Live data from Hacker News

Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

satcom.sysnet.ucsd.edu

111–120 of 145 posts

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#111
post #34

Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…

When driving by Bad Aibling I always wondered why the BND (intelligence agency) invests so heavily in satellite communication eavesdropping. I naively assumed that this kind of communication would be encrypted.

Also a fun fact: For a long time it was only semi-officially known that the BND owned and operated the site. Officially it was called "Long distance telecommunications station of the Bundeswehr" and operated by the "Federal Office for Telecommunications Statistics"

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#113
post #111
post #34

Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…

When driving by Bad Aibling I always wondered why the BND (intelligence agency) invests so heavily in satellite communication eavesdropping. I naively assumed that this kind of communication would be encrypted. Also a fun fact: For a long time it was only semi-officially known that the BND owned and operated the site. Officially it was called "Long distance telecommunications station of the Bundeswehr" and operated b…

At least since the mid-1990s Echelon revelations in the EU parliament anybody who cares knows that Bad Aibling (and similar stations all across Europe like Bude/Morwenstow in the UK) had been operated by the NSA in collaboration with US Army intelligence (if the official name of “18th United States Army Security Agency Field Station” didn’t clue you in.

Officially it has been transferred to the BND; experience suggests all data from there still goes straight back to Fort Meade… (And in exchange the BND gets some morsels back on people _they_ are not allowed to spy on publicly.)

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#114

As an aside, the PDF metadata says it's generated from LaTeX, but the layout and typesetting looks better than the LaTeX output I'm familiar with. Nicely done.

The body font appears to be Libertinus Serif (and I assume Libertinus Sans is the seldom-used sans font), which I agree look much nicer than the default Computer Modern

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#115
post #67

Earlier quoted context omitted.

If the doctor is criminally negligent they could be jailed.

My sister knows a doctor who botched a surgery due to an argument with a junior who wanted to do some step of the surgery. The senior one was not having it at all and just threw the scalpel directly at him. Nothing happened to him because if we start firing doctors for this, we would be missing out on all the surgeries he did successfully.

> Nothing happened to him

There is a world of difference between "nothing happened" and being fired. Just like in the NBA, a fine (monetary penalty) of a sufficient size will get someone's attention without losing their skills forever.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#116
post #34

Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…

I'm waiting for IT departments worldwide to wake up to the threat that your browsers are leaking all of your URI's by default back to the manufacturers.

URI's leak company secrets. I'm sure there's some people at Google using Edge which are leaking company data to Microsoft. I'm sure there's some people at Microsoft using Chrome which are leaking data to Google.

Edge and Chrome both send back every URI you visit to "improve search results" or to "sync history across devices". It's not clear if this includes private mode traffic or not (they don't say).

Huge privacy hole to allow this, and nobody seems to be aware or care.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#117

Earlier quoted context omitted.

> My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. Why would it? The data originates from earth, and should be encrypted during the uplink leg too, so the crypto should all happen in the ground segment (or even well before it reached anything that could be considered part of the satellite setup, honestly).

Satellites have long lifespans and have to outlast current crypto algorithms. Ideally they're nothing more than radio repeaters that rebroadcast the uplink signal.

Correct. That is what almost all geostationary satellites are. If you want encryption, do it at the application layer.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#118

Earlier quoted context omitted.

> This is insane! Not as insane as it was in the early 2000s… > while link-layer encryption has been standard practice in satellite TV for decades Before Snowden, I would say 99% of ALL TCP traffic I saw on satellites was in unadulterated plain-text. Web and email mostly. … the pipe was so fast, you could only pcap if you had a SCSI hard drive!

I was exposed to some of this as a teenager due to a (now dead) family member being heavily into telecoms. You could receive and process POCSAG (the protocol used by paging systems) to pretty much read the entire stream of unencrypted, plain text pager messages going out over the wire. You could also reprogram a generic pager to receive pages for whatever number you liked. You could also transmit your own POCSAG and…

This is still the case today in the US, plenty of pager systems run POCSAG or near equivalents. There is no conditional access or encryption of any kind. Receiving such signals is notionally criminal, but I'm unaware of any prosecutions for such a thing.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#119
post #116
post #34

Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…

I'm waiting for IT departments worldwide to wake up to the threat that your browsers are leaking all of your URI's by default back to the manufacturers. URI's leak company secrets. I'm sure there's some people at Google using Edge which are leaking company data to Microsoft. I'm sure there's some people at Microsoft using Chrome which are leaking data to Google. Edge and Chrome both send back every URI you visit to "…

Wait til you hear about how many companies willfully perform all their work in g-suite and office 365/teams

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#120
post #116

Earlier quoted context omitted.

I'm waiting for IT departments worldwide to wake up to the threat that your browsers are leaking all of your URI's by default back to the manufacturers. URI's leak company secrets. I'm sure there's some people at Google using Edge which are leaking company data to Microsoft. I'm sure there's some people at Microsoft using Chrome which are leaking data to Google. Edge and Chrome both send back every URI you visit to "…

Wait til you hear about how many companies willfully perform all their work in g-suite and office 365/teams

Indeed. And they are trying to find sneaky ways to get you to back up more and more data there.

They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties? Nobody.

Post reply on HN