MobileMesh RF Network Exploitation Getting the Tea from goTenna

Erwin Karincic, Woody

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

In an era increasingly defined by interconnectedness, mesh network technologies are rapidly becoming ubiquitous, underpinning everything from cellular infrastructure to specialized communication systems like MeshTastic and LoRa. This talk, "MobileMesh RF Network Exploitation Getting the Tea from goTenna," delivered by security researchers Woody and Erwin Karincic (also known as Dollar Hyde) at DEF CON 32, delves into the security vulnerabilities discovered across multiple generations of the goTenna mesh network device. The presentation meticulously tracks the evolution of goTenna from its initial release to its third generation, highlighting persistent issues related to the exposure of unique identifiers.

Watch on YouTube

Visual summary for MobileMesh RF Network Exploitation Getting the Tea from goTenna by Erwin Karincic, Woody
Visual summary for MobileMesh RF Network Exploitation Getting the Tea from goTenna by Erwin Karincic, Woody

Key moments

  1. 0:00 Introduction to goTenna mesh technology and talk overview
  2. 1:50 GoTenna Gen 1 exploit: extracting phone numbers via plain text
  3. 3:10 GoTenna Gen 2 changes and continuing vulnerabilities
  4. 4:20 Gen 2 perceived security improvements and Gen 3 introduction
  5. 5:00 The critical importance of protecting unique identifiers (MAC addresses)
  6. 6:00 Speakers' expertise and motivation behind the research

MobileMesh RF Network Exploitation Getting the Tea from goTenna

Speakers: Erwin Karincic, Security Researcher; Woody, RF Hacker Sanctuary Staff

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=KqKj_VY-AHY

Overview

In an era increasingly defined by interconnectedness, mesh network technologies are rapidly becoming ubiquitous, underpinning everything from cellular infrastructure to specialized communication systems like MeshTastic and LoRa. This talk, "MobileMesh RF Network Exploitation Getting the Tea from goTenna," delivered by security researchers Woody and Erwin Karincic (also known as Dollar Hyde) at DEF CON 32, delves into the security vulnerabilities discovered across multiple generations of the goTenna mesh network device. The presentation meticulously tracks the evolution of goTenna from its initial release to its third generation, highlighting persistent issues related to the exposure of unique identifiers.

The core of the discussion revolves around the critical importance of protecting one's RF signature and unique identifiers in a world where such information can be leveraged for tracking, fingerprinting, and surveillance across geographical locations and time. The speakers, drawing on their extensive experience in RF exploitation, hardware and software reverse engineering, and special operations, underscore that even seemingly encrypted communications can inadvertently leak sensitive metadata. This talk serves as a crucial reminder for individuals, law enforcement, government agencies, and corporations alike about the inherent risks in modern communication technologies and the ongoing need for robust cyber and RF security practices.

Background

▶ Watch: Introduction to goTenna mesh technology and talk overview (0:00)

The proliferation of mesh networking has ushered in a new paradigm for communication, enabling devices to relay data through intermediate nodes, thereby extending range and enhancing resilience, particularly in environments where traditional infrastructure is unavailable. goTenna, a prominent player in this space, offers off-grid mesh communication devices designed for areas without cell service or Wi-Fi. The goTenna system is lauded for its efficient meshing capabilities, which allow for flexible and controllable data transmission. However, this talk reveals that the very design choices that make goTenna efficient have, at various stages, introduced significant security and privacy concerns.

The foundation of this research traces back seven years to Woody's initial presentation at the RF Hacker Sanctuary, where he first unveiled exploits against the goTenna Version 1 device. At that time, goTenna Gen 1 communicated with a user's smartphone via Bluetooth. The critical vulnerability identified was that despite offering an "encrypted mode" for messages, the device continuously broadcast certain elements in plaintext. Most notably, the device's unique identifier – which, by default for Gen 1 and Gen 2, was the user's cell phone number – was transmitted unencrypted over the air. This meant an attacker with appropriate RF tooling could passively intercept and extract a user's phone number, even if they believed their communications were secure. The implications were profound: the promise of secure, off-grid communication was undermined by a fundamental flaw allowing for user deanonymization.

