Decrypting Flume Water Monitor Traffic
Previously submitted: https://lobste.rs/s/vnigrw/diving_into_flume_water_monitor Comments
The Flume water monitor uses a proprietary encryption method to secure its MQTT traffic between the device and Flume's cloud server. The encryption is implemented using LibHydrogen's secretbox construction with a single symmetric key stored in flash memory. This key can be read without modifying the device. The encryption parameters, such as context and message ID, can be found in the firmware and are known to be appropriate for the implementation.
The bridge negotiates ephemeral session keys with Flume's server, but these keys are not used for normal MQTT traffic. Instead, all messages are encrypted and decrypted using the static 32-byte key. A transparent man-in-the-middle relay called flumewatch was built to intercept and decrypt the traffic by redirecting it at the network layer.
The relay forwards encrypted payloads byte-for-byte, allowing the bridge and Flume's server to remain unaware of the interception.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.