| |
A security researcher successfully defeated the encryption on Flume Water Monitor's 915 MHz wireless signal between the water meter sensor and home bridge device, reducing the effective encryption from 128 bits to 44 bits through analysis of unencrypted header data and hardcoded key mapping. While the device's use of frequency-hopping and AES-128 encryption provides reasonable consumer-level security, the vulnerability could allow an attacker to generate spoofed messages and potentially enable malicious firmware updates. The researcher was able to brute-force the remaining 44-bit key space in approximately one day using cloud GPU resources.
Read Full Article →
← More Tech news