frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

There are sensitive internal links in the clear on GEO satellites [pdf]

https://satcom.sysnet.ucsd.edu/docs/dontlookup_ccs25_fullpaper.pdf
79•dweekly•2h ago

Comments

fennec-posix•1h ago
Section 6.3.2 is an eye-opener... good lord... Gets even worse at 6.4.2-3
lambdaone•48m ago
It's absolutely jaw-dropping. Either no-one at these companies was capable of understanding the problem, or no-one cared enough to do something about it.
dweekly•1h ago
Website: https://satcom.sysnet.ucsd.edu/

Wired: https://www.wired.com/story/satellites-are-leaking-the-world...

ROBLOX_MOMENTS•1h ago
Is it correct to Assuming the amount of Mexican companies in this paper is because of their receiver being in the major city southwestmost corner of the country ?
jf•59m ago
That’s my interpretation
fennec-posix•44m ago
Yeah that's correct. The study was conducted in San Diego which falls under the satellite beam footprint required for services in Mexico.

If you were in say, Alice Springs in Australia (wink wink) for example, you'd be able to see traffic for Indonesia, Philippines, most of South East Asia, and perhaps parts of China, South Korea and Japan if the beams are right.

dylan604•31m ago
> wink wink

location location location is an apt phrase for more than just real estate

bediger4000•25m ago
I'm not so good at hints. Are you gesturing at the NSA facility at Pine Gap?
modeless•1h ago
> remarkably, nearly all the end-user consumer Internet browsing and app traffic we observed used TLS or QUIC

There was a surprising amount of resistance to the push to enable TLS everywhere on the public Internet. I'm glad it was ultimately successful.

protocolture•56m ago
Had a vendor offer a customer of mine a huge discount if they purchased radios without the encryption license in the year of our lord 2024.

Not even WPA or WEP. Just clear across the sky. And this is terrestrial.

My bet is that in space there would be a noticable increase in heat/energy if they did encryption by default. But its still incredible to see them pretend like space is impossible to get to, ultimate obscurity.

ryandrake•47m ago
Likely no consequences to the decision-makers for data exfiltration or other shenanigans happening, so there's nothing motivating a behavior change.

The reason security is so bad everywhere is that nobody gets fired when there's a breach. It's just blamed on the hackers and everyone just goes on with life singing "We take security very seriously--this happened because of someone else!"

chii•38m ago
> nobody gets fired when there's a breach

this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).

ryandrake•37m ago
Or, the entity being damaged is not the decision maker and has no power to hold the decision maker responsible.
josephg•34m ago
End user license agreements are a huge part of the problem. Ideally users could sue if our data is leaked - and the threat of being sued would put pressure on companies to take security more seriously. Ie, it would become a business concern.

Instead we're constantly asked to sign one-sided contracts ("EULAs") which forbid us from suing. If a company's incompetence results in my data being leaked on the internet, there's no consequences. And not a thing any of us can do about it.

astrange•18m ago
There is in at least California, the EU, and China. A lot of clauses in EULAs aren't actually legal.
lmm•31m ago
Or the damage is diffuse whereas the costs of preventing the breach would be concentrated. Or the connection between the damage and the breach is difficult to prove.
mjevans•21m ago
Why does Space need to decrypt a vast majority of the traffic? Flow can be just as brick not-smart as fiber optic cables under the sea.

Now, management, control, etc? Yeah those you need to decode in orbit.

dooglius•20m ago
The encryption of the payload doesn't need to take place on the satellites
astrange•19m ago
Encryption is basically free as far as I know, but it is more complex and it must be hard to get software updates up there.
lambdaone•52m ago
Absolutely mind-boggling that this is a thing; not just that satellite links aren't per-user link-encrypted, but also that people are still using unencrypted protocols to exchange sensitive information on the public internet in 2025.
dylan604•34m ago
As with anything in life, when it's what you know and do on the regular, that simple thing can look like magic to others. I met an old timer in the satellite business that came out to help install our receiver for a new TV channel the company I was at was getting off the ground. He found out what bird we were using and what its slot was. Based on that, he knew how many satellites over from the satellite he knew and used as his base. It was a long time running TV channel that he could find very quickly. Once that bird was located, he just manually (literally pushed the dish with his hand) counting the number of satellites that came in/out of view until he landed on "our" bird. Once there, connected our receiver and baddaboom baddabing, there it was. Once the satellite was pointed at the proper angle to the south, it took less than five minutes from him connecting his receiver to verify his base signal to packing up and heading off the roof.

His base satellite signal was unencrypted and a main reason he used it for this purpose. Our channel was scrambled, and only verifiable after our receiver with the decoder was connected. It was impressive seeing someone that good at their job make it look so easy, but after he explained the layman's version of orbital slots it became less magical. This is why magicians are meant to not tell you how the trick is done.

wyager•32m ago
I see no issue with the satellite backhaul itself being unencrypted; anyone using the satellite provider should assume they're hostile and encrypt+authenticate everything they send anyway. I don't trust my ISP's fiber to be snoop-resistant just because they nominally have some shitty ONT encryption.

