Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I recently went to a LoRaWan workshop funded by my megacorp (a utility company). It felt like paying someone to try and sell you their stuff.

Anyway, what the LoRa did emphasize is that both the network layer and application layer are encrypted with different keys using AES. This means someone would have to compromise both layers to actually control the devices.

Buuut, given that both encryption keys are stored on the device, I bet someone will just walk up with a chip clip and read the keys right out of EEPROM and then the pretty lights will start.

Or they'll just hack the application servers. I've seen some really god awful pieces of software in use.

A vendor once told me "it's so easy to admin our device over the internet. Just go to 192.168..." And of course due to corporate politics we still bought that piece of shit.



> read the keys right out of EEPROM

Usually keys are stored in a part that is not accessible directly, think of SIM and bank cards. Actually lots of LoRaWan use SIM cards.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: