[00:01.060 --> 00:10.900] All right, so I have so much to talk about, and the last time I did this talk, I was at Chaos Communication Congress, and I didn't realize there were two live translators trying to keep up with me. [00:11.460 --> 00:18.400] Fortunately, that's not the case this time, so I have like 60 slides to get through and like 45 minutes to do it, so let's see how many we can do. [00:19.880 --> 00:22.140] All right, so we are covering a lot today. [00:22.200 --> 00:24.500] We're going to talk about what Meshtastic is and what it's for. [00:24.960 --> 00:30.060] We're going to talk about hardware options and what it's like to build your own nodes, because I personally have been doing a lot of that. [00:30.060 --> 00:46.060] We're going to talk about LoRa and Mesh Networking fundamentals, talking about setting up nodes for specific use cases, joining Mesh Networks in your community, and then one of my favorite ones, which I just updated the slides on from DEF CON, and that is going to be attacks against Meshtastic in [00:46.060 --> 00:46.700] the wild. [00:49.480 --> 00:50.980] So, my name is Kody Kinzie. [00:51.060 --> 00:55.440] I'm a security researcher, and that gives me license to do basically anything, which I love. [00:56.040 --> 00:56.440] Yeah. [00:57.580 --> 00:59.160] Oh, yeah, my slide should be going up. [01:01.360 --> 01:02.340] They sure are. [01:02.620 --> 01:03.600] I'll unplug it and plug it back in. [01:03.960 --> 01:05.060] That will probably fix it. [01:15.740 --> 01:16.140] Right? [01:17.640 --> 01:19.580] Oh, I got excited, but that's not it. [01:21.580 --> 01:22.500] Let's try this one. [01:22.660 --> 01:22.860] Sure. [01:32.750 --> 01:34.630] There's a button here to maybe switch it over. [01:34.810 --> 01:35.150] Try that. [01:35.730 --> 01:35.870] Oh. [01:37.290 --> 01:37.690] Hey. [01:38.710 --> 01:39.950] I'm really good at pressing buttons. [01:42.850 --> 01:44.810] This cable is clearly not plugged into anything. [01:45.150 --> 01:45.730] Yes, it is. [01:45.970 --> 01:46.130] Yeah. [01:46.690 --> 01:47.610] That's not plugged into anything. [01:47.770 --> 01:49.430] And it's definitely this one, because I can see that. [01:49.470 --> 01:50.470] Yeah, it's definitely that one. [01:52.150 --> 01:53.170] Let's bring the... [01:53.990 --> 01:54.990] Bait cable away. [01:54.990 --> 01:55.010] Okay. [01:55.170 --> 01:55.290] Yeah. [01:56.750 --> 01:57.110] Okay. [01:57.370 --> 01:58.410] It's doing the screen jump. [02:15.180 --> 02:15.540] Anything? [02:16.380 --> 02:17.640] Should I unplug it and plug it back in? [02:17.860 --> 02:18.240] I'll try it again. [02:18.400 --> 02:20.600] I'm not the AV team, so I can only make so many suggestions. [02:24.540 --> 02:29.100] I mean, I can do the whole talk from no slides, but it's a lot less fun for everyone else. [02:40.250 --> 02:41.370] Adding a screen thing. [02:41.590 --> 02:42.170] It looks... [02:42.170 --> 02:43.970] It's outputting to an HDMI display. [03:15.000 --> 03:15.320] Oh. [03:15.560 --> 03:16.680] Oh, my slides were working. [03:16.860 --> 03:17.000] Okay. [03:17.240 --> 03:17.760] Okay, okay. [03:17.940 --> 03:18.820] I will just... [03:18.820 --> 03:19.840] I'll just leave it... [03:19.840 --> 03:20.580] I'll just leave it be. [03:20.900 --> 03:23.620] And I'll just talk, because I'm just talking about myself at this point. [03:24.080 --> 03:24.480] All right. [03:24.600 --> 03:31.960] So, my name is Cody Kinsey, and if you want to check out more of my content, you can go to www.hack.gay, which I'm very proud of. [03:32.340 --> 03:35.040] Some of you might have seen me on my YouTube channels. [03:35.240 --> 03:38.220] I created the Nullbyte YouTube channel, although I do not own it, which sucks. [03:38.720 --> 03:47.100] But also, my team, the Retia team, has also been creating content on our own channel, and we also have the Hackbyte channel on TikTok as well. [03:47.280 --> 03:56.000] We travel all over the world teaching cybersecurity and ethical hacking to beginners, and if you come by the ScriptKitty Village, we will teach you a lot of really fun stuff there. [03:57.440 --> 03:57.960] All right. [03:58.080 --> 03:59.820] So, what is the promise of Meshtastic? [04:00.000 --> 04:05.020] So, Meshtastic promises bi-directional encrypted off-grade communication over really long distances. [04:05.160 --> 04:14.120] When I say long distances, I mean I found my current firmware developer while I was flying over Montana, and he was in, I think, Washington, and we were chatting on Meshtastic. [04:14.120 --> 04:16.460] So, you can get really, really long distances. [04:16.780 --> 04:20.260] You can do things like monitor sensors, track objects, and control hardware remotely. [04:20.480 --> 04:28.960] And you can get robust communication in areas that are either super congested, so there's no cell service, or maybe there's non-existent infrastructure. [04:30.140 --> 04:39.000] So, the other thing that's really exciting about Meshtastic is the low cost of these nodes make it practically disposable, provided you are building them yourself or buying really cheap ones. [04:39.120 --> 04:40.520] So, we're going to talk about that as well. [04:41.600 --> 04:45.640] So, what is the cost of participating in Meshtastic? [04:45.760 --> 04:55.600] Well, if you want to make this cursed little Borg sugar cube, you can take two little pieces, a radio and a microcontroller, and you can air wire them together. [04:55.960 --> 05:00.760] And for about $5 pre-tariff, you can get a node up and running. [05:00.980 --> 05:01.780] This thing is horrible. [05:01.980 --> 05:02.900] I made several of them. [05:03.040 --> 05:04.600] I do not recommend it, but it works. [05:04.740 --> 05:10.240] So, if you wanted to make a node that was very, very cheap, if not super reliable, this is absolutely the way to do it. [05:10.440 --> 05:14.800] So, because this is so cheap, obviously it is of interest to us hackers. [05:15.280 --> 05:20.740] And it means that for people who are interested in very, very low cost electronics, something that... Oh, right. [05:20.800 --> 05:21.420] You guys can't see it. [05:21.480 --> 05:21.620] Sorry. [05:23.120 --> 05:27.260] For people who are interested in very low cost electronics, this is super exciting. [05:27.620 --> 05:27.740] Woo! [05:30.600 --> 05:31.040] Hooray. [05:31.040 --> 05:32.080] Thank you so much. [05:32.220 --> 05:33.580] I take all credit for that. [05:34.220 --> 05:34.660] Okay. [05:35.180 --> 05:35.920] Thank you, guys. [05:37.140 --> 05:39.480] So, this little thing, again, is about five bucks. [05:39.680 --> 05:41.460] And this will get you started with Meshtastic. [05:41.760 --> 05:47.880] So, for just slapping together these things and getting started with your own prototypes, it has become so affordable that anybody can do it. [05:48.140 --> 05:49.560] So, what can we make specifically? [05:49.720 --> 05:52.400] Well, we can do off-grid communication between devices in the backwoods. [05:52.400 --> 05:59.160] If we are going to a concert or a rave or a hacker convention, then we can communicate when the cell service might be congested or under attack. [05:59.580 --> 06:05.320] We can do inter-vehicle communication if we are in boats, aircraft, like cars. [06:05.540 --> 06:12.800] And then also, there's a lot of interest in disaster response and encrypted disaster response kind of applications. [06:13.240 --> 06:15.840] Now, the military likes this because it allows them to share map data. [06:15.960 --> 06:20.520] So, they can have scouts go out and then share map details back to a central map, and it gets updated for everyone. [06:20.620 --> 06:21.300] That's called ATAC. [06:21.580 --> 06:23.500] And then there's also remote sensor telemetry. [06:24.000 --> 06:29.280] So, if you want to set this up as a weather station, it's super easy to do that, and that's exactly what I do in my cyber camps. [06:29.520 --> 06:34.940] You can also set this up with a GPS and basically use it as a tracker that doesn't use like a cell network. [06:35.080 --> 06:36.020] It uses just LoRa. [06:36.440 --> 06:38.520] And then you can do remote control of hardware. [06:38.660 --> 06:42.820] So, I've seen like a Tesla coil turned on, and I've seen people remotely launch fireworks with Meshtastic. [06:42.960 --> 06:47.300] And my friend Davis has also got a little remote-controlled car he can drive. [06:48.600 --> 06:54.240] So, when we talk about some of these terms, I just want to go over what they mean if you're completely new to Meshtastic. [06:55.020 --> 06:58.660] So, one of the things that is essential to this is understanding LoRa radio. [06:59.060 --> 07:04.280] LoRa is a standard that's kind of like Wi-Fi or Bluetooth or something like that, but it is very low cost. [07:04.380 --> 07:05.980] It