Obviously the specific examples of end-users failing to encrypt are bad, but that's not really a problem with the satellites.

dsab•8m ago
I was working in space industry and ECSS security guidelines are missleading grant seeking startups to try to reinvent TLS on orbit. There are to mamy bureaucracy. ECSS guidelines for software teams were created by people who never written a Hello World in their life, just look at specs of ECSS Packet Utilisation Service, it's a joke, that's why I prefer to work for VC funded companies than grant funded.

iOS Development with Visual Studio Code: Step-by-Step Setup Guide

https://www.dogancan.dev/blog/iOS-development-with-vscode
1•mlla•4m ago•0 comments

Sora 2 Video Creator

https://www.aisora2.com/
1•DamianLewis•8m ago•0 comments

AI users sue Microsoft in antitrust class action over OpenAI deal

https://www.reuters.com/legal/government/ai-users-sue-microsoft-antitrust-class-action-over-opena...
1•1vuio0pswjnm7•8m ago•0 comments

A Historic Crypto Selloff Erased over $19B, but Two Accounts Made $160M

https://www.wsj.com/finance/currencies/a-historic-crypto-selloff-erased-over-19-billion-but-two-a...
1•mudil•10m ago•0 comments

Why Signal's post-quantum makeover is an engineering achievement

https://arstechnica.com/security/2025/10/why-signals-post-quantum-makeover-is-an-amazing-engineer...
1•qnleigh•11m ago•0 comments

Show HN: Daily Clash Royale Card Guessing Game

https://clashle.app/
1•404NotBoring•13m ago•0 comments

Homely: Home Inventory and Meal Management App

https://drive.google.com/file/d/1zvQRwkxv4x6OqXPQ2CemqLP5T0cEj5mQ/view?usp=sharing
2•nikitakor7•20m ago•0 comments

Show HN: Hexecute, a gesture-based Wayland launcher

https://github.com/ThatOtherAndrew/Hexecute
1•andromedaM31•22m ago•0 comments

Elon Musk Gets Just-Launched Nvidia DGX Spark

https://blogs.nvidia.com/blog/live-dgx-spark-delivery/
2•bcaulfield•27m ago•0 comments

Dalieba

https://en.wikipedia.org/wiki/Dalieba
1•georgecmu•33m ago•0 comments

Crypto tycoon found dead with gunshot wound to the head inside his Lamborghini

https://www.lbc.co.uk/article/crypto-tycoon-dead-gunshot-lamborghini-5HjdFJc_2/
2•anonymousiam•33m ago•0 comments

Stress-relief satisfying web app: Environmental friendly bubble wrap

https://brainteaser.top/bubblespop.html
1•lovegrenoble•34m ago•0 comments

Loveable for Domain Names?

https://www.deepname.co/
1•cybertheory•36m ago•0 comments

There Never Was a West

https://theanarchistlibrary.org/library/david-graeber-there-never-was-a-west#fn_back5
1•anlsh•39m ago•0 comments

Trump Is Now One of America's Biggest Bitcoin Investors

https://www.forbes.com/sites/danalexander/2025/10/10/trump-is-now-one-of-americas-biggest-bitcoin...
3•TheAlchemist•40m ago•1 comments

PDAs: Ancestors of the Smartphones [video]

https://www.youtube.com/watch?v=m7XzvCBb5JU
1•Apocryphon•42m ago•0 comments

Space-Efficient Data Structures for Top-K Completion (2013) [pdf]

http://groups.di.unipi.it/~ottavian/files/topk_completion_www13.pdf
1•todsacerdoti•45m ago•0 comments

Vira Fintech enabled personal assistant

https://efgevira.vercel.app/
1•DreTen2020•45m ago•1 comments

Hubots Service Discovery

https://github.com/hubot-friends/hubot-service-discovery
1•gijoeyguerra•51m ago•1 comments

Show HN: Wordle but you have to predict your score before playing

https://boring.game/invite/SRhyUStjin
4•boringgame•52m ago•6 comments

Redis Backplane for Hubots

https://github.com/hubot-friends/hubot-redis-backplane
1•gijoeyguerra•53m ago•1 comments

Interactive Dashboard to Analyze Express Entry CRS Draws

https://dailistats.netlify.app/?
1•kaypee90•1h ago•0 comments

Before publicly turning on San Francisco, Marc Benioff had privately left

https://sfstandard.com/2025/10/13/publicly-turning-san-francisco-marc-benioff-had-privately-left/
4•donohoe•1h ago•0 comments

RSS – Is It Needed

2•jmspring•1h ago•0 comments

VibeCraft – Starcraft for AI Agents

https://vibecraft.build/
2•rayzhueth•1h ago•1 comments

Apple's streaming service gets harder to tell apart from its streaming app, box

https://arstechnica.com/apple/2025/10/apple-tv-streaming-service-is-renamed-to-just-apple-tv/
3•rurp•1h ago•0 comments

RustPython: A Python Interpreter Written in Rust

https://rustpython.github.io/
3•pykello•1h ago•0 comments

I Is for Intent (2024)

https://acko.net/blog/i-is-for-intent/
1•thunderbong•1h ago•0 comments

New York Times, AP, Newsmax and others say they won't sign new Pentagon rules

https://apnews.com/article/pentagon-press-access-defense-department-rules-95878bce05096912887701e...
25•baobun•1h ago•0 comments

Modifying a Casio F-Series Digital Watch (2020)

https://shellzine.net/casio-f-series-mods/
12•camtarn•1h ago•3 comments