Skip to content
Learn · Security

Encrypted end-to-end, on a network anyone can listen to

Radio is inherently public, anybody with a compatible receiver hears the packets go by. MeshCore's answer is not to hide the transmission, but to make the contents useless to everyone except the intended recipient.

Keys live on your device

The first time you open MeshCore, it generates a keypair on your phone. That keypair is your identity on the mesh. It was never issued by a server, so there is no server that can be compelled to hand it over, and no account to be breached.

Direct messages are encrypted to the recipient's key. Channels use a shared key that everyone in the channel holds. In both cases the encryption happens before the message reaches the radio, and it is not undone until it reaches the destination device.

What a repeater operator sees

Repeaters, including the ones Comchan runs, have to handle your packets in order to forward them. What they handle is an encrypted payload plus the minimum routing information needed to move it along. An operator can see that traffic passed through, how strong the signal was, and how many hops it took. They cannot read it.

This matters because it means you do not have to trust us. Our analyzer publishes signal quality, node health, and traffic volume precisely because that is all there is to publish, it is metadata about the radio network, not about what anyone said.

Honest limits

Encryption does not make you invisible. Radio transmissions can be detected and, with effort, located. A channel key shared with fifty people is a key fifty people can leak. And if the phone in your hand is compromised, no amount of transport security helps.

We say this plainly because MeshCore is often deployed in situations that matter, storms, outages, remote work sites. Knowing exactly what the tool protects is part of using it well.

Legal note

MeshCore operates on license-free ISM spectrum (902–928 MHz in the United States), so no amateur radio license is required and encryption is permitted. That last point is a real difference from ham radio, where encrypting content is generally prohibited. Follow the power and duty-cycle limits your hardware ships with and you are operating within the rules.

Protected

  • The contents of your direct messages
  • The contents of channel messages, to everyone holding that channel's key
  • Your message contents from every repeater that forwards them, including ours
  • Your identity from the network, there is no account, phone number, or email tied to you

Not protected

  • The fact that some node transmitted at some time, radio is observable by anyone listening
  • Messages can be traced to the area where the first repeater heard them, even if the contents are encrypted
  • Positions you deliberately share on a public channel
  • Anything on a channel whose key has been handed out widely, treat those as public
  • The device itself, if someone else gets physical access to your unlocked phone or node

Treat public channels as public

A regional channel is a town square, not a private room. Use direct messages or a small, tightly-held channel for anything you would not say out loud at a meetup.
For organisations

If you're evaluating this for a clinic, farm, or response team

A few things worth knowing before you build a plan around it.

It is not a regulated system

MeshCore is not a certified public-safety or medical communications system. Treat it as a resilient supplement to your primary channels, and document it that way in your continuity plan.

Keep sensitive detail off it

For healthcare, coordinate logistics, beds, transport, staffing, not identifiable patient information. Encryption is strong; your compliance obligations are still yours.

Exercise it before you need it

A radio in a drawer with a dead battery helps nobody. Run it during normal operations so the batteries, the mounts, and the muscle memory are all known-good.