works over a very long range. [07:06.080 --> 07:11.980] It doesn't transmit very much data, and it does it kind of slowly, but it's able to be recognized from a super, super long distance. [07:12.180 --> 07:15.740] And the reason for that is these up-chirps and down-chirps, which we'll get into. [07:15.980 --> 07:19.540] And if you notice, these up-chirps and down-chirps also make up the Meshtastic logo. [07:21.020 --> 07:27.700] So, the Meshtastic protocol sits at layer 3 of the OSI model for any networking nerds who are just getting started. [07:27.840 --> 07:41.140] So, if you want to know exactly what Meshtastic is doing, it's kind of sitting on top of this radio and managing things like the mesh protocol and the encryption and all that other great stuff, and also interfacing with multiple applications that make it user-friendly. [07:41.280 --> 07:44.840] So, it's going to be like a mobile application and then their web interface. [07:46.220 --> 07:54.040] So, the kind of like currency of a node and kind of deciding like what the characteristics will be are based on a couple little components. [07:54.200 --> 07:55.480] The first is the LoRa radio chip. [07:55.600 --> 07:58.380] And this kind of defines how the LoRa radio is going to behave. [07:59.980 --> 08:03.340] The preferred chipset is the SX1262. [08:03.660 --> 08:06.080] And this is the one that we're using in the nodes we're building currently. [08:06.220 --> 08:11.760] The nice thing about this is it's a bit more sensitive, it's more modern, and it can be software-selected for the frequency you want. [08:11.920 --> 08:22.680] Other nodes require you to buy one or the other, and after we traveled to Europe and had to buy two completely different sets of radios, I have to say picking a radio that supports dual bands so if you're traveling you don't have to buy a different one is really nice. [08:23.520 --> 08:25.500] The microcontroller is the brains of the operation. [08:25.740 --> 08:30.160] So, this defines the peripherals and all the other stuff that is going to be running on the node. [08:30.460 --> 08:32.440] So, most of the time, this will be something really nice. [08:32.580 --> 08:35.920] It can ESP32S3, but it can also be something like an RP2040. [08:36.160 --> 08:39.180] And those are the two chips that I chose to build my own nodes off of. [08:39.320 --> 08:43.440] But if you're familiar with microcontrollers, this will give you an idea of the capabilities of a node. [08:43.440 --> 08:48.340] It will define whether it has things like Bluetooth support, Wi-Fi support, and other things that are nice to have. [08:50.260 --> 08:53.620] Now, you'll see that most of the time these little chips aren't very useful by themselves. [08:54.320 --> 09:01.640] For electronics people, for makers, we like to use breakout boards, which basically have other components added to it to make it so it's more useful. [09:01.760 --> 09:07.140] So, in this case, we have GPIO pins so it can be plugged into stuff, and we have a USB port to supply power and data. [09:07.300 --> 09:09.400] And this is generally how we kind of slap together nodes. [09:09.400 --> 09:15.180] We take a radio chip, we take a microcontroller, we slap them on breakout boards, and then we put them together. [09:16.180 --> 09:17.420] So, that's the algebra. [09:17.660 --> 09:20.840] A host microcontroller plus a radio equals a mesh-tastic node. [09:20.940 --> 09:23.300] And this little thing might look horrible, but it actually works. [09:23.480 --> 09:30.380] So, these more sophisticated nodes we'll talk about later are all just different variants of this formula, of just a host microcontroller and a radio. [09:30.520 --> 09:37.580] So, anytime you're looking at mesh-tastic nodes, you can kind of assess how it's going to behave by the underlying microcontroller that runs it and the radio it relies on. [09:37.760 --> 09:41.580] So, here's some examples of a simple node versus a more complicated node. [09:41.760 --> 09:43.560] And the one on the left is a very simple node. [09:43.800 --> 09:45.160] I think this is the wireless stick. [09:45.360 --> 09:49.560] It's just a radio and the microcontroller and kind of nothing else. [09:49.960 --> 09:52.000] The one on the other side is a more complicated node. [09:52.140 --> 09:55.240] This is going to run you maybe like $80 to $120. [09:55.880 --> 09:58.130] But the nice thing here is it's ruggedized. [09:58.720 --> 09:59.960] It has a bunch of stuff built in. [09:59.960 --> 10:02.100] It has an e-ink display, so it sips power. [10:02.520 --> 10:03.820] It's really like a step up. [10:03.960 --> 10:07.100] So, you can get all different kind of varieties of nodes. [10:07.280 --> 10:10.900] There's ones that cost like over $100 and there's ones that cost less than $30. [10:11.980 --> 10:13.920] So, in the future also, this is really exciting. [10:14.060 --> 10:18.960] There's integrated nodes where under the same little metal cap, there's both the radio and the host microcontroller. [10:19.080 --> 10:19.960] So, this little guy is $10. [10:20.520 --> 10:22.140] Obviously, like there's no USB port. [10:22.280 --> 10:24.820] So, this is not very useful without putting on a breakout board. [10:24.920 --> 10:33.660] But for people who are thinking about designing their own like mesh-tastic nodes in the future, it's going to cost you like $10 to get started with the part that just runs mesh-tastic. [10:33.720 --> 10:34.900] You'll still have to add other stuff. [10:35.840 --> 10:38.300] So, we built some of our own mesh-tastic hardware. [10:38.560 --> 10:40.400] And one of them was the Bluetooth Nugget. [10:40.580 --> 10:44.500] This was an update to our Nugget design that we ran at the conference here last year. [10:44.620 --> 10:46.100] And we added a backpack. [10:46.340 --> 10:48.680] And we wanted to make this basically a really great companion node. [10:48.680 --> 10:55.620] And we've been teaching our advanced mesh-tastic class off of this node and flash the custom Defcon mesh-tastic firmware for this. [10:55.700 --> 10:56.740] And it was an amazing time. [10:56.800 --> 10:58.220] We had a really great time at Defcon. [10:58.820 --> 11:00.820] We designed this to be a prototyping powerhouse. [11:00.940 --> 11:03.620] So, we added all sorts of pinouts for adding GPS and other stuff. [11:03.820 --> 11:10.100] So, if you come by our booth, we can show you some of the nodes we built for the kind of high-end like companion-style node. [11:10.520 --> 11:19.380] On the other side, we wanted to create an infrastructure-style node that was a fun soldering class and would allow people who had never gotten started with mesh-tastic before to build their own node and then assemble it. [11:19.520 --> 11:22.640] Our target here was actually some cyber camps, kids cyber camps that we do. [11:22.820 --> 11:27.180] So, this needed to be literally simple enough for a child to put together and get started with. [11:27.540 --> 11:33.540] So, for Chaos Communication Congress, we started out and my artist friend Felix put together a bunch of sketches of these adorable eyes. [11:33.720 --> 11:39.100] And we finally prototyped a version of the nibble that we built for C3. [11:40.180 --> 11:42.900] So, we had a custom version mesh-tastic compiled for it. [11:43.120 --> 11:46.760] And we made this so that it was super easy to add a weather station node. [11:46.940 --> 11:53.220] And also, you could select, and you could either add an ESP32S3 on one side or an RP2040 on the other side. [11:53.360 --> 11:56.940] So, depending on what microcontroller you have available, you can build a node however you want. [11:57.080 --> 11:58.700] This was a super fun idea. [11:59.180 --> 12:06.820] And a bunch of, sorry, very drunk Europeans helped us solder together a bunch of them for the classes, and about 50% of them survived. [12:07.980 --> 12:12.540] So, we learned a lot about how to make simple nodes for beginners over the course of this. [12:12.680 --> 12:16.960] We got some feedback that these little resistors were a little bit small. [12:17.500 --> 12:18.860] But we love this design. [12:19.020 --> 12:20.000] A lot of people enjoyed it. [12:20.120 --> 12:21.620] And we have decided to make it open-source. [12:21.820 --> 12:24.780] So, this is the first conference that we've announced it's open sourcing. [12:24.860 --> 12:29.980] I literally open-sourced it in the courtyard over there while we were putting together the slides. [12:29.980 --> 12:35.820] So, if you want to build one of your own, I hope we have put all the files necessary to do so here. [12:35.960 --> 12:38.560] And you can check out these slides afterwards and build your own node. [12:39.100 --> 12:39.800] Because I think they were great. [12:39.920 --> 12:44.460] And our friend Davis also put together a