Dumping and extracting the SpaceX Starlink user terminal firmware
esat.kuleuven.be
esat.kuleuven.be
Tesla responded by disabling the car's ethernet port, downgrading the firmware, and preventing the car from receiving future upgrades to software.
There is this ex-employee, telling some interesting stories. And regarding the downgrade... he was the one who did it for reasons he explains. I want to see if you are talking about different case or what.
> Question: There's the story online of that hacker who was pulling software images off through the door Ethernet port and found that his car's firmware was remotely downgraded after he uncovered and posted the first references to the P100 models.
> Answer: yup, i'm the guy that installed the older versions. this was a marketing mistake really. if i recall correctly, he ended up getting a marketing car or his car got tagged in the update system as a trusted car and he ended up getting pre-release stuff. this happened from time to time - sometimes marketing would sell off a car and the poo poo erp system wouldn't record the change. that car would then get prerelease and sometimes very broken firmware. i seem to recall another case where we just forgot to remove the prerelease materials from the official build, so all you had to do was look around.
https://forums.somethingawful.com/showthread.php?threadid=38...
one big reason why i'm not particularly thrilled at the prospect of one day owning a car that is actively managed/controllable by the manufacturer.
in the days of the audi 5000 sudden acceleration syndrome, they could take a production car and study it.
how would a third party/government agency trustlessly investigate "brake lose control" when the manufacturer has root and remote access on the vehicle?
Ditto.
So many examples of companies shoving half-baked software updates down our throats... and worse... companies with half-baked security that are compromised with no consequences/little liability and effect the consumer.
Is this not already the case?
a) a specific set of source code was used to generate the logs... so cryptographic security from source text files through compilation to execution on the hardware.
b) that specific set of software was run on a specific machine at a specific time.
it's hard... but beyond that, pretty much all audit logs are just security theater anyhow. sometimes can be mitigated by sending them to multiple places, but they're still meaningless unless you have a proof of what exactly generated them.
Volkswagen tampered with regulated measurements and got away with it for a while. But it was discovered and they paid a huge price for it.
With that precedent, it should create incentive to deal with mistakes transparently.
It does also mean transportation authorities will need to create some amount of leeway for mistakes. But I think there has been plenty of that given to traditional auto manufacturers.
1) unassured/untrusted digital evidence that can be fabricated to say anything, leaving no trace of its previous state. (unless digital forensics has advanced well beyond what i know to be possible)
2) personal testimony that can also be fabricated.
i suppose what's new here is that in a digital world, bits can be set however one likes with no trace of their previous state, where physical evidence left behind physical manifestations of itself.
imagine rootkits that seek not to steal or hide their existence, but rather exist to plant fabricated evidence or hide actual evidence. in today's untrusted computer systems, this is all possible, and terrifying.
The first smashing can be felt more than heard, a subsonic strike something like a vast drumhead being struck with a metre-wide mallet, but so quick, you barely even notice it until it’s over. The second one, however, isn’t far behind, and it’s a bit louder. That second thump gives away its location — whatever it was seems to be happening quite close by — in the direction of the parking structure.
At just this moment a car cruises through the pick-up zone at full speed, barreling along at least 100 kmh. It’s only because of some very fast reactions that no one gets hurt as it passes by. As it zooms past, you notice there’s no one behind the wheel.
Before you have any time to process that, another huge thump nearby causes a section of the barrier wall of an upper floor of the concrete parking structure to shear off. A pile of rubble falls to the ground not very far away from you.
-- Mark Pesce, Oct 2015, https://medium.com/@mpesce/the-great-hack-part-one-attack-70...
(AI-controlled cars feature prominently as weapons.)
(Incidentally, I applaud the top comment at [0]. Everyone involved in recklessly demonstrating the hack on public roads, should have faced serious consequences. As far as I can tell though, nothing came from the police report.)
It's only if you aren't logged in to an account that word filters are applied (and some other things e.g. there are a bunch of subforums not visible to outsiders).
https://www.vrt.be/vrtnws/nl/2020/11/22/onderzoekers-ku-leuv...
https://electrek.co/2019/01/29/tesla-sales-ban-sweden-over-s...
Do you have more information on this? The way you describe sounds like it's targeted at aftermarket mods more than software updates.
Obviously different case, but I think the same principle applies here. A software update that significantly changes the performance characteristics should be recertified and not grandfathered in.
sounds like a win-win
Most likely these are testing locations. Possibly even second homes of testers & engineers. After all, this is a product that has very different operating parameters depending on location.
I wonder if that's what he's alluding to. I don't see an explicit connection to SpaceX, but it seems to fit.
Launches have all been shutdown for COVID reasons, and even before that, not infrequently cancelled due to fire risk.
Perhaps earlier revisions of this used raw NAND? Either that, or somebody got overzealous without thinking through.
It seems like a fair bit of effort for a device like this - I wonder if the same u-boot codebase is used on devices in space which have higher reliability requirements.
They probably aren't doing it, but you could always interleave the data across the emmc blocks. A lost emmc block would therefore corrupt single-digit bytes across many ECC'ed blocks, rather than many bytes within a couple ECC'd blocks. 32 bytes of Reed Solomon should be able to correct up to 16 bytes of corruption. CDs do the same trick to be robust to scratches.
> While we would have to perform some more tests it appears that a full trusted boot chain (TF-A) is implemented from the early stage ROM bootloader all the way down to the Linux operating system.
This unfortunately means it will likely be somewhat difficult (or infeasible) to reflash it with a custom firmware that uses actual GPS location for targeting of satellites but reports a couple km offset to the telemetry service APIs to keep my residence address somewhat private from my ISP.
It's a bummer they didn't share the dumps. It always bothers me when researchers act all coy about their results. Now I have to get my hands on a dish myself and do what they didn't (namely, actually publish the data).
33-9207N-118-3278W.clients.starlink.com
http://wiki.gis.com/wiki/index.php/Decimal_degrees
If it's DMS, again assuming location is correct, ignoring spheroid vs sphere: something between 80 and 100 ft (24.4 - 30.48 meters).
https://www.usgs.gov/faqs/how-much-distance-does-a-degree-mi...
Science in some countries enjoys copyright exemptions for doing research, but not for publishing raw data obtained from commercial sources.
To answer your question directly, no, they have the service address. But with no other data to link the service address to me, this is okay.
With starlink I am hoping to upgrade the privacy setup to +/-2km location fuzziness. I don't think I'll ever use an ISP without 100% of the last mile traffic being VPN'd ever again.
You can also sign up for a "business prepaid" account and they won't even ask for your name. They also don't ask what type of entity the business is, so there's nothing wrong with just making up a Doing Business As off the top of your head.
Frankly, this is how it ought to be. My personal data are none of their business.
It's the same concept as ubering to the house two houses down and across the street. Close enough for rock'n'roll.
It's also possible I'm totally wrong and this would break connectivity—but I doubt it.
Laundering the money through FCC RDOF was a stroke of genius; I tip my hat to whoever came up with that idea.
I don't understand why people are so committed to assuming there's a nefarious "real motivation" behind Starlink. Global telecomms is on the order of $2 trillion in revenue per year and growing. The US military's GPS budget is about $1.5 billion. So we're talking about addressable markets 3 orders of magnitude different in size.
https://www.mentalfloss.com/article/75874/us-navy-returns-te...
I wouldn't be surprised if SpaceX tracks starlink satellite orbits via GPS, so that may limit their use as a redundant GPS system.
Now I'm curious what their command and control links look like. It's possible and perhaps likely that they can only communicate with any given satellite intermittently, as they fly overhead of ground stations.
Though sure, you could make the purchase using a pre-paid card under a fake identity so they can't associate the address with a person. At least not through their own records. House deeds are public record, so if you own the house, they can figure out who you are by making a public records request, which is generally one way refi spammers find you.
Plus, depending on where you are, the government itself might sell your name and address to third parties. I know Texas does this, which is why I put getting a Texas ID for such a long time and continued using California ID until Texas last year decided you can't vote with an out-of-state ID. So now the DMV is selling my identity and I'm getting a lot more spam.
Agreed. Even if I had a dish (waitlist) the odds of me being able to disassemble and reassemble it with my electronics butterfingers is near 0. I would really love to pick apart the firmware though. I've done similar work on firmware disassembly to find ways into devices.
I haven't seen products that use geofences to verify debug flags. Would it be possible to spoof this using a fake GPS e.g. with SDR?
Of course putting your satellite antenna inside of a RF chamber also prevents it from working, so this may not be a viable long term strategy. Plus the terminal is undoubtedly using the GPS coordinates to calculate the antenna steering profile so you won't be able to lock on if your GPS is wrong. But since all they want to do is enable access to dump the firmware this probably isn't an issue.
An interesting question, however, is whether Starlink checks whether the satellite you're tuned to is plausible given the GPS coordinates ...
1: Find the GPS module, and look up its data sheet.
2: Spoof the data coming out of its IO ports. Cheap GNSS modules that spit out NMEA messages on a serial line are everywhere. (I guess because they're super cheap, and easy to integrate)
Might not be as trivial as that makes it sound:
"Continuing through the boot process we can see that U-Boot loads a kernel, ramdisk and Flattened Device Tree (FDT) from a Flattened uImage Tree (FIT) image that is stored on an embedded MultiMediaCard (eMMC).
We can also see that the integrity (SHA256) and authenticity (RSA 2048) of the kernel, ramdisk and FDT is being checked. While we would have to perform some more tests it appears that a full trusted boot chain (TF-A) is implemented from the early stage ROM bootloader all the way down to the Linux operating system."
Desoldering a SOC and replacing it with something similar enough but different in its trusted boot config is somewhat less trivial than "manipulate the firmware" though, at least in my opinion...
Also, now that they have the image, they could try to override the geofence/fuse protections by running it on an SoC without the fuse blown, and a SDR-based GPS spoofer. Seems like a fun endeavor.
It’s a custom SoC. They can’t just buy one off the shelf.
Satellite provider firmware images are a nice target. SpaceX is not the only one. I also inspected some.
I guess the Starlink dish's ~1200 antennas is way way closer to a fighter jet radar than it is to a six antenna Netlink wifi base station...
From the article:
"... it appears that a full trusted boot chain (TF-A) is implemented from the early stage ROM bootloader all the way down to the Linux operating system."
> the GPL 2 doesn't have anything that would prevent Tivoization.
From the GPLv2:
"... plus the scripts used to control compilation and installation of the executable."
https://www.gnu.org/licenses/old-licenses/gpl-2.0.html
From the Software Freedom Conservancy blog post about the GPLv2 installation requirements:
"GPLv2 assures, to the purchaser of an embedded product, their absolute right to receive the information necessary to install a modified version of the GPLv2'd works."
https://sfconservancy.org/blog/2021/mar/25/install-gplv2/Fro...
Of course, that doesn't mean that the proprietary software must continue to function after modifying the GPL software, apparently even the GPLv3 allows what Tivo did. From a presentation about GPLv3 on cars:
"Ironically, even if Linux were GPLv3, Tivo’s method of crypto- lock-down would likely comply with GPLv3."
https://events19.linuxfoundation.org/wp-content/uploads/2017...
IIRC the issue with GPL and iOS was that the GPL was/is incompatible with the App Store ToS.