Receiving unintentional voice transmissions from GPS satellites
rtl-sdr.com
rtl-sdr.com
> Many navigational and meteorological satellites carry a search and rescue (SAR) repeater which is intended to receive UHF emergency locator beacons and rebroadcast them in the L-band or higher. However the repeaters appear to be picking up all sorts of other signals from the ground, including voice transmissions.
https://www.wired.com/2009/04/fleetcom/ https://archive.ph/1WyGR
https://www.wired.com/2009/12/insurgents-intercept-drone-vid... https://archive.ph/xyW4E
You could probably get away with sending a couple messages while pretending to be someone doing it accidentally, but you’d be holding up a “pick me” sign visible to any type of scrutiny.
It's some how comforting to realize this is still possible today.
Edit: specifically radio protocols not carrying internet traffic
I do think that encryption is firmly outside of the amateur culture in most cases, but legality is well covered here: https://www.n5dux.com/ham/files/pdf/Data%20Encryption%20is%2...
I mean, in a sense it was - you're trying to make thing with long runs of patterns look as much like noise as possible, which is the goal of encryption - but in order for it to work as a modem both ends have to have the same "key" which was a very short LFSR that would pull into sync during the training burst.
In practice, at least in the UK, you can more-or-less do what you like as long as you're not making a nuisance of yourself. You literally cannot pay Ofcom to investigate anything on the amateur bands, although you might get a lot of grumbling from daft old bastards.
Also, do bear in mind that most people don't need to care what the FCC says, or stick to their rules. I'm currently operating equipment that quite thoroughly violates FCC rules, and there's not a thing anyone can do about it :-D
As we all learned in WWII, a code is better than encryption when you need complex PKI to achieve encryption. It’s more flexible, and can even convey nuances not intended. Ah, sorry I mean a language, not a code. But still, code words and phrases are still a thing.
>As we all learned in WWII, a code is better than encryption when you need complex PKI to achieve encryption
I was never in WWII and I'm not sure what you mean by code as typically that's just encryption but less formalized.
Radio is like being able to packet sniff (and modify) packets from anywhere.
Edit to add: yes, there are CA's to sign the bits on a network. There is no CA for the radio, only proprietary ones. These can be reverse engineered, subpoenaed, or bought by state actors. Chances are, if you're broadcasting loud enough to be heard by them, they're going to start listening.
This is because the MITM will not have a valid certificate to provide authenticity for the public key returned.
The reason why middle boxes in corp networks can MITM is because the the corp owns the device and has installed their own domain trust to the device. This means the MITM can return a cert and public key that your device will trust. This is because the cert returned will be signed by the installed domain trust.
Another way to think about why HTTPS is secure over radio: HTTPS is at the highest level of the OSI networking model. You could do HTTPS with pen and paper and the mail if you wanted. Think about starlink! The internet today is literally going over radio waves.
This is likely why there isn't progress on encrypting old fashion radios! There is no need to encrypt old fashioned radios -- you'll just use internet over radio instead if you wanted encryption.
You bring a good point through. Since it's radio, anyone can jam your transmissions, but, they won't be able to spoof your intended friend if you are using https via radio.
There is absolutely nothing inherently secure about HTTPS without a secure CA.
This could be done with radio too but we don’t because a typical website transfers hundreds of megabytes and the traffic involved in negotiating an encrypted connection is a drop in the bucket, whereas with most radio traffic, it would comprise a much higher percentage of all your radio traffic.
Plus your average radio equipment has a tiny CPU (although this is changing) whereas your phone or desktop computer has hundreds of gigaflops to do all the encryption and decryption math that you want and then still draw a gif.
Https (or IP for that matter) does not use the physical card to authenticate. That wouldn't make sense, except for very local networks. And since IP relies on ARP for the physical network addreess, even local IP networks can suffer MITM, by way of ARP spoofing.
At the beginning of the connection, you must establish some sort of "trust" between your radio and the other radio (if you want to use encryption). Your wifi does this with a Pre-Shared Secret (PSK). Your https connection does this with CA certificates.
This 'baseline trust' allows you to know the other end is who you expect it to be. With traditional radios, there's not much of that. There's just:
- something you have (the radio characteristics)
- something shared (past experiences/conversations)
- something you are (your voice)
If you don't squint that hard, that's the basis of any kind of authentication. Thus we have that covered. So, I can "authorize" myself as my person. Then I can send my keys over the air so we can have a private conversation.
