# Possible to steal a satellite? Stranger, you are being paged...

**URL:** <https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948>\
**Category:** Factual Questions\
**Created:** [March 17, 2014, 8:39pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948 "2014-03-17T20:39:37Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Habeed](https://avatars.discourse-cdn.com/v4/letter/h/a587f6/32.png) [@Habeed](https://boards.straightdope.com/u/Habeed)\
**Post date:** [March 17, 2014, 8:39pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/1 "2014-03-17T20:39:37Z")

</div>

So, there’s lots of communication satellites in space. These things can be given commands via radio from the ground. There must be an encryption method used to authenticate said commands.

The private companies that build communication satellites (such as Orbital sciences) must have copies of the encryption keys. Also, their clients (the government, telecom companies, etc) must have copies as well or they would not be able to order their satellites to do things.

High security costs money. I’m imagining that the keys are probably on some ruggedized laptop or printed out in some file folder with CONFIDENTIAL stickers on it.  
The laptop/files are probably kept in a safe or a vault when not in use.

But how secure could they possibly be? A crack team of commandos guarding them 24/7 doesn’t sound affordable. It’s doubtful the vault is a fancy one like at Fort Knox. I’m imagining an ordinary office building with perhaps 1-2 aging security guards patrolling it at night. The vault is probably no nicer than a medium range bank vault, if that.

So couldn’t a team of crack thieves, kitted out in the cool gear, plausibly steal the encryption keys and hijack a satellite? I’m sorta imagining a team in ninja suits sneaking their way in the building, stopping at key junction boxes to disable the security system. (they basically just clip the wires going to the modem and the audible alarm and use a cell phone jammer to block the system from calling for help).

They taser the guards and tie em up and use shaped charges to blow open the vault instantly. They grab the secure files and run. In the hours before dawn, before the theft is discovered, some elite hacker types frantically analyze the source code (that they stole) to the satellite’s control systems. They change the keys and digitally sign their firmware patch, and, using cobbled together antenna, send the satellite a firmware patch to change the keys permanently.

After that, they hold the satellite ransom for (pinkie in mouth) 1 MILLION dollars in bitcoins…

---

<div class="post-metadata">

**Author:** ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)\
**Post date:** [March 17, 2014, 8:52pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/2 "2014-03-17T20:52:21Z")

</div>

Hollywood uses ninja suits and explosives. In the real world the satellites are just hacked.

> [@](#):
>
> The successful attacks occurred in 2007 and 2008. The more serious of the two happened in ’08 when NASA had control of the Terra EOS earth observation system satellite disrupted for 2 minutes in June, and then a further 9 minutes in October. During that time, whoever took control had full access to the satellites’ systems, but chose to do nothing with it. The second hack affected the Landsat-7 satellite on two occasions, one in October of ’07, the other in July of ’08. Unlike the Terra OS incident, this hack did not see control taken away, but access was gained.

Full article here:  
[http://hplusmagazine.com/2013/04/04/hacking-satellites/](http://hplusmagazine.com/2013/04/04/hacking-satellites/)

---

<div class="post-metadata">

**Author:** ![Nanoda](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Nanoda](https://boards.straightdope.com/u/Nanoda)\
**Post date:** [March 18, 2014, 2:46am UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/3 "2014-03-18T02:46:27Z")

</div>

:dubious: That seems over the top even for a CSI episode.

How about I use one of the many generic virus toolkits around to put a virus on some USB keys, drop them in the satellite company parking lot, then do whatever from the comfort of my local coffee shop? Then I don’t have to split my bitcoins with those ninja whatchamadealies that probably aren’t cheap. (Or the pirate-assassins you’re gonna need to kill the ninja-commandos, right?)

---

<div class="post-metadata">

**Author:** ![j\_sum1](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@j\_sum1](https://boards.straightdope.com/u/j_sum1)\
**Post date:** [March 18, 2014, 6:17am UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/4 "2014-03-18T06:17:14Z")

</div>

> [@Nanoda](#):
>
> :dubious: That seems over the top even for a CSI episode.
> 
> How about I use one of the many generic virus toolkits around to put a virus on some USB keys, drop them in the satellite company parking lot, then do whatever from the comfort of my local coffee shop? Then I don’t have to split my bitcoins with those ninja whatchamadealies that probably aren’t cheap. (Or the pirate-assassins you’re gonna need to kill the ninja-commandos, right?)

