Don't Shoot the Messenger: Localization Prevention of Satellite Internet Users
David Koisser, Richard Mitev, Marco Chilese, Ahmad-Reza Sadeghi
IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 5
Overview
In an era where global conflicts increasingly impact civilian infrastructure, reliable and private communication channels become paramount. This talk, "Don't Shoot the Messenger: Localization Prevention of Satellite Internet Users," presented by David Koisser and his colleagues from the System Security Lab at the Technical University of Darmstadt, addresses a critical vulnerability in the use of satellite internet services, particularly in hostile environments. The core problem revolves around the potential for adversaries to geolocate users by triangulating signals from their satellite internet terminals, turning life-saving communication devices into potential beacons for attack.

Key moments
- 0:50 Starlink user localization warning and Mari Colvin precedent
- 2:00 Research question: How to guarantee location privacy?
- 3:30 Introducing "Anon": Mesh network, random routing, gateway switching
- 4:00 Proof of concept using Raspberry Pi and LoRa radio
- 6:40 Security feature: Output gateway selection bias to prevent triangulation
- 7:40 Large-scale simulation evaluation using real-world node data
Don't Shoot the Messenger: Localization Prevention of Satellite Internet Users
Speakers: David Koisser, Richard Mitev, Marco Chilese, Ahmad-Reza Sadeghi
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=SosD02AN1fA
Overview
In an era where global conflicts increasingly impact civilian infrastructure, reliable and private communication channels become paramount. This talk, "Don't Shoot the Messenger: Localization Prevention of Satellite Internet Users," presented by David Koisser and his colleagues from the System Security Lab at the Technical University of Darmstadt, addresses a critical vulnerability in the use of satellite internet services, particularly in hostile environments. The core problem revolves around the potential for adversaries to geolocate users by triangulating signals from their satellite internet terminals, turning life-saving communication devices into potential beacons for attack.
The research was spurred by real-world events, notably the widespread deployment of Starlink in Ukraine following the conflict, which saw over 150,000 active users connect within months. Despite Starlink's resilience against jamming, security researchers and even the CEO of Starlink issued warnings about the risk of user localization. This concern is not theoretical; the alleged tracing of journalist Marie Colvin via her satellite phone serves as a stark historical precedent. The talk introduces Anon, a novel approach designed to guarantee location privacy for satellite internet users by leveraging off-the-shelf hardware to create a mesh network that randomizes data routing and dynamically switches output gateways, thereby preventing triangulation attacks.
This work is highly significant for individuals, journalists, humanitarian workers, and military personnel operating in high-risk zones where maintaining anonymity and physical security is crucial. By providing a practical and deployable solution that doesn't rely on custom protocols or pre-installed applications, Anon offers a vital layer of protection against sophisticated surveillance and targeting efforts. The research not only highlights a pressing security concern but also delivers a concrete, evaluated framework for mitigating it, ensuring that the critical function of satellite internet in maintaining connectivity does not inadvertently expose its users to danger.
Background
▶ Watch: Starlink user localization warning and Mari Colvin precedent (0:50)
The proliferation of satellite internet, particularly services like Starlink, has revolutionized communication capabilities in remote areas and conflict zones where traditional infrastructure is compromised or nonexistent. However, this technological leap introduces a significant security challenge: the location privacy of its users. The inherent nature of satellite communication involves ground terminals transmitting signals to satellites, which then relay data to ground gateways. These signals, especially if consistent from a single terminal, can be triangulated by adversaries, revealing the user's precise geographic location. This vulnerability transforms a connectivity solution into a potential liability, as users transmitting sensitive information—such as photos or intelligence—risk exposing themselves to kinetic or cyber attacks.
Prior work in related fields offers some solutions, but none adequately address the unique constraints of this scenario. In emergency communication networks, approaches often involve temporary infrastructure like Unmanned Aerial Vehicles (UAVs) or heavy-duty vehicles (e.g., helicopters) to provide short-term connectivity. While effective for immediate disaster relief, these are not designed for sustained, private communication over extended periods, nor do they prioritize user location anonymity.
