❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayHackers Arise

Off-Grid Communications, Part 4: How to Secure Meshtastic Communications

19 August 2026 at 11:11

Welcome back, aspiring cyberwarriors!

Your messages travel through the mesh network, jumping from device to device, and might stay unencrypted. You need to understand how Meshtastic encryption works and how to set it up correctly, because a poorly configured mesh network can expose your communications to anyone with a compatible radio and basic technical knowledge.

In this article, we will explore the encryption options that Meshtastic provides for group communication and direct messages. Let’s get rolling!

Step #1: Setting Up Your Hardware with the Android Meshtastic App

In this demonstration, I will use the LilyGo T-Echo device and LilyGo T3 V1.6.1 (often labeled T-LoRa V2 1.6). However, you can use any other Metastatic-compatible device. Just make sure your device is running firmware version 2.5.0 or later to use the improved security features. When you connect the device to the Meshtastic app, the firmware version will be displayed.

Step #2: Configuring Pre-Shared Keys for Chat Channels

Chat Channels represent the primary method of group communication in Meshtastic networks. Each channel uses a Pre-Shared Key (PSK) that all participants must possess to participate in the conversation. The PSK serves as the encryption key (specifically AES256-CTR), while the channel is identified by a hash derived from both the PSK and the channel name. This means only devices with the correct PSK can decrypt messages sent on that channel, though it’s important to understand that the encrypted packets themselves are still broadcast over the radio and visible to anyone in range; they just can’t decrypt them without the PSK.

The default channel on a fresh Meshtastic installation (typically called β€œLongFast”) uses a well-known PSK (AQ==, which is simply a single null byte) that provides no real security whatsoever. Anyone with a Meshtastic device can receive and decrypt messages sent on the default channel, making it suitable only for public announcements or testing purposes. For any sensitive communications, you must configure custom channels with randomly generated PSKs that are shared only with trusted participants.

To create a secure channel, we need to open Settings and then the Channels section. At the bottom-right corner, you’ll see a plus sign, click on it, and you’ll see a screen like below.

Here, you need to specify a Channel name; in my case, it’ll be just β€œSecure”. Immediately after entering the name, the app will generate a random PSK automatically. That’s all, click Save.

You’ll be returned to the Channels settings, and click on Send. Now, the channel is ready, and the only thing we need to do is share this channel configuration with other participants who should have access. The easiest method is to generate a QR code that other users can scan with their Meshtastic apps to automatically configure the same channel settings, including the PSK.

To do so, change the tab to Conversations and click on the QR-Code icon; you’ll see a window like below.

Now, any messages you send on this channel will be encrypted with AES256 using that channel’s PSK, and only devices with the correct PSK will be able to decrypt and read them.

Remember: while your messages are encrypted, the radio transmissions are still broadcast publicly. Encryption prevents eavesdroppers from reading the content, but doesn’t hide the fact that communication is occurring.

Step #3: Public Key Cryptography for Direct Messages

Direct Messages in Meshtastic firmware version 2.5.0 and later utilize Public Key Cryptography (PKC) to provide authenticated and encrypted one-to-one communications between devices. Unlike channel communications, where all participants share the same password (PSK), Direct Messages use a more sophisticated system where each device has its own unique public and private key pair based on Curve25519 and Ed25519 cryptography.

When you send a Direct Message to another device, Meshtastic uses a hybrid encryption approach for efficiency:

  1. A random AES session key is generated for that specific message
  2. Your message is encrypted using that session key with AES
  3. The session key itself is encrypted using Curve25519 key agreement with the recipient’s public key
  4. The message is digitally signed using your Ed25519 private key
Source: https://meshtastic.org/

This ensures that only the recipient with the corresponding private key can decrypt the session key (and thus the message), providing confidentiality. The digital signature allows the recipient to verify that the message actually came from you and has not been tampered with in transit, providing authentication.

Important note: While the message content is encrypted, metadata such as sender ID, recipient ID, and timestamps remain visible to anyone monitoring the radio network. This is inherent to how mesh routing works.

The good news is that enabling Public Key Cryptography for Direct Messages requires almost no configuration on your part when using the Android app! In firmware version 2.5.0 and later, the device automatically generates its key pair when you first power it on with the updated firmware, and keys are automatically exchanged with other devices as needed through the mesh network.

