https://www.theregister.com/2023/08/11/satellite_hacking_black_hat/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal Tech (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Blackhat and DEF CON Sysadmin Month The Reg in Space Emerging Clean Energy Tech Week Spotlight on RSA Energy Efficient Datacenters Vendor Voice Vendor Voice Vendor Voice All Vendor VoiceAmazon Web Services (AWS) Business Transformation DataikuDDNGoogle Cloud for StartupsHewlett Packard Enterprise: AI & ML solutionsHewlett Packard Enterprise: Edge-to-Cloud PlatformIntel vProVMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [blackhatan] Black Hat and DEF CON 27 comment bubble on white Want to pwn a satellite? Turns out it's surprisingly easy 27 comment bubble on white PhD student admits he probably shouldn't have given this talk icon Iain Thomson Fri 11 Aug 2023 // 13:01 UTC # Black Hat A study into the feasibility of hacking low-Earth orbit satellites has revealed that it's worryingly easy to do. In a presentation at the Black Hat security conference in Las Vegas, Johannes Willbold, a PhD student at Germany's Ruhr University Bochum, explained he had been investigating the security of satellites. He studied three types of orbital machinery and found that many were utterly defenseless against remote takeover because they lack the most basic security systems. "People think that satellites are secure," he said. "Those are expensive assets and they should have encryption and authentication. I assume that criminals think the same and they are too hard to target and you need to be some kind of cryptography genius. Maybe it wasn't a good idea to give this talk." [blackhatan] Satellite operators have been lucky so far. The prevailing wisdom is that hacking this kit would be prohibitively expensive due to the high cost of ground stations that communicate with the orbital birds, and that such hardware benefited from security by obscurity - that getting hold of the details of the firmware would be too difficult. Neither is true, the research indicates. Those are expensive assets and they should have encryption and authentication. I assume that criminals think the same and they are too hard to target For example, both AWS and Microsoft's Azure now offer Ground Station as a Service (GSaaS) to communicate with LEO satellites, so communication is simply a matter of plonking down a credit card. As for getting details on firmware, the commercial space industry has flourished in recent years and many of the components used on multiple platforms are easy to buy and study - Willbold estimated a hacker could build their own ground station for around $10,000 in parts. As an academic, Willbold took a more direct approach. He just asked satellite operators for the relevant details for his paper [PDF]. Some of them agreed (although he did have to sign an NDA in one case) and the results somewhat mirrored the early computing days, when security was sidelined because of the lack of computing power and memory. [blackhatan] [blackhatan] He studied three different types of satellite: an ESTCube-1, a tiny CubeSat 2013 running an Arm Cortex-M3 processor, a larger CubeSat OPS-SAT operated by the European Space Agency as an orbital research platform, and the so-called Flying Laptop - a larger and more advanced satellite run by the Institute of Space Systems at the University of Stuttgart. * Viasat probe into ailing $700M satellite casts shadow over Q1 results * US National Cyber Director: Fending off cyber threats in space is 'urgent,' needs 'high level attention' * It's that time of the year again: The trinity of infosec conferences The results were depressing. Both the CubeSats failed at a most basic level, with no authentication protocols, and they were broadcasting signals without encryption. With some code Willbold would have been able to take over the satellites' basic control functions and lock out the legitimate owner, which he demonstrated during the talk with a simulation. The Flying Laptop was a different case, however. It had basic security systems in place and tried to isolate core functions from interference. However, with some skill, code, and standard techniques, this satellite too proved vulnerable. Low priority Intrigued by the results, Willbold decided to dig deeper. He contacted developers working on sat systems to check the data, and got nine responses from devs who worked on a total of 132 satellites over their careers. This wasn't easy - it took four months to garner those responses. The results showed that security systems were way down on the list of priorities when it comes to satellite design. Only two of the respondents had tried any kind of penetration testing. The problem, he opined, was that space science is such a rarefied field that the developers just didn't have the security skills to do a rigorous shakedown of a satellite in the first place. Composition of the Moonlighter satellite orbiting Earth Uncle