Earlier quoted context omitted.
It was only successful because Google said you'd rank higher if you did it.
It was only successful because of Let's Encrypt removing any excuse for not having HTTPS on your website, HSTS becoming a thing, and Chrome moving from gentle inducements (that cute green padlock) to nasty looking warnings if you didn't use encryption.
Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
61–70 of 145 posts
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#62Earlier quoted context omitted.
Why does Space need to decrypt a vast majority of the traffic? Flow can be just as brick not-smart as fiber optic cables under the sea. Now, management, control, etc? Yeah those you need to decode in orbit.
> Flow can be just as brick not-smart as fiber optic cables under the sea Wouldn't this still leak metadata for routing?
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#63As with anything in life, when it's what you know and do on the regular, that simple thing can look like magic to others. I met an old timer in the satellite business that came out to help install our receiver for a new TV channel the company I was at was getting off the ground. He found out what bird we were using and what its slot was. Based on that, he knew how many satellites over from the satellite he knew and u…
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#64Had a vendor offer a customer of mine a huge discount if they purchased radios without the encryption license in the year of our lord 2024. Not even WPA or WEP. Just clear across the sky. And this is terrestrial. My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. But its still incredible to see them pretend like space is impossible to get to, ultimate obscuri…
Encryption is basically free as far as I know, but it is more complex and it must be hard to get software updates up there.
> Panasonic told us that enabling encryption could incur a 20–30% capacity loss. In addition, when using IPsec, ESP and IP headers can introduce 20–30 bytes of overhead, which is nontrivial for small-packet applications like VoIP and video calls
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#65Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…
> Real-time military object telemetry with precise geolocation, identifiers, and live telemetry Oops
Another round of OpSec training
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#66Had a vendor offer a customer of mine a huge discount if they purchased radios without the encryption license in the year of our lord 2024. Not even WPA or WEP. Just clear across the sky. And this is terrestrial. My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. But its still incredible to see them pretend like space is impossible to get to, ultimate obscuri…
>Encryption imposes additional overhead to an already limited bandwidth, decryption hardware may exceed the power budget of remote, off-grid receivers, and satellite terminal vendors can charge additional license fees for enabling link-layer encryption. In addition, encryption makes it harder to troubleshoot network issues and can degrade the reliability of emergency services.
So, the only suggestion that there would be greater heat/energy if they did encryption by default is the part about decryption (receiver) hardware having limited power budgets in some cases. There's more than what I copy-and-pasted above, but the overall message is that lots of organizations haven't wanted to pay the direct costs of enabling encryption... although they should.
EDIT: Link to Q&A https://satcom.sysnet.ucsd.edu/#qanda
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#67Earlier quoted context omitted.
> nobody gets fired when there's a breach this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).
If you fire people for stuff they didn’t maliciously introduced you will end up with no people to work with. Imagine jailing doctors for every patient that died you would be out of doctors quite soon.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#68I wonder why the DOI link on the bottom left of the first page does not work: https://doi.org/10.1145/3719027.3765198
It’s quite common for a DOI to be assigned to a paper after it’s accepted during camera ready. However, the DOI won’t work until the conference or journal version is published on the official website (ACM in this case). The version you’re viewing now is simply a preprint directly from the authors.
>The DOI has not been activated yet.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#69Section 6.3.2 is an eye-opener... good lord... Gets even worse at 6.4.2-3
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#70Some of the stuff that was extracted from the unencrypted traffic in the link: - T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text. - AT&T Mexico cellular backhaul: Raw user internet traffic - TelMex VOIP on satellite backhaul: Plaintext voice calls - U.S. military: SIP traffic exposing ship names - Mexico government and military: Unencrypted intra-government traffic - Walm…
>we re-scanned with their permission and were able to verify a remedy had been deployed: T-Mobile, WalMart, and KPU.
The fact that critical infrastructure (e.g. utility companies using satellite links for remote-operated SCADA) was exposed is really scary too.