Ancients

@ancients@infosec.exchange
25 Followers
132 Following
150 Posts

I've been busy as hell this past week.

A lot of people have been asking hard questions about the security of LoRa systems when they hear about mesh radios.

I'm not one to trust the marketing so I and several friends put together two new LoRa tools to help us audit the security claims of LoRa mesh systems!

🀘🏿 πŸ“‘ ✨

#radio #cybersecurity #privacy #meshtastic #lorapipe #meshmarauder #lora #mesh

One of the exploits demonstrated is PKI poisoning, this is where we listen for a complete user profile and only change the public key to one we control.

In the case of mesh marauder we also add a little πŸ₯·to the user name so people can see something is wrong.

If they never have seen this user before they will appear as a green contact.

If this is a contact they already knew the meshtastic app provides a warning but appears to replace the original key without user input.

@Viss Maxed out at 100.8f outside today. Spicy
@Viss
I enjoy my low AF humidity.
IP/Port: 99.251.254.190:5900
Hostname: pool-99-251-254-190.cpe.net.cable.rogers.com
Client Name: chipi chipi chapa chapa
Location: Willowdale, Ontario, CA πŸ‡¨πŸ‡¦
ASN: AS812 Rogers Communications Canada Inc.
VNC Password: N/A
ID: 23981179
Added to DB: 05/06/2025, 10:39:46 PM (UTC)
Last seen: 05/06/2025, 06:52:41 PM (UTC)
https://computernewb.com/vncresolver/browse#id/23981179
@julf Slightly sad that "Heroic Vaccine Developer" is a raccoon and not a ferret.
https://en.wikifur.com/wiki/Chise
@Viss @Heidi This improved the quality of my day. Thank you.

I have had this in my head since i first heard it.

thanks, @Heidi
https://mastodon.social/@Viss/114583784576057280

Congrats to the Psychoholics on another victory! This year was MUCH closer.