Private clusters and channels
Security
Blackout Comms has two models. Private clusters are the higher-security, higher-function path. Channels are the other, documented separately on the firmware site.
Private clusters
A cluster is two or more ChatterBox devices that trust each other and help with mesh delivery. They share a common root, the admin device, and each new device is onboarded once, in person and in proximity. Devices outside the cluster are ignored.
Chain of trust
Devices the root trusts become trusted by the rest of the cluster. The root stays at the top of that chain. Details are on the onboarding page.
Frequency hopping
The cluster rotates frequencies about once a minute in a pattern derived from a key. Off-cluster radios do not sit on the traffic, and a jammed frequency only matters for a short window. Direct exchanges stripe each packet onto a frequency derived from the asymmetric keys of those two devices.
Encryption
Every message, ping, location, and mesh packet is encrypted in transit. Direct messages use asymmetric encryption, so devices that only relay the packet cannot read it. Broadcasts and pings use symmetric encryption so every on-cluster device can decrypt them. Sensitive data at rest is symmetrically encrypted with a password you choose, or with a device-generated key if you do not.
Signatures and storage
Messages are signed with the sender’s private key using ECDSA. The signature travels with the message. Public keys move through the chain of trust, so every device can check the signature, including a timestamp, before it meshes the packet. Relays can validate a direct message without decrypting it.
With private clusters, symmetric and private keys are not shown and cannot be exported. If you use an SD card, sensitive data and configuration are encrypted at rest.
No phone OS in the loop
This is embedded firmware, on FreeRTOS or no OS. There is no mechanism for an operating system to inspect the data, disable an app, or share location with a vendor.
How this differs from Meshtastic
Meshtastic’s model is a single shared channel password. If you know it, you are in. There is no invite-only group and no chain of trust. That one symmetric key is typed by a person into a phone or device, so a phone OS and human eyes have seen it. If it leaks, the channel is compromised.
Meshtastic devices sit on one frequency. That raises the chance of collision and jamming, makes a long recording easier to replay later if the key leaks, and makes triangulation simpler. Blackout Comms hops, signs every packet, and keeps direct-message plaintext off the relays.
Meshtastic can use asymmetric encryption in some cases. The default channel model is still one shared symmetric key entered by hand.