Water meter encryption cracked by corrupting a key in flash memory

Water meter encryption cracked by corrupting a key in flash memory

An enthusiast known as Stephen has figured out how to intercept data from a Flume smart water monitor as it travels through his home network to the company's servers and from there to the water utility. He had previously worked out the mechanical side of how the device measures flow, but his bigger goal was to sniff the reported data while it passed through his own network.

The Flume setup consists of a sensor installed in the water line and a bridge unit that connects to the internet. Stephen scored an early win by tricking the bridge into sending data in plaintext. The trick turned out to be surprisingly simple: he corrupted the public key stored in the device's flash memory. However, that approach had a flaw — the damaged key prevented the device from authenticating with Flume's servers.

Digging deeper into the LibHydrogen encryption implementation revealed something curious. The device appeared to authenticate without using session keys at all, relying solely on a static device secret key that can be harvested from the onboard flash. That discovery allowed Stephen to build a tool that sits between the bridge and the Flume servers. It forwards traffic seamlessly while decrypting and saving it locally at the same time.

With this setup in place, Stephen was able to log water flow and status data from the sensor on his own machine. There is one caveat: the man-in-the-middle arrangement could block the hardware from receiving firmware updates in the future. He also notes that his earlier write-up on demystifying the Flume hardware is worth a look for those interested in how the device works under the hood.

Tags: Hardware
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate