Tag
The author details how they decrypted Flume water monitor MQTT traffic by extracting a static 32-byte key from flash and using libhydrogen secretbox parameters, revealing that no session keys are involved despite noise key exchange code in firmware.
A security researcher analyzed the 915 MHz RF link of the Flume Water Monitor, successfully broke its encryption with moderate effort, and found the security reasonable for a consumer device.