video assembly guide that shows you how to go through all the steps to do this. [12:45.020 --> 12:47.160] So, the consensus was resistors were just too small. [12:47.240 --> 12:48.160] You can see these little things. [12:48.320 --> 12:51.780] Our hardware designer was sure that everybody could get this. [12:51.780 --> 12:56.420] But our updated design took into account that not everybody had the dexterity that he does. [12:56.680 --> 13:02.180] So, it was also mentioned that it would be nice to add a dedicated pinout for the temperature sensor. [13:02.780 --> 13:06.260] And we should also use the dual band SX-1262 radio. [13:06.420 --> 13:08.980] Prior to that, we were using the RFM95. [13:09.320 --> 13:12.340] And that was when we had to basically order double radios. [13:12.440 --> 13:14.400] Some for Europe, some for the United States. [13:15.000 --> 13:22.460] So, the new Nibble Connect, which we have at our booth and we'll be doing some classes off of, has the SX-1262 radio, a pinout just for the weather station. [13:22.660 --> 13:24.680] And there's also breadboard compatible, if you add on pins. [13:24.860 --> 13:28.640] We used it to teach a soldering class with kids, and they loved it. [13:28.720 --> 13:29.600] It was actually really great. [13:30.340 --> 13:36.660] So, if you're looking for a simple project that allows you to build a mesh-tastic node, maybe you have a kid who's interested, or maybe you're looking to teach a bunch of people. [13:36.800 --> 13:42.000] For one, I mean, if you guys want to build a bunch of unregistered off-grid nodes, that's cool. [13:42.140 --> 13:43.620] But also, this is just fun for kids. [13:43.800 --> 13:46.560] And getting a weather and temperature station up and running was a lot of fun. [13:46.700 --> 13:52.540] So, in our Montana cyber camps, which we ran in two different locations, the kids really enjoyed it in both spots. [13:52.980 --> 13:55.220] So, if you want to build your own, you can come by our booth. [13:55.340 --> 13:57.260] We're going to be at the script kitty village. [13:57.740 --> 13:59.540] And we also made a custom design. [13:59.640 --> 14:00.780] We have a few of them here. [14:00.880 --> 14:01.620] They're not fully done. [14:01.720 --> 14:03.020] If you want to check them out, you're welcome to. [14:03.120 --> 14:03.860] This is the... [14:03.860 --> 14:05.780] The creators call it the sweat nibble. [14:06.420 --> 14:08.640] It came from the idea of, what if he had a screen? [14:08.960 --> 14:11.140] And the idea is, it's a cat that wants his belly scratched. [14:12.280 --> 14:13.440] Prototype has a couple of little issues. [14:14.340 --> 14:18.740] Our hardware designer went ahead and launched it without checking to see that the screen was supported by Meshtastic. [14:18.880 --> 14:19.640] So, it's really tiny. [14:20.580 --> 14:22.720] But you actually can solder any OLED screen here. [14:22.840 --> 14:23.860] It just makes the design a little fat. [14:24.000 --> 14:25.160] So, we have these over at our booth. [14:25.260 --> 14:29.320] This was our updated design where we wanted to add a screen in and kind of like play with it a little bit more. [14:29.600 --> 14:30.160] But, yeah. [14:30.840 --> 14:31.080] All right. [14:31.180 --> 14:32.320] So, let's get into LoRa. [14:32.520 --> 14:34.180] So, LoRa stands for long range. [14:34.680 --> 14:38.320] And it's an alternative to the radio standards we might be used to working with as hackers. [14:38.780 --> 14:41.420] It works in unlicensed sub-gigahertz frequency bands. [14:41.620 --> 14:44.520] And that means we can get away with some shit that usually we can't get away with. [14:44.620 --> 14:45.240] And that's great. [14:45.520 --> 14:46.900] Like, sending encrypted packets. [14:47.080 --> 14:50.000] Like, if you are a ham radio person, you know that you're not supposed to do that. [14:50.140 --> 14:55.960] However, if we're operating in the unlicensed spectrum, that means that we are not licensed. [14:56.240 --> 14:59.520] And therefore, we can do some stuff that would be prohibited otherwise. [15:00.200 --> 15:04.980] So, LoRa also has the ability to be read significantly below the noise floor. [15:05.120 --> 15:07.080] 20 dB below the noise floor. [15:07.080 --> 15:09.600] So, that's pretty incredible for a radio standard. [15:09.860 --> 15:18.700] And for something to kind of build off of, it means that even though it might not have good penetration in buildings, when you have line of sight, it's a pretty incredible tool for creating links between different devices. [15:19.680 --> 15:26.400] Now, these upchirps and downchirps are kind of the core, like, currency for, like, sending data when it comes to the LoRa radio. [15:26.600 --> 15:32.040] So, like, the upchirp and the downchirp are how it sends data and how much of the frequency it takes up, how long that chirp is. [15:32.160 --> 15:33.900] That's all kind of, like, arranged in the settings. [15:34.080 --> 15:40.240] However, the fact that these chirps can be received over such a long distance and decoded from what's essentially noise is really incredible. [15:40.380 --> 15:46.780] So, if you're a radio nerd, dive into, like, the upchirps and downchirps and the way that it's decoded because it's probably the most interesting part about Meshtastic. [15:47.040 --> 15:51.800] So, I've kind of gone through the different types of radios, but the frequencies are really what's important to know as well. [15:52.000 --> 16:01.880] You can commit a crime with Meshtastic just by taking a device that is at the wrong frequency and traveling to Europe or India or Asia because you might be transmitting on frequencies that are not licensed there. [16:01.880 --> 16:07.740] So, the first thing that a Meshtastic device does when it boots up is it asks you where you are and it will not transmit until you tell it. [16:08.080 --> 16:11.220] And the expectation is it is preventing you from committing a crime. [16:12.180 --> 16:16.000] Now, there's also other things you can do just with the LoRa radio. [16:16.260 --> 16:20.780] If you have Arduino or CircuitPython or MicroPython, you can actually just address it directly. [16:21.000 --> 16:26.460] And this is, for example, a little, very simple code for sending information over a LoRa radio. [16:26.640 --> 16:27.800] It's not very long. [16:27.920 --> 16:31.860] So, if you wanted to just work with the radio without Mesh Networking, you can totally do that. [16:32.360 --> 16:37.580] And there's lots of things you can do, again, without using Meshtastic, just using the raw LoRa radio. [16:37.760 --> 16:40.920] Like, we created a bad USB device that was triggered via LoRa. [16:41.000 --> 16:45.460] So, if you wanted to do like a USB rubber ducky style attack using LoRa, not that hard to do it. [16:46.120 --> 16:46.440] All right. [16:46.600 --> 16:51.400] So, Meshtastic adds encryption, managed flood routing and convenient applications to LoRa. [16:51.520 --> 16:54.260] And that means you can control nodes via Bluetooth, Wi-Fi, or serial. [16:54.420 --> 17:00.900] So, you can connect it to your home Wi-Fi network and stick it somewhere that's almost impossible to reach and still access it from all of your devices, which is pretty cool. [17:01.120 --> 17:05.010] You can also access it from any computer with a Chrome-based browser. [17:05.560 --> 17:13.260] So, that's really exciting because it means you don't have to have any expectations about, for example, a class full of kids who's going to be taking this and setting it up. [17:13.400 --> 17:18.480] Provided they have a computer with a USB port and a Chrome browser, you should be able to connect and program these. [17:18.980 --> 17:30.700] Now, MeshNets assemble themselves, meaning that when we have these devices they will automatically connect to each other and try to establish routes between each other and send messages in a way that tries to do a best attempted delivery. [17:30.900 --> 17:35.080] It's not super reliable, honestly, but it does allow for huge, huge ranges. [17:35.320 --> 17:39.340] And it means that many moving nodes can be part of an otherwise fixed network. [17:40.920 --> 17:59.320] Now, managed flood routing is super fascinating and I really want to go into deep detail on it, but basically it means there's a protocol underlying Meshtastic that allows it to prevent just absolute flooding of the network by using routers and other nodes in strategic positions to repeat messages [17:59.320 --> 18:07.620] first and then nodes that hear the message last, basically, or hear it at its weakest signal to retransmit it first. [18:07.820 --> 18:20.180] And this is a really interesting principle where if you're interested in how the Mesh networking, how the Mesh actually functions, this is an exploitable principle and it's also something