Sam wants DEF CON hackers to pwn this Moonlighter satellite in space READ MORE One surprising result was that the larger the satellite (and thus more expensive to build and launch), the more vulnerable it was. Larger machinery typically used more commercial off-the-shelf components and was thus more vulnerable since the code base was public, whereas smaller CubeSats tended to use custom code. As for what would happen if a satellite was hijacked, Willbold suggested a number of alternatives. They could be used to transmit malicious information or code to targets on the ground, or to talk to other satellites in a constellation and subvert those too. In a worst-case scenario, a satellite could be moved to crash into another one, spewing debris all over orbit and potentially knocking out more systems. When asked by The Register if it would be possible to retrofit security systems to satellites, Willbold wasn't hopeful. [blackhatan] "From a very technical perspective it would be possible. But realistically these systems are built on very tight margins," he said. "They have planned these systems for every milliwatt of power that is used to run the satellite, so there is not the power budget on existing systems to run encryption or authentication. It's not practical." (r) Get our Tech Resources # Share More about * Black Hat * Satellite * Security More like these x More about * Black Hat * Satellite * Security * Space Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Artemis * Asteroid * Astronomy * Authentication * BEC * Black Hat Asia * Black Hole * BSides * Bug Bounty * Common Vulnerability Scoring System * CSA * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Earth * Encryption * ESA * Exomoon * Exoplanet * Exploit * Firewall * Galaxy * Hacker * Hacking * Hacktivism * Hubble Space Telescope * Identity Theft * Incident response * Infosec * ISS * James Webb Space Telescope * JAXA * Kenna Security * Moon * NASA * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * Roscosmos * RSA Conference * Solar System * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust More about # Share 27 comment bubble on white COMMENTS More about * Black Hat * Satellite * Security More like these x More about * Black Hat * Satellite * Security * Space Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Artemis * Asteroid * Astronomy * Authentication * BEC * Black Hat Asia * Black Hole * BSides * Bug Bounty * Common Vulnerability Scoring System * CSA * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Earth * Encryption * ESA * Exomoon * Exoplanet * Exploit * Firewall * Galaxy * Hacker * Hacking * Hacktivism * Hubble Space Telescope * Identity Theft * Incident response * Infosec * ISS * James Webb Space Telescope * JAXA * Kenna Security * Moon * NASA * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * Roscosmos * RSA Conference * Solar System * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Farewell, Aeolus: Doomed ESA weather sat reenters atmosphere over Antarctica Video Not quite a controlled deorbit but not an uncontrolled one, either Science1 Aug 2023 | 5 Shifting to two-factor auth is hard to do. GitHub recommends the long game Black Hat Slow and steady wins this race with users Black Hat and DEF CON10 Aug 2023 | 11 Can 'Mad Libs for incident response' prevent the next MOVEit fiasco? Black Hat IBM X-Force lead says yes Black Hat and DEF CON9 Aug 2023 | 5 How to bridge data silos and enable cloud-like efficiency within on-prem infrastructure Unlocking data potential with HPE GreenLake Sponsored Feature [blackhatan] Voyager 2 found! Deep Space Network hears it chattering in space Not all heroes wear capes - some are 50-year-old antennas Science2 Aug 2023 | 82 CISA boss says US alliance with Ukraine over past year is closer than Five Eyes Black Hat And maybe shore up that critical infrastructure some more, America Black Hat and DEF CON10 Aug 2023 | 6 Ukraine's Victor Zhora: Russia's cyber 'war crimes' will continue after ground invasion ends Black Hat International laws needed 'to bring accountability' govt chief tells The Reg Black Hat and DEF CON9 Aug 2023 | 18 Infosec imposter syndrome is real. Here's something that can help Black Hat Talk about an insider threat Black Hat and DEF CON10 Aug 2023 | 7 Viasat probe into ailing $700M satellite casts shadow over Q1 results 'We understand the risks involved in space systems, and have insurance' Networks10 Aug 2023 | 1 Airbus to help with International Space Station replacement Orbiter is supposed to be ready by 2028, so JV partners had better hurry Science3 Aug 2023 | 41 Microsoft, Intel lead this month's security fix emissions Patch Tuesday Downfall processor leaks, Teams holes, VPN clients at risk, and more Patches8 Aug 2023 | 8 Sneaky Python package security fixes help no one - except miscreants Good thing these eggheads have created a database of patches Patches26 Jul 2023 | 10 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2023 no-js