Nicholas TongSeeed SenseCAP Card Tracker T1000-E (Meshtastic)
54 / 56
the stranger in Pasadena who read my test message
The pho place on Bellaire opens at seven and I was eleven minutes early, so I sat in the car and sent a test message from a radio the size of a credit card. "test from Bellaire," typed on my phone, handed over Bluetooth to a $39.90 plastic card in the cupholder, and pushed out on 915 MHz with about a watt of ambition. Two hops later a stranger near Pasadena, across the ship channel from me, answered with one word: "copy."
That exchange is the useful part and the whole security model in a single message. A stranger read it because on the default channel, everyone reads everything. The key to that channel is literally published in the documentation, the string "AQ==", base64 for one zero byte. It's not a leak. It's the design, working exactly as written, and I don't think most people buying these radios know that.
what the default channel actually is
The wrong model is Signal for hurricanes: encrypted, private, yours. The right model is a party line with optional private messages. Channel traffic is AES-256, but AES against a shared key that the whole world can download is a curtain, not a wall. The encryption docs say it plainly: the default key is public, there's no forward secrecy, and channel messages carry no authentication, so anyone on the channel can speak as anyone else. The headers travel in the clear, which means every node in range can see which node sent, which node it's for, the hop count, the timing. Position updates ride the channel too, so on the stock setup, a map of who's moving through Houston is public infrastructure that anyone can join.
This is going to sound paranoid, but I left mine on the default channel for two weeks on purpose, because I wanted to know who was actually listening. Answer: hobbyists, a few bots that log positions, and nobody menacing, which is the boring truth. I changed the key after, and so should you, and that takes one minute in the app.
The card itself is the cheapest honest way into this. Seeed's SenseCAP T1000-E is a sealed slab, 85 by 55 millimeters and 6.5 thick, IP65, with a Nordic nRF52840 microcontroller, a Semtech LR1110 radio, a Mediatek GPS chip, a 700 mAh battery, one button, no screen, no antenna connector, charged by a magnetic pogo-pin puck. It's a tracker that can also carry messages, which is the correct order of operations for the hardware, and it's why the whole thing costs less than dinner for two.
how a message crosses the city
Meshtastic is a flood network. Your node transmits on the LoRa band, in the US at 902 to 928 MHz under FCC Part 15.247, unlicensed, legal, no coordination. Every node that hears the packet rebroadcasts it, up to the hop limit, three by default. No routing tables, no towers, no infrastructure, no one in charge. Your phone talks to the card over Bluetooth; the card talks LoRa to the world; the world repeats you.
The encryption layer sits on top of that flood. Channel messages get the shared channel key. Direct messages, since firmware 2.5, use an actual key exchange between the two nodes, and those are the only messages worth the word "private" without a paragraph of footnotes. The flood design is also the availability story: no single point to fail, no operator to go bankrupt or get subpoenaed. During Beryl, cell towers in my part of Houston went dark for days while the grid came back piece by piece. A protocol that keeps working when the infrastructure doesn't is worth forty dollars of anyone's hurricane budget, and I don't say that lightly.
One hardware catch to know before you buy a second node for a family member: the LR1110 radio in this card can't receive packets transmitted by the older SX127x radios, and the Meshtastic docs say fixing it would take a breaking protocol change. Transmitting works, and an SX126x radio in the middle can bridge the two generations. Half the nodes I could hear around town, I couldn't complete a round trip with, and it took me a shamefully long time to figure out that the incompatibility was silicon, not signal.
where it falls over
Range, first, and the honest numbers are smaller than the marketing. Hackaday's two-city test found about six miles reliable in rural New Jersey and poor performance in the suburbs, where trees and stucco eat 915 MHz for breakfast. Houston is flat, which helps, and heavily built, which doesn't. MeshMap showed 46 MQTT-reporting nodes within about 80 kilometers of the city in early October, and that's a skewed sample, gated on people who report to the internet, but the honest read is that density here is thin and your message may simply have nowhere to go.
Battery, second. With GPS on and the radio active, plan on roughly a day per charge; GPS off stretches it toward three. Fine for a tracker, marginal for a disaster kit, and the charging puck is proprietary, so losing it turns the card into a paperweight until a replacement ships. Mine lives on the windowsill next to the plant, which is not a system, it's a habit I don't trust yet.
Firmware history, third, and this is where the security story gets real. CVE-2025-52464, published June 2025, critical: some vendors' flashing processes cloned identical, low-entropy keypairs onto batches of devices running 2.5.0 through 2.6.11, meaning strangers' devices could share keys. Meshtastic's 2.6.11 warns about known-bad keys and 2.6.12 wipes them. If you bought a pre-flashed tracker, update and let it rekey. CVE-2025-53627, forged direct messages shown as encrypted, was fixed in 2.7.15. The stable line is 2.7.26 as of June 2026; 2.8 is alpha, and two 2.8.0 builds were revoked, which should tell you what the project thinks of rushing a flash. Flash the stable release yourself, from the official web flasher, and check the version after.
And the deepest limit is social, not technical: on any shared channel, identity is a nickname. No channel message authentication means anyone can claim to be anyone. In a real emergency, that's exactly when someone would exploit it, and exactly when people are most willing to believe a confident voice on the radio.
what I'd set up first
- Generate a new channel key on your own device before you need the mesh, and put your people on it. One minute, one time.
- Flash current stable firmware yourself and confirm the version in the app, because pre-flashed vendor firmware is where the cloned-key CVE came from.
- Use LongFast and leave it alone unless you know why you're changing it. Every tweak costs range, battery, or both.
- Assume the channel is public, because the default one is: nicknames, coordinates, logistics. Nothing that could hurt you if a stranger reads it, because one did.
- For the kit, add a power bank with the right cable and write on the card which puck charges it. The mesh is only as real as the day-three battery, and Houston hurricanes will test day five.
The card's temperature sensor told me my car's interior hit 48 degrees Celsius at two in the afternoon, a fact I did nothing with and now can't stop noticing every time I park.
That stranger in Pasadena who read my test message wasn't the failure. He was the feature, doing exactly what the documentation said he would. Knowing that before the towers go down is the entire reason to spend the forty dollars.
Test messages are for testing. Change the key.