Just clear across the sky. And this is terrestrial. My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. But its still incredible to see them pretend like space is impossible to get to, ultimate obscuri…

Why does Space need to decrypt a vast majority of the traffic? Flow can be just as brick not-smart as fiber optic cables under the sea. Now, management, control, etc? Yeah those you need to decode in orbit.

> Flow can be just as brick not-smart as fiber optic cables under the sea

Wouldn't this still leak metadata for routing?

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#53
post #34

Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…

> Real-time military object telemetry with precise geolocation, identifiers, and live telemetry

Oops

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#54

Earlier quoted context omitted.

Yeah that's correct. The study was conducted in San Diego which falls under the satellite beam footprint required for services in Mexico. If you were in say, Alice Springs in Australia (wink wink) for example, you'd be able to see traffic for Indonesia, Philippines, most of South East Asia, and perhaps parts of China, South Korea and Japan if the beams are right.

I'm not so good at hints. Are you gesturing at the NSA facility at Pine Gap?

Yes they are trying to be cheeky, but missing the mark.

Pine Gap is a large facility for collecting data coming down from our own satellites.

Foreign satellite collection in Australia happens at two other facilities: https://en.wikipedia.org/wiki/Shoal_Bay_Receiving_Station https://en.wikipedia.org/wiki/Australian_Defence_Satellite_C...

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#55
post #32

Earlier quoted context omitted.

If someone is browsing the internet on in-flight wifi, and their DNS requests get leaked this way, I don't really think its the casual airline user's fault for not encrypting their DNS traffic. Modern cell phone data traffic (4G/5G) is all encrypted, so the same unencrypted DNS requests can't just be passively sniffed. Something similar should happen here. I'd blame the airline or their ISP provider for sending unenc…

It is the fault of the end user software not protecting them. This is why we have encrypted SNI (promoted by Cloidflare, for example).

I don't know if you've ever tried to actually use in flight wifi, but any traffic not subject to inspection is heavily throttled to the point of being unusable.

ESNI is also a technology in search of a problem. It does not provide any meaningful security benefits.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#56
post #5

> remarkably, nearly all the end-user consumer Internet browsing and app traffic we observed used TLS or QUIC There was a surprising amount of resistance to the push to enable TLS everywhere on the public Internet. I'm glad it was ultimately successful.

> I'm glad it was ultimately successful.

What are you talking about? It was an absolute failure.

As soon as we got widespread TLS adoption, Cloudflare magically came along and wooed all the nerds into handing over all the plaintext traffic to a single company.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#57

Had a vendor offer a customer of mine a huge discount if they purchased radios without the encryption license in the year of our lord 2024. Not even WPA or WEP. Just clear across the sky. And this is terrestrial. My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. But its still incredible to see them pretend like space is impossible to get to, ultimate obscuri…

I mean a bunch of those crypto systems turn out to be flawed though. So skipping the vendor implementation and using something in software instead could make sense.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#58
post #39

Earlier quoted context omitted.

It is almost free on modern CPUs that have hardware acceleration, yea

Space-faring electronics aren't exactly cost-sensitive - the cost of a cluster of crypto-accelerated CPUs or rad-hardened FPGAs is peanuts compared to the human and launch costs that go into these satellites.

Issue is the satellite was launched 10 years ago with 20-year-old tech. So, calculations of today may not be applicable on them.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#59
post #34

Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…

> This is insane!

Not as insane as it was in the early 2000s…

> while link-layer encryption has been standard practice in satellite TV for decades

Before Snowden, I would say 99% of ALL TCP traffic I saw on satellites was in unadulterated plain-text. Web and email mostly.

… the pipe was so fast, you could only pcap if you had a SCSI hard drive!

Post reply on HN