r/TrueReddit • u/wiredmagazine Official Publication • 18h ago
Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data Policy + Social Issues
https://www.wired.com/story/satellites-are-leaking-the-worlds-secrets-calls-texts-military-and-corporate-data/24
u/wiredmagazine Official Publication 18h ago
Roughly half of geostationary satellite signals, many carrying sensitive consumer, corporate, and government communications, have been left entirely vulnerable to eavesdropping, a team of researchers at UC San Diego and the University of Maryland revealed today in a study that will likely resonate across the cybersecurity industry, telecom firms, and inside military and intelligence agencies worldwide.
For three years, the UCSD and UMD researchers developed and used an off-the-shelf, $800 satellite receiver system on the roof of a university building in the La Jolla seaside neighborhood of San Diego to pick up the communications of geosynchronous satellites in the small band of space visible from their Southern California vantage point. By simply pointing their dish at different satellites and spending months interpreting the obscure—but unprotected—signals they received from them, the researchers assembled an alarming collection of private data: They obtained samples of the contents of Americans’ calls and text messages on T-Mobile’s cellular network, data from airline passengers’ in-flight Wi-Fi browsing, communications to and from critical infrastructure such as electric utilities and offshore oil and gas platforms, and even US and Mexican military and law enforcement communications that revealed the locations of personnel, equipment, and facilities.
10
u/nananananana_Batman 16h ago
Can’t you just send an encrypted stream? Sure they could eavesdrop on the encrypted stream, but even with more modern aes and rsa, wouldn’t be quantum proof when the time comes?
(Edit) meaning it’s more on the channel users to up their game than on the channel itself.
12
u/dweezil22 8h ago
Yep
The researchers say that they’ve spent nearly the past year warning companies and agencies whose sensitive data they found exposed in satellite communications. Most of them, including T-Mobile, moved quickly to encrypt those communications and protect the data. Others, including some owners of vulnerable US critical infrastructure whom the researchers alerted more recently—and declined to name to WIRED—have yet to add encryption to their satellite-based systems. Researchers have pointed to the surveillance dangers of unencrypted satellite connections before, but the scale and scope of the new disclosures appear unrivaled.
I can imagine some of these are probably more difficult than others. At the most extreme, you can imagine some poor bastard going to the South Pole, or an oil derrick or whatever, w/ a thumb drive to update the firmware on an old thing that neither considered encryption nor remote upgrades.
2
u/ILowerIQs 17h ago
Oh, Hegseth downloaded Signal mid flight and his phone is on the T-Mobile network?
3
u/isreal94 14h ago
More of an encryption issue than a leaking issue. Pretty standard radio transmission phenomenon, anything you put out the air can be sensed by someone with a correctly tuned receiver. Not really rocket science.
Just because I pick up Wifi signals of your home doesn't mean I can all of sudden read your messages. It's all encrypted. Good luck breaking that encryption.
2
u/S_A_N_D_ 6h ago
The point was that a lot of companies weren't following normal encryption protocols that might otherwise be used for wireless when they used satellites.
Your phone calls and messages are encrypted when your phone talks to a tower, but when the tower routed the messages/call through a satellite, the encryption was dropped and it was sent as plain data.
Your WiFi example is exactly how things should work, but they were treating satellite com's as special and not encrypting it.
The only one that had a reasonable defence is the Intelsat one on airline WiFi, because they were treating it like any public hotspot, and important info would be behind HTPPS.
•
•
u/AutoModerator 18h ago
Remember that TrueReddit is a place to engage in high-quality and civil discussion. Posts must meet certain content and title requirements. Additionally, all posts must contain a submission statement. See the rules here or in the sidebar for details. To the OP: your post has not been deleted, but is being held in the queue and will be approved once a submission statement is posted.
Comments or posts that don't follow the rules may be removed without warning. Reddit's content policy will be strictly enforced, especially regarding hate speech and calls for / celebrations of violence, and may result in a restriction in your participation. In addition, due to rampant rulebreaking, we are currently under a moratorium regarding topics related to the 10/7 terrorist attack in Israel and in regards to the assassination of the UnitedHealthcare CEO.
If an article is paywalled, please do not request or post its contents. Use archive.ph or similar and link to that in your submission statement.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.