21 ms·
US Air Force Space Security Challenge 2020: Hack-a-Sat
- sandworm101 6y ago>>Participants who successfully complete a set of qualification challenges on cybersecurity and space this spring will be invited to the ultimate challenge: to (ethically) hack a satellite. Lol. That is so military public affairs. You are allowed to hack a satellite after being vetted and approved by government. Are Canadians allowed to participate? How about Russians? What about crypto-anarchists who will never pass a military-type background check? I cannot think of a less hacker-friendly competition. How about this: Just launch the damn satellite. Tell us which rocket it is on (I assume it is a ride share) and give 100k to the first team that manages to broadcast a rickroll. Bonus round: An extra 100k for any team that leverages the sat to listen in to the spysat network, the one operating on 60 GHz so that it cannot be heard from the ground directly. (Fyi, if you want to meet some men in black, try putting some 60GHz capability on your cubesat. They no like anything that might jam that spectrum.) https://en.wikipedia.org/wiki/Satellite_Data_System https://en.wikipedia.org/wiki/Satellite_Data_System
- iancarroll 6y agoGovernment aside, it’s an extremely standard CTF format to have an online qualifier, and is (more or less) how the normal DEFCON CTF itself works.
- alasdair_ 6y agoCompare this to something like the “Voting machine village” at the last several defcons - none of which required extensive vetting before you were allowed to hack the hardware.
- hlieberman 6y ago> Are Canadians allowed to participate? How about Russians? What about crypto-anarchists who will never pass a military-type background check? Yes. As long as there's at least one US citizen or permanent resident on your team, and you're not a specially designated national, you're allowed to participate.
- sandworm101 6y ago>> The Team Leader must be a U.S. citizen, must speak English and will serve as the official technical point of contact for communications with the HAS organizers. So ya, Canadians are allowed but only if the boss is a US citizen. Don't see any resident language. I make the point because some of the best satellite spotters/finders/hackers are Canadians, such Scott Tilley who was recently in the news for finding a long-forgotten navigation sat. Or Ted Molczan who may have spotted the legendary Prowler sat. (This is natural. Canadians are better positioned to spot satellites due to their darker sky and the longer dawn/dusk periods of higher latitudes.)
- cscurmudgeon 6y ago> allowed but only if the boss is a US citizen official technical point of contact for communications != boss
- sdrothrock 6y agoI'd argue that "Team Leader" means "boss," though.
- nexuist 6y agoIn the hackathon environments I've been in there isn't really an organizational hierarchy per team. Team Leader really means Team Representative; i.e. they only want one person coming up to give/receive items/documents/information, so they ask each team to pick a leader who can interact with the event staff.
- deleted 6y ago[deleted]
- remarkEon 6y agoIs there an actual problem here? Canadians benefit a lot from US Defense spending. This is not an unreasonable ask.
- deleted 6y ago[deleted]
- jonnybgood 6y ago> Are Canadians allowed to participate? How about Russians? What about crypto-anarchists who will never pass a military-type background check? I cannot think of a less hacker-friendly competition. The answers to your questions are in the rules. https://www.hackasat.com/rules-here https://www.hackasat.com/rules-here
- walterbell 6y ago> the one operating on 60 GHz so that it cannot be heard from the ground directly Isn't that the same frequency for ground-based 5G mmWave?
- sandworm101 6y agoYes. It is absorbed by moisture in the atmosphere. That limits its range, which is great if you want to setup lots of cellular towers without them interfering with each other. If 5g used a frequency that wasn't absorbed, individual towers would have to be much further apart, increasing "cell" size and limiting available bandwidth. https://en.wikipedia.org/wiki/Extremely_high_frequency https://en.wikipedia.org/wiki/Extremely_high_frequency
- teh_infallible 6y agoI read a paper about that. It said that 98% of the energy emitted at that frequency is absorbed by oxygen, and this was touted as a benefit, because it effectively “insulated” the towers, so they would not interfere with each other. But I am still surprised that any engineer would design a system that is only 2 percent efficient.
- loeg 6y agoAt scale all radio is absorbed by something... mostly not your recipient's antenna.
- aardvark291 6y agoor continues propagating into the endless depths of space
- loeg 6y agoSure. Unlikely for 5G towers given frequencies and location.
- 6y ago
- deleted 6y ago[deleted]
- 0xb 6y ago>Which rockets it’s on ? It’s kinda dangerous as you might know rockets and missiles operate on the same principles ? They both have a guidance system that decide where to land or not land. It just that rockets don’t have a warhead.
