If the remote machines have the assumption of trustworthy terminals baked in, then this isn't a low threat hack.
If the remote machines have the assumption of trustworthy terminals baked in, then this isn't a low threat hack.
"We will happily ship a Starlink kit to any customer that purchases one. With Starlink kits all over the world, we don't have much control over what users do to them. History shows us that it's hard (and maybe impossible) to make devices completely resilient to persistent attackers with unrestricted physical access – the attacker just has too much power when they have infinite time to modify the hardware. In the limit they could always just build their own user device from scratch, though we know from experience that it's pretty hard to do so. Ultimately, the only way for us to build a secure system is to assume that attackers will eventually get into the Starlink kit, and add additional layers of defense-in-depth to protect our network and the other users within it. Other parts of the Starlink network, like satellites, might be more difficult for a consumer to get their hands on, but similarly are built with layers of defense. To provide these additional layers of protection, there are a number of security properties that we believe are important both in the Starlink kit and in the rest of the system"
From https://api.starlink.com/public-files/StarlinkWelcomesSecuri...
Given the general competence level of the engineering at SpaceX, I would not put any money on this being true.
Maybe if the system were designed by Sony...
They really don't want you to root your PlayStation, but that's mostly because it allows you to hack offline games. Hacked consoles are usually banned pretty quickly from online services.
It doesn't mean Sony has the best track record when it comes to security just that they are not completely clueless.
Another time as a team building activity, we were using mission control and backup mission control to play a multiplayer space ship bridge simulator game. My team was winning, up until our terminals started failing. Someone on the other team had credentials to the IT system, and was remotely rebooting them.
(That said I'd be pissed)
They fixed that with the newer batteries as I recall but was a pretty big hole at release