Summary

In this article, we covered Pre-Shared Keys for securing group chat channels and Public Key Cryptography for protecting Direct Messages on your Meshtastic device. By implementing these encryption mechanisms, you can achieve decentralized communications where message content is protected from eavesdropping and tampering.

The post Off-Grid Communications, Part 4: How to Secure Meshtastic Communications first appeared on Hackers Arise.

Off-Grid Communications, Part 1: Break Free from the Grid with Meshtastic

11 August 2026 at 09:06

Welcome back, my aspiring cyberwarriors!

In our eventful time, the ability to communicate off-grid has become more valuable than ever. In telecommunications, β€œoff-grid” means communicating without relying on traditional infrastructure, such as cell towers or Wi-Fi networks. It’s about staying connected (or at least able to send/receive messages) in places where that infrastructure doesn’t exist or has failed.

Whether you’re preparing for emergencies or want a decentralized communication network that doesn’t rely on cellular towers or internet infrastructure, Meshtastic is a great solution to check out.

In this article, we will explore what Meshtastic is and what it has to offer.

What is Meshtastic?

Meshtastic is a project that lets you use inexpensive LoRa-based transceivers as a long-range communication platform in areas with no existing infrastructure or unreliable communication infrastructure. Its core technology, LoRa, is a long-range radio protocol that’s available in most regions without requiring additional licensing or certification. The radios automatically relay received messages, forming a distributed mesh network that allows every member of a group to receive messages – even from the most distant participant. Depending on the settings used, a Meshtastic mesh can support up to around 80 device nodes (though generally more may be possible).

Meshtastic radios can be paired with a single phone so that your friends and family can send messages to your specific radio. Each device supports a connection from only one user at a time.

Among its notable features are a long communication range (with a record of 331 km), the ability to communicate without a phone, decentralized communication with no need for a single router, encrypted messaging, excellent battery life (depending on the device, though power efficiency is built into the software), and additional GPS-based location features (which can be turned off, or set to send a fake location) and more.

Key Purposes and Use Cases

These communication systems serve a few main purposes. First, they’re great for outdoor activities. For example, people use them while hiking, camping, backpacking, or off-roading. That’s because they let a group stay in touch over long distances, even without cell towers nearby.

On top of that, these systems matter a lot during emergencies. For instance, they can keep people connected during natural disasters, power outages, or other times when cell networks go down. In fact, this makes them a reliable backup when normal communication fails.

Finally, these systems also play a key role in search and rescue efforts. In these situations, staying connected can make all the difference.

Meshtastic Node Map

Additionally, they facilitate messaging in remote or restricted areas where connectivity is poor or internet access is limited. Community members and hobbyists use these systems to create local mesh networks for experimentation, conduct large-scale testing at events such as DEF CON, or establish backup communication systems for urban areas.

Ultimately, these universal communication systems enhance safety, build community connections, and ensure reliable communication in various challenging environments.

How Does Mashtastic Work?

Meshtastic operates on hardware such as ESP32-based boards (e.g., Heltec, LilyGO T-Beam) or pre-built nodes equipped with LoRa modules. These devices are programmed with Meshtastic firmware and function on unlicensed ISM radio bands, making them legal in most regions without the need for a ham radio license, although using higher power may require one in certain areas.

A LILYGO TTGO T-Beam running in client mode on battery power

Communication Process

Sending a Message: First, connect a Meshtastic device (called a β€œnode”) to your phone. You can do this over Bluetooth. To do this, you’ll need a companion app. These are available for Android, iOS, the web, and desktop. Next, type your message in the app. Then, it gets sent to your node.

Broadcasting: After that, the node broadcasts the message over LoRa radio. The message is encrypted first, for safety. It’s worth noting that LoRa only works well for small amounts of data. So, it’s good for short text messages. However, it can’t handle voice or video.

Meshing and Relaying: Meanwhile, nearby nodes pick up the packet. Each node checks if the packet is new. This step matters, because nodes keep track of packets they’ve already seen. That way, they avoid sending duplicates. If the packet is new, though, the node rebroadcasts it. But first, it lowers a number called the β€œhop limit” by one. This limit is usually set to about 3. It exists so messages don’t loop forever. As a result, the message hops from node to node. Eventually, it either reaches its target or runs out of hops.

