What I noticed about Meshtastic is that you can create your own encrypted channels and the mesh can forward messages for you, even if they can’t read them.
But they forgot to add a MAC to the encryption protocol. It’s AES-CTR, so anyone who forwards your message can just arbitrarily change it!
26.01.2025 19:03
👍 4
🔁 0
💬 1
📌 0
Share the risk, share the exploit? 😂
22.01.2025 13:05
👍 0
🔁 0
💬 0
📌 0
On my way to Hamburg for #38c3! 😊
26.12.2024 11:53
👍 6
🔁 0
💬 0
📌 0
Boom! Daan Keuper (@daankeuper), Thijs Alkemade (@xnyhps), and Khaled Nassar (@notkmhn) from Computest Sector 7 (@sector7_nl) took no time in executing their SOHO smashup - going from the QNAP QHora-322 to the TrueNAS Mini X. TThey're off to the disclosure room. #Pwn2Own
24.10.2024 14:25
👍 2
🔁 1
💬 0
📌 0