back
98 comments
There was remarkably little in the way of security for early satellites (or space probes).

I recently encountered here on HN the suggestion that, the main reason you can't find particularly in-depth details on the Voyager space probes, is project security. Security through obscurity, mostly. If amateurs can detect the signal from the Voyager probes with a small dish antenna, it's at least conceivable someone might hook up a really powerful transmitter, aim it in the probe's direction, and start issuing commands. There's no cryptography, of course. The resources required to hijack like that in the 1970s would have been much greater, and I doubt being hacked was much on the designer's minds.

The Apollo Program was the same; today anyone with the documentation, a small dish antenna, a software radio, and some nerd dedication, would be able to hack Apollo midflight via its radio link. It was the equivalent of a root prompt with no password on an exposed port.

A bit closer to home, there's a tremendous amount of semi-functional orbital junk with a similar lack of security, decades-old computers still waiting for telecommands.

> If amateurs can detect the signal from the Voyager probes with a small dish antenna

They can't, at least not for any reasonable definition of small. As I'm writing this, NASA is listening to Voyager using the DSS-14 antenna of the Deep Space Network, a dish with a 70 meter diameter, and the signal it receives is 10^-19 Watt. That's only 15000 photons per second. Coincidentally the area of that 70 meter dish is also roughly 15000 m^2, so a small dish of 1 m^2 will catch roughly 1 photon per second. Given that the datarate is 40 bits/second, it's physically plain impossible to receive the signal with a small dish.

Voyager's security is that it's really far away and you need a big, expensive dish to talk with it.

https://news.ycombinator.com/item?id=34227604

DonHopkins on Jan 3, 2023 | root | parent | next [–]

John McCarthy trolled me once!

When I met him, we were chatting about Stanford, and I mentioned that I really admired that huge radio telescope that you could see around 280 and Page Mill Road in the hills above Stanford.

He looked puzzled and confused, and asked "Which huge radio telescope?"

I was flustered and explained how you couldn't miss it, right by 280 and Page Mill Road, it's out there in a field, its huge, it's enormous, gigantic I tell you, there's no way you can miss it, bla bla bla...

He let me go on and on, describing it, and acted like he had absolutely no idea what I was talking about, like I was crazy for hallucinating a gigantic radio telescope that both of us must have passed zillions of times.

Finally he let on and said, "Oh, you mean that SMALL radio telescope???"

inamberclad on Jan 3, 2023 | root | parent | next [–]

It's just called The Dish, and I mean, it's only medium sized (46 meters) compared to the main antenna at a DSN site (70 meters).

There is fundamental limit (Shannon limit) on decoding a signal Eb/No = -1.6dB [0]

where Eb is energy received per bit of information and No is noise spectral density.

This makes it paramount to collect as much energy per bit (Eb) as possible which in turn requires large antennas for far away objects such as Voyager probe.

[0] https://en.wikipedia.org/wiki/Eb/N0#Shannon_limit

But you dont need to hear voyager in order to hack it. It just needs to hear you. Nasa needs the big dish to hear voyager's tiny transmitters. Someone wanting to send a disruptive message to voyager could use a massive transmitter and a relatively smaller dish.

But you dont even need that. You need just enough outbound signal to jam the legitimate uplink, enough that voyager can no longer tell you from the real signal. That is likely much less than the power needed to send a command.

Or you could jam the nasa ground stations. A one-watt transmitter on a carefully positioned cubesat in low orbit would be enough to nullify voyager's real signal. (Setup the orbit to be over the deep space network stations every day as voyager comes into view.)

It's an air gapped system effectively
If 70 m is the diameter, not radius, that area is a factor of 4 too high. Should be more like ~3850 m^2. Still physically impossible at that size but it does make the required size a bit more tenable.
At the current rate of progress, when will it become physically impossibe to receive signals from it?
> […] a small dish of 1 m^2 will catch roughly 1 photon per second. Given that the datarate is 40 bits/second, it's physically plain impossible to receive the signal with a small dish.

