DEF CON 33 VIdeo
TeamHackerPager
DEF CON 33 · Day 1 · Main Stage
Overview
The "Hacker Pager" talk at DEF CON unveiled a unique and highly anticipated hardware badge that transcends the typical conference collectible, evolving into a robust open-source communication and analysis tool. Developed by TeamHackerPager, this device draws inspiration from the iconic 1995 movie Hackers and the aesthetic of classic Motorola Advisor pagers, aiming to provide attendees with a functional piece of hardware they can use for research and engagement beyond the conference walls. It integrates deeply with the Meshtastic protocol and the LoRa (Long Range) radio standard, offering a tangible platform for exploring decentralized, long-distance communication.

Key moments
- 0:18 The Hacker Pager: More than just a badge, a tool
- 2:13 Overcoming ambitious design challenges and production delays
- 3:35 Integrating Meshtastic for long-range communication via LoRa radio
- 4:40 Live demonstration of Meshtastic network and messages at Defcon
- 6:00 On-device LoRa packet capture to PCAP files
- 7:22 Custom Wireshark dissector for detailed LoRa packet analysis
Hacker Pager: A LoRa Communication and Analysis Tool for the Defcon Community
Speakers: TeamHackerPager
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=Omfyox5kxUQ
Overview
The "Hacker Pager" talk at DEF CON unveiled a unique and highly anticipated hardware badge that transcends the typical conference collectible, evolving into a robust open-source communication and analysis tool. Developed by TeamHackerPager, this device draws inspiration from the iconic 1995 movie Hackers and the aesthetic of classic Motorola Advisor pagers, aiming to provide attendees with a functional piece of hardware they can use for research and engagement beyond the conference walls. It integrates deeply with the Meshtastic protocol and the LoRa (Long Range) radio standard, offering a tangible platform for exploring decentralized, long-distance communication.
The significance of the Hacker Pager lies in its dual identity: a nostalgic homage to hacker culture and a cutting-edge, open-source development platform. It addresses a critical need for accessible tools that enable security researchers and enthusiasts to interact with and analyze LoRa-based networks, which are increasingly prevalent in IoT and mesh communication. By providing on-device packet capture, spectrum analysis, and a developer-friendly environment, TeamHackerPager has delivered a powerful instrument designed to foster deeper understanding and research within the LoRa ecosystem, reinforcing DEF CON's ethos of community-driven innovation and knowledge sharing.
Background
▶ Watch: The Hacker Pager: More than just a badge, a tool (0:18)
The genesis of the Hacker Pager badge was rooted in TeamHackerPager's annual tradition of creating a DEF CON badge that serves not merely as a decorative item, but as a genuine tool for the security community. Their guiding principle was to develop something with lasting utility, encouraging ongoing research and contribution to the "security agenda." The specific inspiration for this year's badge coalesced from two distinct sources: a collective admiration for the movie Hackers, frequently quoted and celebrated by the team, and a personal collection of Motorola Advisor pagers owned by one of the members, Xenax, who had long harbored the desire to remake such a device. This fusion of retro aesthetics and functional ambition was powerfully articulated by Cody, who presented a compelling concept for an "apocalyptic communication device," solidifying the team's direction.
The development journey for the Hacker Pager was fraught with ambitious technical and logistical challenges. Unlike previous badges, which often comprised simpler PCB stacks, the team committed to designing a fully enclosed device with a custom case, integrated screen, and physical buttons for a comprehensive user interface. This significantly increased the complexity, leading to an initial over-ambition that prevented its release at the previous year's DEF CON. A major setback involved a large batch of circuit boards being stuck in customs for weeks, delaying assembly. Despite these hurdles, the extra year allowed for substantial refinement, resulting in a much more polished product. Hardware challenges also included unanticipated issues with the display's pogo pins creating excessive pressure on the board, necessitating the design and implementation of an internal brace to prevent restarts during button presses. Software-wise, supporting features like an on-screen keyboard and, notably, custom 8x8 pixel emoji fonts for the retro-style LCD, required considerable effort as no pre-existing solutions were available. The team's dedication to the community was evident in their commitment to making the device open source, building upon the Meshtastic firmware and a GPL license, ensuring its accessibility and extensibility for other developers and researchers.
Key Findings
▶ Watch: Integrating Meshtastic for long-range communication via LoRa radio (3:35)
The primary "finding" presented by TeamHackerPager is the Hacker Pager itself: a highly functional, open-source LoRa-based communication device and research platform that successfully blends nostalgic design with modern utility. It stands as a testament to what a community-driven hardware project can achieve, moving beyond superficial aesthetics to deliver a powerful tool.