As goTenna evolved, the company made efforts to address these issues. goTenna Version 2 introduced several changes in response to earlier findings. Crucially, the RF modulation scheme shifted from 2 FSK (Frequency Shift Keying) to 4 FSK, a more complex modulation that required a different approach for demodulation and analysis. While the direct linkage to a user's phone number as the unique identifier was reportedly "fixed" by the new management, the underlying problem of transmitting a unique identifier persisted. Clayton Smith, a key contributor to this research, did significant work on Gen 2, demonstrating that while the specific identifier might have changed, it was still possible to extract unique identifiers from the air, albeit requiring a 4 FSK demodulator. Furthermore, Gen 2 offered more flexible connectivity, allowing users to hardline their device to a phone instead of solely relying on Bluetooth, and provided expanded frequency bands (140 to 170 MHz or 445 to 480 MHz) and bandwidth controls. These improvements aimed to enhance security and user control, but as the researchers would explore, the fundamental challenge of balancing unique identifiers for routing with user privacy remained. The talk then pivots to explore whether similar vulnerabilities, particularly regarding the exposure of Group IDs (GIDs) or call signs, could be found in the latest goTenna Version 3.

Key Findings

▶ Watch: GoTenna Gen 2 changes and continuing vulnerabilities (3:10)

The central theme of this talk is the persistent challenge of unique identifier leakage in mesh communication devices, particularly as observed across goTenna's product generations. The key findings illuminate how seemingly minor design choices can have significant privacy implications, even when explicit encryption is employed.

For goTenna Version 1, the primary discovery was the unencrypted broadcast of the user's cell phone number, which served as the device's unique identifier. This occurred despite messages being sent in "encrypted mode." An attacker could passively listen to the RF spectrum and extract these phone numbers, along with call signs and message content if the message itself was unencrypted. This flaw allowed for straightforward deanonymization and tracking of goTenna users, fundamentally compromising the privacy assumed by its users. The researchers demonstrated this using a custom script that could run against a Gen 1 device to pull the phone number directly from the air.

goTenna Version 2 introduced improvements, including a shift from 2 FSK to 4 FSK modulation and a move away from the phone number as the default unique identifier. However, the research by Clayton Smith confirmed that the principle of unique identifier leakage remained. While the specific identifier changed, an attacker equipped with a 4 FSK demodulator could still extract these identifiers from the air. This meant that users could still be tracked and potentially fingerprinted, even if their direct phone number was no longer explicitly broadcast. The talk emphasizes that any persistent unique identifier, regardless of its format, poses a significant risk for tracking over space and time, mirroring concerns seen with MAC addresses in Wi-Fi networks.

The talk then poses the critical question regarding goTenna Version 3: "Are those GIDs for the call signs present?" While the provided transcript does not explicitly detail the successful exploitation or specific findings for Gen 3, it frames the ongoing research as an attempt to determine if similar identifier leakage vulnerabilities persist in the latest iteration. The researchers' intent is to ascertain whether the "new management" efforts to fix past issues have truly addressed the root cause of identifier exposure or if new, perhaps more subtle, forms of tracking data are still being broadcast. The overarching finding, therefore, is not just about specific vulnerabilities but the recurrent nature of unique identifier exposure across product generations, highlighting a fundamental tension between the operational requirements of mesh networking and the privacy expectations of users.

Technical Deep Dive

▶ Watch: Gen 2 perceived security improvements and Gen 3 introduction (4:20)

The technical exposition of the goTenna vulnerabilities spans its first two generations, detailing the modulation schemes, communication protocols, and the specific data leakage mechanisms.

goTenna Version 1 relied on Bluetooth for communication between the physical goTenna device and the user's smartphone. This Bluetooth link facilitated the configuration and sending of messages. Over the air, the RF communication utilized 2 FSK (Frequency Shift Keying) modulation. FSK is a method of transmitting digital data by changing the frequency of a carrier wave. In 2 FSK, two distinct frequencies are used to represent binary 0s and 1s. The critical flaw in Gen 1 was that when a message was sent, even if marked as "encrypted" within the goTenna application, the unique identifier of the transmitting device was broadcast in plaintext. For Gen 1, this unique identifier was, by default, the user's cell phone number. This number was embedded within the RF packets, allowing any passive receiver capable of demodulating 2 FSK to extract it. The researchers developed a custom script to automate this process, demonstrating the ease with which phone numbers, call signs, and unencrypted message payloads could be captured. The presence of the phone number in plaintext, even when the actual message payload was encrypted, meant that the sender's identity was trivially exposed.

goTenna Version 2 marked a significant evolution in its RF characteristics and internal design. A notable change was the shift in RF modulation from 2 FSK to 4 FSK. 4 FSK is an extension of FSK where four distinct frequencies are used, allowing for the transmission of two bits of data per symbol (e.g., 00, 01, 10, 11). This change increased the data rate and spectral efficiency but also presented a new challenge for reverse engineering, as it required a 4 FSK demodulator to interpret the signals. The researchers, particularly Clayton Smith, adapted their tooling to handle this new modulation. While goTenna's management reportedly "fixed" the direct exposure of phone numbers, the underlying issue of unique identifier transmission persisted. Instead of phone numbers, other unique identifiers (referred to as GIDs or call signs) were still found to be broadcast. These identifiers, while not immediately recognizable as a phone number, could still be used for tracking and fingerprinting if an adversary could correlate them over time and space, or link them to other publicly available information.

