Live data from Hacker News

Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

satcom.sysnet.ucsd.edu

121–130 of 145 posts

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#121
post #111

Earlier quoted context omitted.

When driving by Bad Aibling I always wondered why the BND (intelligence agency) invests so heavily in satellite communication eavesdropping. I naively assumed that this kind of communication would be encrypted. Also a fun fact: For a long time it was only semi-officially known that the BND owned and operated the site. Officially it was called "Long distance telecommunications station of the Bundeswehr" and operated b…

At least since the mid-1990s Echelon revelations in the EU parliament anybody who cares knows that Bad Aibling (and similar stations all across Europe like Bude/Morwenstow in the UK) had been operated by the NSA in collaboration with US Army intelligence (if the official name of “18th United States Army Security Agency Field Station” didn’t clue you in. Officially it has been transferred to the BND; experience sugges…

[dead]

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#122
post #120

Earlier quoted context omitted.

Wait til you hear about how many companies willfully perform all their work in g-suite and office 365/teams

Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…

I believe the point of the above comment is "The trust model already trusts the recipient, so nobody cares that the recipient is seeing query params because they trust the recipient to ignore them."

> who knows if that is true? There's no oversight

The oversight is that those companies rely heavily on being trustworthy, and proving untrustworthy would be disastrous for their business models. Companies don't have to care right now because they have reason to believe Google, MS, et. al. aren't sniffing that data. If they came to believe they were?

Google alone is making $43 billion on Cloud and would prefer not to jeopardize that revenue stream.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#124
post #120

Earlier quoted context omitted.

Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…

I believe the point of the above comment is "The trust model already trusts the recipient, so nobody cares that the recipient is seeing query params because they trust the recipient to ignore them." > who knows if that is true? There's no oversight The oversight is that those companies rely heavily on being trustworthy, and proving untrustworthy would be disastrous for their business models. Companies don't have to c…

> If they came to believe they were?

That's what I don't get - security and compliance people are paranoid.

This is the kind of thing they shouldn't be requiring evidence to care about, given the rest of their job is about the "what-ifs". Just seems crazy to me.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#125

Who needs hackers when companies broadcast their secrets to half the planet?

Intercepting non-obvious (in the sense that you can't just, like, open your wifi menu and see them) broadcasts is still hacking. Heck, even intercepting obvious (in the sense that it says "your data is not secure" on the screen of the people communicating) broadcasts is still hacking. Doing what Firesheep does, before Firesheep, was hacking. And then someone made Firesheep and it was still hacking, but now anyone could do it by clicking a few buttons, without any hacking skill whatsoever, not even using a command line, so it was finally patched.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#126
post #120

Earlier quoted context omitted.

Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…

I believe the point of the above comment is "The trust model already trusts the recipient, so nobody cares that the recipient is seeing query params because they trust the recipient to ignore them." > who knows if that is true? There's no oversight The oversight is that those companies rely heavily on being trustworthy, and proving untrustworthy would be disastrous for their business models. Companies don't have to c…

Facebook for example has been shown in multiple public scandals and lawsuits to be untrustworthy. It is still among the largest social media platforms, and many businesses, for example, reveal large chunks of their marketing strategies to Facebook through its advertising tools.

The reason why this does not result in a significant loss of usage is because trustworthiness-usage is not a linear function or a even a continuous function -- it is a step function. To cause less usage, the loss-of-trust force has to be higher than the networking effect force. Otherwise, behavior does not change.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#127
Ah, this brings back memories of listening to long-distance phone calls using a C-band dish and a general coverage (aka shortwave) receiver. Voice channels were placed on single-sideband channels between roughly DC and 6 MHz, and that whole set of signals was transmitted to the particular satellite transponder just like a video signal would be. The dish receiver couldn't decode that but it had a subcarrier output intended for accessories (stereo decoders maybe?). By plumbing the subcarrier output to the antenna input of the shortwave radio you could dial around to individual voice channels. I could only hear one side of the calls, but it was still very enlightening. I heard a number of mundane conversations, one drug deal, and a woman cursing in ways I'd never heard before. This was pre-internet and I was an impressionable kid - maybe 13 or so. Fun times.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#128
post #40

Earlier quoted context omitted.

Likely no consequences to the decision-makers for data exfiltration or other shenanigans happening, so there's nothing motivating a behavior change. The reason security is so bad everywhere is that nobody gets fired when there's a breach. It's just blamed on the hackers and everyone just goes on with life singing "We take security very seriously--this happened because of someone else!"

Who do you imagine will get fired? The CISO who's been recommending various security imporvements and been trying to get them implemented, but been unable to do so due to a lack of C level interest in IT. Or the C level's who lack interest in IT security until it bites them in the investor? At least here in the EU we're moving toward personal responsibility for C level's who don't take IT and OT security serious in c…

Who currently gets fired due to engineering malpractice? It would be the same thing if there was actual certifications and engineering sign-offs in cybersecurity or other critical areas of development.

I wont pretend that accountability in the physical engineering world is all smiles and rainbows but at least there are actual laws dictating responsibilities, certification and other real consequences for civil engineers. When a Professional Engineer in Canada signs-off (seal) on work they are legally assuming responsibility which means the practitioner could be held accountable in the event of professional misconduct or incompetence regarding the engineering work. There is no reason but corporate greed and corruption why there isn't similar legislation in North America for cybersecurity or software engineering where you have professional bodies certify people to be legally obligated to sign-off on work (and refuse work that isn't up to standards).

But this would require introducing actual legislation which god-forbid how could we do such a thing to the poor market! It would stifle their innovation at leaking everyone's data.

There's no reason we couldn't extend the same existing system of licensure [1] that professional engineers require.

Sure maybe its overkill for someone stringing together a python app, but if you're engineering the handling of any actual personal information then this work ought to be overseen by qualified, licensed and accountable professionals who are backed by actual laws.

[1]https://en.wikipedia.org/w/index.php?title=Regulation_and_li...

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#129
post #120

Earlier quoted context omitted.

Wait til you hear about how many companies willfully perform all their work in g-suite and office 365/teams

Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…

WHEN they get caught and the fine never outweighs the sale price of the data. It's not a coincidence. It's a clear factory in the cost of doing that into business. There's no Moreland ethical backbone here.

Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

#130
post #46
post #12

Earlier quoted context omitted.

> nobody gets fired when there's a breach this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).

If you fire people for stuff they didn’t maliciously introduced you will end up with no people to work with. Imagine jailing doctors for every patient that died you would be out of doctors quite soon.

We don't get delivered to us 18-year-olds that happen to be in perfect health. And a lot of Americans don't believe in wellness visits. Although more and more it's the insurance companies that are practicing medicine. Sorry it's a sore subject with me lol
Post reply on HN