9 ms·
SATCOM terminals under attack in Europe: a plausible analysis
- CrazyStat 5y agoElon Musk mentioned this attack in one of his tweets a few days ago: https://twitter.com/elonmusk/status/1499585449450344451 https://twitter.com/elonmusk/status/1499585449450344451
- teknopaul 5y agoReplying to @elonmusk Is there anything to stop it on starlink? Musk replies "game on". The russians have recently demonstrated their ability to physically take out satelites, and willingness to use it. If Putin did that, creating a lot of debris, US would loose the space advantage and we would push human advancement in to space back by perhaps 1000 years while we wait for the skys to clear. US MUST stop provoking Russia. "game on" is hard to interpret as anything but a flippant challenge to a dangerous man with military resources in space. Is diplomacy that hard to grok?
- CrazyStat 5y agoAppeasing murderous dictators is also a good way to set back human advancement, on the ground and in space. Giving in just because your opponent might do something stupid is equally bad diplomacy.
- AdamJacobMuller 5y agoSeems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target for this for some reason (seems more like Iridium is used in these scenarios).
- lxgr 5y agoKA-SAT seems to be used for SCADA control of 11 Gigawatt worth of wind turbines in Germany, among other things [1]. Not sure at all if this was the intended/primary target, but Europe is certainly scrambling for every Watt at the moment... Also note that KA-SAT/Viasat and Eutelsat seem to be different platforms. I've seen reports of services based on the former being affected (e.g. SkyDSL [2]), but not the latter (Konnect), so far. I was also surprised to learn that Ka-band based stationary consumer satellite internet services seem to be using (mostly) plain DOCSIS as the protocol. That possibly introduces its own share of vulnerabilities due to OTA updates/provisioning. [1] https://thestack.technology/viasat-ka-sat-outage-cyber/ https://thestack.technology/viasat-ka-sat-outage-cyber/ [2] https://www.connexionfrance.com/French-news/Thousands-in-France-lose-internet-in-suspected-Russian-cyberattack https://www.connexionfrance.com/French-news/Thousands-in-Fra...
- adrr 5y agoTaking a country's infrastructure through a cyberattack is considered an act of war. Same as if you bombed the power generation infrastructure.
- toxik 5y agoSure, but can you prove it to the public in enough certainty to declare war? No. Suppose it was Russian flag, they could very easily just claim they were framed - and they very likely could’ve been.
- krisoft 5y ago> Sure, but can you prove it to the public in enough certainty to declare war? This is not a court of law, proof is not what is missing to declare a war against Russia. They have a credible nuclear deterent, that is why war is not declared against them by other countries. It is in fact a very sweet idea to think that a war declaration depends on meeting or not meeting some evidentiary standard.
- Nextgrid 5y agoI've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the web UI and any services you don't use, considerably shrinking the attack surface to pretty much just the kernel). And don't get me started on mobile network equipment where untrusted data is parsed at the kernel level and the motto is still security by obscurity (and the impossibility to obtain said equipment for the average Joe). What I think happened is that they breached the control infrastructure which gives them access to an "internal" VLAN that the satellite terminals use to communicate with the mothership for firmware updates, configuration changes, etc, and from there were able to attack these as if they were locally connected (or worse - since that network segment is presumed "internal" and may expose services not normally available - think whatever is the TR-069 equivalent for BGAN terminals), either just pushing an incorrect configuration that prevents the terminal from connecting (essentially bricking it until you can get out-of-band access and reconfigure it properly) or obtaining root (via exploit or pushing a specially-crafted firmware update) and overwriting /dev/mtd* to completely kill the terminal. "Cyberattack on satellite network" sounds so serious but I very much doubt it's got anything to do with the satellite part of it. They've done the equivalent of breaching into the management network at a terrestrial, wired ISP and sent garbage configuration over TR-069 to brick the modems. Attacking the satellite layer would require much more effort for essentially the same gain (and if your objective was to get into the satellite layer, why waste that access on breaking everything in a highly-visible way when you're better off silently sitting there and using the access to eavesdrop on everything, especially when it's used for SCADA traffic of critical systems that's itself unencrypted and vulnerable to tampering?).
- bewaretheirs 5y ago> why waste that access on breaking everything in a highly-visible way when you're better off silently sitting there and using the access to eavesdrop on everything The subtle approach takes more time. Take the PoV of the hypothetical Russian decision maker.. you can either take all them down now with something quick & dirty while the tanks are rolling, or inject a stealthy targeted piece of malware you haven't finished yet next week after Kiev is already in the hands of a puppet government....
- CoastalCoder 5y agoCan someone versed in military doctrine / strategy talk about dealing with the uncertainty of a false-flag attack? Does the best-known approach just boil down to weighing the cost/benefit of (acting | not acting) x P(most likely aggressor | some other cause)? Or has someone figured out a better approach?
- nonomaybeyes 5y agoThe purpose of a false flag is to drive a certain narrative, so it's always accompanied by incessant media coverage. That is not the case here, the attack is likely for genuine tactical purposes.
- CoastalCoder 5y ago> That is not the case here Are you sure that false-flag attacks always involve a media blitz? Just thinking that if I were planning a false flag, and I know that people would recognize it as such because of the media blitz, then I'd look for a workaround. That seems consistent with what we have here.
- numbsafari 5y agoWhat’s the point of a false flag if nobody knows about it? See GP… the point of a false flag is to drive a narrative. Otherwise you are just damaging yourself for no reason.
- hammock 5y agoDo you have an example of a false flag without a media circus around it?
- CoastalCoder 5y ago> What’s the point of a false flag if nobody knows about it? I agree. A false-flag attack is all about optics. But IIUC the GP, they're saying the SATCOM failure isn't widely known, so it wouldn't make sense as a false-flag attack. That's where GP loses me. Because we are discussing it here, as members of the general public. And the discussion isn't limited to a small nerdy site like HN; it's also being covered by Reuters [0]. [0] https://www.reuters.com/business/energy/satellite-outage-knocks-out-control-enercon-wind-turbines-2022-02-28/ https://www.reuters.com/business/energy/satellite-outage-kno...
- Animats 5y agoAny other sources on this yet? This, if real, is big enough there should be multiple news articles.
- lxgr 5y agoThe outage itself has already been widely reported (at least in EU media), especially the (potential) impact on wind electricity generation capacities: https://www.reuters.com/business/energy/satellite-outage-knocks-out-control-enercon-wind-turbines-2022-02-28/ https://www.reuters.com/business/energy/satellite-outage-kno...
- ridaj 5y agoWould Russia (assuming it's the source of this attack) have suffered collateral damage / friendly fire on its own satellite terminals?
- walrus01 5y agoI have personally seen that a lot of "cheap" point to multipoint contended access VSAT modems have very little security on them. Would not be surprised in the slightest if something like a new firmware load or configuration push coming from the hub of the network was not properly validated by the modems using a secure crypto key/signature method. Keep in mind that what we're talking about here is the European equivalent of the viasat/hughesnet/wildblue low cost, highly contended access geostationary vsat modem service. It's about the cheapest possible thing you can buy that is two way IP data via geostationary at 64:1 oversubscription ratio or more. There are very demanding economics factors in play that require the company to make the end user terminal hardware as absolutely cheap as possible, for all of the sub components (physical dish/mounting, LNB, Tx/BUC/SSPA, cabling, and modem).
- Scoundreller 5y agoWell, if my paytv CPE experience means anything here… One brand of electronic countermeasure would cause a firmware write that wouldn’t allow the receiver to boot because you’re a lazy hacker that didn’t lock the flash chip at the hardware WE pin level. There were a couple of strategies to resolve: 1) remove chip and re-program (not fun on TSOPs) 2) JTAG reprogram (easy and cheap when computers had parallel ports: just some wires and a DB25 connector and the port can bit bang everything) 3) the device does a Power on self test. If it detects a corrupted flash file, it will grab a fresh and clean one from the satellite stream and overwrite your nasty one. You can trigger this by shorting/grounding the right address lines on the flash chip at the right time in the self-test. It won’t pass checksum validation and will think a corrupted update occurred and rewrite it. That was all for the parallel flash chip (a 28 or 29f series I think). If it was a serial flash chip like a 24 series, that would be even easier to deal with.