For location privacy in mesh networks, several academic approaches exist:
- Phantom routing and network coding aim to obscure traffic paths. However, they often rely on impractical adversarial models, such as assuming the attacker is unaware of the technology being used (as with network coding).
- Fake traffic and pseudonymity approaches attempt to confuse attackers by flooding the network with decoy data or frequently changing identifiers. The main drawback here is an impractical network overhead, significantly decreasing throughput and making real-time communication cumbersome.
- Overlay networks like Tor, while excellent for anonymity in the general internet, assume a fully connected underlying network infrastructure. This assumption does not hold for dynamically formed mesh networks in remote or disaster-stricken areas, making them unsuitable for direct application.
The critical gap identified by the researchers is the lack of a robust, practical, and hardware-agnostic solution for location privacy in satellite internet mesh networks. Existing methods are either too resource-intensive, rely on unrealistic attacker models, or are architecturally incompatible. This void necessitated the development of a new approach that could be rapidly deployed using readily available components, provide strong privacy guarantees, and maintain acceptable performance—leading to the creation of Anon.
Key Findings
▶ Watch: Introducing "Anon": Mesh network, random routing, gateway switching (3:30)
The central finding of this research is the successful design, implementation, and evaluation of Anon, a novel system that effectively prevents the localization of satellite internet users in sensitive environments. Anon distinguishes itself by:
- Hardware Agnosticism and Off-the-Shelf Deployment: Unlike many academic proposals, Anon is built entirely on off-the-shelf hardware, specifically demonstrated with Raspberry Pis and LoRa (Long Range radio) modules. This makes it highly practical for rapid deployment in areas lacking sophisticated infrastructure or specialized equipment.
- Protocol Independence: Anon does not rely on custom protocols or pre-installed applications on user devices. Users can connect their standard Wi-Fi-enabled devices to a base station as they normally would, simplifying adoption and minimizing configuration overhead.
- Mesh Network for Anonymity: The core mechanism involves equipping every base station with a long-range radio (LoRa), spanning a mesh network across all participating base stations. User data, instead of being directly forwarded to the satellite gateway, is randomly routed through this mesh network. This obfuscates the origin of the traffic, making it challenging for an adversary to pinpoint the user's location.
- Dynamic Output Gateway Switching: To prevent localization over time, the network regularly switches to a different output gateway. This continuous change in the egress point for user traffic makes it difficult for an attacker to build a consistent profile of the user's location through repeated triangulation attempts. The system adheres to a maximum allowed number of hops to balance privacy with performance.
- Output Gateway Selection Bias for Enhanced Security: A critical security feature introduced is the selection bias for output gateways. For each client, the origin gateway generates a random direction and weight bias when selecting the next hop. This technique actively shifts the center of the potential "circle" of the user's location that an attacker might try to draw based on triangulating multiple gateways. By randomizing the apparent direction and distance, Anon makes it significantly harder for an adversary to trace the user's true origin.
- Demonstrated Feasibility and Performance: Through a proof-of-concept implementation and large-scale simulations using real-world mesh network data, the researchers validated Anon's feasibility. They showed that LoRa-based mesh networks could achieve acceptable throughput for common tasks like uploading photos (e.g., 200 KB in ~50 seconds for 30 clients) while maintaining low packet loss. Crucially, they quantified the anonymity set size, demonstrating that a user could be indistinguishable from hundreds or even thousands of other users in a sufficiently dense network (e.g., 4,177 users in the Hong Kong dataset).
In essence, Anon provides a practical, robust, and deployable solution to a critical location privacy problem for satellite internet users, leveraging a combination of mesh networking, random routing, and clever output gateway selection strategies to obscure user location effectively.
Technical Deep Dive
▶ Watch: Proof of concept using Raspberry Pi and LoRa radio (4:00)
The Anon architecture is designed for simplicity, deployability, and robust location privacy, built upon readily available hardware and open-source software. At its core, the system consists of multiple base stations, each a self-contained unit capable of providing Wi-Fi connectivity to local users and participating in a wider mesh network.
Each base station is typically implemented using a Raspberry Pi, which serves as the computational and networking hub. These Raspberry Pis are equipped with two primary communication interfaces:
- Wi-Fi Access Point (AP): This allows standard user devices (laptops, smartphones, tablets) to connect to the base station out-of-the-box, providing local internet access. The Raspberry Pi acts as a NAT (Network Address Translation) gateway for these client devices.
- Long Range (LoRa) Radio Module: This is the critical component for forming the mesh network. LoRa operates in sub-GHz unlicensed frequency bands, making it legally usable in various regions without requiring special licenses. The researchers considered alternatives like FLRC (Fast Long Range Communication) for LoRa 2.4 GHz but found current implementations impractical for their use case due to higher power consumption or complexity. LoRa's long-range capabilities (several kilometers) and low power consumption are ideal for spanning a mesh network across dispersed base stations.
To enable IP packet transmission over the LoRa radio, the researchers utilize the open-source software TNC attach. TNC attach creates and configures network interfaces to translate standard IP packets into LoRa frames and vice-versa. A notable modification made by the researchers was the addition of simple fragmentation support to TNC attach. The original implementation lacked this, limiting packet sizes to the maximum LoRa packet size and potentially slowing down the translation process between Ethernet (from the Starlink router) and LoRa. This fragmentation ensures that larger IP packets can be efficiently transmitted across the LoRa mesh.
The data routing mechanism within Anon is central to its privacy guarantees:
- When a client connects to an "origin" base station (e.g., Raspberry Pi 1), their traffic is encapsulated and forwarded to the LoRa interface.
- Instead of directly sending data to the satellite gateway, the origin base station routes the data randomly through the mesh network. This random routing involves selecting intermediate base stations (hops) until an "output" gateway (e.g., Raspberry Pi 3) is reached.
- The output gateway is the one directly connected to the Starlink router via Ethernet, responsible for forwarding the user's data to the satellite internet.
To prevent an adversary from observing consistent traffic patterns from a single output gateway over time, Anon implements a crucial connection management strategy. The origin gateway keeps track of the duration of each client's connection. If a connection remains active for too long, the origin gateway proactively creates and injects a TCP packet with the RST flag set into the packet flow in both directions. This effectively "kills" the existing TCP connection. Once the connection is terminated, the origin gateway establishes a new route for that client, potentially selecting a different path through the mesh and a different output gateway. This dynamic switching prevents persistent links that could be exploited for long-term triangulation.
Further enhancing location privacy is the output gateway selection bias. An adversary attempting to geolocate a user might try to draw a circle around all output gateways used by that user over time, assuming the user is at the center of this circle. To counter this, for each client, the origin gateway generates a random direction and weight bias when selecting the next hop and ultimately the output gateway. This bias ensures that the "center" of the inferred circle of output gateways is randomly shifted, making it impossible for an attacker to accurately pinpoint the user's true location.
For evaluation, the researchers leveraged various public Wi-Fi and Wi-Fi mesh network node location datasets, such as those from Freifunk. These datasets, featuring up to 5,441 nodes per dataset (e.g., New York, Hong Kong, Paris), allowed for large-scale simulations of the Anon network topology and performance.
The simulations explored several key parameters:
- Network Performance: With parameters like a 5 km range per terminal, 166 KB/s max LoRa throughput, and a maximum of three hops, the simulations showed that the average time to send a 200 KB photo (a common social media image size) increased logarithmically with the number of clients, reaching approximately 50 seconds for 30 clients.
- Distance Metric: Evaluating the key security parameter of "Max Hops," the researchers measured the average physical distance from the client's origin gateway to the output gateway. For dense datasets like Lind and Adelaide, even two hops were sufficient to reach the maximum possible distance within the network. In contrast, geographically widespread datasets like Hong Kong and Renea showed a nearly linear increase in distance with an increase in Max Hops, highlighting the importance of network topology.
- TLS Setup Evaluation: Recognizing that most internet services use TLS, the researchers evaluated the performance of establishing and maintaining TLS sessions. Dense networks (Adelaide, Lind) showed better performance due to closer nodes, but this came with an implicit tradeoff: lower average distance between nodes also means a smaller potential 'distance to origin' for an attacker.
- Security Guarantees: The primary security metric used was the anonymity set size, defined by Cha and The as the set of parties from which one is indistinguishable. For a 5 km range, Hong Kong's dataset yielded an average anonymity set size of approximately 4,177 users, meaning a user could blend in with over four thousand others. They also calculated the effective set size (proposed by Zanto et al.) which measures the reachability of each node, yielding 278 for Hong Kong. Additionally, the average number of paths and unique paths between any two gateways were calculated to assess general connectivity and reliability against node failures.
This detailed technical framework demonstrates Anon's potential to provide robust location privacy while operating within the practical constraints of real-world deployments.
Demo / Proof of Concept
▶ Watch: Security feature: Output gateway selection bias to prevent triangulation (6:40)
To validate the theoretical underpinnings and simulation results, the researchers developed a tangible proof of concept (PoC) implementation of Anon. This PoC was built using Raspberry Pis as the base stations, integrated with LoRa long-range radio modules for mesh networking, and connected to a live Starlink base station to simulate real-world satellite internet access.
The PoC allowed for empirical measurements of network performance and the practical implications of the Anon architecture. Key demonstrations and measurements included:
- Round Trip Time (RTT) Measurement: Standard ping commands were used to measure the RTT from a client device, through the Anon mesh, to a server on the internet via the Starlink connection. Measurements were taken for 0, 1, and 2 LoRa hops:
- 0 hops: Directly connecting to the Starlink router (or through a single Anon gateway acting as a direct passthrough) showed an RTT of approximately 50 milliseconds. This baseline highlights the inherent latency introduced by the Starlink satellite connection itself.
- 1 LoRa hop: RTT increased to around 100 milliseconds.
- 2 LoRa hops: RTT further increased to approximately 211 milliseconds.
The measurements showed a remarkably low packet loss rate, ranging from 0% to 4%, even with multiple LoRa hops. This indicates the reliability of the LoRa mesh for packet transmission.
- Image Upload API Service: To simulate a common real-world use case for satellite internet users in conflict zones—uploading sensitive data like photos—the researchers implemented their own API service. This service utilized REST over TLS using HTTP/2 for secure communication.
- The demo involved uploading pictures with sizes ranging from 50 kilobytes to 200 kilobytes, representative of average image sizes used on social networks (e.g., WhatsApp, Skype).
- The time taken to upload these images varied:
- A 50 KB image took approximately 60 seconds.
- The largest 200 KB image took up to 276 seconds.
While these times might seem considerable compared to broadband internet, they are a practical tradeoff for achieving robust location privacy in a low-bandwidth, long-range mesh network deployed with off-the-shelf hardware. The demonstration successfully proved that Anon could facilitate practical data transfers, albeit with increased latency due to the multi-hop routing and LoRa's characteristics, while maintaining the crucial privacy guarantees.
The PoC effectively showcased Anon's viability, demonstrating that location privacy for satellite internet users is achievable using accessible technology, even under challenging performance constraints. It provided concrete evidence that the system could operate reliably and securely in a simulated real-world scenario.
Defensive Implications
▶ Watch: Large-scale simulation evaluation using real-world node data (7:40)
The "Don't Shoot the Messenger" research provides crucial insights and actionable intelligence for various stakeholders involved in defending individuals and organizations relying on satellite internet in high-risk environments. The primary defensive implication is the urgent need to address the localization vulnerability inherent in current satellite internet deployments.
For individual users and field operatives (journalists, humanitarian aid workers, military personnel in non-permissive environments), the message is clear: using satellite internet without location privacy measures can turn a communication lifeline into a beacon for targeting. Individuals should seek out and deploy solutions like Anon, or similar technologies, whenever possible. This means:
- Prioritizing systems that implement multi-hop routing and dynamic egress points: Users should understand that directly connecting to a satellite terminal, especially for prolonged periods or sensitive data transfers, exposes their location.
- Leveraging off-the-shelf hardware solutions: The ease of deployment with readily available components (Raspberry Pis, LoRa modules) makes Anon a practical choice for rapid, decentralized implementation in the field.
- Understanding performance tradeoffs: While Anon introduces latency, the security benefit of location privacy often outweighs the performance cost in life-or-death situations. Users should be aware of these tradeoffs and plan their communication strategies accordingly (e.g., batching data transfers).
