1
 
 

Quite new to meshcore, so here goes: What do you do regarding position sharing? The approach I followed was set a location close by and share it in adverts. I assume this can be helpful to others and keep me mostly private. Most users seem to not share their position, then there's also the option of sharing your exact location from the GPS. Would love to hear your opinions on this and the reasoning behind. I have a lot to learn!

2
 
 

I only learned about this effort today. They seem to document the air protocol and the companion protocol, so that compatible implementations can be written to expand the universe of MeshCore nodes.

I'm not sure I agree with using ZephCore (a port of MeshCore to Zephyr RTOS, apparently initially AI-generated using Claude) as the reference material -- as opposed to directly referencing the MeshCore mainline repo. But nevertheless, it's a good start to formalizing the protocol behavior necessary for an interoperable implementation to those existing nodes in the field.

3
 
 

Posting this blog post in case anyone here hasn’t seen the update on the state of MeshCore and the dispute with Andy Kirby. It’s sad that the community built up around MeshCore is being eroded by what’s going on.

4
 
 

cross-posted from: https://infosec.pub/post/48881151

The People’s Repeater is a cheap solar-powered LoRa mesh repeater you can build yourself using a $10 garden light and a small, 3D printed hub. In this video I walk through the design, do a range test, blast the repeater with pressurized water for an hour, and then show you how to build one step by step.

My goal is to get Meshcore and Meshtastic into actual neighborhoods, where ordinary people can build their own off-grid, encrypted text messaging infrastructure.

Support Black Flag Civilian & connect to the BFC discord: https://www.subscribestar.com/blackflagcivilian

FREE DOWNLOAD of People's Repeater Hub & Mount STL Files: https://www.printables.com/model/1768397-the-peoples-repeater-affordable-solar-mesh-repeate

People's Repeater Hubs & Mounts for sale on Black Flag Civilian's web store: https://blackflagcivilian.bigcartel.com/product/3d-printed-peoples-repeater-hub-mount

Parts lists (including links to specific parts) are available at both Printables and the BFC Webstore, linked above.

5
 
 

Tldr: meshcore is great. Rooms are buggy and disappointing. Flashing devices from Android would save at much time and effort on the go. Direct messages should automatically try flooding after the saved path fails, it's confusing for normies that it doesn't.

Post:

I started with meshtastic about 2 years ago, there was no activity in my area, and my friends were interested but never got onboard.

I recently moved, and my new location has a strong meshtastic presence. I initially was excited, and played with it for a couple of weeks, before becoming frustrated. Even with access to a strong network with many repeaters, it was basically impossible to hold a conversation with anyone more than 1 hop away.

I read about meshcore, and wanted to try it. I also had a camping trip coming up, a trip where I knew I'd have access to a tall hill that should cover a lot of beach and campsites.

Also, meshcore promised store and forward messaging, via rooms. Which to me is THE most appealing part of meshcore.

So I spun up a repeater and a room, and a couple companion devices.

Now disclaimer: I did put the room into repeat mode, to save on wasting an extra device, since I only have so meant to play with.

At home, it all worked perfectly. But once I got to the site, the problems started. The repeater was up almost 100ft relative to camp, but after a half mile full of trees, only the companions with high gain antennas could access it.

So I had to drive to a library to use their computer to flash a companion into a repeater 🤦‍♂️ Can we get flashing and programming from Android please?

But that worked, I strung that up about 15/20 feet into a tree at camp, companions had signal for at least a quarter mile in all directions.

Once that was working, I started testing the killer feature I wanted: rooms. But suddenly they weren't working anymore.

The room was hosted on the repeater on the hill, so it was one hop to get to it. But even the second room hosted on the camp repeater wasn't working properly.

I could have two companions logged into the same room, each sending messages that the other never ever got.

Then I'd fire up a third companion, and it would log into the room and download the messages from one of the companions but not the other, and then its own messages weren't seen by anyone else.

They just.. didn't work.

Direct messages worked well, and messages to the camp channel and public channel all worked perfectly. Heck we even got some tropo across the lake from Michigan into Wisconsin, 60 miles direct!

But the rooms were not working properly. Just failing silently, which is the worst failure mode.

We only had 4 companions going, middle of nowhere, so it's not like we were overloading it, this was the perfect use case.

The other problem we had, was the remembered routes didn't switch to flood when they failed.

So if I was at camp, texting my buddy directly, zero hop. But then I went to the beach and tried to 2 hop from the hill to the camp repeater, it would try 5 times zero hop, then fail to deliver, and quit. The path would change from "direct" to "flood", and if I manually resent the message, it would flood correctly and reach him, then change the path to "2 hops".

This is fine for me, I understand what's happening. But my friend is not techy, and struggled to grasp and remember what was happening and how it works and why it wasn't working. It was frustrating for them. I feel like this should happen automatically?

Ultimately we did end up using them a few times. I used them a lot for testing and probing and seeing where I could ping the repeaters, and how far the signal goes. The two times we really needed them, the relevant people either forgot their companion at camp (but still had their phone), or forgot to check it at all before deciding to send out a search party for me when I was late back to camp. I was like guys, check your phone. They checked, saw my message sitting there, and were like oh sorry 🤦‍♂️

I plan to try it again. I just really wish those rooms would've worked, and I don't understand why they didn't. Next time I'll have a dedicated repeater, and a dedicated room 🤷‍♂️ maybe room repeat mode just isn't ready for prime time. (Yes I know in a strong mesh, it's preferable to keep them separate).

But otherwise it was awesome, very cool technology. I made 1.8 miles contact, over 2 hops, just by setting up some repeaters. So very cool! And practical!

6
 
 

Im trying to flash a new node and cant seem to get the web flasher working. Anyone have any luck?

https://flasher.meshcore.io/heltec-v3/

Looks like im getting a Server Not Found error?

7
8
 
 

A crafted MeshCore node name could compromise any Home Assistant instance running meshcore-card as soon as someone viewed a dashboard with that card.

The same XSS (cross-site scripting) pattern appears to be present in MeshCore-Home-Assistant-Panel-v2 and its HACS variant

To be abundantly clear, and the post goes into detail why, this is not a bug in MeshCore but rather in how web dashboards are not properly sanitizing untrusted input. In this case, the untrusted input is via a field that any malicious MeshCore node could send.

Well worth a read and a follow on their Mastodon.

9
 
 

cross-posted from: https://lemmy.world/post/47111253

I recently bought a Lilygo T-Deck Plus and had assumed it would include an antenna, since i ordered it with an external antenna. Today it arrived and apparently doesn't come with any external antenna, just a hole in the top with a rubber bung where one would go.

I had heard the antenna it comes with isn't very good, so i bought a Stubby from ZBM2 Industries. What i need to know is what connector piece i need to go between the antenna and the circuit board. The little brass-colored thing that the antenna screws onto. What's that part called and is there anything i should watch out for when finding one?

10
 
 

A reasonable overview of the MeshCore architecture and tunable parameters.

Probably the only part I don't agree with is the idea that the companion/repeater dichotomy is an inherent part of the MeshCore architecture. I don't believe it is, although it's certainly part of the practical implementation. That is to say, if someone wants to use MeshCore purely as a private point-to-point link, then they can jettison the motions of companions and repeaters entirely. As a person to person mesh network, though, companions and repeaters are essential. The distinction I'm trying to draw is that MeshCore can be a lot more than text messages sent amongst friends.

While reading, the explainer for the three-tier t delay seemed especially analogous to me to how circuit breakers are arranged: a nearby power strip might have a fast-tripping 15 amp thermomagnetic breaker, the upstream main panel might be using a 20 amp curve B (moderate trip rate) thermomagneric breaker, and the utility might be using a magnetic 400 amp breaker. By their nature, thermomagneric breakers will handle localized faults that are 3-5x the rating, while the utility's magnetic breaker will trip precisely at 400.1 amps, to protect line-side equipment. Whereas if the utility breaker tripped first, it would unnecessarily black out a whole neighborhood.

Also observe that MeshCore's "flood-then-direct" behavior is identical to that of Ethernet (ie unknown unicast, then unicast), except that Ethernet frames do not get appended with the network path as they progress, which is akin to the postal service where letters arrive at their destination but with no indication of the routing. Accordingly, the MeshCore sender necessarily reserves space to store the mesh route, choosing a tradeoff between node-count (up to 64) or granularity (up to 3 bytes per repeater). This seems complex, but just like with the tax code, complexity is necessary to handle every reasonable scenario.

I will also reiterate the ongoing bug in MeshCore's encryption, which is the use of AES-ECB in the year 2026. Although it's AES-256, ECB has been a known encryption vulnerability for decades and should not have been used in the MeshCore spec. Meshtastic appears to have avoided this particular foible.

Note: the author's blog mentions in the About page that some AI is used to assist in his writing.

11
 
 

I spent over 100k sats on 2 pieces of landfill trash, because of retailers and other websites and random people lying about LoRa mesh protocols being "open source."

The goal was already to spread the word about lies these retailers and other related sites spread, e.g. gaslighting users about end-to-end encryption, but there's no point using the network to spread the word about the lie of being open source. It's a fool's errand, the corporations already scammed my money out of me and they'll just use me to make even more money while I try to tell people to stop wasting the money.

So now I have a SenseCap and a Wio Tracker L1 Pro shipping to me for nothing except to scrap for parts like the batteries, and throw the malware transceiver/computer parts in the garbage so nobody can use them to spread this piece of shit malware cult.

Have fun downvoting/removing/banning me, to the majority here moronic enough to side with the scammers even after reading the truth.

12
 
 

What can be done

The most glaring problem with MeshCore is that the maintainers do not openly communicate vulnerabilities. Users are left without knowledge of any problems, unable to judge whether to trust MeshCore with their private communication.

13
 
 

Here is the thing about open source, Andy: it isn't yours to fence. You don't get to ride a community's goodwill into a USPTO filing and a paywall. You don't get to turn "we built this together" into "I own this, pay me." That isn't a pivot. That's a rug pull dressed up as a business model.

And here is the thing about the "license check" you shipped: it is a 32-bit djb2 hash of the device's Android ID, XORed with the four ASCII bytes MCPP, hex-encoded. That's it. Thirty-two bits. Less entropy than a decent ZIP password. A first-year CS student could break it. You used Claude to generate the code. We used Claude to read the code. It took 19 minutes. The receipts are one click away.

14
 
 

Migrating to the new meshcore.io site

15
 
 

cross-posted from: https://lemmy.world/post/45567835

Created my first meshcore solar powered repeater. Using the lilygo t-beam supreme and a overkill solar panel. All mounted on a din rail in a waterproof electrical cabinet.

It also included some more monitoring, using a esp32c6 running esphome with zigbee and deep sleep. Because i want to keep track of the solar performance.

It was a lot of work to get running, from soldering, 3d printing but also some little firmware changes. I even tough i burned out the lora module by running it without the antenna sometimes. I couldn't test it because i only had 2 other t-beams that where 443Mhz. Today, after buying a hot air station and some soldering i now have 2 board that work with 869Mhz (swapped the sx1278 with a sx1262). Now i am just waiting on the last 869Mhz module so i can modify my last board.

A little cursed i think but the new module didn't have the same footprint so this also works.

firmware

I like how easy the firmware is to edit, when you have some arduino experience. I added support for the 443Mhz t-beam, made it possible to connect via the app and via the home assistant integration at the same time and created a custom sensor that controls 2 relays, so i can control them remotely. But for some reason the screen just wont work, i tried using the example arduino sketch, different versions and all, none work. I do know the screen is functional because with the test firmware from lilygo it does work.

range

I haven't really tested it with the new antenna, but when i let it run for some time using the stock one, i got contacts from over 125km away, which did really surprise me. I hope with this new antenna that i can also send messages not only receive them.

Some more pictures

16
 
 

Mapme.sh is a community-built coverage map for MeshCore. You connect your device to your phone over Bluetooth through a browser app, and the site logs your GPS position with signal strength data as you move. It aggregates everything into color-coded hex cells on a map, from green for strong signal down to blue for barely there. You earn points for mapping new hexes, and a leaderboard tracks top contributors. Privacy controls let you choose between real-time visibility, a 3-hour delay, or full ghost mode with a 24-hour delay. The site comes from the HanseMesh community in Germany, so it's bilingual in German and English.

17
 
 

I've actually been using meshtastic since January of last year, and I've known of meshcore pretty much since its release. However, until now, I have refused to use it because there was no open source application for smartphones to use with it. And I do not touch software that is not open source if I can at all help it. A couple of weeks ago, I learned about a new meshcore app called Meshcore-open that is currently in alpha. Last night I decided to give it a try, and so far I do like what I see. Unfortunately, the population of my city is only like 45,000, and there are only a couple of meshtastic nodes even in the area, and so I'm all alone here. I unfortunately am unable to put up my own repeater because my yard is absolutely full of trees and a solar node just will not stay charged.

18
submitted 6 months ago by to c/Meshcore@feddit.org
 
 

tbh I'm not a big fan of proprietary firmware, but I thought someone might find this interesting.

19
 
 

I recently checked out Meshcore because I live in the outskirts of Ottawa, and the city has completely switched to it from Meshtastic. I was impressed with how big the mesh is, and how well I was able to communicate with someone clear across to the other side! I was on a beach, connecting direct to a repeater 30km away, and they were recieving me another 20 km from there. Very cool.

Anyway, I learned about meshmapper.net from an active Ottawa mesh community member, and dev of the site, Mr. Alders0n.

Been having fun wardriving the area and mapping the mesh's reach into the outskirts.

Just made this app, which is a portal to easily access the war driving web app, and the mesh maps, and added a way to pin the city instead of trying to navigate the globe map to select it... yeah I know I can just add shortcuts to my browser for both, but this was more fun :)

20
 
 

cross-posted from: https://gregtech.eu/post/25654151

Basically title. I'm in the EU, so I need a 868Mhz one. I need it to be weather-resistant, because I'm making an outdoors node. Cost and size are not an issue. I plan to mount it relatively high.

I'll most likely install it on a Heltec T114.

21
submitted 10 months ago by [M] to c/Meshcore@feddit.org