If you want. But remember than in Hollywood you have to do the whole lot on a Mac.

---

<div class="post-metadata">

**Author:** ![andrewm](https://avatars.discourse-cdn.com/v4/letter/a/c57346/32.png) [@andrewm](https://boards.straightdope.com/u/andrewm)\
**Post date:** [March 20, 2014, 2:00pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/5 "2014-03-20T14:00:03Z")

</div>

Seems like a lot of effort and risk for the reward.

- I think there would be a lot of time and expense in preparing: finding out exactly where the data is stored, reverse-engineering the control protocols / building your own control software (this sort of thing does _not_ get done in a couple hours!), transmitters and antennas to actually send the control signals, etc. For the number of people and time required, the payoff probably wouldn’t be that great.

- The break&enter half of the team would probably be better off dealing in physical goods that could be fenced, rather than dealing with risky ransom.

- The software people should be able to get absolutely risk-free well-paying employment.

- Assuming physical security at these places currently isn’t great, you probably couldn’t pull this off very many times before that changed.

---

<div class="post-metadata">

**Author:** ![nevadaexile](https://avatars.discourse-cdn.com/v4/letter/n/eb8c5e/32.png) [@nevadaexile](https://boards.straightdope.com/u/nevadaexile)\
**Post date:** [March 20, 2014, 2:15pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/6 "2014-03-20T14:15:05Z")

</div>

Why not get an operative hired into the satellite firm (assuming that we are talking about a private company, not a government agency) and have that individual learn enough about the company’s security and processes to have them access the satellite from the headquarters? Then have the person perform whatever task that you intending and have them leave the company shortly thereafter.

Or…put someone ( male or female) in the path of the person who you know has the necessary access to control the satellite. After a whirlwind sexual relationship, have that person begin to gather information for you and allow you to gain access to the satellite company’s internal organization,including security details,passwords, telemetry,etc.

Or…locate a brilliant , but disgruntled employee. Either through bribes or guile have that person provide you with all of the necessary information to access the satellites and use that as when you see the need. Or have that person create a “back door” program for you to access the system yourself (assuming that it’s not an INTRAnet). Or have that person secretly gather other employees pass codes and use them to disguise his involvement in your accessing the satellite.

The limits are really the imaginations of the people who want to take over the satellite for whatever purpose.

---

<div class="post-metadata">

**Author:** ![busterpickle](https://avatars.discourse-cdn.com/v4/letter/b/258eb7/32.png) [@busterpickle](https://boards.straightdope.com/u/busterpickle)\
**Post date:** [March 21, 2014, 1:57pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/7 "2014-03-21T13:57:46Z")

</div>

The problem is that when they had originally designed the satellites there was no concept of security. It was deemed to far-fetched for anyone to actively pursue them due to technology constraints. Think security like back in the 80’s with “password, password” or “admin, admin” to get in. However, that main road block, SATCOM equipment, can now be found all over places like eBay, etc., as the terrestial stations are upgraded.

Can this equipment be used to go after the latest satellites? No. But, there are a whole lot of satellites that are still up there that can be accessed. True, one would need a largish SATCOM dish to accomplish this but it’s not the typical hacker that is going after them, it’s enemy states that are. They do have the resources as most countries that I can think of that we would need to worry about have terrestrial SATCOM stations. With relatively little effort one could take over any of the older, non-secured, satellites.

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [March 21, 2014, 2:08pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/8 "2014-03-21T14:08:11Z")

</div>

What about physically stealing it, would also count. We can dock with satellites and grab them with robotic arms, how likely is that to be able to happen? (yes this assumes having a spacecraft).