- osmode 5y agoviasat under attack? probably by a 3rd grader. #ViaShat
- sbierwagen 5y agoSimultaneously, Russian ground forces have had a hell of a time using their encrypted radios, resulting in the logistical and tactical omnishambles observed by many, and fallback transmitting in the clear using civilian ham radios or cell phones. Some have attributed this to difficulty in distributing encryption keys to forward units or just general incompetence, but one fun theory I saw on twitter is that Russia uses SDRs somewhere in their radio net and a similar poison packet bricked them all.
- rasz 5y agohttps://twitter.com/ralee85/status/1367614591698690056 https://twitter.com/ralee85/status/1367614591698690056 >Interfax reports that the Deputy Chief of the General Staff and the most senior communications officer in the Russian military, Colonel General Khalil Arslanov, has been arrested for fraud in relation to the purchase of special equipment. >The case involves Colonel Pavel Kutakhov, who was arrested last week for stealing an estimated 30 M RUB from an 800 M RUB contract for comm systems. 30M rubles, pocket change >Kommersant reports that Colonel General Khalil Arslanov, head of Russia's Signal Troops and Deputy Chief of the General Staff, was charged in the theft of 2.2 B RUB and was hospitalized after suffering a hypertensive crisis during his interrogation 2B rubles, now we are starting to talk real money >After expanding their investigation, investigators discovered that Russian troops had received equipment that was made in China even though it was supposed to be from Russia (they changed the labels). >The investigation isn't limited to 2.2 B RUB worth of theft, but also to fraud related to contracts for the Azart comm system built by NPO Angstrem JSC and Yaroslavl Radio Plant. Of 18 B RUB spent on the radios, 6.5 B RUB might have been stolen due to artificially high prices 6B rubles, ouch >Arslanov says that they saved so much on the purchase of R-187-P1 Azart radios, 6.7 B RUB of the contract's 18.5 B RUB was allegedly embezzled, because the radios were purchased from China in almost finished form with some components added in Russia so corruption and potentially backdoored by China and this is how you end up with https://twitter.com/radio_research/status/1500847259948236802 https://twitter.com/radio_research/status/150084725994823680... Chechen soldiers wearing 3 non military radios (susceptible to basic radio finding/tracking), one being Motorola DRM and two analogs.
- warner25 5y ago
- Sporktacular 5y agoIt's not clear how any of the suggested attacks constitute 'permanent' damage: disabling the transmitter, corrupting the antenna pointing logic, demod, power params can all be solved by reflashing the firmware and FPGAs. Not always simple but possible at least by the manufacturer. One way to really destroy a transmitter is to transmit at full power without an antenna attached. Another is to burn the receiver front end by directing the full transmitter output to the receiver input. If the RF path is configured with software controlled RF switches a hack could burn out the front end circuitry for good. All depends on how permanent we're talking.
- stephen_g 5y agoCan confirm that this kind of software is terrible. I've worked in SATCOM for years, we've deployed modems to military that have hardcoded passwords for web UI and SSH that you can google on the internet... Obviously some effort goes into firewalling all that off very carefully, and then often separate VPN over the top (hardware crypto, etc.), but the modems themselves are appalling. The SSH host keys also change when you do a firmware upgrade which makes me think that might be hardcoded and just changed in each version, not generated for each device... I haven't checked though. Unfortunately that was the modem that the satellite operator required us to use, there was no other option!
- BartekVSAT 5y agoIf someone have access to bricked modem and can ship it for analysis we can try to collect evidence what happen and how modem was bricked - who knows, may be log partition wasn't overwritten or other artefacts are left (significant events like update are permanently logged). As side effect, recovery instruction can be created. Best contact point is via https://www.satsig.net/cgi-bin/yabb/YaBB.pl?num=1646161484 https://www.satsig.net/cgi-bin/yabb/YaBB.pl?num=1646161484