Do you just mean plain impossible with the specific type of system used with Voyager, or are making a general argument that all systems that have a 1 photon/second rate cannot carry 40 bits/second of data?

Documentation and logs of the Voyager and Apollo projects are public, comprehensive, and fascinating reading. They do use authentication and keep the keys secret. They are literally rocket scientists.
CuriousMarc, kens, and crew have been recreating the up & downlinks for Apollo using vintage NASA hardware. They recently were able to send commands to their AGC[0][1] remotely. No encryption used, just a hefty investment in RF engineering.

The techniques were probably closely held at the time to prevent Soviet interference, but these days you can just download the circuit diagram PDFs.

[0] Simulated, since the owner of the original AGC wanted it back.

[1] https://www.youtube.com/watch?v=tBy1j9cTYKc

> Documentation and logs of the Voyager and Apollo projects are public, comprehensive, and fascinating reading. They do use authentication and keep the keys secret.

Can you link to the documentation for the authentication mechanism?

> They are literally rocket scientists.

Literally they are not. The rockets used to launch the Voyagers were built by Martin and General Dynamics.

I've looked hard for details and specs on the computers for the Voyagers and it's just not online, beyond high-level descriptions. Almost nothing when compared to Apollo (which has assembly source code for the software, and circuit diagrams for the computers, available).
Was there authentication right from the beginning or was it patched in later?
I think it’s even more amusing that that, these folks invented rocket science.
CuriousMarc on Youtube has a very large playlist of him and a few others restoring the apollo systems they have been able to get their hands on, and youre absolutely correct on the hacky possibilities. There was no authentication, just lock on and issue commands. They were not only able to restore pretty much everything to a working apollo comms and control system, they were even able to use lab equipment to communicate with apollo outright. I linked the first part of the series. Its a long one but very worth the watch even if you arent into everything they cover.

Many sats were and are similar, theres not much security. Newer ones with specific uses are most definitely encrypted.

The only real saving grace is that the size of dish/antenna and power you need to do anything with stuff actually in space at long distances is beyond what most people could do (not saying a very dedicated nerd couldnt, look at SaveItForParts for example).

https://www.youtube.com/watch?v=2KSahAoOLdU

It hasn't been suddenly moved in 2024 and nobody knows why, it was left in an inconvenient place (now) decades ago and there's no (found) record of who/why.
Define early. And it does not include this vehicle. I can't personally speak for Skynet 1A, but the DSCS II satellites, first launched in 1971 (so developed at roughly the same time), most definitely had an encrypted command uplink.
The US Navy has has a problem with people hijacking their old FLTSATCOM comm satellites as a walkie-talkie.

https://www.wired.com/2009/04/fleetcom/

> The Apollo Program was the same; today anyone with the documentation, a small dish antenna, a software radio, and some nerd dedication, would be able to hack Apollo midflight via its radio link. It was the equivalent of a root prompt with no password on an exposed port.

Is this right? In a recent curiosmarc video I got the impression the astronauts on board had to enable remote commands. This was frequently done but they did have a cutoff.

These guys "hacked" an entire space probe:

https://www.theregister.com/2014/07/07/space_hackers_fire_up...

Voyagers are so far away that possibility of owning necessary antenna is probably limited to nation-states or mad billionaires. Also DSN-sized antenna is not exactly easy to hide. If you are hell-bent on breaking Voyager and have such resources I think you could acquire necessary information anyway (I guess you could get uplink data for reverse-engineer framing format by standing near DSN antenna with SDR?).

>would be able to hack Apollo midflight via its radio link. It was the equivalent of a root prompt with no password on an exposed port.

Indeed, but in that case it would be port opened with a switch: https://youtu.be/2Jt0PsxLM7k?t=1732

> There was remarkably little in the way of security for early satellites (or space probes).

Compared to what? What was (or is) worth securing? From what? Talking about security in abstract is nonsensical

Satcom 3 was lost after launch in 1979 and wound up in a non-geosynchronous orbit.

