Don’t look up: There are sensitive internal links in the clear on GEO satellites

Nadia Heninger, Annie Dai

39th Chaos Communication Congress (39C3): Power Cycles · Day 2 · Saal One

Overview

In a revealing talk at 39C3, Nadia Heninger and Annie Dai presented their groundbreaking research into the unencrypted data streams broadcast from geostationary (GEO) satellites. Their work, conducted with co-authors Morty Jen, Keegan Ryan, Dave Leven, and Aaron Schulman, demonstrated that with readily available, consumer-grade satellite dish equipment, it is possible to passively intercept a wealth of sensitive internal network traffic from critical infrastructure, military, telecommunications, and financial systems across entire continents.

Watch on YouTube

Visual summary for Don’t look up: There are sensitive internal links in the clear on GEO satellites by Nadia Heninger, Annie Dai
Visual summary for Don’t look up: There are sensitive internal links in the clear on GEO satellites by Nadia Heninger, Annie Dai

Key moments

  1. 0:00 Introduction and research summary
  2. 1:30 Primer on geostationary satellites and their uses
  3. 3:20 Satellites as "dumb repeaters," where encryption happens
  4. 4:00 The naive research plan and new disclosures
  5. 5:00 Choosing cheap, off-the-shelf consumer satellite equipment
  6. 7:30 The challenge of precise satellite dish alignment

Don’t look up: There are sensitive internal links in the clear on GEO satellites

Speakers: Nadia Heninger, Professor, UC San Diego; Annie Dai

Conference: 39C3

YouTube: https://www.youtube.com/watch?v=fM5w7bFNvWI

Overview

In a revealing talk at 39C3, Nadia Heninger and Annie Dai presented their groundbreaking research into the unencrypted data streams broadcast from geostationary (GEO) satellites. Their work, conducted with co-authors Morty Jen, Keegan Ryan, Dave Leven, and Aaron Schulman, demonstrated that with readily available, consumer-grade satellite dish equipment, it is possible to passively intercept a wealth of sensitive internal network traffic from critical infrastructure, military, telecommunications, and financial systems across entire continents.

The core of their discovery lies in the "bent-pipe" nature of GEO satellites, which merely re-broadcast signals without performing any encryption themselves. This often leads organizations to treat satellite links as just another transparent segment of their internal network, neglecting to apply proper end-to-end encryption. The research highlights a significant blind spot in cybersecurity, where highly sensitive data—from phone calls and text messages to SCADA commands and credit card numbers—is exposed in plaintext to anyone with the right setup within the satellite's extensive footprint.

This talk is crucial because it exposes a pervasive vulnerability stemming from decades-old legacy infrastructure, economic disincentives, and a critical lack of visibility into network configurations by the very organizations relying on these satellite links. Heninger and Dai not only detail their methodology for capturing and parsing these complex data streams but also present numerous case studies involving major corporations and government entities, many of whom were unaware their data was being broadcast unencrypted. The findings necessitate an urgent re-evaluation of threat models and defensive strategies for satellite-dependent communications.

Background

▶ Watch: Introduction and research summary (0:00)

Geostationary (GEO) satellites are a cornerstone of global communication infrastructure, providing reliable, continuous coverage over vast geographical areas. Unlike low Earth orbit (LEO) or medium Earth orbit (MEO) satellites, GEO satellites maintain a fixed position relative to the Earth, hovering approximately 35,786 kilometers above the equator. This characteristic makes them ideal for critical applications requiring uninterrupted service, such as television broadcasting, internet backhaul, and various industrial and governmental communications. There are approximately 590 active GEO satellites currently in orbit, each equipped with dozens of transponders that operate across different frequency bands, including KU, KA, and C-band. The research presented focused primarily on the KU band, which is commonly used for satellite television and internet services, making it accessible with smaller, consumer-grade dishes.

A key architectural aspect of GEO satellites relevant to this research is their function as "bent-pipes." In industry terms, they are essentially dumb repeaters. This means no encryption or decryption occurs on the satellite itself; they simply rebroadcast whatever signal is transmitted to them from a ground terminal. Consequently, any encryption must happen before the signal reaches the satellite. This can occur at three primary layers: the link layer (at the terminal), the network layer (router equipment before the terminal), or the application layer (end-user encryption like TLS). The reliability and constant coverage of GEO satellites have led to their adoption in critical, often decades-old, legacy infrastructure. The satellites themselves are designed for operational lifespans of up to 15 years, meaning the underlying communication protocols and security postures can also be quite outdated. Previous academic work has demonstrated the possibility of observing unencrypted data in this domain, particularly in maritime and aviation sectors, but this research significantly expands the scope and impact of such observations.

Key Findings

▶ Watch: Satellites as "dumb repeaters," where encryption happens (3:20)

The research uncovered a widespread and alarming prevalence of unencrypted sensitive data traversing GEO satellite links across various critical sectors. The speakers detailed numerous case studies, categorizing the findings into several key areas:

  1. In-Flight Wi-Fi and Entertainment: Traffic from major in-flight Wi-Fi vendors like Intelsat and Panasonic was found to be largely unencrypted. While end-user web traffic (HTTPS) was often secured, DNS lookups were consistently in plaintext, revealing hostnames visited by passengers. More critically, endpoints for crew software were also exposed. The seatback entertainment systems transmitted scrambled video but unencrypted audio, and surprisingly, partial RSA keys were found, posing a potential cryptographic challenge. Vendors, when disclosed to, dismissed these concerns, likening the service to "cafe Wi-Fi"—a comparison deemed inadequate given the continental scale of the satellite footprints.
  1. Cell Network Backhaul: Perhaps one of the most surprising findings was the extensive unencrypted data from remote cellular towers using satellite backhaul.
  • T-Mobile (US): Full phone call audio and raw text messages were recovered from towers in remote mountainous regions. T-Mobile's swift response revealed they thought their traffic was encrypted via an IPSec tunnel, but it was configured with a null cipher, effectively rendering it plaintext.
  • AT&T Mexico: Control plane data, including session keys, was observed. While AT&T Mexico's response was mixed, the transponders eventually ceased broadcasting this data.
  • Telmex (Mexico): Unencrypted VoIP calls, including SIP setup and raw RTP voice data, were continuously broadcast. Despite multiple disclosure attempts, Telmex did not respond, and the data remains exposed.

The speakers highlighted that while cell phone-to-tower communication is carefully encrypted, the data is often stripped of this radio encryption at the tower and then sent unencrypted over the satellite link, exposing it to continent-wide eavesdropping.

  1. Military and Government Communications:
  • Mexican Government: Unencrypted asset location updates (e.g., GPS coordinates of ships and helicopters) from military data systems were observed. Initial disclosure attempts were ignored, but after local press attention and a query to the Secretary of Defense, the Navy responded, and the specific transponder was taken down. However, other unencrypted traffic from the National Guard persists.
  • US Government (DISA/Navy): New disclosures revealed traffic including IPSec tunnels between US Defense Information Systems Agency (DISA) IP addresses, unencrypted VoIP traffic to a city with a large Navy base, and satellite terminal configuration files referencing Raven satellites with US military codes. This traffic was traced to an Inmarsat Government provider (later acquired by Viasat). The transponders are now inactive, indicating a fix.
  1. Critical Infrastructure:
  • PG&E (Pacific Gas and Electric): Unencrypted data from PG&E's internal networks, including SCADA commands to infrastructure, SNMP traffic (with community strings acting as passwords), and DNP3 protocol data, was intercepted. PG&E was highly responsive, working with the researchers to encrypt their satellite communications. This finding carries significant implications for national security and public safety due to the potential for monitoring or even injecting commands into power grids.
  1. Payment Systems:
  • Sagenet: This service provider, operating its own satellite network for payment systems, was found to be transmitting unencrypted credit card transactions, including full card numbers. Additionally, transactions from the US public food assistance (EBT) system, including partial and full card numbers, balances, and transaction failures, were exposed. Sagenet was responsive and encrypted their traffic.

The systemic issues contributing to these vulnerabilities include:

  • Encryption Overhead: Encryption can add significant overhead (up to 30% for some services) due to additional headers and reduced compression efficiency, creating a technical disincentive.
  • Economic Disincentives: Historically, encryption has been treated as a premium "add-on" service by satellite providers, creating an economic barrier to its widespread adoption.
  • Lack of Visibility and Audit: Many organizations, even highly resourced ones like government agencies, had no effective means to audit their satellite communications. They often believed their data was encrypted, only for it to be exposed due to misconfigurations or contractual complexities.

Technical Deep Dive

▶ Watch: The naive research plan and new disclosures (4:00)

The research methodology employed by Heninger and Dai, along with their team, was a testament to academic ingenuity and persistence, built on a surprisingly modest budget. Their "naive research plan" involved acquiring consumer-grade equipment and systematically exploring the geostationary arc.

Hardware Setup:

The team's primary goal was to establish a low-cost ground station. They opted for readily available, off-the-shelf components operating in the KU band, which is common for satellite TV and easier to pick up with smaller dishes. Their setup included:

  • A motor to precisely point the dish.
  • A standard satellite dish for signal reception.
  • A Low-Noise Block (LNB) downconverter to focus the signal and filter noise.
  • A tuner card (commercial off-the-shelf, designed for satellite TV) to process the signal into a raw byte stream. Notably, this specific tuner card became out of stock and out of production after their paper's publication, highlighting the niche nature of their chosen equipment.