Key capabilities and contributions demonstrated by the Hacker Pager include:
- Standalone Meshtastic Communication: The device operates entirely independently, allowing users to set up, read, and send messages on a Meshtastic mesh network without requiring a smartphone or other external device. This was a crucial design decision for true field utility.
- On-Device LoRa Packet Capture: A significant feature is its ability to perform direct packet captures of LoRa traffic, saving the data to an SD card in a standard pcap file format. This provides essential visibility into LoRa communications, which is typically challenging to achieve without specialized hardware.
- Wireshark Integration: To complement the packet capture, the team developed a custom Wireshark plugin (dissector) that decodes and decrypts (where keys are available) the captured LoRa packets. This enables detailed analysis of not only user messages but also underlying telemetry and mesh communication, greatly simplifying LoRa protocol understanding.
- Spectrum Analyzer: The inclusion of a basic spectrum analyzer allows users to sweep across frequency bands (e.g., 903 MHz, 852 MHz) to identify active LoRa channels. This helps users hone in on specific frequencies for targeted packet capture and analysis.
- Open-Source Development Platform with Bassband Access: The Hacker Pager is built on open-source firmware (derived from Meshtastic, GPL licensed) and explicitly supports developers who wish to modify or extend its functionality. Critically, it provides the ability to write directly to the bassband of the radio, offering a deep level of control for advanced LoRa research and experimentation.
- Community Engagement and Demand: The overwhelming community response, with all initial inventory selling out in less than three minutes, underscores the high demand for such a device and validates the team's vision for a functional, community-focused badge.
- Future Research Potential: The speakers hinted at upcoming research leveraging an "SX patching feature" that will further expand the capabilities of the Hacker Pager and potentially other Meshtastic-compatible devices, suggesting deeper insights into LoRa hardware and software manipulation are on the horizon.
Technical Deep Dive
▶ Watch: Live demonstration of Meshtastic network and messages at Defcon (4:40)
The Hacker Pager is engineered around the LoRa radio standard, a long-range, low-power wireless technology ideal for IoT and decentralized communication networks. At its core, it leverages the Meshtastic protocol, an open-source, peer-to-peer mesh networking protocol that runs on LoRa hardware. Meshtastic enables off-grid text messaging and group chat functionalities, creating a resilient local communication network capable of covering significant distances, especially in environments like DEF CON where traditional cellular networks might be overloaded or unavailable. The Hacker Pager functions as a full-fledged Meshtastic node, capable of sending and receiving messages, displaying network status, and identifying other nodes within range. During the talk, the device demonstrated seeing 59 nodes in a 10-minute span and over 200 nodes since its last reset on the dedicated DEF CON Meshtastic channel, highlighting the protocol's widespread adoption at the conference.
One of the most powerful technical features is the on-device LoRa packet capture. Users can initiate a capture directly from the pager's interface, specifying various channel settings and frequencies. The captured raw radio data is then written to an SD card as a standard pcap file. This is a critical capability because LoRa traffic is not easily intercepted or analyzed using conventional network tools; it requires specialized radio hardware. To make this data accessible and meaningful, TeamHackerPager developed a dedicated Wireshark dissector plugin. This plugin allows security researchers to import the pcap files into Wireshark, where the LoRa packets are decoded, parsed, and, if the network keys are available, decrypted. This provides granular visibility into all aspects of the Meshtastic network, including user messages, network telemetry, node advertisements, and routing information. This level of insight is invaluable for understanding the protocol's inner workings, identifying potential vulnerabilities, and analyzing network behavior.
For initial reconnaissance, the Hacker Pager includes a basic spectrum analyzer. This tool allows users to sweep across a range of frequencies, visualizing active radio signals. At DEF CON, the analyzer quickly identified significant spikes at frequencies like 903 MHz and 852 MHz, indicating areas of high LoRa activity. This functionality helps researchers quickly pinpoint relevant channels for more targeted packet capture, optimizing their analysis efforts.
The device is designed as an open-source development platform, with its firmware based on the Meshtastic codebase and released under a GPL license. This commitment to open source extends to providing advanced control: developers can access and modify the radio's bassband. This low-level access allows for direct manipulation of the radio's fundamental operations, opening doors for advanced research into LoRa modulation, encoding, and potential new attack vectors or defensive techniques that operate below the standard protocol layers. This capability distinguishes the Hacker Pager as more than just a consumer device; it's a serious tool for radio frequency (RF) and protocol-level security research.
From a hardware perspective, the Hacker Pager is a sophisticated assembly, moving beyond simple PCB designs. It features a custom-designed case, a mounted screen, and tactile buttons for user interaction. An SD card slot facilitates data storage for packet captures and firmware updates. Power is supplied via a battery, with the team humorously noting the complexities of flying with a "carry-on just stacked with badges" and their many batteries, adhering to TSA regulations of under 100 watt-hours per battery. The team also overcame significant manufacturing challenges, including designing an internal brace to prevent reboots caused by pressure from the display's pogo pins during button presses, a critical fix for usability. On the software side, the inclusion of an on-screen keyboard, complete with an emoji keyboard, required the creation of custom 8x8 pixel emoji fonts—a testament to the team's dedication to a full-featured, standalone user experience. The badge also includes a Chip-8 emulator, providing a nod to retro computing and adding a playful element to its extensive feature set.
Demo / Proof of Concept
▶ Watch: On-device LoRa packet capture to PCAP files (6:00)
During the talk, the TeamHackerPager members provided a live demonstration of the Hacker Pager's core functionalities, showcasing its capabilities in a real-world DEF CON environment. The demonstration started by displaying the pager connected to the dedicated Meshtastic network set up for DEF CON. Messages were seen actively streaming in, illustrating the live, decentralized communication occurring across the conference floor. The speakers pointed out the sheer volume of activity, noting that the device had detected 59 unique nodes in the last 10 minutes and over 200 nodes since the last reset, underscoring the ubiquity of Meshtastic at the event.
Next, the on-device packet capture feature was demonstrated. The speakers explained how users could select various LoRa channel settings and frequencies, then initiate a capture. The device was shown actively collecting data, which would then be saved as a pcap file on its internal SD card. This visually confirmed the ability to intercept raw LoRa traffic, a crucial step for in-depth protocol analysis. While a live Wireshark dissection wasn't performed on-screen due to the live demo format, the speakers emphasized the availability of their Wireshark dissector for post-capture analysis, highlighting how it decodes and decrypts the collected packets.
The spectrum analyzer was then activated, sweeping across the radio frequencies. The display clearly showed spikes in activity at specific frequencies, notably around 903 MHz and 852 MHz, indicating the primary LoRa channels in use at DEF CON. This visual tool effectively demonstrated how users could quickly identify active communication channels for more focused monitoring or interaction.
Finally, to showcase its standalone communication capabilities, a message was composed and sent directly from the Hacker Pager using its on-screen keyboard. The speakers highlighted the effort put into making this a seamless experience, including the development of a custom emoji keyboard with 8x8 pixel emoji fonts. A waving hand emoji was included in the message, which was then successfully broadcast to the Meshtastic mesh, confirming the device's ability to act as a fully independent messaging client. The demonstration concluded by briefly mentioning the inclusion of a Chip-8 emulator for games, reinforcing the badge's blend of utility and entertainment.
Defensive Implications
▶ Watch: Custom Wireshark dissector for detailed LoRa packet analysis (7:22)
The Hacker Pager, while primarily presented as a research and communication tool, carries significant defensive implications for organizations and individuals operating or monitoring LoRa-based networks. Its capabilities provide unprecedented visibility into a technology that is often opaque to traditional security tools, offering both insights into potential vulnerabilities and a blueprint for more robust defense strategies.
Firstly, the on-device LoRa packet capture and accompanying Wireshark dissector are game-changers for network defenders. LoRa networks, particularly those used in industrial IoT (IIoT), smart cities, or critical infrastructure, often operate in spectrums not easily monitored. The Hacker Pager allows defenders to:
- Gain Visibility: Intercept and analyze LoRa traffic from their own devices or even surrounding networks, identifying unknown devices, communication patterns, or unauthorized transmissions.
- Protocol Analysis: Understand the specifics of LoRa and Meshtastic protocol implementations in their environment, including how data is structured, encrypted (or not), and transmitted. This is crucial for identifying misconfigurations or non-standard behaviors.
- Vulnerability Research: Use the detailed packet analysis to uncover potential vulnerabilities within LoRaWAN implementations, Meshtastic deployments, or proprietary LoRa protocols. This could include issues with key management, replay attacks, or data integrity.
Secondly, the spectrum analyzer provides a fundamental capability for RF defense. By identifying active LoRa frequencies, defenders can:
- Monitor Spectrum Usage: Detect unauthorized LoRa devices operating within their controlled airspace.
