Scott Thompson
Scott Thompson, KF5CPY, is a Cloud Architect for a motorsports team by day and a compulsive tinkerer by night, with a home lab full of Raspberry Pis, SBCs, and a backlog of HackerBox projects that will absolutely get soldered eventually. He earned his Technician license in 2019 for the most practical reason possible: surviving a back-country trip into the New Mexico desert without cell service. He has spent most of his career security-adjacent, doing the kind of remediation work that gives you strong opinions about how things break. This is his first conference talk.
Session
Meshtastic does exactly what it says: it carries your text off-grid to whoever shares your channel key. The risk is what people assume it does on top of that. The mesh does not keep your secrets and does not vouch for your neighbors, and a growing number of people are betting real stakes on both, using it for protest logistics, disaster response, and off-grid safety where "trusted friends on a channel" is exactly the wrong threat model. We go looking for the beasts that live in that gap, impersonation, forgery, silent packet-dropping, traffic analysis, and node-database floods, each shown live on a real mesh with a custom firmware fork and a Python toolkit. The uncomfortable part is how little it took: two developers who do not write firmware for a living built the whole offensive stack with AI assistance in about 16 days of evenings. This is not a dunk on Meshtastic. It is a field guide to its actual threat model, and to operating like you know the difference.