that's really cool because it means it's able to cut down on the amount of traffic on the network and spread [18:20.180 --> 18:21.560] messages as far as possible. [18:22.900 --> 18:24.160] So, really, really interesting. [18:24.440 --> 18:31.860] It's kind of the principle I would say you should look up if you want to go really deep into carrier sense collision avoidance and the way that this actually works. [18:32.300 --> 18:35.880] If I want to get into the attacks against Meshtastic though, I can't go as deep as I did before. [18:36.760 --> 18:38.000] So, check that out separately. [18:38.980 --> 18:39.120] All right. [18:39.280 --> 18:40.820] So, different devices that you can use. [18:40.900 --> 18:42.580] You can see kind of the full spectrum here. [18:46.500 --> 18:52.720] If you're looking for a companion node or something that goes with you all the time, obviously, you're going to want something with a screen and buttons so you can use all the functions. [18:53.020 --> 19:06.980] But, if you're using Meshtastic for IoT devices, if you're out there like setting this up for like farmers, like monitoring things and crops, you're probably going to use like a rack wireless setup which is a like modular industrial style more like industry focused nodes. [19:07.200 --> 19:09.340] So, there are all sorts of different options available. [19:09.960 --> 19:13.740] The Helltech V3 is like one of the most common nodes out there for people's first nodes. [19:14.180 --> 19:16.420] These, I see the like Tdex I see everywhere. [19:16.760 --> 19:20.440] And then, these are generally like a lot of people say these are disappointing because the firmware is not great. [19:20.560 --> 19:21.820] I've had kind of a similar experience. [19:21.960 --> 19:23.740] But, some people like this as well. [19:24.880 --> 19:26.300] So, encryption cheat sheet. [19:26.420 --> 19:33.080] If you are sending messages on the long fast default channel with the default public encryption key, all nodes can see all of your messages. [19:33.340 --> 19:37.700] So, even though it is encrypted, it's encrypted with the same key that everybody has by default. [19:37.840 --> 19:39.320] So, that's not really encrypted at all. [19:39.320 --> 19:41.660] So, just keep in mind like, yeah, it is encrypted. [19:41.860 --> 19:43.620] But, anybody who has a Meshastic node can read it. [19:43.880 --> 19:46.200] And, it's not something you should assume other people can't see. [19:46.780 --> 19:52.520] Next up is if you are communicating on the same long fast channel, but you change the encryption key and distribute it to your friends. [19:52.820 --> 19:58.340] Well, now, everybody who knows that secret key that you just distributed can see messages, but nobody else can. [19:58.820 --> 20:01.600] So, your packets will actually go through other people's nodes. [20:01.780 --> 20:03.600] However, they won't be able to read them. [20:03.720 --> 20:04.100] So, that's good. [20:04.180 --> 20:08.820] It means you can communicate with your friends on your long fast channel and use other nodes to hop through. [20:08.980 --> 20:11.380] However, those nodes can't read your packets. [20:11.740 --> 20:12.200] That's pretty good. [20:12.700 --> 20:18.240] So, next up, if you have nodes that have exchanged encryption keys communicating via DMs, that is, like, signed. [20:18.360 --> 20:19.140] It is, like, encrypted. [20:19.140 --> 20:20.780] That is using a private key. [20:20.980 --> 20:24.020] If you're DMing someone, then nobody else can read that message. [20:24.220 --> 20:27.960] So, it's kind of three different circles of encryption to keep in mind when you're sending messages. [20:28.120 --> 20:36.840] And this also used to be particularly relevant because you could get a man in the middle position early, like, early on in Meshastic and be able to read unencrypted DMs of people that were going through you. [20:36.980 --> 20:38.600] So, subsequent updates have prevented that. [20:38.720 --> 20:42.960] But it was interesting to note that a lot of people just assumed that encrypted meant that no one could read it. [20:43.040 --> 20:47.520] But it was not actually end-to-end encrypted, at least the DMs, until recently. [20:48.160 --> 20:50.280] So, in order to install this, we can use the web flasher. [20:50.400 --> 20:55.380] We can use esptool.py, or we can use our website, nugget.dev. [20:55.720 --> 20:57.280] This is a very simple process. [20:57.300 --> 21:00.460] You just plug it in in boot mode and flash over the firmware. [21:01.020 --> 21:03.880] When you want to use it, you can use a mobile or desktop application. [21:04.140 --> 21:07.440] And you can connect, again, via Wi-Fi, via Bluetooth, or via serial. [21:07.600 --> 21:10.320] So, it gives you tons of options if you want to connect to one of those. [21:10.480 --> 21:18.820] The only circumstance I've seen is if you have a node that only communicates over serial, it can't be used with iOS because iOS devices do not support serial connections. [21:18.940 --> 21:22.600] Other than that, provided it has Bluetooth or Wi-Fi, you should be able to use a node. [21:24.000 --> 21:26.180] So, again, when you plug this in, it will not work. [21:26.320 --> 21:27.480] And that disappoints a lot of people. [21:27.600 --> 21:29.600] In order to get started, you have to plug the node in. [21:29.600 --> 21:30.800] You have to select the region. [21:30.960 --> 21:32.640] And it's highly advised to add an antenna. [21:32.900 --> 21:37.140] We had a whole class almost fry their radios by trying to transmit without adding their antenna first. [21:37.160 --> 21:38.220] So, it is not recommended. [21:38.260 --> 21:39.300] It can damage the radio. [21:40.420 --> 21:42.800] So, there's eight different profiles for Meshtastic. [21:43.040 --> 21:51.640] And basically, the underlying settings that this is tweaking are so complicated that I was using just the raw lower radio in CircuitPython trying to get this to work. [21:51.640 --> 21:56.340] And if you get one tiny little thing different between devices, nothing can hear. [21:56.440 --> 21:57.740] It's like the other one. [21:57.840 --> 21:59.660] Like, it's as though it's shouting into a void. [21:59.800 --> 22:13.340] So, it's so easy to mess this up that Meshtastic has created different profiles that basically allow you to set all these kind of underlying, like, ticks, all without having to, like, think about copying them over to another device. [22:13.340 --> 22:17.800] So, provided you select one of these and your friend selects one of these, you should be able to communicate. [22:18.300 --> 22:21.260] Now, these have trade-offs between long-range or short-range. [22:21.420 --> 22:29.280] And the benefit here is if you're at a conference like Defcon, you want to be using as little airtime as possible because there's hundreds of other people broadcasting. [22:29.520 --> 22:41.460] If you're in the middle of the woods and somebody else is, like, way, way far away, like a hundred miles, you're going to want to be using a very slow transmission time that has the best possibility of being received even very far away with lots of error correction. [22:41.460 --> 22:44.980] But you're going to be using multiple seconds to transmit the same message. [22:45.480 --> 22:49.840] So, that kind of transmission time would kill the ability for others to transmit at a conference. [22:50.080 --> 23:00.080] So, it's very important to set these appropriately for what you're trying to do because, like, a very long, slow speed in, like, a dense area is going to use up tons of bandwidth and make it so other people can't transmit. [23:01.020 --> 23:03.040] So, device roles are also very important. [23:03.640 --> 23:06.980] There's only a couple, honestly, that you should probably be using under most circumstances. [23:07.180 --> 23:13.160] Client, which basically connects it to your phone and acts as, like, a router basically forwarding packets to you and acts as a buddy. [23:13.300 --> 23:14.160] It's a companion. [23:14.400 --> 23:15.260] It's traveling with you. [23:15.340 --> 23:17.920] A client mute means that you don't want to forward packets from other devices. [23:18.180 --> 23:19.120] You want to save battery. [23:19.260 --> 23:21.660] You only want to receive messages and send them when you want. [23:21.960 --> 23:28.000] Client hidden also means that it only broadcasts as needed and it basically, like, doesn't even appear in the list. [23:28.340 --> 23:29.460] And then we have some other ones. [23:29.520 --> 23:34.340] If we want to set it up as a sensor, this will turn it into a weather station and begin immediately transmitting telemetry. [23:34.340 --> 23:39.300] If we want to set it up as a router or repeater, you're going to get people mad at you. [23:40.080 --> 23:44.440] This