Security is not in my wheelhouse, so I'm curious what others think about this comment (pasted below as well) in the ensuing discussion. I think it makes a valid point - while also missing the point entirely. In a nutshell, should they even bother with security at all if they're not going to prioritize it? If so, why?
Ben @jianmin@defcon.social
Who is encouraging activists to use meshtastic or any lorawan devices? Probably they are the ones most at fault here.
I think the security docs from meshtastic are fairly transparent about what they offer and don't offer.
Correct me if I'm wrong, but your tool primarily abuses the Trust On First Use model for establishing trust. Also without digging into code, I suspect you can combine this with the limited space for nodes in the nodedb to easily spoof arbitrary users that aren't saved/favorited.
It's not as much of a bug as it is an artifact of how the designers decided to handle the limited bandwidth in terms of which features to prioritize. They don't claim to provide security or privacy and seem to prioritize lower bandwidth and operability.
