The hacking of Starlink terminals has begun
wired.com
wired.com
https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre...
https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20pre...
If the remote machines have the assumption of trustworthy terminals baked in, then this isn't a low threat hack.
Given the general competence level of the engineering at SpaceX, I would not put any money on this being true.
Maybe if the system were designed by Sony...
They really don't want you to root your PlayStation, but that's mostly because it allows you to hack offline games. Hacked consoles are usually banned pretty quickly from online services.
It doesn't mean Sony has the best track record when it comes to security just that they are not completely clueless.
Another time as a team building activity, we were using mission control and backup mission control to play a multiplayer space ship bridge simulator game. My team was winning, up until our terminals started failing. Someone on the other team had credentials to the IT system, and was remotely rebooting them.
(That said I'd be pissed)
They fixed that with the newer batteries as I recall but was a pretty big hole at release
"We will happily ship a Starlink kit to any customer that purchases one. With Starlink kits all over the world, we don't have much control over what users do to them. History shows us that it's hard (and maybe impossible) to make devices completely resilient to persistent attackers with unrestricted physical access – the attacker just has too much power when they have infinite time to modify the hardware. In the limit they could always just build their own user device from scratch, though we know from experience that it's pretty hard to do so. Ultimately, the only way for us to build a secure system is to assume that attackers will eventually get into the Starlink kit, and add additional layers of defense-in-depth to protect our network and the other users within it. Other parts of the Starlink network, like satellites, might be more difficult for a consumer to get their hands on, but similarly are built with layers of defense. To provide these additional layers of protection, there are a number of security properties that we believe are important both in the Starlink kit and in the rest of the system"
From https://api.starlink.com/public-files/StarlinkWelcomesSecuri...
I assume that the actual received and transmitted packets from the terminal are encrypted so "outside in" inspection is very very difficult.
This hack just gives the user access to what they should always have had access to.
[1] https://www.wired.com/story/starlink-internet-dish-hack/
Might be better to encourage placeholder repository to avoid concerns from the public such as this but as long as the presenter ultimately controls the namespace it is not really at issue.
Not only are they one of their largest customers, they have physical control over the place where Microsoft and GitHub staff live and work.
From README
> We are not providing exact glitch parameters. The presentation slides contain various hints and the parameters will vary depending on how you patch the firmware.
Some may see this as capitulation towards Starlink business interests but a more benign reason could involve the glitch parameters varying based on various hardware factors and as stated the execution of firmware as well.
> As is typically the case with any technology, the increase in use and deployment of Starlink and other satellite constellations also means that threat actors have a greater interest in finding their security holes to attack them.
> Indeed, Russia saw an advantage in taking out a satellite providing internet communications across Europe by attacking its technology on the ground as Russian troops entered Ukraine on Feb. 24.
Viasat orbits at 22,000 miles, Starlink is in LEO. Precisely for this reason Starlink is naturally more resistant to jamming, and is used in Ukraine because of this.
Locally compromising a UT is a hack of an endpoint connection device, which has nothing to do with ELINT and electronic warfare activities (which is an entirely different kind of attacks for satellite networks).
In the case of Viasat they had access to a badly configured VPN appliance and used it to deploy on the terminals. Which is a classical case of network compromise, not a direct hack of the user devices.
Also considering this aspect the comparison is not there: it's a local access to the hardware vs an "I own your infrastructure and I'm able to deploy my firmware".
Yes, performing this reverse engineering requires physical access. But it potentially enables one to find further vulnerabilities and systems knowledge necessary to build attacks that brick network terminals or otherwise disrupt the network. Russia's action proves these attacks are viable and useful (even if an authenticated management vector was used).
Your original comment about the constellation height was a non-sequitur: we're talking about threat actors' attacks on end-user terminals. The article makes clear ("on the ground") that this is what it was referring to.
Yes, jamming, etc, are also useful attacks that threat actors use but not what we're talking about.
For example you could modify the terminal to transmit at the exact time another user is supposed to be transmitting, therefore clobbering their data and DoS-ing them.
The transmission schedule of exactly which user should be transmitting in which slots is probably transmitted with a single encryption key the terminal has access to.
https://www.viasat.com/about/newsroom/blog/ka-sat-network-cy...
