Live data from Hacker News

Decoding Data from Iridium Satellites

rtl-sdr.com

21–30 of 52 posts

Re: Decoding Data from Iridium Satellites

#21

The doppler shift described at ~14:45 was a really interesting component of Iridium that I recall when I learned about it many years ago. These guys are great, this was an enjoyable presentation.

The doppler shfit also supposedly provided a clue about the whereabouts of MH370 after it disappeared: https://theaviationist.com/2014/03/27/inmarsat-helps-finding...

To be fair, that wasn't Iridium, that was INMARSAT. Completely different company with a very different satellite system.

Re: Decoding Data from Iridium Satellites

#22

It's not surprising considering age of Iridium. Also I believe they don't make lot of money, so any development (also security related) is pretty much ceased.

Iridium is basically only still in business because of US armed forces (and maybe diplomatic services? though not sure how much field work they do..) operational dependencies. Editorial retraction, mea culpa: Wrong about the TACSAT statement here. See parent below for the http://www.airspacemag.com/space/the-rise-and-fall-and-rise-... Post chapter-11 (2000), investors got the whole Iridium infrastructure at sub-penni…

Well, the dude is german, so he isn't in US jurisdiction so he's probably less concerned about it. Still jeopardizing his personal security for sure, and probably going to make it difficult to travel internationally.

Re: Decoding Data from Iridium Satellites

#23
post #4

> Later in the presentation he shows some interesting examples such as an intercepted Iridium satellte phone call to a C-37 aircraft. So Iridium has been cracked, and no reactions so far? Am I missing something? This sounds like a Big Deal.

No. As with other satellite phones, security/encryption is an additional feature that you buy. For everyone else, there's no security/encryption - you just need to implement the system and protocols to tap into it - which is what has been done here. (And for the parts that have encryption, it's the data that's encrypted, while metadata (e.g. call setup) is still plain text)

Also ... correct me if I misremember ... but I think it is the case that with Iridium - encryption or no encryption - Eve can discern your physical location and get GPS coordinates for you.

Am I remembering that correctly ? I believe that got some journalists killed in Syria a few years ago ...

Re: Decoding Data from Iridium Satellites

#24
post #23
post #4

Earlier quoted context omitted.

No. As with other satellite phones, security/encryption is an additional feature that you buy. For everyone else, there's no security/encryption - you just need to implement the system and protocols to tap into it - which is what has been done here. (And for the parts that have encryption, it's the data that's encrypted, while metadata (e.g. call setup) is still plain text)

Also ... correct me if I misremember ... but I think it is the case that with Iridium - encryption or no encryption - Eve can discern your physical location and get GPS coordinates for you. Am I remembering that correctly ? I believe that got some journalists killed in Syria a few years ago ...

I remember hearing that as well, although I can't find a citation.

Re: Decoding Data from Iridium Satellites

#25
post #6

> Later in the presentation he shows some interesting examples such as an intercepted Iridium satellte phone call to a C-37 aircraft. So Iridium has been cracked, and no reactions so far? Am I missing something? This sounds like a Big Deal.

It sort of like how US drones used to broadcast video unencrypted. They didn't bother since they thought the barrier to entry for seeing the feed was too high, until it wasn't. https://www.wired.com/2012/10/hack-proof-drone/

Nobody seems to have learned a thing since the phreakers poked and prodded the phone network...

Re: Decoding Data from Iridium Satellites

#26

Earlier quoted context omitted.