Here's the issue, as soon as I broadcast my keys, someone with a "louder" (technically, brighter) radio broadcasts my voice with different keys. Next, they do the same thing when you broadcast your keys. Bam, we've been MITM'd without even realizing it.
So, ok, you say. Maybe we'll snail mail our keys to each other. Sure, that'll work. Yet still, even then, we'd only be able to talk to each other. At that point, why not just pick up a phone or start up a telegram chat?
The weakest link in any kind of encryption is always during the key exchange. Always. Mostly because we are human... we click through warnings, get our mail stolen, misstype things, and all kinds of dumb things.
My other point about code: we can agree on a dictionary. It's virtually uncrackable and fluent to have a coded conversation. For example, there's 0% chance you'd have any idea what this actual phrase from Afganistan means:
"the dust is blowing in, so we'll need about 5 mins to pick up my sister and head home"
spoiler:
"the americans are here, so we'll need about 5 mins to set up the guns and be the rendezvous."
Code is always better than encryption. Always. The issue is the "dictionary" and the fact that it can be leaked. Encryption gives better guarantees in that regard. But when you already have 'authentication and authorization' via the things I mentioned above, code does quite well...
Basically you are taking a subset of encryption using only substitution and calling that a code.
Cipher: exchanging letters to hide a message.
Code: exchanging words/phrases to hide a message.
Encryption: combining math + ciphers (sometimes code too!) to hide a message.
Codes are great for real people having fluent conversations, not so great for computers. We actually use "codes" all the time, but when they're used in large groups (and not a 'secret'), we call it "jargon."
"Push it to main, and I'll pull it in to my buggy branch to see if that works" will make almost no sense to anyone but a programmer who works with git and even then, only someone who's used git since everyone renamed the 'master' branch to 'main.'
So they developed a vocabulary of 411 Navajo words to stand for common military terms. E.g., BESH-LO, which is Navajo for "iron fish", meant "submarine".
The vocabulary included a phonetic alphabet to represent the 26 English letters. E.g., the three Navajo words MOASI, TLA-GIN, and BA-GOSHI all represent English words beginning with C (cat, coal, cow). So, they could spell out arbitrary English words not in their vocabulary.
It was secure against an enemy that lacked Navajos and probably didn't even know what language was being spoken or if they were intercepting some weird form of audio scrambling. But, if the Japanese had been able to translate the messages to English, the code would probably not have survived cryptanalysis for long.
https://www.cia.gov/stories/story/navajo-code-talkers-and-th...
However it sounds like they were mainly used in heavy combat conditions where the enemy didn't have recording equipment for later analysis. So in that scenario specifically (but in that alone) it was pretty secure.
If you've ever gone to a foreign country, you know you will have zero idea what anyone is saying for quite a long time. They knew as long as they kept the messages short enough, nobody was going to learn it from immersion.
There are still ancient languages that nobody have deciphered, despite having copious samples to choose from. I don't think it's as simple as you're making it out to be.
Not since 1976.
Ultimately it boils down to you needing to bootstrap your web/chain of trust somehow. In a military it might be easier; radios would be distributed to field troops with the needed trusted keys already present.
But more "public" radio? We don't have a sort of "radio CA", and there are no radios that know how to deal with such a thing. I suppose we could reuse the TLS CAs, though, and build SDRs to use it, which wouldn't rely on any particular hardware. But the point is that this just isn't set up at all.
https://www.history.navy.mil/content/dam/museums/nmas/educat...
It's very easy to look these things up.
We switched to Disney+ at the start of the year, otherwise I'd have been able to confirm the show.
An important reason that I see is because (at least in Germany, I guess worldwide) ham radio operators are not allowed to encrypt their traffic. Commercial companies are a lot more conservative concerning encryption than "hacker people".
I guess it's because it would eliminate the possibility of collaboration and also enable using it for commercial purposes without anyone being able to check.
There's an exception for command and control systems like satellite control.
Modern radios sync their keys when they are within range of wifi at HQ.
Also, see: https://www.cbc.ca/news/canada/toronto/toronto-police-tow-tr...
If the local authority or civilization corrupted, good luck rebuilding it.
So then I found channel 70-83 on the TV, and discovered that AMPS cell phone conversations would drift in and out on those channels if I just let them sit for long enough. So Dad strictly enjoined me not to reveal what I learned from those conversations. And I lost interest, because not much interesting was being said, and the broadcasts were partial, probably because the typical use of AMPS was for car phones, not people walking by on the sidewalk.
