Vic Huang

UCCU Hacker / Member

Independent Researcher / Security engineer.

He is interested in Web/Mobile/Blockchain Security and privacy issue.

Vic shared his research on BlackHat, HITB, CODE BLUE, ROOTCON, Hack.lu, Ekoparty REDxBLUE pill, HITCON, CYBERSEC, DEFCON village before.

SPEECH
4/17 (Thu.) 11:45 - 12:15 1F 1A Space Cybersecurity Forum Live Translation Session
Eerie Glow: Unveiling Security Vulnerabilities in Open-Source Satellite

Historically, the high costs associated with satellite manufacturing, design, and launch limited satellite production to government agencies or research institutions. However, in recent years, the development and widespread use of small satellites have emerged due to the significant reduction in launch costs associated with their smaller size. Consequently, projects developing satellite protocols and DIY cub satellites have proliferated. This study shares insights into classic vulnerabilities identified in past satellite attack research, along with new security issues we have discovered. We focus on a recent open-source satellite project, SPACECAN, and the decade-old open-source satellite communication protocol, libcsp, which is already in use by satellites. Our research identifies three vulnerabilities in the SPACECAN project related to CAN bus message transmission and highlights a flaw in message verification within the libcsp project. By revealing these vulnerabilities, we aim to raise awareness about the security of satellite communication systems, advocate for secure implementations in open-source satellite projects, and provide actionable recommendations to mitigate these risks.