---

<div class="post-metadata">

**Author:** ![nevadaexile](https://avatars.discourse-cdn.com/v4/letter/n/eb8c5e/32.png) [@nevadaexile](https://boards.straightdope.com/u/nevadaexile)\
**Post date:** [March 21, 2014, 3:12pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/9 "2014-03-21T15:12:24Z")

</div>

> [@kanicbird](#):
>
> What about physically stealing it, would also count. We can dock with satellites and grab them with robotic arms, how likely is that to be able to happen? (yes this assumes having a spacecraft).

James Bond films aside, it is impossible for a state-level actor (the only ones who could launch a spacecraft into orbit at this time) to surreptitiously launch a rocket, put a craft into orbit,approach a satellite and then attempt to forcibly retrieve it using the launched craft without all of those activities being detected by another state-level actor.

The nation(s) which did this would have to do some serious explaining as to what they were doing, had done or were going to do with the satellite that they seem to have purloined. Depending on the state of affairs and the reasons given, the other state-level actor might take a number of actions against the offending state, none them of very pleasant.

Finally, there’s the problem of what anybody would **DO** with a satellite stolen from orbit. It couldn’t be ransomed, it couldn’t be sold and it probably couldn’t be used making simply snatching an expensive exercise providing no tangible benefits for the purloiner.

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [March 21, 2014, 6:08pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/10 "2014-03-21T18:08:29Z")

</div>

> [@nevadaexile](#):
>
> James Bond films aside, it is impossible for a state-level actor (the only ones who could launch a spacecraft into orbit at this time) to surreptitiously launch a rocket, put a craft into orbit,approach a satellite and then attempt to forcibly retrieve it using the launched craft **without all of those activities being detected by another state-level actor.** …

First is there such a James Bond movie? which one?

Anyway

Bold mine

Such a action I would expect to be noticed - that would be the point, but the main point is that nation has the power to do so and is using it. Expressing superiority in space and to hold the world ransom and establish protocols, precedents and fees for country ‘overflights’. The reason for taking such a satellite would be enforcement for not paying such fees, investigation of potential spying, and also other ‘illegal’ activities such as relaying internet which portions of that may be banned in the country.

---

<div class="post-metadata">

**Author:** ![Stranger\_On\_A\_Train](https://avatars.discourse-cdn.com/v4/letter/s/13edae/32.png) [@Stranger\_On\_A\_Train](https://boards.straightdope.com/u/Stranger_On_A_Train)\
**Post date:** [March 21, 2014, 6:16pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/11 "2014-03-21T18:16:26Z")

</div>

> [@nevadaexile](#):
>
> Finally, there’s the problem of what anybody would **DO** with a satellite stolen from orbit. It couldn’t be ransomed, it couldn’t be sold and it probably couldn’t be used making simply snatching an expensive exercise providing no tangible benefits for the purloiner.

The primary advantage would be a denial of service (DoS) type attack. In theory, someone could hold a satellite hostage, or even potentially use it to threaten other satellites. The satellite and telecommunications industry originally had little in the way of security (despite that cautionary documentary of _Dr. No_) but they have since learned of the need for secure authentication and encrypted telemetry (two separate but related capabilities) and most modern satellites have reasonably sophisticated authentication protocols. The obvious method of making sure that any single set of authentication or encryption “keys” are not compromised is to have multiple sets of keys or several different key sets which allow recovery of command authority and lockout in the case of compromise, and thus, the _Die Hard_/_Mission Impossible_ scenario can be averted by robust security protocols.

Stranger

---

<div class="post-metadata">

**Author:** ![Stranger\_On\_A\_Train](https://avatars.discourse-cdn.com/v4/letter/s/13edae/32.png) [@Stranger\_On\_A\_Train](https://boards.straightdope.com/u/Stranger_On_A_Train)\
**Post date:** [March 21, 2014, 6:19pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/12 "2014-03-21T18:19:37Z")

</div>

> [@kanicbird](#):
>
> First is there such a James Bond movie? which one?

The patently absurd _You Only Live Twice_ (the first Bond film that had nothing whatsoever to do with the source material, and the first to feature ninjas and a giant volcanic fortress).