Satellite Alignment and Identification:

Achieving precise alignment was a significant challenge for non-satcom engineers. The process involved:

  1. Initial Alignment: Using an Augmented Reality (AR) tool for an overlay of visible satellites and an SDR (Software-Defined Radio) to observe signal strength. The goal was to find any active satellite along the geostationary arc.
  2. Arc Alignment: Since their motor only provided one degree of freedom, they had to align the motor's sweep to the natural arc of the geostationary satellites, centering on a known satellite.
  3. Satellite Identification: This was a non-trivial reverse engineering task. In some cases, simply running strings on the raw downlink data revealed the satellite's name (e.g., AMC3) and orbital parameters. For KU band, cross-referencing observed TV channel listings with public data proved effective. Once one or two satellites were identified, the known public spacing between GEO satellites allowed them to identify others along the arc by counting degrees.

Data Processing and Protocol Reverse Engineering:

The initial raw byte stream from the tuner card presented a significant hurdle. Early attempts to process internet data were thwarted by the tuner card's default filtering, which optimized for TV formats. A critical discovery by co-author Keegan Ryan was a hidden setting to disable this filter, enabling the capture of much richer data.

Once raw data streams were obtained, the team faced the challenge of parsing them into analyzable formats:

  1. Initial Reconnaissance: Running strings on raw captures often yielded immediate plaintext, such as configuration files or human-readable messages. An amusing example cited was a configuration file for a device, broadcast in plaintext ASCII, and a peculiar sequence that, after a character transposition, revealed "military true" and IP packet headers.
  2. Protocol Dissection: The core of the technical deep dive involved learning and implementing various proprietary and non-standard satellite protocols. While some protocols like DVB-S2 and GSE (Generic Stream Encapsulation) are publicly documented, implementations often deviate or include "quirks" that required extensive graduate student labor and reverse engineering. This process was described as a "monument to suffering" due to the myriad variants and non-standard behaviors.
  3. Custom Parsers: The team developed custom Python-based parsers to transform the raw captures into standard pcap (packet capture) files. These pcaps could then be opened and analyzed using tools like Wireshark, allowing for detailed inspection of network traffic, including IP addresses, protocols, and application-layer data. The code for these parsers, which support multiple protocol variants, has been open-sourced on GitHub, with some YouTubers already demonstrating their own proofs of concept using the tools.

Encryption Layers Observed:

The researchers noted that only about 6% of the observed transponders employed ubiquitous encryption, typically using IPSec tunnels. This highlights the widespread lack of network-layer encryption. Application-layer encryption like TLS/HTTPS was effective for end-user browser traffic, but critical infrastructure and control plane data rarely used it. Crucially, the researchers could only observe the downlink side of communication, as their dish was within the continental footprint, but they did not see the highly directional uplink traffic.

Demo / Proof of Concept

▶ Watch: Choosing cheap, off-the-shelf consumer satellite equipment (5:00)

While the talk did not feature a live, real-time demonstration of intercepting data, the entire research project itself serves as a comprehensive proof of concept for passive satellite eavesdropping. The speakers effectively demonstrated the capabilities of their system by showcasing the results of their data collection and analysis.

The core of their "demo" involved presenting reconstructed pcap files, which are the output of their custom parsing tools. These pcaps, when opened in Wireshark, revealed the full extent of the unencrypted data streams. Examples shared included:

  • A "very funny configuration file" broadcast in plaintext ASCII, providing device information.
  • The "military true" example, where a seemingly unintelligible byte stream, after a specific character transposition, revealed plaintext and IP headers, showcasing the need for their sophisticated parsers.
  • Recovered full phone call audio and raw text messages from T-Mobile's satellite backhaul.
  • SCADA commands and SNMP traffic from PG&E, visible in clear text.
  • Full credit card numbers and EBT transaction details from Sagenet, also in plaintext.

The existence of their open-source Python parsers on GitHub further serves as a public proof of concept, allowing other researchers and enthusiasts to replicate their methodology. They explicitly mentioned that "YouTubers have also already found it and they have published their proofs of concept to YouTube," indicating that the technical feasibility of their findings has been independently validated by the community. This demonstrates that the tools and techniques required to perform this type of surveillance are not only effective but also accessible.

Defensive Implications

▶ Watch: The challenge of precise satellite dish alignment (7:30)

The findings presented by Heninger and Dai have profound implications for defenders across various sectors, necessitating an urgent re-evaluation of security postures for satellite-dependent communications. The core message is clear: satellite links, even for internal networks, cannot be treated as inherently secure or private.

