Thales seizes control of ESA demonstration satellite in cybersecurity exercise
thalesgroup.com
thalesgroup.com
Not much details available online but I found this: https://www.spacesecurity.info/thales-demo-at-cysat-what-was...
It looks like that they didn't do a hack of the ground station, or anything like a radio signal hack.
My understanding is that ops-lab is like a kind of "SDK", and so they had allowed access to this special satellite that is a kind of shared projects machine, like a mainframe or a virtual machine host.
So, basically they did a chroot escape. The computer being a satellite instead something else is just a detail. They did not hack to get a remote access.
It's also a bit frustrating because (assuming it is a useful exercise) there are plenty of private companies that could have built this for ESA much more quickly and cheaply. Planet and Spire could have dedicated or loaned out one of their satellites. Starlink certainly has spares and coverage. I suppose these companies are US-based, so it wouldn't help develop ESA capabilities. Feels a little like a handout to Thales.
It's neat that I can borrow a satellite to train a neural net, but is it useful? And if it is, do I need a demo to prove it's possible?
High time - I have been waiting for satellite hacking since the days of Golden Eye[0] and Die Another Day[1]. Interestingly, both featuring Pierce Brosnan.
[0]:https://ora.ox.ac.uk/objects/uuid:9af9771d-74cd-49f3-88e3-f3...
[1]:http://www.cs.ox.ac.uk/files/11922/Pavur%20et%20al%20A%20tal...
[2]:https://ora.ox.ac.uk/objects/uuid:6e4194fa-474b-41cb-81fa-db...
[3]:https://www.cs.ox.ac.uk/people/publications/date/James.Pavur...
Note: I'm not associated with Dr. Pavur in any way other than being fascinated by some of his papers and Defcon presentations.
>Throughout the exercise, ESA had access to the satellite's systems to retain control and ensure a return to normal operation.
Was this a test bench or on orbit? The release seems to contradict itself. Did they do it on the test bench, and then for real?
https://en.wikipedia.org/wiki/OPS-SAT
https://www.esa.int/Enabling_Support/Operations/OPS-SAT
Launch took place on 18 December, 2019, when OPS-SAT was injected into a circular, polar orbit at 515 km altitude.
Real-time tracker: https://www.n2yo.com/satellite/?s=44878
"Throughout the exercise, ESA had access to the satellite's systems to retain control and ensure a return to normal operation."
My reading of this: ESA let the teams attempt their hacks on the real satellite under supervision.
I guess I don't understand your implicit distrust here - it's just a 2 million EUR, 7 kg satellite explicitly launched for communications experiments.
It is a private press release by a company on its own site, advertising same services touted in the release. I assume every truth that can be bent in their favor has been done so by the PR and Marketing teams. However, the youtube video above with the interview seems much more unequivocal.
Again, it's a (relatively) super cheap satellite explicitly meant for comms experiments.
"An old satellite was hacked to broadcast signals across North America" - https://www.freethink.com/space/decommissioned-satellite-hac...
And in Brazil they have been using some US Navy satellites for years.
"The Great Brazilian Sat-Hack Crackdown" - https://www.wired.com/2009/04/fleetcom/
LEO sure, you don't need to adjust your perigee or even your angle of attack much to change orbit. But then very little from a satellite will reach the ground.
msot of traffic between satellite and earth is unencrypted ( RC4 like encryption is not encryption ), there are hundreds satellite listening stations all over the world.
for example "Abhörstation Königswarte" can listen to african presidents talking over satelite phones.
snowden leaks provided some info about collections thru these kind of stations. ( NOTHING in snowden leaks, showed to public, was unknown / not already opensource )
And I doubt very much that Starlink or OneWeb (OW is using AES256) satellites are that easy to hack, and they by themselves are most of the satellites.
Many satellites are also able to monitor contacts made from the ground and if someone is able to gain access to the communication stream, they'll quickly (within 10min) have to learn how to hack the onboard software to reset these monitors.
so with ESA putting this amount of (american made) computation, you can see where it is going.
im proponent of having telemetry not encrypted, we need this for same reason we use ADS/AIS
there are multiple "channels" from / to satellite. not all have to use consumer grade encryption.
some other comments provide link to mission statement, there you can read it was developed to do tests about spacecraft security, im not sure they ment computer security, tho. you can write ESA, you can find some ESA people on twitter even.
is 20 year old tech hackable ? is not sourcable. what is done to satellites is not really possible to source, people need to work. and even bull is considered secret, proprietary etc....
for threat model: hybrid war is "new". " attacking infrastructure was considered war, full stop " this changed for some reason.
american corporation have 4 pictures of "earth" everyday, in database, starting from 1996... and still even today, you can point antenna up and capture geostationary satellite pictures, not in that resolution tho. ( NOAA / old russian meteo satellites - this was not in threat model. source is point antenna up)
im not talking about things like FLTSATCOM 7 and FLTSATCOM 8 which are known and covered by news.
im not confused about what is telemetry, control, data, transponder, etc
most nonmainstream things / themes are not "googleable". because hybrid war. hobbysite from 20 years ago - cqham.ru has some articles about "downloading" nonencrypted traffic from satellites with for todays standard, primitive equipment