There's no reason that Starlink is any less susceptable to that. The attackers got into a terminal management network and issued various commands to shut down the endpoints. There's no reason an LEO constellation is more or less susceptible to this type of attack than a GEO system.
This is a bit misleading. The article mentions the Viasat hack in the next-to-last paragraph of the article before the update in the context of satellite security more broadly:
> "As an increasing amount of satellites are launched—Amazon, OneWeb, Boeing, Telesat, and SpaceX are creating their own constellations—their security will come under greater scrutiny. In addition to providing homes with internet connections, the systems can also help to get ships online, and play a role in critical infrastructure. Malicious hackers have already shown that satellite internet systems are a target. As Russian troops invaded Ukraine, alleged Russian military hackers targeted the Via-Sat satellite system, deploying wiper malware that bricked people’s routers and knocked them offline. Around 30,000 internet connections in Europe were disrupted, including more than 5,000 wind turbines."
Orbit height is incredibly and completely irrelevant to the ease of breaking into systems...
Essentially these chips are locked by setting certain flags in memory. Various flags control various peripherals, including a flag to disable read/write access to the firmware. Obviously once you disable access, it’s permanent because you don’t have access to reenable it.
This side channel attack takes advantage of a flaw in the actual silicon, where branches can be skipped if the power is altered momentarily. So if you skip that first check, the attacker has low level firmware control.
(This was also how the firmware was dumped on the Apple AirTags)
The only mitigation is to use a chip that doesn’t suffer from this flaw or change the software to prevent “root” access even if an adversary has access to the entire firmware (ie do things server side)
The problem with mitigations is that they are just speed bumps.
Of course, the challenge there is that you've merely eliminated one glitching candidate.
Stuxnet had code blocks that encrypted by a hash of target hardware identifiers. No way to know what all code is contained, until it happens to run on the target system.
https://blog.quarkslab.com/bradley-hash-and-decrypt-gauss-a-...
Under voltage fault injection - "In general, single instruction skips are easily achievable, though skips of multiple nearby instructions are more difficult to induce and control."
https://research.nccgroup.com/2021/07/07/an-introduction-to-...
https://en.wikipedia.org/wiki/Kessler_syndrome
Of course that could also happen with random bugs and no hacking I guess?
> However, NASA officials in charge of the day-to-day operations of the ROSAT mission at Goddard, including GSFC Rosat Project Scientist Rob Petre, say definitively that no such incident occurred. Talleur's information appears to have come from one of his interns who exaggerated a hacking incident on an office computer not related to flight operations.
Some things never change.
I think you’re more likely to find a job than trouble — SBIR has a bunch of grants in that area. (Last I looked.)
The approach used for the Starlink terminal is more like what was done to reprogram satellite TV smart cards. Get a copy of the ROM, count the processor cycles and find the operation you don't want happens and mess with the voltage or frequency at that point to let you send in unsigned/unauthorized updates.
Even if they wanted to become one, they'd need access to tremendous amounts of capital and low launch costs to re-create what Starlink is.
It's an open question if Amazon will be able to compete with it's eventual system or not.
The former would be quite illegal and difficult to scale, the latter would be quite expensive.
tl;dr yep, he could have been shoveling CRUD shit and making more money, or implementing high end algorithms within broken operating systems, or implementing high end algorithms with insufficient education or time to prove them, while getting dumber
scratch that he got a bug bounty for his work so his net gain is equal. check mate
The article specifically uses the phrasing "uses off-the-shelf parts that cost around $25". It doesn't say anything about the cost to develop, it doesn't say anything even slightly misleading or ambiguous about this.
Like, what should the article have done instead? How could it possibly be clearer and more explicit about what $25 referred to here?
https://api.starlink.com/public-files/StarlinkWelcomesSecuri...
“Bring on the bugs”.
This is how you properly engage the security community. In times where journalists are taken to court for looking at a webpage’s HTML source it’s really great seeing a company that “gets it”. Kudos.
At least if you find a bug, go and exploit it and bring the satellite down. This way we can all have some fun, not just the VPs sitting on the company board. And then they call their conferences with menacing names such as 'Black Hat' or 'DEFCON'. Sounds more like pony-con to me.
I'm not shocked they did lock it down, but why do you think it's important to the security?
Essentially 0% of those devices are user-controlled in the "I can make the radio do whatever I want" sense.
For example, an IMSI catcher isn’t technically _connected to_ any cell network, but it does exploit the assumptions of clients who attempt and expect to connect to one.
EDIT: But at least the engineers and/or marketing is supportive (from another thread here): https://api.starlink.com/public-files/StarlinkWelcomesSecuri...
To my reading, "the hacking of Starlink terminals has begun" is a little bit ominous looking, but maybe the error is on my side.
Begun, the hacking of Starlink terminals has
Here, hacking is a more well established term- hacking networking hardware is something I suspect most people would associate with black-hat type hacking.
Wikipedia claims the term was widespread by the 60s
https://en.wikipedia.org/wiki/Hacks_at_the_Massachusetts_Ins...
At the time, using "hacker" to mean a black-hat was popular in the press, but not among actual hackers. And "growth hacking" was a metaphor for doing clever things to get growth, but not the primary association with "hacker".
For example, when there is a certain word that you and your peer group use as an in-joke, you usually have to wink or smirk to invoke the joke meaning, that acts as a signal to the group to resolve the word to its group-specific meaning.
A lot better than companies that would try to prosecute him..
[0]: https://api.starlink.com/public-files/StarlinkWelcomesSecuri...
> We want our devices to only run software that we wrote. This isn't like a personal computer where the user can install apps or save files – the only software we want to run on our devices is software that we've explicitly built, tested, and signed off on.
> The same concepts that go into secure boot on our satellites are also useful on the Starlink user terminals. Even though we know that an attacker with persistent and invasive physical access will eventually be able to defeat secure boot on their own device, the protections of secure boot are still valuable for protecting against remote attacks over the Internet (or over wifi). There is a big difference between being able to take your own device off your roof and attack it, vs. someone else being able to compromise your device without you noticing.
But recognize that it's not foolproof:
> We expect attackers with invasive physical access to be able to take malicious actions on behalf of a single Starlink kit using its identity, so we rely on the design principle of "least privilege" to constrain the effects in the broader system. We treat Starlink user terminals as inherently untrusted and only expose the minimal necessary information and capabilities to each specific client.
The article talks about the researcher "exploring the Starlink network" as if there's a screen on the satellites that will suddenly display "Access Granted" with a blinking cursor now that he's achieved root on his own dish. Getting access to the dish is an important step if the former is to be achieved, but it's by far the easier of the two steps.
That PR says: <<from embedded Linux running hundreds of thousands of computers in space>>
Are these "computers" strictly controlled/owned by SpaceX? If yes, are there multiple computers per satellite? Please help me to understand this claim. In 2022, I assume when someone says "computers" they mean kernel count.
With small computers being relatively cheap and lightweight, I suppose a satellite has a highly available internal computing configuration, with large level of redundancy, capable of functioning even after serious hardware degradation.
A salary in the hundreds of thousands, or equivalently 'six figures', clearly includes a salary that starts with 1.
But when it's a definite figure which is being approximated I would tend to agree with you.
[1]: https://www.zdnet.com/article/spacex-weve-launched-32000-lin...
I'm not impressed by a PCB board being cheap. Does anyone else feel this way about similar headlines?
Uh, yep thats exactly what I want to do :-)
Edit: fixed for clarity of thought
Conspicuously missing is the cost of the equipment in the lab where he developed the first prototype.
Like affording the $25 worth of hardware is really the most difficult obstacle to overcome here.
Making something accessible to the masses makes it a more impressive achievement.
That said it is a clever approach and it’s good it was discovered by someone without nefarious intentions.
E.g.
You may want to protect end users against implants and other attacks from physical tampering with their terminals.
You might not want hostile parties to have an easy time reverse engineering terminals so they can more easily search for remote vulnerabilities in the terminals.
You may not want to hand hostile parties a phased array optimized to transmit to Starlink running arbitrary software of their choice, along with keys identifying the terminal, because even though you think the satellites and authentication mechanisms are robust, making it hard to get this information adds defense in depth.