- cs02rm0 6y agoIf you don't meet the criteria, presumably they'd rather you trade any hacks you find with a different interested party happy to pay for the information?!
- misja111 6y ago>> .. the ultimate challenge: to (ethically) hack a satellite. .. which will be used to coordinate drone attacks on foreign targets. So much for ethics ..
- henvic 6y agoI'd bet they're most certainly doing this so smart kids are brainwashed and drink the kool-aid of warmongers.
- hongseleco 6y ago> Anti-MIC comment Depends on where you draw your ethical boundaries? I mean it's a lucrative career in itself and you get to work in cutting edge tech that hopefully never gets proliferated to other countries (esp. the oppressive ones).
- TheAdamAndChe 6y agoThe whole point of the exercise is to recruit good people into the military. That means they've got to know who's doing the hacking.
- Zenst 6y ago60GHz is covered in IEEE 802.11a - https://en.wikipedia.org/wiki/IEEE_802.11ad https://en.wikipedia.org/wiki/IEEE_802.11ad
- sandworm101 6y agoOn earth. Its use in space is another matter covered by different rules.
- deleted 6y ago[deleted]
- ryanmarsh 6y agoCould ITAR have something to do with the need for a vetting process? ITAR = International Traffic in Arms Regulations https://www.pmddtc.state.gov/ddtc_public?id=ddtc_kb_article_page&sys_id=%2024d528fddbfc930044f9ff621f961987 https://www.pmddtc.state.gov/ddtc_public?id=ddtc_kb_article_...
- pstrateman 6y agoThis is pretty obviously a recruiting event. Makes sense that they only want potential recruits to participate.
- someuser54541 6y agoMy work focuses primarily on consumer application development, however cybersecurity and CTF challenges like this have always been an interest. What specific technical skills are required to successfully complete challenges like this?
- amiga 6y agoFor starters, have you participated in a ctf before?
- someuser54541 6y agoNo, I haven't.
- jrwr 6y agoHave you ever had to debug a "blackbox" before, Application code or hardware that you had really nothing to do with and had to figure out how in the hell it works? or worked with embedded devices or embedded radios? Would love to help you out likewise anyway, hit me on up twitter @JRWR
- someuser54541 6y ago> Have you ever had to debug a "blackbox" before, Application code or hardware that you had really nothing to do with and had to figure out how in the hell it works? I suppose so, yes, but probably not to the extent required in some of these challenges. I just read through https://cybersecurity.att.com/blogs/security-essentials/capture-the-flag-ctf-what-is-it-for-a-newbie https://cybersecurity.att.com/blogs/security-essentials/capt... and some of the accompanying write ups[0] on Github which was very insightful. [0]: https://github.com/1337pwnie/ctf-writeups/tree/master/2017/UIUCTF https://github.com/1337pwnie/ctf-writeups/tree/master/2017/U...
- deleted 6y ago[deleted]
- jb775 6y ago$14 billion 2020 budget for the USAF space portfolio[1], $50 thousand prize (split between entire team) to reveal detailed procedure to hack the USAF space portfolio. I feel like they should be a bit more generous here. [1] https://www.af.mil/News/Article-Display/Article/1783601/air-forces-fiscal-2020-budget-focuses-on-modernization-readiness-confronting-gl/ https://www.af.mil/News/Article-Display/Article/1783601/air-...
- HenryKissinger 6y ago"Won the Air Force Space Security Challenge" on your resume is basically a license to k̶i̶l̶l̶ name your own salary with any reputable tech company.
- amiga 6y agoThe winners are certainly a potential threat to national (global?) security. What's the price of a celebrity status like that?
- saagarjha 6y agoAn open offer to work at the NSA?
- tomcooks 6y agoPeople will call you POTUS for 4 years /s
- ackbar03 6y agoYou could ask how the other ctf defcon winners are regarded? The top teams are all pretty hardcore, I always felt they'd be treated specially as well but seems not to be the case
- psifertex 6y agoWon three times, definitely didn't hurt my career.
- leoh 6y agoI'll bet that foreign intelligence people that actually know how to hack satellites are looking at each other and laughing.
- fakedang 6y agoI bet that American intelligence officials looking to snag naive foreign cyber operatives are looking at each other and laughing too.
- d_silin 6y agoWould be interested in any US citizen to join our team. We have the skills, but we are all either Canadian or British, sadly. Email me at contact@exodusorbitals.com P.S. Any cybersecurity experience is an asset, but not a requirement.
