Hacker News new | ask | show | jobs
by noselasd 3583 days ago
No. As with other satellite phones, security/encryption is an additional feature that you buy. For everyone else, there's no security/encryption - you just need to implement the system and protocols to tap into it - which is what has been done here. (And for the parts that have encryption, it's the data that's encrypted, while metadata (e.g. call setup) is still plain text)
4 comments

Here's a transcript of the intercepted call that they played:

> You have reached the 310 airlift squadron C-37 aircraft, tail number 0028.

> To call the CSL press 1.

> To call secure telephone number one, press 2.

> To call secure telephone number two, press <missing>

> Satcom direct Inmarsat connection in progress, please hold while we attempt to connect your call.

> The approximate global connect time is <missing>

> <ringing>

I suppose that selecting to connect to the secure phones could trigger an encryption layer on top of the call.

That puts it into perspective, thanks. Interesting that unprotected metadata is something that the US army is willing to accept.
Also ... correct me if I misremember ... but I think it is the case that with Iridium - encryption or no encryption - Eve can discern your physical location and get GPS coordinates for you.

Am I remembering that correctly ? I believe that got some journalists killed in Syria a few years ago ...

They mention in the talk that the satellite will periodically downlink both its location as well as where it thinks the particular spot beam you're using hits the earth.

So while at the very least I'm not sure you'd get GPS-quality data, if you monitored that data for awhile I'd think you could eventually get "good enough" accuracy.

I've also read about the Syrian bombs targeting Iridium users. Maybe they used triangulation to locate the source of the signal that was being broadcast from earth. Does/did the Syrian govt have that tech? Would they need satellites, or would helicopters be enough? And which government/supplier did they buy it from?
You can probably deduce quite a lot position-wise by observing the doppler shifts and doppler shift corrections.
I remember hearing that as well, although I can't find a citation.
Whats the timestamp in the youtube video for that