So, if you make things harder and someone comes along that invests more effort to overcome, can you really call that a vulnerability? It'd be a real vulnerability if with this access to a user terminal they could elevate permissions on the satellites, but that hasn't been shown (yet?).
Yes. Just because executing the attack doesn't seem to get you anything particularly valuable doesn't make it "not a vulnerability."
We're not personally insulting it, we're just describing reality.
If it's hard enough that only state actors can potentially do it, then what does it matter in real life that it's theoretically vulnerable?
To put it another way, consider physical locks, which must inherently be able to resist direct physical tampering by an adversary. Under your definition, no flaw in a lock could be considered a vulnerability since any lock can eventually be cracked. The problem is that this doesn't provide us any useful insight, it just makes the word "vulnerability" useless. It's already well-known that any lock can eventually be cracked, but tradeoffs still have to be made in deciding which lock to use for a certain situation.
Yes? This is defense in depth. Anything that bypasses a defense is still a vulnerability, even if your backup defenses protect you.
Defending physical hardware is indeed a theoretical impossibility as on paper, it will always be possible to make a perfect electrical clone of the original hardware and then modify it to suit. However, reality is different, and mitigations against physical access have become much more effective in recent years (iPhone anti-jailbreaking and the Xbox One come to mind as fairly successful).
So, this is a vulnerability indeed, just not a high severity one. One layer of the defenses are bypassed, but the remaining defenses remain.
https://en.wikipedia.org/wiki/Defense_in_depth_(computing)
For the same reason, security-by-obscurity is also a valid (though not sufficient) tactic for one of those layers (which also surprises people).
Its about delay and demotivation to slow down your attackers.
All in all there are plenty of devices in the world that are protected against physical access, so if Starlink tried doing that and failed, then that's definitely through an exploited vulnerability.
Have they? I know Apple an Nintendo have been trying for years and we have jailbreak and Homebrew, I believe there is even jailbreak for nintendo switch.
If there isn't yet an exploit to gain root on Xbox and PS5, it's only a matter of time.
Xbox One didn't have a root exploit for its entire lifetime and counting. It was released back in 2013. That's nine years. So one could say MS "solved it".
I don't know if they really "solved" it. I think the appetite for new hacks dwindled with broadband internet everywhere and streaming services.
Cat doesn't care for the mouse so much when there's kibble everywhere.
https://en.wikipedia.org/wiki/Conditional_access#Digital_sys...
EDIT: More than that, some recent ones even solved so called 'card sharing' which is basically using a legitimate card to transmit control words over network to many users.
And as an example satellite TV providers did it (or acquired a license for it). If you're saying that incentives to hack them aren't there anymore, then that's just wrong because the foundation on which such security is based on affects many things.
Declining popularity of SatTV as a whole in a particular country is neither here, nor there. If a hacker mentioned in the article could hack a CA system, he would've.
> Curious why an iPhone hasn't been susceptible to this type of hack before?
The answer is probably, "it's complicated." These sort of hardware hacks are quite clever, and typically depend on using chips in unintended ways -- I mean most circuits will have some undefined behavior if you start shorting parts!
There are lots of reasons an iPhone might not get a widely popularized exploit like this. Firstly it might be low-priority -- iPhones are general purpose computing devices, so there are usually software bugs for people who want to root their iPhones. Second, it might legitimately be more difficult. Apple has lots of experience in hardware, their circuits might be more robust. And iPhones are quite tightly integrated, it might be hard to sort out which parts you need to short when everything is on a handful of chips.
This is different than a Starlink base station. Base stations aren't built to be hardened against a physical attacks, and are rather intended to be untrusted links to the satellites.
So it's kind of in a grey area, but I would also not consider this a vulnerability of the Starlink base station itself, in the same way that rooting an iPhone with physical access would be a vulnerability.
See mobiles like iPhones, gaming devices like XBox, Playstation etc. authenticators like chipcards or security token and HSM. All have to asume that the attacker has physical access to the device.