- fergbrain 6y agoEmailed
- gjhan 6y agoResponded.
- mawuenash 6y agoSent
- hongseleco 6y agosomething something 5 eyes?
- coretx 6y agoWhy on Earth would you help them militairise outerspace and draw a crosshair on your forehead while being at it ? As if current spacejunk isn't enough of a threat to humanities future in space already. This sounds all awesome at first, but think about it for a second.
- luch 6y agoBecause they would do it anyway. I've heard "stories" of attackers gaining control of a sat, "flipping it" to prevent it from listening to incoming commands, and then asking for a ransom from the original owners.
- Gustomaximus 6y agoAny satellite is likely going up regardless. It may make it safer if you help stop bad actors getting access to what will be there anyway. Some terrorist would probably love to steer one satellite into another... or whatever options control gives.
- coretx 6y agoArmies are organizations build around aggression per definition and therefore _are_ the terrorist in outerspace. The good guys in space are found at civil presence such as the ISS. People from all nations and cultures working together in peace. A symbol of hope for humanity. Much unlike military organizations with boots on the ground.
- mehrdadn 6y ago> Why on Earth would you help them militairise outerspace Why on Earth is an interesting question. Why in space might have some reasons though ;)
- readme 6y agoMan space is going to be militarized no matter what. Haven't you seen star wars?
- scollet 6y ago
- jauer 6y agoBold to expect Defcon to happen this year.
- 4gotunameagain 6y ago>..the ultimate challenge: to (ethically) hack a satellite. I guess "legally" would be the right word here. Ethics are subjective. But who are we kidding, they know exactly why they chose this word.
- viksit 6y agoIs there a pointer on where to read more about challenges like this - technical information on how space com systems work, and what some example CTFs are?
- readme 6y agohere's the guide on how to play in a CTF https://trailofbits.github.io/ctf/intro/find.html https://trailofbits.github.io/ctf/intro/find.html for space comms, search "site:nasa.gov satellite"
- viksit 6y agoThanks, but I was referring to space comms ctfs specifically :) it’s one thing to find a buffer overflow exploit on http but I don’t even know what the carrier protocol for a ku band transponder is called..
- IMAYousaf 6y agoHello. My CS experience is quite elementary, and I'm a decent enough Web Dev and Scientific Programmer. If I wanted to be the type of hacker capable of taking down a Satellite, what would be everything that I would need to learn? I assume that this is super complex (Duh) but am curious as to the actual extent of knowledge required to pull this off.
- rkagerer 6y agoIs the target an actual satellite in space, or is it on the ground / simulated?
- saul_goodman 6y ago"The FlatSat CTF Event occurs with FlatSat hardware and a virtual/simulated space environment." For the uninitiated: when an operator builds a satellite they usually build at least 3 or 4 of the same bird for every one they launch. This includes the initial "FlatSat" which is a fully working prototype but built onto a flat proto-board rather than the launched form factor, this makes troubleshooting easier in the initial stages. Later on these development prototypes can also be used to troubleshoot problems that occur in space. So somewhere there is an Air Force warehouse packed to the gills with all the development and flat-sats that were never intended to fly. Although obviously they would never use real hardware on an event like this for a number of reasons, if they did it would only be for old hardware that's been retired. But still an interesting idea.
- devchix 6y agoBruce Schneier already posit that hack-a-thing challenge is not a good test or proof of whether a thing is vulnerable. Back in the days when everyone was coming out with hash and cipher algo there were bounties offered as PR of how strong thingX was. Not everyone is going to take up a challenge, if I were a real criminal I would discover the vulnerability (if any) and keep it to myself because the exploit, especially a secret one, is worth more than the bounty, and has a longer pay period.
- exabrial 6y agoAgree 100%, if someone was to seriously think and ad-hoc team was a replacement for a formal security audit... well they get what they deserve. I'm not sure where these fall in the mix, but they definitely seem useful, more eyes on a problem the better.
- heyflyguy 6y agoI hope there is a def con this year
- readhn 6y agoIs it just me or is $50K is really low price to pay, almost like a slap in the face, for a satellite level vulnerability? If i remember correctly military satellites often carry civilian comm services: important business communications/financial networks etc. What would be the black market price for something like this? It has to be at least 10x more at $500K as a low end. Realistically a million $+
- gccxsse 6y agoIt looks like a ctf not a bugbounty.
- benbojangles 6y agoWhat SDR uses +6ghz? I heard HackRF only goes to 6ghz but not over?
- ralston3 6y agoAnyone want to participate in this? Please contact