  1. Encrypt Everything on Internal Networks: The most critical defensive measure is to implement end-to-end encryption for all data traversing internal networks, especially when satellite backhaul is involved. The assumption that internal network segments are "trusted" or "private" is fundamentally flawed when those segments extend over continent-sized broadcast footprints. This means moving beyond application-layer encryption like HTTPS for user traffic and ensuring that critical control plane data, VoIP, SCADA commands, and other sensitive internal communications are robustly encrypted at the network or link layers. The example of T-Mobile's null-ciphered IPSec tunnel highlights that merely having encryption mechanisms in place is insufficient; they must be correctly configured and actively enforced.
  1. Rigorous Auditing of Satellite Service Providers and Configurations: Organizations must demand greater transparency and conduct independent, continuous audits of their satellite service providers. This includes verifying that encryption services are not only contracted but also correctly implemented and actively used. The researchers' experience of having to validate fixes for major entities underscores that even highly resourced governments and regulated industries often lack the ability to audit their own satellite communication security. Defenders should treat satellite links as untrusted external networks, regardless of contractual agreements.
  1. Update Threat Models for Telecom and Critical Infrastructure: The traditional threat models for telecom (e.g., compelled legal access, IMSI catchers, undersea cable tapping) must be expanded to include passive, continent-wide eavesdropping on satellite backhaul. For critical infrastructure, the exposure of SCADA commands (DNP3, SNMP) means that not only is confidentiality compromised, but the potential for unauthenticated command injection becomes a serious concern, requiring robust authentication and integrity controls beyond simple encryption.
  1. Beware of Economic Disincentives: The revelation that encryption is often an "add-on" service from satellite providers creates an economic disincentive for security. Defenders must advocate for robust security as a baseline requirement, understanding that the cost of a breach far outweighs the cost of encryption overhead.
  1. Consider LEO Satellite Migration: The speakers noted that the transition to Low Earth Orbit (LEO) satellites like Starlink, particularly for cell network backhaul, offers improved security. These systems often utilize LTE encryption between the satellite and the phone/terminal, potentially closing some of the vulnerabilities observed in GEO systems. Defenders should evaluate such upgrades as a long-term security enhancement.
  1. Defense-in-Depth: The findings reinforce the principle of defense-in-depth. Relying on a single layer of security (e.g., encryption between phone and cell tower) is insufficient if subsequent links in the communication chain are exposed. Every segment, especially those involving broadcast mediums, must be secured independently.

Key Takeaways

  • Widespread Exposure: Sensitive internal network data from critical infrastructure, military, telecom, and financial sectors is being broadcast unencrypted via geostationary satellites across continental footprints.
  • Accessible Eavesdropping: Consumer-grade satellite dishes and open-source tools, combined with reverse engineering, enable passive interception of this data, challenging traditional assumptions about satellite link security.
  • Systemic Vulnerabilities: Issues like encryption overhead, economic disincentives (encryption as an add-on service), and a critical lack of visibility or auditing capabilities by organizations contribute to the problem.
  • Critical Data at Risk: Recovered data includes full phone calls, text messages, session keys, SCADA commands, GPS coordinates of military assets, credit card numbers, and EBT transaction details.
  • Urgent Need for Auditing and Encryption: Organizations must implement end-to-end encryption for all internal network traffic that traverses satellite links and rigorously audit their satellite service providers' configurations, as many are unknowingly broadcasting plaintext data.
  • Updated Threat Models: The security community must update threat models for satellite communications to account for passive, continent-wide eavesdropping, especially for critical infrastructure and government communications.

About the Speaker(s)

Nadia Heninger is a Professor at UC San Diego, specializing in computer security. Her work often involves large-scale empirical analyses of cryptographic systems and network security. She led this significant research project, which involved years of effort to set up the ground station and analyze the intercepted satellite data. Nadia’s expertise in cryptography and systems security provided the foundational knowledge for understanding the vulnerabilities and developing the necessary parsing tools.

Annie Dai is a researcher who contributed significantly to the practical aspects of the project, including the challenging task of aligning the satellite dish and reverse engineering the complex, often proprietary, satellite protocols. Based in Maryland, her involvement highlights the collaborative nature of this academic research.

Keegan Ryan is also a co-author of the research and was present at the conference. He was credited with a crucial discovery during the project: finding a hidden setting in the tuner card software that enabled the unfiltered capture of internet data, a pivotal moment that allowed the team to move beyond just TV channels. He also developed a "fun little algorithm" for partial RSA key recovery mentioned in their paper.

All talks from 39th Chaos Communication Congress (39C3): Power Cycles