> [@kanicbird](#):
>
> Such a action I would expect to be noticed - that would be the point, but the main point is that nation has the power to do so and is using it. Expressing superiority in space and to hold the world ransom and establish protocols, precedents and fees for country ‘overflights’. The reason for taking such a satellite would be enforcement for not paying such fees, investigation of potential spying, and also other ‘illegal’ activities such as relaying internet which portions of that may be banned in the country.

There are far easier ways of doing this than attempting to “take over” a satellite, and any nation with the ability to threaten another country’s satellites will almost certainly have satellites of their own which are similarly vulnerable.

Stranger

---

<div class="post-metadata">

**Author:** ![CalMeacham](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/calmeacham/32/35_2.png) [@CalMeacham](https://boards.straightdope.com/u/CalMeacham)\
**Post date:** [March 21, 2014, 11:27pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/13 "2014-03-21T23:27:52Z")

</div>

> [@](#):
>
> The patently absurd You Only Live Twice (the first Bond film that had nothing whatsoever to do with the source material, and the first to feature ninjas and a giant volcanic fortress).

Well, it DID have Ernst Stavro Blofeld in command, and was set in Japan, and had “Tiger” Tanaka, and, after all, a volcano is close enough to mud geysers. But, yeah, it was the first to deviate significantly from the source. Blame Fleming, for being dead, and his pal Roald Dahl (Roald Dahl! Of Willie Wonka and The Witches and other great stuff!) for the whacko script. (He wrote about the experience in _Playboy_, which gives the impression that he wasn’t all that much in charge)  
But the ninjas were cool\*. And everybody always cheers when the swordsman takes out all the SPECTRE bad guys and re-sheathes his _katana_.  
\*the first major western movie I know to feature ninjas.

---

<div class="post-metadata">

**Author:** ![CalMeacham](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/calmeacham/32/35_2.png) [@CalMeacham](https://boards.straightdope.com/u/CalMeacham)\
**Post date:** [March 21, 2014, 11:43pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/14 "2014-03-21T23:43:18Z")

</div>

A more credible fictional treatment is Larry Niven and Steven Barnes’ 1982 novel _The Descent of Anansi_.

> **[The Descent of Anansi](https://en.wikipedia.org/wiki/The_Descent_of_Anansi)**
>
> The Descent of Anansi is a 1982 science fiction novel by American writers Steven Barnes and Larry Niven.
> A space station manufactory attempts to become commercially independent from its government backers by exporting super-strong nanowire that can only be manufactured in free-fall.
> Following an attempt to sabotage their first delivery and hijack the cargo, the intrepid crew realizes they can escape the hijackers. Their shuttle Anansi can become a modern-day version of its namesake, an African ...

What’s that? Sinclair molecule chains don’t exist? Well, imagine it’s using carbon nanotubes. _Future_ nanotubes, that are longer and stronger.

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [March 21, 2014, 11:59pm UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/15 "2014-03-21T23:59:34Z")

</div>

We aren’t exactly a high-value target, but I can give you some specific details on a cubesat I wrote the firmware for.

All upstream and downstream communication is encrypted with AES-128. Each direction has its own key. I chose this because there might be multiple parties which want to see the downsteam information, and like all secrets, the more people with possession, the more likely it is to leak. The upstream key is necessary to actually control the satellite and is kept quite private.

There is a further security layer that protects the more “dangerous” commands (anything that affects the physical structure of the satellite). The commands require an extra token to be sent alongside the data. If the token doesn’t match, the command is ignored. An attacker that knew the upstream key would not be able to trigger any of these commands until the first time we had used them ourselves–in which case an attack is irrelevant (these commands are really only useful near the end of life). It’s a simple form of a one-time-pad.

---

<div class="post-metadata">

**Author:** ![nevadaexile](https://avatars.discourse-cdn.com/v4/letter/n/eb8c5e/32.png) [@nevadaexile](https://boards.straightdope.com/u/nevadaexile)\
**Post date:** [March 22, 2014, 12:57am UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/16 "2014-03-22T00:57:18Z")

</div>

> [@kanicbird](#):
>
> First is there such a James Bond movie? which one?
> 
> Anyway
> 
> Bold mine
> 
> Such a action I would expect to be noticed - that would be the point, but the main point is that nation has the power to do so and is using it. Expressing superiority in space and to hold the world ransom and establish protocols, precedents and fees for country ‘overflights’. The reason for taking such a satellite would be enforcement for not paying such fees, investigation of potential spying, and also other ‘illegal’ activities such as relaying internet which portions of that may be banned in the country.

