Geostationary satellites transmit internet and phone data to areas where conventional cables cannot be laid, but researchers have found that anyone can intercept this sensitive data with equipment costing about $600.
A team of six scholars from the University of Maryland and the University of California stated in a paper published on Monday that "an astonishing amount of sensitive traffic" is being broadcast in plaintext within satellite networks and is unencrypted.
This includes cellular communication encryption keys, citizen text messages, and even traffic data from military systems and critical infrastructure.
The researchers reported that they discovered these issues by installing consumer-grade satellite antennas on the roof of a university building in San Diego, observing 39 geostationary satellites.
"Anyone can passively observe this data with just a few hundred dollars of consumer-grade hardware," the researchers said.
As it is unclear whether providers encrypt the data traffic, the researchers recommend that users take precautions using services like VPNs, which can hide IP addresses and encrypt data.
While messages and voice communications should be conducted through end-to-end encrypted applications like Signal or Telegram, which automatically protect user privacy, satellite communication providers could also offer encryption as an additional feature of their services.
"Encryption should be used at every layer as a deep defense to prevent individual failures. Treat encryption as a necessity, not an add-on," the researchers said.
During the study, the researchers informed several major providers about the issue, which claimed to have taken measures to address it.
"There is no single stakeholder responsible for encrypting GEO satellite communications," they said.
After rescanning the networks used by T-Mobile, Walmart, and KPU, the researchers stated they verified that fixes had been deployed, but also warned that they reserved information about other affected systems as disclosures are still ongoing.
One key reason for the unencrypted data traffic is the associated indirect costs; some remote off-grid receivers cannot afford the hardware and licensing fees, the researchers noted.
At the same time, encryption may complicate troubleshooting network issues and reduce the reliability of emergency services. Others simply do not understand the risks or underestimate the ease and risk of intercepting data.
"While academia and activists have invested significant attention in ensuring that modern web browsers universally use encryption, the focus and emphasis on satellite network communications are much lower," the researchers said.
The study focused on geostationary equatorial orbit (GEO) satellite systems that maintain a fixed position. It did not investigate low Earth orbit systems, such as Musk's Starlink, as that requires more complex receiving hardware.
Related: JPMorgan executives confirm they will offer cryptocurrency trading services but will not directly custody assets
Original article: “Researchers: Satellite Leaking Your Data Is Worse Than Coffee Shop WiFi”
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。