Live data from Hacker News

The hacking of Starlink terminals has begun

wired.com

11–20 of 267 posts

Re: The hacking of Starlink terminals has begun

#11

Is there any mitigation against these kinds of power/timing attacks? I think the Switch was originally hacked this way.

New hardware revisions are required to fix usually. You can probably detect a compromised terminal on the network though.

Re: The hacking of Starlink terminals has begun

#12
post #6

I see a lot of articles that quote the cost for hacking a product or service. I feel like these type of titles undermine the effort that took place. Surely the lab Wouters used had tools and processes that aren't cheap, nor would you consider his expertise inexpensive. I'm not impressed by a PCB board being cheap. Does anyone else feel this way about similar headlines?

Price is a factor for how accessible the hack is. If it requires an expensive FGPA or a lot of AWS time to crack then that makes it less appealing.

Exactly. For me it's about the replicability of the attack. Is it restricted to government-sized organizations? Or can anybody with the skills do it?

Re: The hacking of Starlink terminals has begun

#13
This reads to me like the (more complicated but ultimately) equivalent of "a user reverse engineers the website's javascript!". As in, this allows the user to mod their client but it doesn't change anything for anyone else, and wasn't meant as a real secure element. I'd assume that getting root access to the user terminal gives them no additional privileges to access the actual Starlink data & control planes.

Re: The hacking of Starlink terminals has begun

#14
post #6

I see a lot of articles that quote the cost for hacking a product or service. I feel like these type of titles undermine the effort that took place. Surely the lab Wouters used had tools and processes that aren't cheap, nor would you consider his expertise inexpensive. I'm not impressed by a PCB board being cheap. Does anyone else feel this way about similar headlines?

Absolutely. This modchip is just a raspberry pi plus a couple parts. You'd have to try hard to get it to be expensive. The BOM for most embedded systems is going to be cheap unless you need some exotic hardware. It really does seem to ignore the amount of time this guy spent to get to figure out what parts he needed and where to solder them. If it was developed by a company instead of an individual, you can bet it wouldn't have cost "only $25 to develop".

Edit: fixed for clarity of thought

Re: The hacking of Starlink terminals has begun

#15
Great response by SpaceX:

https://api.starlink.com/public-files/StarlinkWelcomesSecuri...

“Bring on the bugs”.

This is how you properly engage the security community. In times where journalists are taken to court for looking at a webpage’s HTML source it’s really great seeing a company that “gets it”. Kudos.

Re: The hacking of Starlink terminals has begun

#16
The response from Starlink[0] was pretty amazing. I love this quote: "we want to congratulate Lennert Wouters on his security research into the Starlink user terminal – his findings are likely why you're reading this, and help us create the best product possible."

A lot better than companies that would try to prosecute him..

[0]: https://api.starlink.com/public-files/StarlinkWelcomesSecuri...

Re: The hacking of Starlink terminals has begun

#17

Is there any mitigation against these kinds of power/timing attacks? I think the Switch was originally hacked this way.

I don’t think you can eliminate them, just make them harder to exploit. Require multiple glitches to succeed etc.

Re: The hacking of Starlink terminals has begun

#18
post #6

I see a lot of articles that quote the cost for hacking a product or service. I feel like these type of titles undermine the effort that took place. Surely the lab Wouters used had tools and processes that aren't cheap, nor would you consider his expertise inexpensive. I'm not impressed by a PCB board being cheap. Does anyone else feel this way about similar headlines?

It’s just low grade journalism trying to inflate the impact of the bug.

Conspicuously missing is the cost of the equipment in the lab where he developed the first prototype.

Re: The hacking of Starlink terminals has begun

#19
post #6

I see a lot of articles that quote the cost for hacking a product or service. I feel like these type of titles undermine the effort that took place. Surely the lab Wouters used had tools and processes that aren't cheap, nor would you consider his expertise inexpensive. I'm not impressed by a PCB board being cheap. Does anyone else feel this way about similar headlines?

I think it's useful to differentiate between attacks anyone can do with common hardware and things like smartcard attacks that you can only do with access to an electron microscope.
Post reply on HN