For organizations, NGOs, and governments funding or deploying satellite internet in conflict zones or disaster areas, the research highlights a critical architectural oversight. Future deployments and current operational guidelines should integrate localization prevention as a fundamental security requirement. This could involve:
- Architectural integration: Designing and deploying satellite internet networks with built-in mesh networking capabilities and dynamic routing from the outset.
- Funding and development of privacy-enhancing technologies: Supporting further research and development into practical, scalable localization prevention systems that can be integrated with existing satellite internet services.
- Training and awareness: Educating users about the risks of geolocation and the available mitigation strategies.
For network architects and security engineers, the research offers concrete technical strategies:
- Embrace diverse routing paths: Implement mechanisms that ensure user traffic does not consistently exit through the same gateway. This includes random routing, path diversification, and load balancing across multiple egress points.
- Dynamic session management: Proactively terminate and re-establish connections with new routes and egress points to prevent long-term tracking. The TCP RST injection method demonstrated by Anon is an effective technique.
- Implement output gateway selection bias: Actively manipulate the apparent origin of traffic by introducing randomness in gateway selection. This makes triangulation efforts by adversaries significantly more complex and less accurate.
- Consider network density and topology: Recognize that the effectiveness of localization prevention (quantified by anonymity set size) is directly related to the density and interconnectedness of the mesh network. Deployments should aim for sufficient node density to provide robust anonymity.
In summary, Anon serves as a proof of concept that robust location privacy for satellite internet users is achievable with practical, deployable technologies. Defenders must move beyond simply providing connectivity and integrate sophisticated privacy-enhancing techniques to protect the physical security of those relying on these critical communication links.
Key Takeaways
- Satellite internet users, particularly in conflict zones, face significant risks of geolocation via signal triangulation. Historical precedents and warnings from security experts underscore this critical vulnerability, turning communication tools into potential targeting beacons.
- Anon provides a practical and deployable solution for localization prevention using off-the-shelf hardware. It leverages Raspberry Pis and LoRa radio modules to create a mesh network, offering an accessible alternative to complex or proprietary systems.
- Key privacy mechanisms include dynamic, random routing and proactive output gateway switching. User data is routed through multiple hops in the mesh, and egress points to the satellite internet are regularly changed to prevent consistent signal triangulation.
- An innovative output gateway selection bias enhances security by actively obscuring the user's true location. By introducing random direction and weight biases, the system shifts the perceived center of an adversary's triangulation efforts, making accurate user localization extremely difficult.
- Anon demonstrates acceptable performance for critical tasks, such as uploading images, even with multiple hops and increased latency. While performance tradeoffs exist (e.g., 200KB image upload in ~276 seconds), the system maintains low packet loss and provides strong anonymity guarantees, with anonymity set sizes potentially in the thousands.
- Existing location privacy solutions are often impractical for satellite internet mesh networks. The research highlights that approaches like Phantom routing, network coding, fake traffic, and Tor are unsuitable due to impractical adversarial models, excessive overhead, or architectural incompatibilities, solidifying Anon's unique contribution.
About the Speaker(s)
The research presented in "Don't Shoot the Messenger: Localization Prevention of Satellite Internet Users" was conducted by David Koisser, Richard Mitev, Marco Chilese, and Ahmad-Reza Sadeghi. All speakers are affiliated with the System Security Lab of the Technical University of Darmstadt. Their work collectively reflects a strong expertise in system security, with a particular focus on addressing real-world vulnerabilities in communication networks and developing practical, robust solutions to enhance user privacy and security. Their academic background at a prominent technical university suggests a rigorous, research-driven approach to tackling complex security challenges, especially those with significant societal impact.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research presents Anon, a crucial and practical system for preventing localization of satellite internet users in high-risk zones. Leveraging off-the-shelf hardware and clever routing strategies, it offers a robust defense against real-world threats, addressing a critical gap in communication security. This isn't just theory; it's a deployable solution that matters.
Heather Calloway (CISO) — STRONG ACCEPT
This research directly addresses a critical, often overlooked, physical security risk for personnel relying on satellite internet in hostile environments. It provides a practical, deployable solution that organizations must consider to fulfill their duty of care and mitigate severe business and human impact.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024