There is something wonderfully optimistic about putting a computer on a rocket. Down here, we struggle to keep printers connected. Up there, we expect software to survive radiation, manage communications, and remain obedient while travelling around the planet. Then somebody at a security conference raises a hand and asks whether anyone has checked the authentication. Space exploration briefly becomes an IT meeting with a better view.
For anyone who remembers Telnet, the feeling is familiar. A remote machine would present a login prompt, and suddenly a distant computer seemed remarkably close. Telnet itself was no magic skeleton key: access still depended on credentials, configuration, and vulnerabilities. But ordinary Telnet sent passwords and session contents without encryption, giving anyone able to observe the traffic an unnecessarily generous reading experience. It was remote administration conducted with the discretion of a postcard. RFC 4248
Satellites tempt us into a different kind of misplaced confidence. They are expensive, difficult to reach, and surrounded by vacuum. Surely that counts for something. Physically, it does. Digitally, a satellite must communicate, accept legitimate instructions, and often receive software updates. Every necessary connection creates something that needs defending. Altitude is an excellent engineering parameter and a disappointing substitute for access control.
The phrase “hacking a satellite” also does considerable unpaid work for headline writers. It can describe compromising a spacecraft, entering a ground network, attacking a customer terminal, or interfering with a radio link. These are different achievements with different consequences. Listening to an unencrypted transmission does not automatically grant command authority. Jamming a signal does not require logging in. A broken dish does not mean somebody has acquired the keys to the constellation.
The February 2022 attack on Viasat’s KA-SAT service illustrates the distinction. According to Viasat, attackers exploited a misconfigured VPN appliance, entered a management network, and used management commands to overwrite important data in customer modems. Tens of thousands went offline. The company reported no evidence that the satellite itself had been compromised. The damage was serious; the route in was painfully terrestrial. A space communications crisis had arrived through the sort of problem that also ruins an ordinary company’s Tuesday. Viasat’s incident report
Researchers have demonstrated effects aboard spacecraft, too. In a supervised 2023 experiment, a Thales team uploaded software containing a deliberately introduced vulnerability to ESA’s OPS-SAT flying laboratory. Exploiting it let them alter an image and change the satellite’s pointing. They had special access and advance knowledge; ESA retained control, and the spacecraft was restored safely. This was a controlled exercise with unusually accommodating conditions. Still, watching software change where a satellite looks gives “unexpected application behaviour” a certain grandeur. ESA’s account
Starlink supplied another memorable example in 2022, when researcher Lennert Wouters bypassed secure boot on a user terminal through voltage fault injection. This required invasive physical access and additional electronics. He compromised hardware on the ground, without demonstrating a takeover of the satellite fleet. SpaceX publicly congratulated him and explained why it considered the wider impact limited. Somewhere in the history of corporate communications, thanking someone for electrically confusing your product counts as progress. SpaceX’s response
That response matters because the useful question is what happens after one component fails. A customer terminal should have strictly limited authority, even when somebody has persuaded it to abandon its original career plans. Security depends on containing failures as well as preventing them. Otherwise, the cheapest device in the system becomes an unexpectedly affordable management console.
Starlink’s current security page describes several layers of protection: secure boot, signed software, network segmentation, restricted staff access, continuous monitoring, and rapid updates, including to the satellite fleet. It also invites responsible vulnerability reports through a bug bounty programme. These are the company’s stated practices, rather than proof that every possible attack has been defeated. They do, however, address the connected system from customer equipment through space to ground infrastructure. Starlink security
Even reassuring language deserves careful reading. Starlink describes traffic encryption between the user terminal and a Starlink point of presence. That boundary matters: it does not, by itself, promise encryption all the way to every website or application beyond Starlink’s network. An encrypted journey still needs clearly identified endpoints. “End to end” becomes considerably more informative once everyone agrees where the ends are. Starlink security
There is also something quietly magnificent about patching a machine you cannot visit. The familiar helpdesk instruction to switch it off and on again becomes more consequential when nobody can check whether it came back. Remote updates are essential, but so are trustworthy update mechanisms and ways to recover from failure. The glamorous launch is followed by the less photogenic business of keeping the software healthy.
This is where the Telnet nostalgia becomes useful. The resemblance lies in the recurring temptation to confuse connectivity with trust, technical sophistication with safety, and a system working today with a system that will withstand tomorrow’s curiosity. Rockets have improved enormously. Human confidence still occasionally ships with the default settings.
The encouraging development is that researchers are being invited into the conversation before an attacker dictates its terms. A reported flaw can become a patch, a better design, or a narrower permission boundary. That is a practical form of optimism: build extraordinary machines, then let sceptical people examine them.
We have carried our computers into the heavens. The system administrator was always going to have to come along.




No comments yet