is frequently disabled in conference builds because it causes chaos on the network. [23:45.160 --> 23:58.280] Unfortunately, if you set up a bunch of routers all in a bad place and you think you're doing a good job and you're helping, but actually you're creating sinkholes in the network where those routers have preference over other devices to grab packets and basically steal a hop and make it so that they can't escape from areas. [23:59.240 --> 24:02.560] So most of the time, you're going to want to use like the first three settings. [24:02.820 --> 24:08.820] It's kind of rare that you would have a position where you would use a router or repeater that doesn't like piss other people on the mesh network off. [24:09.460 --> 24:11.580] So you can also kind of see that there's some trade-offs here. [24:11.700 --> 24:19.200] And I frequently had to reboot Meshtastic or reflash it because I thought I bricked it, but in fact, I just set it to a router and it turned off the Bluetooth and the screen. [24:19.540 --> 24:23.820] So it's important to note that like different device roles will cause the device to act differently. [24:23.880 --> 24:29.100] So if you set this to a router and suddenly you can't connect to it anymore, it's because it turned the Bluetooth off. [24:29.240 --> 24:31.280] So just a little fun fact. [24:32.140 --> 24:34.380] All right, so adding sensors and hardware is super easy. [24:34.540 --> 24:43.400] Under the telemetry module, you can go in and basically just add this little module enabled tick and you end up being able to add any of these supported sensors. [24:43.540 --> 24:51.380] And that's everything from like a heart rate sensor to a body temperature sensor to a barometric pressure humidity and temperature sensor. [24:51.580 --> 24:55.620] So really easy to build weather station style things and lots of different sensors are supported by default. [24:55.740 --> 25:00.900] You plug it in and Meshtastic recognizes it by its I2C address and immediately start sending the data. [25:01.060 --> 25:02.220] No configuration required. [25:03.920 --> 25:16.600] Also, UART devices like GPS, spy devices like screens or other types of sensors, and then analog out devices, notification sensors like passive infrared or millimeter wave human detectors, and then notification LEDs, NeoPixel strips. [25:16.680 --> 25:19.940] All these can be added really easily, remotely controlled via Meshtastic. [25:20.720 --> 25:22.600] So the modules here, there's lots of them. [25:22.720 --> 25:24.000] And I'm going to touch on them kind of lightly. [25:24.260 --> 25:26.120] The ambient lighting lets you control a light strip. [25:26.340 --> 25:31.780] The audio lets you do limited voice communications on something that there's literally one device that supports this, so I'm not going to go into it. [25:32.140 --> 25:35.680] Canned messages allow you to preload messages and send them later. [25:35.820 --> 25:38.620] So let's say you have a standalone device that has a screen and buttons. [25:38.800 --> 25:47.600] You can load a bunch of messages like, let's meet back at the car or something like that, distribute them to your friends and send these canned messages to each other, as well as your GPS location. [25:47.980 --> 25:48.900] That's pretty useful. [25:49.180 --> 25:53.880] So there's also the detection sensor, which lets you turn this into a remote sensor. [25:53.980 --> 25:57.440] So let's say that you're monitoring an area where nobody is supposed to be. [25:57.540 --> 26:01.420] This would alert you if somebody's in that area and send the message over the Meshtastic network. [26:01.600 --> 26:09.040] I decided to try this, so I set it up to send toilet cam alert every time I walk past the sensor, and then I forgot to change the default key. [26:09.100 --> 26:14.240] So I ended up blasting my regional mesh network with just toilet cam alert over and over and over. [26:14.420 --> 26:19.380] So if you're going to test this, please make sure to change over to a different channel before triggering the telemetry. [26:20.340 --> 26:23.400] MQTT, if you're aware of what MQTT is, you can set up Adafruit I.O. [26:23.480 --> 26:27.720] You can connect one of these nodes to it and then start sending packets that you see. [26:27.840 --> 26:29.260] That allows you to map different nodes. [26:29.360 --> 26:30.640] It allows you to monitor sensors. [26:30.940 --> 26:32.360] It's really cool and really easy. [26:33.040 --> 26:35.420] And then the pack scanner is perhaps the most confusing one. [26:35.560 --> 26:41.500] That one uses the Wi-Fi and Bluetooth radio to try to measure how many people are in an area based on the number of wireless devices nearby. [26:41.500 --> 26:42.880] It doesn't work all the time. [26:43.820 --> 26:49.460] So we also have the range test module, which is also a great way to take up a ton of bandwidth on your local community net. [26:49.760 --> 26:53.420] I left this on and ended up consuming 35% of SoCal Mesh's bandwidth. [26:53.580 --> 26:55.860] So please turn that off when you're done using it. [26:55.920 --> 27:00.720] But basically, it broadcasts a continuous stream of messages and allows you to drive around and build a map of where you can receive it. [27:00.980 --> 27:06.720] The serial module allows you to connect and control this device remotely, which we'll use for an attack in a second. [27:06.720 --> 27:13.360] And then the store and forward module allows you to store messages briefly and then forward them to nodes that might have gone offline. [27:14.340 --> 27:16.200] So we can control nodes over Python. [27:16.460 --> 27:18.180] And that obviously is useful to hackers. [27:18.360 --> 27:21.280] We can get it to do all sorts of interesting things like automatically trace routing. [27:21.520 --> 27:24.300] We can get it to send messages and receive messages automatically. [27:24.920 --> 27:32.660] I like to use this for signals intelligence when I'm flying to find out critical nodes that are routing basically traffic for the whole area and find out which nodes are most popular. [27:32.660 --> 27:34.900] And you can also do set up scripts in Bash. [27:35.040 --> 27:40.660] So if you're familiar with Bash, you can use it to remotely control nodes as well from a serial port. [27:41.140 --> 27:43.020] Now there's multiple different ways of using a mesh network. [27:43.180 --> 27:45.800] You can set up your own devices and just have them routing. [27:46.060 --> 27:49.720] Or if you want to, you can also use a semi-private mesh. [27:49.880 --> 27:54.640] And that basically means that you have other people's nodes sending your packets, but you have a different encryption key. [27:54.780 --> 27:56.580] That extends your range pretty significantly. [27:56.760 --> 28:01.700] And if you're part of a local mesh net, that means you could get hundreds of miles of range, which is pretty incredible. [28:03.320 --> 28:05.640] So speaking of regional networks, there's a lot. [28:05.840 --> 28:11.300] And in my area, SoCal Mesh, the Meshtastic Bay Area group and Central Valley Mesh are absolutely huge. [28:11.520 --> 28:16.300] In Southern California, I can send a message from Santa Clarita to San Diego some of the time. [28:16.420 --> 28:24.900] And that's because a lot of the nodes are basically in people's cars or sometimes I'll bounce off of an airplane landing in LAX that someone has a node in their luggage. [28:25.140 --> 28:30.200] It's pretty crazy the temporary links that this network kind of builds all of the time. [28:30.200 --> 28:33.240] The network is constantly mutating and changing and adapting. [28:33.540 --> 28:34.820] So is it reliable? [28:35.000 --> 28:35.260] No. [28:35.460 --> 28:36.200] But is it huge? [28:36.360 --> 28:36.560] Yes. [28:36.740 --> 28:43.920] And if you check out some of these nodes in local areas, you'll see that there's just hundreds of them, and they're constantly being updated. [28:44.500 --> 28:53.400] Now, speaking of checking them out, you can go to mesh-tastic.liamcoddle.net and see a semi-live map of mesh-tastic nodes just about anywhere that has a collector node nearby. [28:53.780 --> 29:00.380] What that means is there's a node that's connected to Wi-Fi and forwarding packets it sees over MQTT to this map. [29:00.560 --> 29:03.180] Any node that's sharing its location appears on the map. [29:03.300 --> 29:06.360] So you are not shouting into the void when you broadcast on mesh-tastic. [29:06.520 --> 29:11.560] It is, in fact, probably being received, recorded, and sent over MQTT and processed in some way. [29:11.840 --> 29:19.920] Now, if your node isn't broadcasting its location, it won't show up on this particular map, but it will show up for anybody else who's scanning through packets and wants to see what's going on. [29:20.000 --> 29:27.720] So if you're in a city or if you're in an area where anybody's running a collector node, it's very, very likely that you will be mapped if you are sharing your location. [29:28.020 --> 29:29.600] So what does that mean? [29:30.020 --> 29:32.520] Well, nodes on the default channel are not private. [29:32.720 --> 29:34.960] This is my actual flight out of Burbank. [29:35.220 --> 29:36.800] Actually, I think I took LAX that time. [29:36.860 --> 29:37.220] That sucks. [29:38.000 --> 29:48.760] But you can see that I took off, and then I flew up and over Fresno, and then I stopped being picked up by whatever node was running the collector somewhere east of Carson City. [29:49.240 --> 29:53.260] So I could tell so much specific information about my flight as a result. [29:53.400 --> 29:58.420] If you have a node that has GPS on, and there's collectors nearby, you can be mapped like this. [29:58.800 --> 29:59.560] Is that a big deal? [29:59.720 --> 30:00.380] You tell me. [30:00.560 --> 30:07.300] Or, like, if you're going back and forth from your house to work, or, like, if you're doing other things that might maybe not need to be mapped, then just keep this in mind. [30:07.300 --> 30:14.060] I was a little surprised that I docked myself to this point, that people could look up my flight number based on the time I took off and the route that I took. [30:14.240 --> 30:15.860] So, a little interesting. [30:17.260 --> 30:19.460] So, we're going to talk about Meshtastic attacks. [30:19.620 --> 30:23.140] And this is my favorite part of the presentation, because I get to say I told you so, so many times. [30:24.280 --> 30:36.280] I'm an active member of the Meshtastic Discord community, and sometimes I think they're really great, and I've met some good researchers, and other times people have tried to, like, gaslight me out of, like, contributing my findings, because they don't like them. [30:37.340 --> 30:38.920] So, let's see how that went for them. [30:39.600 --> 30:41.940] So, first up, we have a malicious writer sinkhole. [30:42.020 --> 30:43.800] We kind of already talked about that, but it's worth a mention. [30:44.040 --> 30:49.440] We also have a really stupid one, adding a lock emoji to unencrypted node names to trick people into thinking it's encrypted. [30:49.860 --> 30:54.240] We have our most hated spamming the B-movie script uncontrollably. [30:55.180 --> 30:59.920] We have demonstrated at the Layer 1 conference soft-banning users via sequence spoofing. [30:59.980 --> 31:00.480] Very interesting. [31:00.960 --> 31:07.820] Then we have a node reflection slash replay attack, an attack that I theorized in the Meshtastic Discord community. [31:08.140 --> 31:10.360] Nobody was interested and then appeared at DEF CON. [31:11.240 --> 31:12.220] I did not do it. [31:12.740 --> 31:16.300] And then we also have changing the long and short name of a target radios remotely. [31:16.520 --> 31:23.080] So, if you went to DEF CON, you might notice that your node may have had its node name changed to have a ninja emoji on there, and I'll explain how that happened. [31:23.700 --> 31:30.540] We also have memory exhaustion of stored nodes slash encrypted keys, something I also brought up repeatedly in the Meshtastic chat. [31:30.900 --> 31:33.640] And we also have PSK-only channel spoofing. [31:33.740 --> 31:36.800] So, that's basically the ability to spoof messages from other users in the group chat. [31:37.520 --> 31:39.380] So, first, malicious router sinkhole. [31:39.520 --> 31:40.560] If you create a whole bunch of... [31:40.560 --> 31:45.320] Let's say that you take my class today, you build seven Meshtastic nodes, and then you set them all up as routers. [31:45.460 --> 31:50.060] Meshtastic has a maximum hop of seven, meaning it will only travel through seven nodes. [31:50.160 --> 31:57.260] So, if you set those nodes up in terrible places, the likelihood that a single packet will escape this conference and go to other parts of the city are very low. [31:57.440 --> 32:02.260] So, you can create these sinkholes deliberately or accidentally, depending on, you know, what your intent is. [32:02.420 --> 32:05.840] But the router settings have been disabled for a lot of conferences as a result. [32:06.180 --> 32:10.920] The stupidest one is just setting a green lock emoji in your Meshtastic name. [32:11.080 --> 32:14.560] This makes people think they're sending messages to an encrypted node when, in fact, they're not. [32:14.800 --> 32:16.000] And that means it's interceptable. [32:16.040 --> 32:17.260] It's basically a downgrade attack. [32:17.480 --> 32:18.800] It's more of a social engineering attack. [32:19.620 --> 32:21.920] So, spamming is really easy to do. [32:21.920 --> 32:26.000] You can see the response that it got in the Meshtastic community. [32:26.900 --> 32:33.980] This is a Python script that, I think it's like 80 lines, and it will continuously spam the Meshtastic, the B-movie script over Meshtastic forever. [32:34.620 --> 32:42.340] I asked about the legal implications of this, whether it counted as jamming, and I was told that I should go ask a sovereign citizen about it in the Meshtastic security discord. [32:43.580 --> 32:48.100] But it was really useful to know what the limits of this were, because I went around and was teaching a bunch of kids, you know? [32:48.180 --> 32:50.660] And I really needed to understand, like, at what point could they get in trouble? [32:50.660 --> 32:57.100] So, looking it up and getting some actually very proactive and very informative responses from the community, it wasn't all bad. [32:57.540 --> 32:59.660] I was able to teach kids, like, basically... [33:22.970 --> 33:23.310] ...sequence numbers. [33:23.610 --> 33:24.050] So... [33:24.050 --> 33:24.930] Oh, wow. [33:25.810 --> 33:26.870] So, there we go. [33:26.990 --> 33:27.090] All right. [33:27.210 --> 33:31.530] So, Meshtastic uses sequence numbers to make sure that nodes aren't retransmitting the same message over and over. [33:31.770 --> 33:43.530] A researcher at Layer 1 found out that you could identify a target and then start sending sequence numbers that had not been broadcasted yet to nearby nodes, basically spoofing that node and just putting nonsense in the packets. [33:43.910 --> 33:50.670] When those nodes received a real packet from that victim, they would not retransmit it, because they thought they already received that packet. [33:50.730 --> 33:52.450] They already got a packet with that sequence number. [33:52.570 --> 34:01.050] So, it caused basically a soft banning effect, where packets... nodes nearby would no longer amplify that node, and it would basically be confined to its own little corner. [34:01.270 --> 34:04.890] This is a really interesting attack, because it allows you to kind of take a node off the network. [34:05.050 --> 34:08.950] It means that other nodes will no longer transmit any messages from that node. [34:09.090 --> 34:12.130] And it was pretty effective, although it was unable to contain the B-movie attack. [34:15.330 --> 34:17.850] So, next up, we have node reflection and replay. [34:18.090 --> 34:26.390] So, this was one that I theorized being very possible because there's a very similar attack in Wi-Fi that I absolutely love, which is a beacon-spamming attack. [34:26.730 --> 34:36.430] Now, in Wi-Fi, we can spam a bunch of beacon frames to create the appearance of up to hundreds of fake Wi-Fi networks, and that makes it very difficult to know when you're connecting to a real Wi-Fi network. [34:36.530 --> 34:40.310] So, if you have a needle in a haystack, it's very difficult to know which one you're connecting to. [34:40.550 --> 34:44.410] In this case, I said, hey, could somebody apply the same attack to Meshtastic? [34:44.590 --> 34:52.630] Could somebody, every time a real node joins, create ten fake nodes and begin rebroadcasting them over and over and over with the same information? [34:52.810 --> 34:55.150] And that is exactly what somebody at DEF CON did. [34:55.350 --> 35:03.610] So, this replay attack basically amplifies every node that joins the network a hundredfold, and it makes it so it's so difficult to know which node is the real node. [35:03.750 --> 35:06.790] It's almost impossible for somebody to message the correct person. [35:07.030 --> 35:14.250] So, this is super annoying, obviously, but it also creates a problem because it makes the UI interface useless for anybody who's trying to communicate with anybody else. [35:14.430 --> 35:20.350] So, if you're looking to disrupt communication on a Meshtastic node, making it impossible to connect with each other is a pretty good place to start. [35:22.570 --> 35:31.110] So, my favorite one is you can spoof a packet that pretends to be from the victim himself, herself, themselves. [35:31.630 --> 