Live data from Hacker News

The hacking of Starlink terminals has begun

wired.com

31–40 of 267 posts

Re: The hacking of Starlink terminals has begun

#31

It shouldn't count as a vulnerability that you can get root of a device that you have physical possession of. If there's any real vulnerability here, it's that having root of your terminal gives you any extra privileges to the rest of the network.

I have to agree to be fair. Physical access is obviously incredibly different than exploiting a vulnerable even a particularly egregious design flaw. Wouters has to literally short the board.

That said it is a clever approach and it’s good it was discovered by someone without nefarious intentions.

Re: The hacking of Starlink terminals has begun

#32

It shouldn't count as a vulnerability that you can get root of a device that you have physical possession of. If there's any real vulnerability here, it's that having root of your terminal gives you any extra privileges to the rest of the network.

If a system is designed to not allow that access, and you can compromise that design, it is most definitely a vulnerability.

Re: The hacking of Starlink terminals has begun

#33

This reads to me like the (more complicated but ultimately) equivalent of "a user reverse engineers the website's javascript!". As in, this allows the user to mod their client but it doesn't change anything for anyone else, and wasn't meant as a real secure element. I'd assume that getting root access to the user terminal gives them no additional privileges to access the actual Starlink data & control planes.

It might allow them to do things like connect to the Starlink network outside of their geofence. Or hacking a stationary antenna to work on a moving vehicle.

Would this negatively affect the network? My understanding is that it would make your device less reliable. This is simply a warranty voiding event.

Re: The hacking of Starlink terminals has begun

#34

Earlier quoted context omitted.

It might allow them to do things like connect to the Starlink network outside of their geofence. Or hacking a stationary antenna to work on a moving vehicle.

> connect to the Starlink network outside of their geofence I was wondering about that but can't they determine the location "server side" by triangulation? Or maybe they could in theory but they don't in practice?

Knowing the positions of all the clients and satellites is a basic requirement for operating the network.

Re: The hacking of Starlink terminals has begun

#36

The response from Starlink[0] was pretty amazing. I love this quote: "we want to congratulate Lennert Wouters on his security research into the Starlink user terminal – his findings are likely why you're reading this, and help us create the best product possible." A lot better than companies that would try to prosecute him.. [0]: https://api.starlink.com/public-files/StarlinkWelcomesSecuri...

> Wouters revealed the vulnerability to SpaceX in a responsible way through its bug bounty program before publicly presenting on the issue.

Re: The hacking of Starlink terminals has begun

#37

It shouldn't count as a vulnerability that you can get root of a device that you have physical possession of. If there's any real vulnerability here, it's that having root of your terminal gives you any extra privileges to the rest of the network.

I think it should count as a defect that you can't get root of a device that you have physical possession of.

Re: The hacking of Starlink terminals has begun

#39

The response from Starlink[0] was pretty amazing. I love this quote: "we want to congratulate Lennert Wouters on his security research into the Starlink user terminal – his findings are likely why you're reading this, and help us create the best product possible." A lot better than companies that would try to prosecute him.. [0]: https://api.starlink.com/public-files/StarlinkWelcomesSecuri...

Step 1: Why does Google Chrome on KDE/GNU/Linux refuse to allow me to copy text from this PDF??? So f-in annoying!

That PR says: >

Are these "computers" strictly controlled/owned by SpaceX? If yes, are there multiple computers per satellite? Please help me to understand this claim. In 2022, I assume when someone says "computers" they mean kernel count.

Re: The hacking of Starlink terminals has begun

#40

The response from Starlink[0] was pretty amazing. I love this quote: "we want to congratulate Lennert Wouters on his security research into the Starlink user terminal – his findings are likely why you're reading this, and help us create the best product possible." A lot better than companies that would try to prosecute him.. [0]: https://api.starlink.com/public-files/StarlinkWelcomesSecuri...

Step 1: Why does Google Chrome on KDE/GNU/Linux refuse to allow me to copy text from this PDF??? So f-in annoying! That PR says: > Are these "computers" strictly controlled/owned by SpaceX? If yes, are there multiple computers per satellite? Please help me to understand this claim. In 2022, I assume when someone says "computers" they mean kernel count.

It works fine using the pdf viewer builtin to Linux firefox (running on FreeBSD-current).
Post reply on HN