Receiving: Finally, the destination node gets the packet. Then, it decrypts the message using AES256 encryption, along with a shared channel key. After that, it sends the message to the connected app or phone, so you can read it. On top of that, nodes can also share their location. This way, everyone in the group can see where each other are on a map.

Differences Between LTE, 5G, and Meshtastic

Many of us depend on LTE and 5G networks daily, so it’s important to compare them with Meshtastic.

AspectMeshtastic (LoRa Mesh)LTE (4G)5G
TechnologyLoRa radio (915 MHz ISM band in US, license-free)Cellular (various bands, e.g., 700–2600 MHz)Cellular (sub-6 GHz + mmWave high bands)
InfrastructureDecentralized mesh: User-deployed nodes relay messagesCentralized: Carrier-owned cell towersCentralized: Dense cell towers + small cells
Coverage/Range5–20+ km per hop (line-of-sight, terrain-dependent); extends via meshNationwide/global where towers exist; indoor/outdoorSimilar to LTE but denser for high speeds; mmWave short-range
Data SpeedVery low: ~0.5–20 kbps (text-only, short messages)5–100 Mbps typical (up to 300 Mbps peak)100 Mbps–1+ Gbps typical (up to 10–20 Gbps theoretical)
LatencySeconds to minutes (mesh hopping)20–50 ms1–10 ms (ultra-low for real-time apps)
Data TypesText messages, GPS positions, basic telemetryVoice, video, high-speed internet, appsAll LTE + AR/VR, IoT, autonomous vehicles
Power ConsumptionVery low: Weeks/months on battery/solarModerate: Drains phone battery quicklyHigher (especially mmWave); improved efficiency in newer devices
CostLow one-time (devices + optional solar); no subscriptionsMonthly plan + deviceHigher plans; premium for full speeds
Reliability in OutagesExcellent: Works off-grid, no single point of failureFails without power/towers (e.g., disasters)Same as LTE; more vulnerable to congestion
LimitationsText-only, slow, needs multiple nodes for rangeRequires signal/subscriptionLimited high-speed coverage; higher battery drain

These technologies serve different purposes: Meshtastic for resilient, infrastructure-independent communication in remote or emergency scenarios, versus LTE/5G for high-speed, everyday mobile internet and voice.

Summary

Meshtastic is a free and user-friendly tool that allows you to send messages without relying on the internet or mobile networks. It connects small, specialized devices to form a network, allowing communication over long distances. This makes it great for outdoor adventures, emergencies, or communication in remote areas.

Stay tuned as we continue to explore off-grid communication in future articles.

The post Off-Grid Communications, Part 1: Break Free from the Grid with Meshtastic first appeared on Hackers Arise.

Anti-Forensics: How to Encrypt Messages in Any Messenger or Social Network

6 July 2026 at 10:24

Welcome back, aspiring cyberwarriors!

Many of us are being pushed toward insecure messengers and social networks. These communication channels may be monitored and are not trustworthy. That does not mean private communication is impossible. Far from it. One of the oldest and most practical problems in cryptography is how to send a secret message through an open channel without making the message obvious to anyone who sees it. And that problem has already been solved very well.

The encrypted text does not always have to look like encrypted text. A message can be hidden in plain sight so that it looks like ordinary content, or it can be embedded inside something else entirely, such as audio, video, or text that does not raise suspicion. That is the realm of steganography. Cryptography protects the meaning. Steganography helps hide the fact that a message exists at all.

For most people, though, the real need is much simpler. They want a practical and convenient way to encrypt messages quickly and reliably. So let’s look at some easy tools that make that possible.

Workflow

The workflow is always the same. First, the sender and recipient agree on a secret password or passphrase. A short sentence made up of several words is often better than a single word because it is easier to remember and usually much stronger. Then the sender pastes the message into the tool, clicks Encrypt, enters the password, and sends the resulting encrypted text through whatever channel they want, even if that channel is insecure. The recipient then uses the same tool and the same password to decrypt the message.

That is the basic pattern, and it stays consistent across different tools and platforms.

