3 ms·
You definitely could have an encryption protocol that works on a unidirectional 38kHz IR system. You put your public key in the receiver, then you, the sender,
by gravescale 2y ago
You definitely could have an encryption protocol that works on a unidirectional 38kHz IR system. You put your public key in the receiver, then you, the sender, can sign a message with the matching private key and the receiver can verify the match. You can't authenticate that only authorised devices receive the message (which is usually what the secure crypto chips with a private key in them bring to the party). You also don't need to provide any kind of secrecy - the message content is about to be broadcast in thousands of LEDs. But then you've made it much less reliable as you have to get a lot of bits across in perfect order, and adding enough forward error correction to compensate affects throughput.
Plus if you or the venue staff fluff the crypto it's another failure mode that results in Taylor Swift's legal team uncapping their Mont Blancs.
Whereas the real beauty of this system is that it leans into the noisy channel and is designed so dropping a few bits here and there is basically imperceptible. Anyone in a position to mount a malicious IR transmitter that can overwhelm the existing ones (assuming that even works and doesn't just mutually interfere and break everything) is presumably already an insider and can probably just copy "naked_hitler_flipping_the_bird.mkv" to the Jumbotron controller anyway.
- Wowfunhappy 2y agoBut isn't this trivially susceptible to a relay attack? Anyone could capture the IR sequences that cause the band to light up in each color, and rebroadcast them whenever they want. But I think we're in agreement that this is pointless anyway...
- bobmcnamara 2y ago> Anyone could capture the IR sequences that cause the band to light up in each color, and rebroadcast them whenever they want. Add a monotonic counter/nonce > But I think we're in agreement that this is pointless anyway... Agreed.
- deleted 2y ago[deleted]
- kelnos 2y agoThey certainly could do that, but: 1. Most people at this sort of concert want things like this to work. I don't think there are many people who are going to buy a ticket to go just to screw with the LED wristbands. Then again, who knows, some people are unfathomably stupid. 2. It would be fairly difficult to sneak a 30W IR lamp into the concert undetected. I suppose you could do something (much) smaller and low power; maybe disguise it as a phone or a point-and-shoot camera (which concert security may or may not allow), but then you're not going to affect all that many devices. And it also might not be hard for security to find you if they can see some sort of radius of effect from where you're standing. You'd probably have to hold it up in the air, continuously, for a while.
- Wowfunhappy 2y agoRight, which is why I've been saying there's no point encrypting any of this!
- lormayna 2y agoPublic key encryption is computational expensive in embedded devices and microcontrollers. Using a simmetric key encryption with a pre shared key it's simpler and less complex.