| https://twitter.com/Ancients | |
| Defcon.social | https://defcon.social/@Ancients |
| https://twitter.com/Ancients | |
| Defcon.social | https://defcon.social/@Ancients |
oh god my samba configuration broke
I never have a good time when I have to remember samba exists
I've been busy as hell this past week.
A lot of people have been asking hard questions about the security of LoRa systems when they hear about mesh radios.
I'm not one to trust the marketing so I and several friends put together two new LoRa tools to help us audit the security claims of LoRa mesh systems!
🤘🏿 📡 ✨
#radio #cybersecurity #privacy #meshtastic #lorapipe #meshmarauder #lora #mesh
One of the exploits demonstrated is PKI poisoning, this is where we listen for a complete user profile and only change the public key to one we control.
In the case of mesh marauder we also add a little 🥷to the user name so people can see something is wrong.
If they never have seen this user before they will appear as a green contact.
If this is a contact they already knew the meshtastic app provides a warning but appears to replace the original key without user input.