On a tour of the satellite manufacturer, RCA Astro, years after the loss, we heard this story: during the transfer of control from NASA to RCA Astro contact was lost and not re-established. Eventually the U.S. military was asked, "Errrh, did you see where Satcom 3 went?". The answer came back "Yup, looks like isn't in the geosynchronous orbit you expected".

The thought was that during the handover a command to fire the apogee motor was inadvertently sent and obeyed!

The fix for FUTURE launches was a protocol of checksummed commands. Beyond that, the new, more cautious sequence, became:

  1. uplink dangerous command.

  2. spacecraft verifies checksum and downlinks a copy of the proposed dangerous command

  3. a keylock on the RCA  command console is turned on and the "execute that dangerous command" instruction is uplinked.

  4. upon verifying the execute command's checksum, the dangerous command is executed.

No further launches suffered a failure similar to Satcom 3.

Satcom 3's hulk is still in orbit.

See: https://nssdc.gsfc.nasa.gov/nmc/spacecraft/display.action?id...

https://space.skyrocket.de/doc_sdat/satcom-1.htm#:~:text=Sat...

- "We need to avoid what I call super-spreader events. When these things explode or something collides with them, it generates thousands of pieces of debris that then become a hazard to something else that we care about."

There was one of these just a couple weeks ago (and that was not the first),

https://news.ycombinator.com/item?id=41904346 ("Intelsat 33e breaks up in geostationary orbit")

This was also the premise of the 2013 film Gravity starring Sandra Bullock and George Clooney.

https://en.wikipedia.org/wiki/Gravity_(2013_film)#Plot

....is this really a problem in a geostationary orbit?
This didn't happen recently. From the article:

>Almost certainly, it was commanded to fire its thrusters in the mid-1970s to take it westwards.

TLDR:

While the title says that it is not known who has moved an abandoned UK satellite used for military telecommunications, the article very strongly implies that it was someone from USA, who does not want to acknowledge this.

The satellite had been built by USA and initially operated also by USA, before being handed down to the UK, so they had the capabilities to control it at any time.

UKs nuclear deterrence is built by the USA.

It is a testament to deGaulle's genius that he never fell into that trap.

Its current position above Central America would certainly have been useful to the US in the mid 1970s when it apparently moved, perhaps more useful than it would have been to the UK over post-colonial East Africa.
A simple malfunction is not considered in the article. Is that so unlikely, e.g. a sticky relais or some-such?
It was spin stabilized. A stuck relay would have just created equal thrust all the way around the spin - ie the thrust would cancel out to zero. This design required thrusters that fired for very short intervals at a given delay after the earth sensor saw the earth, so the thrust would line up in the desired vector. In other words, no a simple malfunction cannot result in an orbit change.

That said, it's an assumption in the article that the orbit change wasn't due to the cumulative effect of the normal gravitational perturbations the pull on all these vehicles. You'd need to dig up what orbit it was in 40 years ago and then calculate how the orbit would have drifted over those 40 yrs. Good luck.

Sorry it was me.

I was going to put it back and then I got distracted and forgot.

Please tidy your space.
If satellite warfare will be like chess, this could be a preparatory move.
Man, whoever did it back in the 70s must have been really forward thinking.
New strat just dropped
We now have historians investigating things that happened in my lifetime. Not sure if this is awesome or not.
Welcome to getting old!
Wild speculation with zero evidence since no one else is: it wasn't broken, and the US/CIA intentionally moved it so they could communicate with agents in SA/Chile (during Allende etc)
This is literally a historian can't find paperwork from ~50 years ago.

A UK historian can't find in part classified paperwork that would be created by the U.S. Department of Defense who had control and moved a broken satellite in the 1970's

Re-framed as a puzzle, why was this location chosen it becomes interesting. But I get BBC are just chasing NPC clicks from sites like HN

Was the command a wow-signal from a random source?

https://en.wikipedia.org/wiki/Wow!_signal