EP 19: YOUR SATELLITE CALLS AREN'T ENCRYPTED. HERE'S WHY.
DESCRIPTION
Your phone call might have traveled 22,000 miles through space with zero protection, and someone with an $800 satellite dish could have heard every word. A new study from UC San Diego and the University of Maryland intercepted real, unencrypted satellite backhaul: voice calls, text messages, login credentials, and DNS queries, all pulled out of the air with consumer hardware.
I explain how everyday data ends up on satellites in the first place, remote towers, ships, aircraft, rural networks, and why so much of it stays unencrypted while TV signals have been scrambled for years. Vendors sell encryption as an extra license, carriers downplay the risk, and recent telecom cybersecurity rules got rolled back.
Then the part you can control: end-to-end encrypted messaging instead of SMS, a trusted VPN in remote areas or in flight, and HTTPS and official apps for anything sensitive.
TRANSCRIPT — EP 19
Your phone call just traveled 22 ,000 miles through space It was completely unencrypted and someone with an $800 satellite dish heard every word of that conversation This isn't hypothetical. It's happening right now to millions of people and most of them have no idea I'm Tyler Woodward. This is the Tyler Woodward project and today we're talking about why you're most private data, your voice calls, your text messages, your passwords, your Google searches might be flying over satellites with zero protection and what you can actually do about it. In October 2025, researchers at
UC San Diego and the University of Maryland They published a study called Don't Look Up. And here's what they did. They bought $800 worth of consumer grade satellite equipment. Things like a motorized dish, a tuner card, you know, the kind of stuff people use to watch satellite TV. They pointed it at the sky and they started capturing data traveling through geostationary satellites. What they found was roughly 50 % of all IP traffic they intercepted was completely unencrypted. That means unencrypted phone calls, unencrypted text messages, unencrypted passwords, unencrypted
banking credentials, unencrypted everything. And here's what that means. You probably have data on those satellites right now, and you don't know it. Your carrier didn't tell you. Your bank didn't warn you. It just happens silently in the background. By the end of this episode, you'll understand why this is happening, what specific data is at risk, and what you can do to protect yourself starting today. Let me start with what the researchers actually found because this is where it stops being abstract When they captured
the satellite traffic, they saw unencrypted voice calls from cellular networks actual conversations They could hear people talking They intercepted text messages and clear text SMS content they could just read right there in the open They saw banking credentials usernames and passwords transmitted with absolutely zero encryption corporate login information internal System traffic They also saw DNS queries which means they could see what people were searching for on Google medical symptoms financial concerns Personal information,
all readable right there in the open. One researcher mentions in the video that when they intercepted their first unencrypted phone call and heard a real person's voice, they immediately stopped. They closed the tool because they were afraid of what else they'd find if they kept looking. Think about that for a second. An academic researcher. Someone whose job it is to document vulnerabilities got so disturbed by what they were seeing that they immediately had to close the tool. Here's why that matters for you specifically. If you've
ever made a phone call from a remote location, maybe a mountain, a royal area, an airplane, that call might have been routed through one of these satellite backhauls. If it did, and if that backhaul wasn't encrypted, someone with a satellite dish could have listened in. If you've ever texted someone from somewhere with spotty cell coverage, that text may have been routed over satellite, unencrypted, completely readable. If you've ever logged into your email or your bank from a remote location, even over HTTPS, an attacker on a satellite, could potentially see what you're accessing through your bank.