Iridium is basically only still in business because of US armed forces (and maybe diplomatic services? though not sure how much field work they do..) operational dependencies. Editorial retraction, mea culpa: Wrong about the TACSAT statement here. See parent below for the http://www.airspacemag.com/space/the-rise-and-fall-and-rise-... Post chapter-11 (2000), investors got the whole Iridium infrastructure at sub-penni…

INMARSAT is a different system entirely. Iridium uses a relatively massive constellation (77 birds, plus or minus) of Low Earth Orbit (LEO) satellites. Inmarsat runs a handful of Geosynchronous (GEO) satellites. Iridium has some advantages. It has coverage at the poles, where GEO sats typically do not. The mobile units can be small(ish) and handheld. But it also has some significant limitations. Datarates are in the…

> Iridium has some advantages. It has coverage at the poles, where GEO sats typically do not. The mobile units can be small(ish) and handheld. But it also has some significant limitations. Datarates are in the 2400bps range. Latency goes all over the place due to the way the calls get routed through the constellation. Dropped calls are common.

I seem to recall the south pole base use multiple iridium phones in a aggregation setup as a backup data channel.

Re: Decoding Data from Iridium Satellites

#27

> Later in the presentation he shows some interesting examples such as an intercepted Iridium satellte phone call to a C-37 aircraft. So Iridium has been cracked, and no reactions so far? Am I missing something? This sounds like a Big Deal.

There was nothing to crack, the only security is in the availability of easy-to-use receivers. Assume that any intelligence agency in the world has an archive of Iridium transmissions going many years back.

Was there not some talk about how Taliban or some such used open sat coms, and still "we" were unable to find them?

Re: Decoding Data from Iridium Satellites

#28
post #12

Earlier quoted context omitted.

Iridium is basically only still in business because of US armed forces (and maybe diplomatic services? though not sure how much field work they do..) operational dependencies. Editorial retraction, mea culpa: Wrong about the TACSAT statement here. See parent below for the http://www.airspacemag.com/space/the-rise-and-fall-and-rise-... Post chapter-11 (2000), investors got the whole Iridium infrastructure at sub-penni…

SSSS is meaningless, never heard of anyone that had meaningful issues as a result of having this flag. What is SSSS? See the Wikipedia page: https://en.m.wikipedia.org/wiki/Secondary_Security_Screening...

Here is an anecdote for you. I was once held up at gunpoint on a business trip and my wallet was taken (gotta love Orlando, FL).

I went to the airport 3 hours early with no identification and told them the situation. They still printed my boarding pass and put SSSS on it. I went to the huge long line and I went around it entirely and went into the secondary screening room. They did a full patdown and entirely emptied my carry-on. It was no big deal and was done in 20 minutes, less time than I'd have stood in line. After that I boarded the plane and went home.

I've sometimes contemplated putting SSSS on my boarding pass with a red sharpie when there is a very long line just to get around it entirely.

Re: Decoding Data from Iridium Satellites

#29
post #18

It's not surprising considering age of Iridium. Also I believe they don't make lot of money, so any development (also security related) is pretty much ceased.

They're already produced and will start soon launching Iridium NEXT [1] satellites, moreover developed a whole platform called Iridium Prime [2]. [1] https://www.iridium.com/network/iridiumnext [2] https://www.iridium.com/company/industryleadership/iridiumpr...

It would be pretty nice if they partnered up with someone like Verizon and offered service in places where there is no regular 2G/3G service, your phone would need to have a chip for it I suppose.

Re: Decoding Data from Iridium Satellites

#30
post #17

Earlier quoted context omitted.

I was just thinking about how aggravating it must be from the POV of someone who used to fly a lot. If I was still flying twice a week consulting I'd be livid. If I was perma-SSSS'd. I'm sure he's under far more vigilant security scrutinization--I mean even pre-9/11 DEFCON had 'spot the fed' games as a lark because they were so obvious. Most of the major conferences I'm sure have attendees listed (not a new practice…

Have you ever flown with an SSSS, if so, how did it cause any issues? If not, at best your response is speculative. My experience is that those with SSSS get through TSA screening faster and given they expect the search, don't have anything worth searching. Clearly if you have an SSSS and create problems or provide surface for friction, then sure it's a pain, but then again, with or without an SSSS there's the potent…

I have (and upvoted your previous comments) see my anecdote in your previous comment.
Post reply on HN