> How are these remote systems kept secure? How do you prevent someone just constantly brute forcing the password?
I would be somewhat surprised if any proactively secured tech used a password. Key pair encryption is the way. A password over 20 random characters is virtually un-brute-forceable if there was one.
DDOS would involve either a botnet or a nation-state. Both could be solved by the US government if needed. It would be a bad target because you would almost certainly gain fed attention and that isn't attention you want. A satellite could probably be signal jammed with the only possible way to stop it being to blow up the jamming device.
I think your model of a satellite being more special than a web server is probably not all that correct. It's probably not significantly different than your home router in an abstract sense, just with a humongous antennae.
Most serious networking devices separate the control of the device from the operation of the device, so it's possible that there are specific configuration antenna or specific configuration frequencies, or sequences of frequencies that are used for configuration. There is probably some wireless equivalent of "using a different cable."
ACL's are probably standard, rate limiting is probably standard. I would be surprised if there were not 2fac. I would be surprised if there was not an incredibly monitored machine that is the only machine with credentials for those satellites, maybe even air-gapped from the internet at large.
I would potentially be worried about my hardware supply chain, for example if components came from China, they would probably inspect them quite carefully.
Your model of attacking the satellite itself is probably also wrong. Exploiting a companies networking devices, particularly from the outside is probably quite hard, what people go after is employee devices. There are probably a number of starlink employees with access and compromising their laptops might compromise all satellites. This means attacking the satellite system is probably like any other corporate hacking job, phish some employees or compromise a supply chain, use that to move around a company's network, hopefully undetected, etc.
If I wanted to compromise Starlink, and I was a nation-state, I would keep a list of all starlink employees or attempt to get that list via technical means and then try to compromise an employee. Compromises can be done technically, with bribery, extortion, and then violence.
The first stage of hacking is figuring out information. Who are the employees, who are the suppliers, what is the security architecture, etc. That informs the approach. Maybe there is a piece of software that would be easier to find a zero day for. Maybe it would be easier to compromise a supply chain. Maybe it's easiest to honeypot the employee with a beautiful person.
Setting up a coffee shop next to a starlink office and putting some great cameras and microphones in it for example, would probably be fruitful.