Security Engineering Ch. 16 "Physical Tamper Resistance" is a good read for some special classes of devices. But I would recommend all topics from this book even unrelated to this thread. ;)
I was wondering about that but can't they determine the location "server side" by triangulation? Or maybe they could in theory but they don't in practice?
They could effectively reimplement GPS or an equivalent location tech with their network but why when a high quality positioning solution already exists.
They will be continually syncing time and position data for the orbits of satellites and positions of clients. (static clients obviously don't need this often outside of timekeeping, but you can set up a mobile plan for RVs, boats, etc which obviously move a lot)
Edit: I misrecalled. StarLink can provide 10x more precise positioning than GPS.
https://www.telecomstechnews.com/news/2020/sep/28/starlink-s...
Build it, maintain it, rely on it.
Alternatively you could just embed a cheap GNSS chip and let other people build and maintain it.
> I misrecalled. StarLink can provide 10x more precise positioning than GPS.
GPS can also provide much more precise positioning than it does for consumers. There are encrypted bands used for military, etc with significantly better specs.
If too many people do this, things stop working, because you exhaust the limited resource.
https://resources.infosecinstitute.com/topic/how-to-hack-mob...
...found a vulnerability (CVE-2022-20210) that can be abused to disrupt the device’s radio communication via a malformed packet causing a DoS condition. This vulnerability allows attackers can neutralize communications in a specific location.
This info is enough to calculate their exact position and is constantly updated as their orbits change due to degradation or powered movements.
But accurately hitting an object at 400km altitude moving at 10km/s is outside the capability of all but corporate and state actors and starlink is not great target because their sats are so small and there's so many of them.
It would cost a fortune in missiles just to make a dent in the constellation.
Would a nuke in space even work to take out a group of them, maybe even via an EMP surge or are they hardened?
Sometimes I wonder if the world would be more peaceful if cellphone networks couldn't work anymore but there would be so much other chaos so guess not.
SpaceX replacement rate would be higher then Russia destroy rate.
Assuming of course that SpaceX will not increase its launch cadence, and that this act of war will not provoke a response that stops is. The concept is laughable. It is intractable at every level of execution.
These possibilities are not at the behest of your logic but at the will of a small number of people far away.
Your idea that space will somehow not be militarized is quite laughable. There's an actual history that proves you wrong:
https://hir.harvard.edu/anti-satellite-weapons-and-the-emerg...
On this altitude debris would quickly drop out so you would never get Kessler synonym.
Russia would have to shoot down a huge amount of sats.
And SpaceX can easily have 100-1000x the upmass of Russia.
And this is before you can consider lots of counter-measures the US could potentially do.
After that… I imagine it’d become impossible to launch anything ever again. So much debris in LEO would be depressing (though maybe the satellites could be given a deorbit burn order before being exploded, if it ever became clear they’d gotten targeted in this way)
In addition, its far harder then you would think. Each such missile would still need complex computer system and propulsion hardware and so on. It would be cheaper then a Starlink sat but not by that much.
Also, even if you assume 1/10 the weight, SpaceX can easily launch 10x more then Russia can. With Starship coming online SpaceX by themselves can launch 100x what Russia can.
And of course if Russia did such a think SpaceX would have US government support.
> After that… I imagine it’d become impossible to launch anything ever again.
I do not think this is actually true. The decay is to fast on this altitude for this to actually happen.
We flew a rocket to the moon with less computing power than a modern pocket calculator. I’m inclined to say we’d manage.
I think I’m confused about your term ‘launch capacity’. If we’re talking average/sustained payload/day, then sure. But I think the capacity of the soyuz and falcon is about the same.
Edit: Never mind, Soyuz has like 2 times less capacity than a default Falcon.
It’s probably not fair to use Starship for that comparison (as much as I want to) because it has yet to successfully launch.
> But I think the capacity of the soyuz and falcon is about the same.
Per launch a Falcon 9 lifts about double and in the last couple years Falcon 9 has launched 2-4x as often.
> It’s probably not fair to use Starship for that comparison (as much as I want to) because it has yet to successfully launch.
As of right now Russia likely also doesn't have the missiles you suggest. I would argue that Starship is closer then an advanced anti-sat weapon that can split up in orbit and hit many targets.