Starlink's User Terminal Firmware
blog.quarkslab.com
blog.quarkslab.com
I am both a major Buildroot contributor and have Starlink internet service.
Their router firmware is OpenWRT based and while they have posted some source code for that it is not the source code corresponding to the binary firmware builds they actually distribute.
I have NAND dumps of both the User Terminal and router.
Funny enough a few years back their internal firmware CI even accidentally sent me some emails about broken builds since they applied some of my buildroot patches from upstream.
There's an immediate application to this research, and that's answering the following question:
How does the implementation of their geo-fencing enforcement actually work? As you may know, you can't use starlink in India (or Iran etc.), even with a roaming plan.
Sure, it is possible that the satellites just "go off" whenever passing over these territories. However, from experience, there's a good chance that this isn't how it works. Perhaps there is some cooperation from the client side (at the software level). Perhaps the terminal being hard-to-root had made it "trusted enough" for this purpose in their security design.
If anyone is up to answering that question, I'm sure they'll get a bunch of karma on their HN post.
It’s actually really easy to jam or pirate many satellites for this reason. I’m unsure if spacex has more auth than the industry standard.
Source: I used to geolocate jammers and pirates.
Yes, all indications are that SpaceX auth is also very modern and very good, but the very nature of the system means they have to have quite precise location information on both sides. The satellites will simply not transmit where it's not permitted by regulators, and can do that with high resolution because they simply physically cannot usefully see very big circles. That's exactly why thousands and thousands of satellites are needed.
In another comment you mentioned "if there's any beam shaping" which seems to indicate you really haven't ever taken any real look at Starlink? It's nothing like an old HEO sat system.
I haven’t! I enjoyed being enlightened by your comment though.
SpaceX has been developing sat to sat links, but in the current system a majority of traffic just goes up and down like a bent pipe. However because of the speed the sats move the system needs to know the location of all endpoints in real time. A given sat is only visible to a base station for something like 90 seconds. So it's very different from traditional GEO services, or even MEO services like Iridium et all for that matter.
The sats themselves are regulated by the launching country, the US only.
Plus, with things like updating the constellation, which likely is a significant security concern, they would probably be relying on some sort of geofencing.
They probably also just authenticate based on end user (e.g. what is the account being used and where is if registered), and make it against usage terms to operate in certain geolocations. The uplink terminals may also include GPS metadata but that doesn’t seem necessary since most won’t move and extra GPS equipment would be added expense.
Now, Thuraya is a bit weird in that they have some price plans that differ by the country you're calling from. Most sat phone networks don't do that but Thuraya is the cheapest in airtime by far especially when using some of these plans.
But I wouldn't be surprised if most networks work this way. After all a gps receiver costs peanuts these days and takes up trivial amounts of space.
If this is the case it's kinda cool because it can then also be used to circumvent these restrictions by spoofing the GPS signal either over the air or in the transceiver itself. Highly illegal obviously but technically cool.
Also, simply turning off the sat over these areas is not so easy because the footprint will cover a radius of hundreds of kilometers. So border areas will be a big problem.
You won't be able to spoof the gps location too much though because if you give it a location way outside your footprint I'm sure the sat is smart enough to block you.
It's easier to focus from LEO (low earth orbit) like Starlink but there you're dealing with a constantly moving footprint. And see how small a Starlink sat is. Good luck fitting the big cantenna (and really you want several). Phased array yes but not a huge one. The more elements the tighter the focus.
With GEO (geostationary orbit) you don't have the moving problems and they do use static "cantennas" or rather dishes but you're so far away that you can't focus tightly anyway. The footprint of a single GEO cell dish is still the size of a small country.
Since the Starlink satellites aim themselves to an extent, I’d think spoofing your location _too_ far away from where you actually are could end up with you unable to actually get a lock on any satellites.
People tried spoofing in 2021
----
0: https://www.esat.kuleuven.be/cosic/blog/dumping-and-extracti...
Gotta love this
Anybody done a comb over OpenWRT similarly? There's numerous slightly customized versions of that in all sorts of hardware.
I went "wait, what?" and then "well, that makes perfect sense actually"
https://github.com/fkie-cad/FACT_core
It's a super neat tool that does lots of interesting things.
And they contribute by not sharing the firmware :(
I know it might have legal issues, but this is not helpful for other researchers if we keep things hidden
They probably had a NDA or something that prohibits them to release the firmware publicy.
W for overcomplicated C++ OOP patterns enjoyers.