Sitemap

Are Satellite Communications Insecure?

5 min readNov 15, 2025

--

The persistence of unencrypted satellite communications and metadata.

I don’t usually deal with topics like this, but on this occasion the issue has caught my attention. Artificial satellites often appear in the press or in films as almost magical artifacts, remote devices that are only operated by governments and large corporations. In reality, quite the opposite is true: much of our daily life constantly bounces off them, from calls between remote villages, ATM transactions anywhere, corporate emails from a supermarket chain, telemetry from an electrical grid, to even the navigator on an airplane where you can connect to the Internet. My point is that, as a group of researchers from the University of California, San Diego, and the University of Maryland have just demonstrated, there is a not insignificant fraction of all this that travels through the sky practically “naked,” unencrypted, as if no one could be so rude as to look up.

Press enter or click to view image in full size
Image NOAA / Gizmodo.

This work, which has been mentioned in many media outlets, is titled, quite intentionally: Don’t Look Up: There Are Sensitive Internal Links in the Clear on GEO Satellites and will be presented at the ACM CCS conference, one of the most important forums on computer security. The initial idea was seemingly innocuous, namely to systematically observe how communications passing through geostationary satellites are encrypted, those that “hang” over the same point on Earth and function as long-range repeaters to connect remote infrastructures. The execution, however, was anything but trivial. For several years, the team analyzed IP traffic from 39 geostationary satellites “visible” from a rooftop in San Diego and discovered that approximately half of the data traffic links they observed transmitted information without encryption at the link or network level.

Most strikingly, no fancy antennas or secret laboratory were needed. With a Ku-band dish, a standard LNB head, a commercial DVB-S2(X) reception card, and a few cables — in other words, with a setup costing around €700, replicable by any reasonably persistent amateur — they were able to “listen” to the downlink from these satellites. The experiment was strictly passive; they did not transmit, attempt to break any codes, or hack into any systems. They simply received what was already being broadcast. From there, the rest was reverse engineering, i.e., trying to locate active transponders, reconstruct IP packets, and classify what types of networks and services were literally traveling above their heads.

The result is a kind of accidental X-ray of a slice of global communications. Among the data they managed to intercept without breaking any encryption were backhaul communications from several mobile operators (T-Mobile, AT&T Mexico, and Telmex, among others) containing metadata from thousands of calls and text messages, and even audio from some conversations when the satellite link was unprotected. They also identified internal traffic from large companies and banks, such as Walmart Mexico, Santander Mexico, and others, with emails, inventory records, and ATM network data traveling in clear text. Added to this are links to critical infrastructure, such as electric companies and gas networks, in-flight Wi-Fi communications from various airlines, as well as transmissions related to ships and military units in the United States and Mexico, including positioning information, anti-drug trafficking operations, and equipment maintenance records.

To understand why all this is possible, it is necessary to remember a physical detail that is often overlooked. A geostationary satellite is not a cable, it is a radio source. The uplink, from the ground antenna to the satellite, is highly concentrated and only “seen” by the satellite. But the downlink is broadcast over a large geographical footprint. Any antenna within that footprint, pointing at the same satellite and transponder, can receive the same signal that is intended for a specific station. For years, the industry seemed to rely on the assumption that this combination of distance, equipment cost, and technical expertise offered a kind of security through obscurity (something like, who would try something so complicated?). The study shows that this assumption is now obsolete. With modest hardware and a little patience, a significant fraction of the internal traffic of half the world can be observed from a single rooftop.

But of course, we shouldn’t jump to the conclusion that “everything that passes through a satellite is visible.” The authors are very careful about their limitations. They only see the downlink, not the uplink, and they only analyze geostationary satellites visible from San Diego, which accounts for approximately 15% of the Ku-band satellites in service. Furthermore, within what they receive, many communications are already encrypted at the application level using HTTPS or other protocols. In such cases, the potential spy cannot read the content of a web form or chat message, but they do obtain valuable metadata, such as which domains are visited, from which IP addresses, at what times, and for how long. The most serious problem is concentrated in specific links in the chain, such as satellite backhaul for remote mobile towers, corporate networks interconnected by satellite, SCADA systems for critical infrastructure, or ATM networks that use links

Why, then, are so many such links still unencrypted at this point, when the word “cybersecurity” has become something that is mentioned on a daily basis? The reasons are a mixture of economics and habit. For decades, satellite bandwidth was expensive and scarce. Adding link-level encryption meant consuming additional bits and potentially degrading service. Many pieces of equipment and software licenses treat encryption as an optional extra that has to be configured and paid for. In some remote environments, where power and computing capacity are limited, the temptation to disable it “temporarily” to gain some margin is strong, and once the configuration is working, no one wants to touch it. Added to all this is a problem of diffuse responsibility. Between the satellite operator, the service provider, the local integrator, and the end customer, it is not always clear who is responsible for ensuring that a particular section carries a VPN, IPsec, or link-layer encryption. And above all, there was that false sense of cosmic anonymity, the idea that, honestly, no one was going to be looking.

The work also raises an interesting legal and ethical dilemma. The researchers limited themselves to receiving broadcasts that were already being transmitted over large regions, but in many countries, intercepting communications, even if it does not technically involve “breaking into” any system, borders on or crosses the lines set by wiretapping and data protection laws. To navigate this complicated terrain, the team systematically anonymized personal information, destroyed the data once it had been analyzed, and devoted a significant portion of the project to responsibly notifying the affected organizations, helping them to close the leaks where possible. A real adversary, of course, would have neither such scruples nor such patience. The underlying recommendation is quite simple, although its practical application is not so straightforward. We must stop treating satellite links as something “special” and start seeing them for what they are: an open network equivalent to a large public Wi-Fi network. In practice, this means layering defenses, such as end-to-end encryption in applications, from the browser to messaging, VPN or IPsec tunnels for any link carrying sensitive internal data, and, where feasible, encryption at the link level on satellite equipment. At the same time, regulators and companies in the sector would have to accept that security through obscurity is no longer an acceptable model and that, just as certain minimum standards are required for mobile or fiber networks, satellite links used for critical services should meet basic confidentiality and authentication requirements.

--

--

Alejandro Polanco Masa
Alejandro Polanco Masa

Written by Alejandro Polanco Masa

Science Writer, Graphic Designer and Mapmaker. alpoma.info