It’s the plot of the film the film _ **You Only Live Twice.** _. A non-state actor kidnaps astronauts using a space capsule launched from the crater of an extinct volcano located on an island in Japan.

And simply jamming the satellite or blinding it with a ground-based laser would be far cheaper and easier. Also, if some nation or group wouldn’t pay the fees that they contracted to, their access would simply be cutoff and they wouldn’t get any information.

As far as Internet, it would be easier and cheaper to interdict it on the ground than trying to do so in space.

---

<div class="post-metadata">

**Author:** ![Habeed](https://avatars.discourse-cdn.com/v4/letter/h/a587f6/32.png) [@Habeed](https://boards.straightdope.com/u/Habeed)\
**Post date:** [March 22, 2014, 2:41am UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/17 "2014-03-22T02:41:02Z")

</div>

> [@Dr.Strangelove](#):
>
> There is a further security layer that protects the more “dangerous” commands (anything that affects the physical structure of the satellite). The commands require an extra token to be sent alongside the data. If the token doesn’t match, the command is ignored. An attacker that knew the upstream key would not be able to trigger any of these commands until the first time we had used them ourselves–in which case an attack is irrelevant (these commands are really only useful near the end of life). It’s a simple form of a one-time-pad.

Can I ask how or where you secured the actual keys or command listings?

Since it’s a cubesat, I take it that the files are probably stored in someone’s desk or in a filing cabinet belonging to your institutional sponsor?

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [March 22, 2014, 3:38am UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/18 "2014-03-22T03:38:04Z")

</div>

> [@Habeed](#):
>
> Since it’s a cubesat, I take it that the files are probably stored in someone’s desk or in a filing cabinet belonging to your institutional sponsor?

They’re stored in our source code repository. That is, admittedly, a weak part of the system–anyone that stole a laptop or guessed a password for the repository would have access to the keys and tokens. Obviously we aren’t as careful as we’d be if this were a billion dollar satellite.

To be honest, actual hacker-proofness is a secondary consideration. Our licenses with NOAA and other groups _require_ encryption. So, the primary purpose is simply to comply with government regulation. We don’t want to be totally careless, but due diligence doesn’t require us to treat the keys like the nuclear football.

---

<div class="post-metadata">

**Author:** ![johnpost](https://avatars.discourse-cdn.com/v4/letter/j/f17d59/32.png) [@johnpost](https://boards.straightdope.com/u/johnpost)\
**Post date:** [September 7, 2014, 2:59am UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/19 "2014-09-07T02:59:27Z")

</div>

maybe

Space Station Defies Humans, Launches Satellites Without Permission

> **[Space Station Defies Humans, Launches Satellites Without Permission](https://gizmodo.com/space-station-defies-humans-launches-satellites-withou-1631443009)**
>
> The International Space Station has a cannon that launches tiny CubeSat microsatellites into orbit. Most of the time, those launches are triggered by human scientists on board or back on Earth. But this week, the ISS launched two CubeSats entirely on...

---

<div class="post-metadata">

**Author:** ![JKellyMap](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jkellymap/32/15880_2.png) [@JKellyMap](https://boards.straightdope.com/u/JKellyMap)\
**Post date:** [September 7, 2014, 5:11am UTC](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948/20 "2014-09-07T05:11:51Z")

</div>

> [@johnpost](#):
>
> maybe
> 
> Space Station Defies Humans, Launches Satellites Without Permission
> 
> [Space Station Defies Humans, Launches Satellites Without Permission](http://gizmodo.com/space-station-defies-humans-launches-satellites-withou-1631443009)

Yikes! Like one commenter wrote, “Open the cube bay doors…I can’t do that, Steve.”

[Next page](https://boards.straightdope.com/t/possible-to-steal-a-satellite-stranger-you-are-being-paged/683948.md?page=2)