- Identify Interference: Pinpoint sources of RF interference that could disrupt legitimate LoRa communications, potentially indicative of jamming attempts or faulty equipment.
- Geolocate Threats: In conjunction with other tools, the ability to identify active frequencies can contribute to the triangulation and localization of rogue LoRa transmitters.
Furthermore, the Hacker Pager's open-source nature and the ability to write to the radio's bassband are a double-edged sword. While intended for research, these features empower advanced attackers (red teams) to:
- Develop Custom Exploits: Experiment with low-level LoRa radio manipulations, potentially crafting custom packets, developing advanced jamming techniques, or exploiting hardware-specific vulnerabilities. Defenders must be aware that such tools exist and are becoming more accessible.
- Assess Resilience: Organizations can leverage the Hacker Pager in red team exercises to proactively test the resilience of their LoRa deployments against sophisticated RF attacks.
Finally, the Meshtastic integration highlights the growing adoption of decentralized mesh networks. Defenders need to consider:
- Supply Chain Security: If critical infrastructure relies on LoRa/Meshtastic, the security of the devices and their firmware, as demonstrated by the Hacker Pager's open-source base, becomes paramount.
- Insider Threat: The ease of creating and communicating on such networks could pose risks if not properly managed within an enterprise environment.
The mention of upcoming research on an "SX patching feature" strongly suggests that TeamHackerPager has identified or is exploring vulnerabilities or advanced capabilities within the LoRa radio chips themselves. Defenders should closely follow this research, as it could reveal critical insights into hardware-level attacks and necessitate firmware updates or hardware revisions for secure LoRa deployments. Overall, the Hacker Pager serves as both an educational tool for understanding LoRa security and a stark reminder that robust defenses must extend to the often-overlooked RF layer.
Key Takeaways
- The Hacker Pager is a DEF CON badge that doubles as a powerful, open-source LoRa communication and analysis tool, inspired by the movie Hackers and classic pagers.
- It functions as a standalone Meshtastic device, enabling off-grid text messaging and group chat over the LoRa radio standard without requiring a smartphone.
- Key features include on-device LoRa packet capture (saving to pcap files on an SD card) and a Wireshark dissector for detailed decoding and decryption of LoRa traffic.
- The device incorporates a spectrum analyzer to identify active LoRa frequencies (e.g., 903 MHz, 852 MHz), aiding in targeted analysis and reconnaissance.
- As an open-source development platform (GPL licensed firmware based on Meshtastic), it provides advanced users with the ability to write to the radio's bassband for deep-level LoRa research.
- The project faced significant hardware and software development challenges, including custom case design, pressure issues with pogo pins, and the creation of unique 8x8 pixel emoji fonts for its retro display.
About the Speaker(s)
The talk was presented by TeamHackerPager, a collective of hardware hackers deeply embedded in the DEF CON community. While the presentation highlighted specific contributions, the ethos was clearly one of collaborative effort. Key individuals mentioned include:
- Xenax: Credited with the initial idea to create a badge inspired by classic pagers, a long-held personal ambition. He has been attending DEF CON since Defcon 15, highlighting his long-standing connection to the community and his passion for the culture.
- Cody: Instrumental in shaping the badge's vision with his "apocalyptic communication device" sales pitch and concept art. He was heavily involved in the complex hardware and software development, including the intricacies of the case design, screen mounting, and button integration. He also humorously recounted the logistical challenge of flying with a carry-on "stacked with badges" and their numerous batteries.
- Ian: Specifically recognized for his significant contributions to the software, particularly in supporting emojis on the retro-style display, which involved the creation of custom 8x8 pixel emoji fonts.
- SGX: Acknowledged for the intricate and challenging case design, which transformed the badge from a simple PCB into a fully enclosed, functional device.
The team emphasized their deep commitment to the DEF CON community, viewing it as their "home" and a place to further the "security agenda." Their goal is consistently to create badges that are not just collectibles but functional, open-source tools that empower others to engage in hardware hacking and security research, embodying the spirit of "Hack the Planet."
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A genuinely fun community hardware project that delivers real utility — standalone Meshtastic node, on-device pcap, Wireshark dissector, spectrum analyzer, bassband access. Sells out in three minutes because the DEF CON crowd recognizes a real tool when they see one. But as a talk, it's a product launch with a war story attached, not a security research presentation.
Heather Calloway (CISO) — PASS
A DEF CON hardware badge project — well-executed by the community, for the community, and firmly outside the lane this review covers. There is no governance angle, no institutional risk, and no organizational decision to be made from this talk.