Web-Based Encryption Tools

There are browser-based applications that can encrypt text very effectively, and they are often the easiest place to begin. But there is one very important detail. You want to make sure the encryption happens entirely on the client side. That means the message is processed inside your browser, on your own machine, and the password never leaves your device. If the server never sees the key, the risk of leakage is much lower.

That point is worth checking. A good looking website is not automatically secure. One way to verify local processing is to monitor browser traffic using Developer Tools, or DevTools, and see whether your password is being sent over the network. Another way is to use a firewall application such as Little Snitch and observe whether the service tries to communicate with remote servers during encryption or decryption. If the system is truly local, the encrypted message can later be decrypted either through the same browser-based Decrypt form or offline with OpenSSL.

There are a few websites out there.Β 

The first one is Encrypt Online. It uses AES-256-CBC to encrypt text, strings, JSON, YAML and config data directly in your browser. It’s considered to be a strong, mathematically unbreakable encryption algorithm.

Encrypt Online

Paranoia Text Encryption uses AES-256 in EAX mode with keys derived from passwords using Argon2. That combination is strong and modern.

Paranoia Text Encryption

LOCK.PUB is another browser-based option, focused on creating encrypted online notes, polls, images, audio and a lot more. The content can only be accessed with the correct password.

Lock Pub

For users who want something more flexible and technical, GCHQ CyberChef is a powerful open-source option from the UK’s GCHQ intelligence agency. It supports many encryption and encoding operations.Β 

Cyber Chef

AES UtilsΒ is another choice, using AES-256-GCM with PBKDF2 while keeping the interface simple.

AES Untils

Warning

As a contrast, it is useful to look at what should not be considered a proper secure solution. MagicTool encrypts and decrypts text without requiring a password.Β 

Magic Tool

At first glance that may sound convenient, but from a cryptographic point of view it means the same built-in secret is used every time. If anyone knows the website and the service’s behavior, they may be able to infer or recover the messages. In that setup, the tool itself is functioning like the secret key simply by existing.

That is not a strong cryptographic model. However, in some situations, β€œencryption” without a user-provided key could still serve a purpose. For example, it might be used to deceive an adversary into believing you are an inexperienced user who does not know how to encrypt messages properly, when your real objective is to feed them specific information in a controlled manner.

Offline Encryption Software

Browser tools are convenient, but sometimes you want something local, traditional, and fully under your control. Linux, Windows, and macOS all have native or widely trusted applications that can encrypt text and files without relying on a remote browser service.

Common examples include command-line tools such as GnuPG, OpenSSL, and ccrypt, along with password managers, VeraCrypt, Cryptomator, and a wide range of similar utilities. These tools are often used not only for text messages but also for file encryption, container protection, and secure storage.

Offline tools have an advantage because they reduce the number of outside systems involved in the process. You are not dependent on a remote website staying available, and you do not need to trust a third-party server with your content or password. For many users, that is a better model from a privacy perspective. At the same time, it is important to understand that privacy tools still leave traces. On a Windows system, a digital forensics investigator may be able to see installation artifacts, program execution history, registry keys, recent files, shortcut files, jump lists, user activity traces, prefetch data and remnants of encrypted containers or text editors. Even when the content itself remains protected, the fact that you used a particular application may still be visible in the system’s history.

That is why privacy-conscious users often prefer systems that are designed to leave fewer traces by default. A privacy-oriented operating system, live environment, or hardened Linux distribution can be a better choice when your goal is to reduce unnecessary local exposure.Β 

Summary

Encrypting messages is a simple and useful privacy skill. Whether you use a browser-based tool or you prefer offline software the basic principle is the same.Β 

The right tool depends on the situation. Browser-based tools are convenient and fast. Offline tools give you more independence and more control. Some systems are designed for strong cryptography, while others are only suitable for demonstration or deceptive use. Understanding the difference matters.

If you want to go deeper into how privacy can be preserved on real systems and how forensic traces are created and analyzed, our Anti-Forensics training is your next step. We covered advanced techniques for preserving your privacy and understanding what investigators can still see even when you think you have covered your tracks.

The post Anti-Forensics: How to Encrypt Messages in Any Messenger or Social Network first appeared on Hackers Arise.

❌
❌