They could see the timing and the volume of your traffic. They could infer things about your behavior. So why is your data even on satellites in the first place? The simple answer is because fiber doesn't go everywhere, not yet. Remote locations, mountains, deserts, royal areas, ships, airplanes, These places don't have terrestrial infrastructure. So, cell carriers, banks, utilities, everyone with data to move, they utilize satellites as the backhaul. When you make a call from a remote cell tower, that call gets digitized, packetized, and sent up to a geostationary satellite. The
satellite rebroadcasts it. Someone at a hub station on the ground receives it. and then routes it to wherever it needs to go. Your data doesn't stay on a secure network during that process. It becomes an IP packet. That packet travels through space and the person receiving it at the hub on the ground has no way to know if it's been intercepted by someone else. And here's the thing. Geostationary satellites are in a fixed position above the equator. From any location in North America, you can see between 30 and 40 different satellites at any given time. When a ground station sends a signal up to one of
those satellites, that satellite doesn't send it in a tight beam to one receiving station. It broadcasts it over thousands of square miles. Anyone and that footprint with the right equipment could potentially receive it. For television, this was solved decades ago. TV signals are scrambled, you need a decoder box to watch it. But, IP traffic? Often, no encryption at all. Here's the frustrating part. This problem isn't new. It's not a surprise vulnerability that just got discovered The satellite industry has known for decades that unencrypted
backhaul is a risk. They just decided not to fix it. Why? Well, because encryption cost money. Satellite equipment vendors sell encryption as a separate expensive license, but not a feature. A license. You buy the modem, and then you pay extra to enable IPSec or link layer scrambling of some sort. From a business perspective, if you're a satellite or a cellular carrier operating remote towers, you have to do a risk calculation. The cost of encryption versus the probability that someone will intercept this specific satellite
link. For a long time, The calculation looked like the probability is low, so we'll skip that feature for now. That calculation just got proven catastrophically wrong. When the researchers contacted T -Mobile about their unencrypted cellular backhaul, T -Mobile responded within weeks. They implemented encryption because the liability of saying, We were transmitting your phone calls unencrypted over satellites. Is, you know, existential. Other organizations the researchers contacted,
slower responses. Some encrypted quickly, others are still assessing their options. Here's the real problem. There's no regulatory pressure to fix this. In January 2025, the FCC tried to mandate basic cybersecurity for telecommunication carriers. That included encryption on important links. In November of 2025, weeks after this satellite research went public, the FCC rolled it back. 2 to 1 vote. They said, mandatory security
wasn't quote effective unquote. So we're in a regulatory vacuum. There's no legal requirement that your carrier encrypt their satellite backhaul. There's no standard that says encryption must be the default. The leverage is all with the companies themselves at this point. Let me make this concrete with Actual scenarios that apply to you scenario one You're traveling and make a phone call from a remote area Your call is routed via satellite backhaul. If that backhaul is unencrypted, which is common Your conversation
is being broadcast across space Someone with a satellite receiver can listen They can hear your voice the other person's voice everything you say Scenario 2 You text from an airplane or a remote location Your SMS is routed via satellite unencrypted Someone can read it Scenario 3 You're on a flight. You know the flights Wi -Fi and log into your email Your login credentials are traveling through multiple networks, some of which might be satellite based. Even with HTTPS on the web browser, an attacker can see you're
accessing your email provider. They can see the timing and volume of your traffic, which tells them something about your behavior. Scenario 4 You're in a royal area with spotty cellular signal and you do a Google search That DNS query the request to look up that domain might travel via satellite Unencrypted an attacker can see what you're searching for your medical symptoms your financial concerns your personal secrets and lastly scenario five you access your bank's website from a remote location. With HTTPS, your
password is encrypted, but an attacker can see that you're accessing your bank. They can see when you access it, how often, the volume of data transferred, they can infer things about your financial behavior. The common thread here You probably don't know when your data is being routed through satellite systems. Your phone's not going to tell you. Your bank doesn't tell you. Your carrier doesn't tell you. It just happens. So, you can't control whether your carrier uses satellite backhaul. You can't control whether they encrypt it. But you can still protect yourself.
First, Use end -to -end encrypted messaging. Things like Signal, WhatsApp, iMessage, or another encrypted messenger instead of plain SMS. These apps encrypt your message on your phone, and that encryption survives the journey through the satellite. Even if an attacker intercepts the satellite traffic, they can't read what was in that message. This is the single most effective thing you can do right out the gate Second use a VPN when you're in a remote area if you're relying on satellite internet Sellier and a remote
location or in -flight Wi -Fi turn on that VPN a Good VPN encrypts all your traffic before it leaves your device So even if your data routes through one of these unencrypted satellite links, it's encrypted by the VPN. The satellite operator sees the encrypted traffic, but can't actually see what the data is. Now, this doesn't make you 100 % safe. The VPN provider themselves could theoretically see your traffic if they wanted to. So, make sure to use a VPN that you trust. But I'll tell you this it's dramatically better
than nothing at all third use HTTPS everywhere Most browsers enforce HTTPS by default now anyways, so this is mostly automatic But if you see a padlock and HTTPS in your address bar, you're encrypted at the application layer If a website offers both HTTP and HTTPS, always go for HTTPS. Fourth, don't assume corporate networks are secure just because they're on your phone. If your company has a corporate VPN app or a corporate email app, use it. Don't just use your personal browser
to access corporate resources from a remote location. The corporate app likely has additional encryption and security built into it. Fifth, be skeptical about banking from a remote location. If you're banking from a remote area, use the official bank app rather than the website if possible. Apps often have better security than the browser -based access. If you must use a browser, verify you're on the real website with a valid HTTPS certificate. Six, understand what's at risk. Medical data, financial data, passwords, personal
information. These shouldn't be transmitted over encrypted links, period, full stop. If you can defer that transmission until you're on a secure network, do it. If you can't defer it, encrypt it. None of these steps are going to be perfect, but collectively they make you a much harder target than someone who's just transmitting everything and clear text over satellites. Here's what should concern you more than your personal privacy.
This is a systemic vulnerability in how critical infrastructure operates. The researchers found unencrypted cellular backhaul, banking systems, utility operators. Not all of it was encrypted, but roughly half of what they intercepted was completely exposed. Imagine if someone with bad intentions, not academic researchers, gained this capability. Imagine if they spent six months intercepting cell backhaul data, identifying patterns, understanding when high -value individuals are traveling. They could know when a CEO is
in a remote location. They could intercept financial transactions. They could monitor critical infrastructure operations. Again, this isn't hypothetical. Geostationary satellites are visible to anyone in a wide geographic area. The equipment is consumer grade and available on the open market. The knowledge is now public. The scary part isn't what academics prove. The scary part is that It's been possible for so long and almost nobody cared enough to fix it
Here's what I think and my opinion should happen again my opinion Satellite operators should encrypt all IP traffic by default Not as some sort of optional premium feature as a baseline encryption should be included, not sold separately. And if that makes the price higher for equipment, so be it. Telecommunication carriers should mandate encryption in their service agreements with these satellite operators. They should say, if you're carrying our traffic, it has to be encrypted.
And, obviously. regulatory bodies should require it. Here's what will probably happen though. Companies that get breached or face public scandal because of unencrypted satellite data will start demanding encryption from their vendors. Their vendors will respond by enabling it. Eventually, encryption will become standard because the cost of not doing so exceeds the cost of implementing it. Of course, it's going to take years. In the meantime, your data is still floating through space unencrypted, visible to anyone with the right equipment. If there's anything you should
take away from this, it should be this. Some of your data is routed through satellites right now. You don't know when. You don't know which data. But if you live in or travel to remote areas, use in -flight wifi, or rely on cell and royal regions, it's happening. Not just fear. That's how infrastructure works. 2. Encryption is never guaranteed. Just because your phone feels secure doesn't mean the backhaul is secure. Just because you're using a cellular network doesn't mean your data is encrypted end -to -end. Your carrier is responsible for their own backhaul,
and many carriers are not enforcing encryption. And third, you can protect yourself, but you have to do it intentionally. Use Signal or some other encrypted messenger. Use a VPN in remote areas. Check for HTTPS. Don't transmit passwords or sensitive data over unencrypted links if you can avoid it. These steps work. Do them. And if you're going to remember one thing from this episode, satellite backhaul is not a secure communications link. It's getting there, but it's going to take time. It's a radio signal broadcast that crossed
hundreds of miles. Treat it as such. When researchers at UC San Diego started studying satellite security, they were asking a very simple question. How easy is it to spy on satellites? Turns out the answer is pretty easy. And it's happening right now. to millions of people. Your phone call from a remote location might be flying over satellites unencrypted. Your text messages? Same thing. Your password? Same thing. The fix isn't complicated.
It's just encryption. But until the industry decides that encryption is the baseline and not a luxury, your data... is going to be public. Visit TylerWoodward .me for links to the full Don't Look Up research paper. I'm gonna put it in the description. A technical breakdown of how satellite backhauls work and a guide to choosing the right VPN if you're in any of these situations. If you want more stuff like this, follow at tylerwoodward .me on threads and blue sky. I post quick security tips, interesting new research, and my take on
how the industry is reacting. And if this episode was helpful, hit subscribe, drop a like, give it a rating on your favorite podcast platform so you don't miss the next one. Thanks for hanging out with me today. I'm Tyler. This is the Tyler Woodward Project. I'll catch you next week.