35:42.610] So, the idea here is if a Meshtastic node receives a packet that's updating the node information, but the node information is itself, then it will actually change its own name. [35:42.770 --> 35:48.130] So, I can send a message to your Meshtastic node that says, hey, update your node information for this node. [35:48.250 --> 35:52.750] And if I set that node to be you, it will just update your node information to whatever I say. [35:52.850 --> 36:06.730] So, people at Defcon were getting the ninja emoji in their node name, and this was spreading to other people because, basically, somebody was spoofing node information from those nodes and sending it to them and adding the emoji to the end of their name. [36:06.850 --> 36:09.110] Super simple, very elegant, and super effective. [36:16.930 --> 36:22.350] So, last up, and I love this one, I brought up the fact that these devices are resource-constrained. [36:22.530 --> 36:29.090] So, they can only hold about 100 different encryption keys, meaning that if we want to have secure communications via direct... [36:29.090 --> 36:37.510] So, the previous hack made it really difficult to communicate, you know, either in the main chat because of the spamming, or between DMs because of all these fake nodes. [36:37.730 --> 36:47.850] What if we made it so it's not even possible to communicate with an encrypted key because we take up all the encryption keys with junk fake ones with our fake nodes? [36:47.850 --> 36:56.870] So, if we create 100 fake nodes with 100 arbitrary fake encryption keys and take up every single slot that's available, there's literally no room left for real people. [36:57.290 --> 37:05.050] And it means that all of your node information and all of your DMs are basically pointed at fake nodes, and there's no way for you to actually communicate. [37:05.350 --> 37:12.590] So, this attack is particularly effective because it exploits the fact that there's a finite number of nodes that can be discovered and held on a mesh-tastic device. [37:12.590 --> 37:21.450] So, if we fill them all up with the previous techniques, it means that the average user is confronted with tons of fake nodes and no valid encryption keys to communicate. [37:21.830 --> 37:30.430] And in fact, it can also potentially overwrite encryption keys for nodes they were communicating with previously, meaning they would no longer be able to communicate with the person they were chatting with before. [37:30.790 --> 37:31.950] Pretty devastating attack. [37:34.490 --> 37:35.130] All right. [37:35.310 --> 37:36.190] This one's pretty funny. [37:36.450 --> 37:41.870] So, the last attack that was demonstrated at Defcon was a PSK channel spoofing attack. [37:42.150 --> 37:52.410] So, in channels that used a PSK to secure the communication, to secure the chat, anybody could basically spoof messages from anybody else, which was pretty hilarious. [37:52.710 --> 38:02.270] So, that meant that it was possible for people to have conversations with themselves while pretending to be the other side because messages that were sent into the chat were not signed by individual users. [38:02.410 --> 38:04.690] They were only signed by the group of PSK. [38:04.950 --> 38:15.470] So, that's a pretty silly mistake because it means that anybody in that chat can act maliciously and simulate conversations or, like, if somebody goes offline, continue the conversation pretending to be that node. [38:15.670 --> 38:28.170] So, the combination of these attacks, being able to silence a node, being able to spoof nodes, and being able to pretend to be somebody else in a group conversation, all that means that comms on Meshtastic might not be as secure as you initially assumed. [38:29.790 --> 38:30.230] All right. [38:30.450 --> 38:31.470] And that's the majority of my talk. [38:31.590 --> 38:32.570] I think I'm just running up on time. [38:32.690 --> 38:33.610] I want to take a couple of questions. [38:33.770 --> 38:41.010] I also want to thank everybody at the Redia team who helped to build these devices and also help get them to the point we can assemble them and share them with other people and run these classes. [38:41.390 --> 38:50.910] Felix, Wolfgang, Davis, Zach, Ella, Michael, and Whiskey26, our firmware developer, all made huge contributions to the community and the open sourcing of the Nibble. [38:51.050 --> 38:52.350] So, I just want to thank all of them. [38:52.710 --> 39:00.050] If you like to teach, then we have more kits available, and we love creating educational hardware for the purpose of getting people started on these sorts of things. [39:00.370 --> 39:05.290] And if you want to keep in touch, you can see our inspector there, making sure our boards are, you know, ready to go. [39:05.610 --> 39:06.930] You can join our Discord server. [39:07.110 --> 39:08.670] You can find our store at ready.io. [39:08.910 --> 39:14.790] You can flash devices at nugget.dev, and you can find more of my work at www.hack.ca. [39:26.890 --> 39:28.070] Were there any questions? [39:31.480 --> 39:31.920] Yes? [39:32.240 --> 39:35.600] You showed, like, eight different mesh-tastic profiles. [39:36.820 --> 39:40.080] Can they inter-operate, or do they both have to be on the same talk? [39:40.820 --> 39:43.080] So, I showed a number of different mesh-tastic profiles. [39:43.200 --> 39:44.460] You're talking about the radio profiles, right? [39:44.720 --> 39:44.860] Right. [39:44.960 --> 39:45.980] How did you get through the track? [39:52.210 --> 39:52.590] Yes. [39:52.910 --> 39:55.370] So, the question was about these different radio profiles. [39:56.790 --> 39:58.690] So, almost everybody uses longfast. [39:58.710 --> 39:59.510] It's the default one. [39:59.570 --> 40:01.050] It's a good compromise between everything. [40:01.270 --> 40:09.110] A couple local channels, like mesh networks, or mesh communities will switch to a different one because of bad behavior on the primary one and kind of only distribute that to members. [40:09.990 --> 40:13.470] The channels have to be exactly the same on both sides. [40:13.630 --> 40:19.570] So, you know, both have to use the exact same radio profile, and then they also have to use the same encryption key. [40:19.690 --> 40:24.130] If either one of those are different, then they will not be able to read packets. [40:24.130 --> 40:30.910] However, if they're using the same radio profile and different encryption keys, they'll still forward packets, but they won't be able to read them. [40:31.070 --> 40:32.390] So, that might be useful. [40:33.350 --> 40:38.850] So, basically, the reason why most people choose to keep it on longfast is almost everybody is running longfast by default. [40:39.010 --> 40:47.770] So, if you want to have the largest possible network to hop through, then that would be the ideal circumstances, is having the channel that most people are kind of stuck on. [40:47.930 --> 40:50.530] I will say short turbo is the most common for conferences, though. [40:50.670 --> 40:55.270] So, when people build mesh-tastic for conferences, I tend to see short turbo for indoor events. [40:56.590 --> 41:01.770] We have a question from the live stream, which is, is there a guide anywhere for hardening tips for nodes? [41:02.370 --> 41:04.210] Ah, that's a really good question. [41:04.470 --> 41:17.650] So, I would say mesh-tastic has actually pretty decent documentation on their month of modules, and the remote administration module is really interesting because it allows you to remotely administer these nodes, which also includes hardening them. [41:17.650 --> 41:27.150] So, that means like setting up a private key, setting up keys that are allowed to modify that node remotely, and locking it down so that only authorized nodes can use it. [41:27.390 --> 41:33.430] So, like honestly, going through the step of setting up remote administration, like forces you to kind of lock it down and set all the security settings. [41:33.590 --> 41:40.610] So, if you want to go through and see kind of what's recommended for that, I would check out the remote administration module and like the steps necessary to go through it. [41:40.730 --> 41:47.730] Because those steps are very similar to also what you would need to do to just harden the node and set a good password and make sure that everything is using robust encryption. [41:47.930 --> 41:50.170] Because the default encryption key is like very short. [41:52.770 --> 42:01.210] Do you know if anyone's gotten like Zigbee or Z-Wave, like working as a bridge to these for long-range sensors and done that? [42:01.370 --> 42:11.130] And the second quick question, do you know if anyone's gotten it working with other more traditional SDRs in like GNU radio for like debugging and hacking on this? [42:11.570 --> 42:15.530] So, there's a lot of work around like debugging and hacking, Laura and Meshtastic. [42:15.670 --> 42:24.770] I know at least one person at the layer one conference had made like a custom Arduino library for Meshtastic that allows you to send and dissect packets and do stuff like that. [42:25.150 --> 42:32.850] When it comes to connecting this to other services, like I've been using Adafruit IO and it makes it relatively simple to like hook it into other things or create actions. [42:33.250 --> 42:36.790] I'm not sure about other interfaces, but MQTT is basically... [42:36.790 --> 42:42.590] is a pretty versatile like way of like interacting with services like Zapier or If This Then That and stuff like that. [42:42.810 --> 42:47.150] Do you know if that debug stuff was based on like Wireshark or anything or compatible with that? [42:47.530 --> 42:48.490] That I'm not sure. [42:48.830 --> 42:50.970] That I do not remember. [42:51.310 --> 42:57.050] I think that there are Wireshark dissectors for Meshtastic packets and I was also going to mention Meshtastic. [42:57.190 --> 43:03.030] There's other devices that will run like 2.4 gigahertz Meshtastic there's only a handful of them. [43:03.130 --> 43:05.630] And those are the ones that offer like voice support potentially. [43:06.190 --> 43:15.450] But because there's so few devices that do support that, like I didn't really mention it, but it's interesting to note that Meshtastic there are Meshtastic devices beyond LoRa that are on like 2.4 gigahertz instead. [43:16.070 --> 43:16.530] Thank you. [43:17.350 --> 43:19.790] Another question from the live stream. [43:19.970 --> 43:25.550] Will there be a way for virtual attendees to see the material list and follow along instructions for building these? [43:25.870 --> 43:26.810] That's a great question. [43:26.810 --> 43:27.390] Yes. [43:27.610 --> 43:32.590] I'm going to put these slides in the same folder that I am open sourcing the nibble. [43:33.210 --> 43:34.950] So I will add that there. [43:35.550 --> 43:36.890] And there we go. [43:37.110 --> 43:37.850] I will add that there. [43:38.130 --> 43:41.030] So github.com slash ready at LSE slash nibble. [43:41.270 --> 43:44.290] And that way you can access, you know, the slides. [43:46.290 --> 43:47.830] You mentioned line of sight. [43:47.830 --> 43:53.510] I live in a river valley and it looks from the map like the closest node is probably 20 miles up river. [43:53.850 --> 43:57.430] Like, how line of sighty? [43:57.530 --> 43:58.850] You also mentioned being in a forest. [43:58.850 --> 44:00.530] So I assume trees are not an issue. [44:01.130 --> 44:01.530] Like... [44:01.530 --> 44:04.950] Yeah, so I live in Montana and the part with a lot of mountains. [44:05.190 --> 44:07.730] So I have to be very aware of line of sight because it's... [44:07.730 --> 44:10.290] If I get a good spot, it means I can see everything. [44:10.490 --> 44:12.690] But if I get a bad spot, it means I'm limited in all directions. [44:12.970 --> 44:22.810] There's a lot of radio tools that are like web-based radio tools that basically you pick a location, you pick a height, and it tells you and it shows you topographically where you're going to be able to be received. [44:23.090 --> 44:24.310] So there's two different ways of doing it, right? [44:24.350 --> 44:31.690] You can do it hands-on like me, like an idiot, where I turn on the mapping module and then I drive around and I build a map of like the reception. [44:31.930 --> 44:39.390] Or I can just literally just pull up like the program that like ham radio people use to place antennas and it'll show me exactly what my reception is going to be. [44:39.650 --> 44:42.030] I would say when it comes to line of sight, it's really important. [44:42.370 --> 44:50.010] Like when I put a node on my drone and fly it up over my roof line, I can see like seven to eight nodes in my city and when I come back down, they're gone. [44:50.690 --> 44:51.930] So line of sight is super important. [44:52.030 --> 45:01.930] And again, I was able to message from like Montana through Idaho over to like eastern Washington on a flight with line of sight. [45:02.070 --> 45:03.930] So line of sight, the reception is incredible. [45:04.070 --> 45:15.310] As soon as you start getting trees and other stuff in the mix, like it becomes a little dubious, but that's where you start using the radio profiles that are super resistant to interference and it might take like three or four full seconds to send a relatively short message. [45:15.470 --> 45:20.310] But you'll get pretty incredible range and you'll be able to compensate for some of the objects that get in the way. [45:21.970 --> 45:23.150] Another live stream question? [45:23.390 --> 45:23.550] Yeah. [45:23.710 --> 45:25.210] I have a potentially silly question. [45:25.510 --> 45:34.170] So to be a security researcher, assuming of course a good face, do I just self-proclaim as a security researcher or do you need to be an affiliate of some university or other org? [45:34.370 --> 45:38.710] I just started calling myself a security researcher so I would stop getting in trouble when I was poking for things. [45:38.850 --> 45:43.730] And eventually a company hired me and made that my job title for like five years and it's on my LinkedIn. [45:44.510 --> 45:45.150] So, no. [45:45.750 --> 45:55.610] If you're really good at what you do, if you're really interested in a subject, if you do deep dives on it and you can teach other people about it, like I consider you to be a security researcher. [45:55.830 --> 46:08.190] Like I don't think you need to be an academic, which is funny because I rub shoulders with academics who are so talented and they like some of the hands-on weird stuff I do because I'm getting in the field and I'm doing things like in the real world and a lot of my partners in academia are doing [46:08.190 --> 46:11.290] things theoretically that inspire me but don't get played out in the real world. [46:11.410 --> 46:12.330] They don't get to see the results. [46:12.570 --> 46:16.630] So, kind of being on the results side of things has been really nice for me. [46:17.490 --> 46:27.750] But I have to say, I really respect people like Matthew Van Hoff who's a security researcher who does a lot of Wi-Fi research that I've applied to Laura and Meshtastic to kind of like think of some of these attacks. [46:28.510 --> 46:33.170] Like, so, I highly respect them but I don't think it's necessary to call yourself a security researcher. [46:36.600 --> 46:37.040] Hi. [46:37.740 --> 46:46.480] Would you announce a channel name and an encryption key for the conference attendees to have a private network besides longfast probably put up at your booth or something? [46:47.280 --> 46:49.360] We haven't created a custom one yet. [46:49.900 --> 46:59.000] However, it's like common for us to put up like something that's just, you know, just for the conference to avoid it, to avoid any experimentation spreading to the local community. [46:59.200 --> 47:03.980] There's a pretty active Mesh community here and I would hate my first introduction to them to be just the B-movie script. [47:04.500 --> 47:11.700] Yeah, but that's already happening because everybody is going on longfast so would you announce in different key and channels so we have a place to communicate? [47:12.020 --> 47:12.740] Yeah, absolutely. [47:13.180 --> 47:15.500] Yeah, so if you come by our booth we'll set up a separate chat. [47:15.640 --> 47:22.820] And there's lots of ways of having either a QR code, a web URL, or an NFC tag to communicate the channel to other people. [47:24.240 --> 47:32.140] Has there been work on using Meshtastic in a C command and control sort of way for red teaming or pen testing? [47:32.560 --> 47:34.420] I am so excited for this. [47:34.540 --> 47:42.400] So I have used LoRa to execute bad USB attacks and because it's bi-directional I was just like, hmm, this seems like a little C2 server, interesting. [47:42.740 --> 47:43.800] And I made a mental note. [47:43.800 --> 47:48.700] But no, as far as I know I have not seen anybody using Meshtastic as a C2 server. [47:48.920 --> 47:55.380] But the second that I do I imagine that it is going to be in the news and somebody will want to investigate and try to police it. [47:55.580 --> 47:57.040] So it's just a matter of time, honestly. [47:57.240 --> 47:59.360] Like this is capable of being used for so much bad shit. [47:59.820 --> 48:08.900] It's just a matter of time before like somebody makes an example that's going to be scary enough, you know, like a virus running on Meshtastic and something like that. [48:09.200 --> 48:12.660] So that's a really good question and that's coming very soon, I think. [48:18.050 --> 48:19.090] Alright, I think that's it. [48:19.210 --> 48:19.650] Thanks, everyone.