In most of Europe you can listen all you want and talk about it. I think in the US some frequencies were forbidden to listen to and to this day these are blocked on scanners. Not sure why as analog cellphones are long obsolete.
Of course listening to ham radio bands is allowed since they are meant to be public. But unlike in other countries the UK does mind if you speak about what you heard on the bands. I've heard several people getting berated for this on the bands.
I suppose for stuff that's actually meant to be prive it's even illegal to intercept it, I don't know. Personally I think such laws are just theater. Just like the cell band blocking on scanners in the US. Spend 2 minutes on mods.dk and a soldering iron and problem solved.
Occasionally the astronauts will get on the radio as well and chat with you! I haven't been lucky enough to do that yet. But I have heard them talking when passing overhead.
https://amsat.org has more information.
ISS: NA1SS is listening HAM: NA1SS this is whiskey one alpha whiskey in Hartford, Connecticut ISS: W1AW, welcome board the ISS! HAM: 73
repeat for everyone trying to make a contact :-)
Basically something I can take with me while hiking, and have somebody else in civilization listen and have some conversations with ?
Ideally a radio for satellites is full duplex (you can hear simultaneously while transmitting). Those radios cost much more though. Many people just use two radios.
For shortwave radio, you could use something like the trusdx: https://dl2man.de/
Note that in both of these cases, to transmit, you'll need a license... and if you want to talk to someone specific it may be hard to do. Talking to random amateur radio operators is much easier.
The options I posted are cheap - you can easily spend tens of thousands of dollars on radios, antennas, amplifiers, towers, etc.
121.5 and 243 MHz are no longer officially monitored for voice distress signals, but I wonder if they're still being gathered on the fleet.
Perhaps the best mitigation, I suppose a reduced set of these signals are monitored for voice distress calls. The satellites should support geofenced/location-selective rejection of signals on 406 MHz and 1544.2 MHz identified as non-emergency traffic to prevent misuse by pirates, drugs dealers, and warlords coordinating attacks.
As a pilot I can say that claim is false - guard is very actively monitored everywhere in the United States. Were you referring to some other locations?
ATC does still monitor 121.5, but that's with an eye towards voice transmissions, not radio beacon activations. COSPAS-SARSAT has never carried voice traffic on 121.5, the satellites attempted onboard Doppler direction finding of the beacon tone (not very accurate at all, one of the reasons it is obsolete). At the same time, ATC no longer has RDF capability from most (all?) GATRs, so receiving the ELT beacon tone is mostly useless to ATC, and ATC is unlikely to receive it anyway since GATRs have very poor coverage down to ground. ELTs do still transmit on 121.5 for convenience of search aircraft, but it's becoming increasingly irrelevant with high COSPAS-SARSAT coverage (if the ELT activated at all, rescue coordinators already know the location by GPS coordinates) and increasing rarity of direction finding equipment (and pilot experience with RDF) on aircraft.
One way to sum it up is this: 121.5 is monitored for distress calls from aircraft in the air, but it is not monitored for distress calls from aircraft on the ground. The latter is the goal of search and rescue systems, and the use of 121.5 has been replaced by the much more modern COSPAS-SARSAT system originally developed for maritime rescue.
https://en.m.wikipedia.org/wiki/International_Cospas-Sarsat_...
> The International Cospas-Sarsat Programme is a satellite-aided search and rescue (SAR) initiative. It is organized as a treaty-based, nonprofit, intergovernmental, humanitarian cooperative of 45 nations and agencies (see infobox). It is dedicated to detecting and locating emergency locator radio beacons activated by persons, aircraft or vessels in distress, and forwarding this alert information to authorities that can take action for rescue. Member countries operate a constellation of around 66 satellites orbiting the Earth which carry radio receivers capable of locating an emergency beacon anywhere on Earth transmitting on the Cospas-Sarsat frequency of 406 MHz.
That said, the claim I was responding to was "121.5 and 243 MHz are no longer officially monitored for voice distress signals", which is pretty obviously false.
Besides, there's not really much motivation to mitigate this problem. First, pirate satellite communications by SARSAT transponders are rare compared to other satellite systems very popular with pirates like legacy US Navy communications satellites. Second, satellite piracy isn't that popular overall. Mitigating the ability of criminal organizations to communicate this way would require taking down a lot of different satellite systems, and then they would just fall back to HF radio, which is already the more popular approach. It's doubtful there would be any major reductions in crime and the type of crime that seems to motivate the most use of satellite piracy---unlicensed fishing near the Phillipines---isn't super high on the list of international priorities.