Satellite Snooping Reveals Sensitive Unencrypted Data
Submitted 2 days ago by mesamunefire@piefed.social to technology@lemmy.world
https://hackaday.com/2025/10/27/satellite-snooping-reveals-sensitive-unencrypted-data/
Submitted 2 days ago by mesamunefire@piefed.social to technology@lemmy.world
https://hackaday.com/2025/10/27/satellite-snooping-reveals-sensitive-unencrypted-data/
specialwall@midwest.social 2 days ago
What confuses me is what they mean by “corporate VPN data containing unencrypted login details.” Unless the VPN server connects to the backend servers with unencrypted traffic through these satellites (which definitely should not happen) then this should not be possible.
FauxLiving@lemmy.world 2 days ago
From, the paper: …ucsd.edu/…/dontlookup_ccs25_fullpaper.pdf
These companies are leasing these satellite links for various purposes and then transmitting their network data over the links with no encryption. You can, for about $600 and some software (github.com/ucsdsysnet/dontlookup) read this data.
The researchers discovered data from US Military, Walmart-Mexico, AT&T, Government of Mexico, TelMex, Grupo Santander, Intelsat, Panasonic Avionics, WiBo, KPU. The researchers disclosed the vulnerability to all of these entities between 2024 and 2025.
Someone (I don’t know who but T-Mobile is the only cellular carrier in their list…) was transmitting call and text data, in plaintext:
PancakesCantKillMe@lemmy.world 2 days ago
Yah, I am sure there is a ton of unencrypted data of some form flowing, but anything end-to-end encrypted would be unreadable.
AbidanYre@lemmy.world 2 days ago
Is it even possible to configure something like wireguard so incorrectly that it’s unencrypted?
WhyJiffie@sh.itjust.works 2 days ago
I guess lots of companies still use some ancient proprietary thing
mjr@infosec.pub 2 days ago
It reads like “definitely should not happen” was indeed happening!
I wonder if some techs got a basic unencrypted test working, then a pointy haired boss moved them on to another project and it got deployed into use with no-one setting up the encryption.
MonkderVierte@lemmy.zip 2 days ago
More likely “encryption in satellites is expensive, so let’s not do that. Pennies saved on my quarterly report, yay!”.