Decentralized Communications: Deep-Dive into APRS and Ham Radio Security

Ankur Tyagi, Mayuresh Dani

BSidesSF 2025 — Here Be Dragons · Day 1 · Main

APRS (Automatic Packet Reporting System) and Meshtastic represent two fundamentally different approaches to decentralized, infrastructure-independent communication — one optimized for range and open situational awareness, the other for privacy and modern mesh networking. Ankur Tyagi and Mayuresh Dani delivered a technically grounded exploration of both protocols, their security models, and practical guidance for the security community on when and how to use them. ---

AI review

A technically honest deep dive into APRS and Meshtastic security that will be genuinely useful to the ham radio adjacent crowd and emergency preparedness community. The comparative analysis is clear-eyed and the CVE callout for Meshtastic RCE (CVE-2025-2497) is timely. Won't move the needle for most practitioners, but it's not trying to — and it doesn't pretend to be more than it is.

Watch on YouTube