Furthermore, Gen 2 introduced more flexible connectivity options. While Bluetooth remained an option, users could now also hardline their goTenna device to their phone, potentially reducing the Bluetooth attack surface. The operating frequency bands were also specified as either 140 to 170 MHz or 445 to 480 MHz, offering users some control over their RF environment and potentially allowing for better spectrum management. The talk highlights that despite these improvements, the fundamental design choice of transmitting unique identifiers for mesh routing purposes inherently creates a privacy risk that needs continuous scrutiny. The researchers' ongoing investigation into goTenna Version 3 focuses on whether these new identifiers or other metadata continue to be broadcast in a manner that compromises user privacy, particularly concerning the presence of GIDs and call signs. The core problem, as articulated, is the inherent trade-off in mesh networks: efficient routing often relies on unique node identification, which can directly conflict with user anonymity and security.

Demo / Proof of Concept

▶ Watch: The critical importance of protecting unique identifiers (MAC addresses) (5:00)

The speakers highlighted a clear demonstration of their findings, specifically for goTenna Version 1. While the presentation itself showed a video of the exploit in action rather than a live demonstration, the specifics of what was demonstrated were clearly articulated.

The video showcased a script running against a goTenna Version 1 device. This script was designed to intercept and parse the RF communications from the device. The key outcome of this demonstration was the ability to extract the user's cell phone number from the air, even when the goTenna device was configured to send messages in its "encrypted mode." The visual representation on screen displayed the intercepted data, which included:

  • The phone number, clearly visible as the unique identifier.
  • The call sign associated with the user.
  • The message content itself.

The speakers clarified a crucial distinction: in unencrypted mode, the entire payload (phone number, call sign, and message) was visible. However, even in encrypted mode, the phone number and call sign were still broadcast in plaintext, making the sender's identity discernible to anyone with the necessary interception capabilities. This concrete proof of concept underscored the severity of the vulnerability, demonstrating that the promise of encrypted communication did not extend to user identity in the initial goTenna design. The speakers also mentioned that a live demo of this Gen 1 exploit was available at the RF Hacker Sanctuary for those interested in seeing it firsthand. For goTenna Version 2, while the technical details of exploitation were discussed (e.g., the need for a 4 FSK demodulator), a specific demonstration of extracting Gen 2 unique identifiers was not explicitly detailed in the provided transcript, though the successful analysis by Clayton Smith implies such a capability.

Defensive Implications

▶ Watch: Speakers' expertise and motivation behind the research (6:00)

The findings presented in this talk carry significant defensive implications for users of mesh networking devices, particularly goTenna, and for the broader cybersecurity community. The core message revolves around the critical importance of understanding and protecting one's RF signature and unique identifiers.

Firstly, users must recognize that "encrypted communication" does not automatically equate to anonymity or complete privacy. As demonstrated with goTenna Gen 1, even if message content is encrypted, metadata such as unique identifiers (like phone numbers or device IDs) can still be broadcast in plaintext. Defenders, whether individuals or organizations, need to be acutely aware of what information their devices are transmitting over the air, beyond just the message payload. This requires a deeper understanding of the device's underlying protocols and how it handles identifiers.

Secondly, the talk underscores the pervasive threat of fingerprinting and tracking based on persistent unique identifiers. Just as MAC addresses can be used to track Wi-Fi devices over time and space, any consistent identifier broadcast by a mesh device can be exploited for surveillance. The industry's move towards rolling unique identifiers (e.g., randomizing MAC addresses) in other technologies is a direct response to this threat, and similar considerations should apply to mesh network designs. Users, especially those in sensitive professions (e.g., law enforcement, military, journalists, activists), must prioritize devices that implement robust identifier randomization or ensure that identifiers are never broadcast in an unencrypted or persistent manner.

Thirdly, the evolution from 2 FSK to 4 FSK in goTenna Gen 2 highlights the need for adaptable defensive strategies. Adversaries will continuously refine their tools and techniques to analyze new modulation schemes and protocols. Defenders must stay abreast of these developments and invest in capabilities like Software Defined Radios (SDRs) and advanced demodulators to monitor and analyze their own RF footprint effectively. Understanding the specific frequency bands (e.g., 140-170 MHz and 445-480 MHz for goTenna) is crucial for targeted monitoring.

Finally, the speakers' work with law enforcement, government, and corporations emphasizes the need for comprehensive education on RF security. This goes beyond traditional cyber security to encompass the physical and electromagnetic aspects of communication. Organizations deploying mesh networks for critical operations must conduct thorough security assessments, not just of the software and network layers, but also of the RF layer. They must ensure that the devices they use are designed with privacy-by-design principles, particularly concerning the handling of unique identifiers, and that their personnel are trained to minimize their RF signature. The goTenna case serves as a stark reminder that even devices designed for off-grid resilience can harbor significant privacy vulnerabilities if not rigorously vetted for RF leakage.

Key Takeaways

  • Unique Identifiers are a Critical Risk: Even when message content is encrypted, devices like goTenna Gen 1 and Gen 2 have been shown to broadcast unique identifiers (e.g., phone numbers, GIDs) in plaintext, enabling user deanonymization and tracking.
  • "Encrypted Mode" is Not Always Private: Users should not assume that enabling "encrypted mode" on a device protects all aspects of their privacy, especially metadata or unique identifiers that might be transmitted unencrypted for network functionality.
  • Mesh Networks Present Unique Challenges: While efficient for extending range and facilitating communication, the design requirements of mesh networks (e.g., identifying nodes for routing) can inherently conflict with user privacy, necessitating careful security architecture.
  • RF Signature Protection is Essential: Individuals and organizations, particularly those in sensitive roles, must understand and actively work to minimize their RF footprint to prevent tracking and surveillance over space and time.
  • Adaptation in RF Exploitation: The shift from 2 FSK to 4 FSK modulation in goTenna Gen 2 demonstrates that attackers and defenders must continuously adapt their tools and knowledge (e.g., using 4 FSK demodulators) to keep pace with evolving RF protocols.
  • Continuous Security Research is Vital: The ongoing investigation into goTenna Gen 3 highlights the necessity of persistent security research to identify and mitigate threats in new and updated technologies, ensuring that reported "fixes" truly address underlying vulnerabilities.

About the Speaker(s)

Erwin Karincic (Dollar Hyde) is a dedicated security researcher with extensive experience in hardware and software reverse engineering and RF exploitation. His professional mission, as articulated during the talk, is to protect nations and their citizens by proactively identifying and mitigating threats before they become widely known or exploited. This commitment drives his work in uncovering vulnerabilities in critical technologies.

Woody is a prominent figure in the RF security community, serving as staff for the RF Hacker Sanctuary (also known as the RF Village). He is a co-author of the original goTenna attack, which laid the groundwork for the research presented in this talk, and has contributed to other significant exploits such as "Raptor Captor" and various vehicle exploits. Woody brings a unique perspective to cybersecurity, having spent 20 years in special operations before transitioning into the world of security research. His work focuses on educating law enforcement, government entities, and corporations on how to understand and control all aspects of their security footprint, encompassing not just the physical and digital, but also the electromagnetic (light and RF) dimensions of their operations and daily lives.

The speakers also extended credit to Clayton Smith for his substantial contributions, particularly for his in-depth work on the second generation of the goTenna device, which was crucial in making this DEF CON talk possible.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk delivers a brutally honest and technically deep dive into persistent unique identifier leakage across multiple generations of goTenna mesh network devices. Researchers Woody and Erwin Karincic meticulously demonstrate how even "encrypted mode" fails to protect user anonymity by broadcasting phone numbers or other unique IDs in plaintext, evolving from 2 FSK to 4 FSK exploitation. This research offers critical, actionable insights for anyone relying on off-grid mesh communications, exposing fundamental tensions between network routing efficiency and user privacy that vendors consistently fail to address.

Heather Calloway (CISO) — STRONG ACCEPT

This talk meticulously exposes persistent vulnerabilities in goTenna mesh network devices, highlighting the critical risk of unique identifier leakage even when communications are presumed encrypted. It serves as a stark reminder that operational security extends beyond software, demanding a deep understanding of a device's RF signature. The research provides actionable insights for organizations deploying off-grid communication, forcing a re-evaluation of trust assumptions and accountability for privacy and surveillance risks.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage