Just unlocked my computer twice with Knock (http://www.knocktounlock.com/ ) while running a bluetooth packet capture for each unlock attempt.
-
-
Replying to @charliesome
Both times the iOS app appears to send exactly the same data to the computer. Take from that what you will.
2 replies 0 retweets 1 like -
Replying to @charliesome
@charliesome I take it the message contains your password, and that passwords/PSKs are terrible for machine-to-machine use1 reply 0 retweets 0 likes -
Replying to @bascule1 reply 0 retweets 0 likes
-
Replying to @charliesome
@bascule but there doesn't appear to be any one time nonce or anything, so all that app level encryption is moot1 reply 0 retweets 0 likes
Replying to @charliesome
@charliesome add replay attacks to their "Is it secure?" section saying it's secure because it uses 1024-bit RSA
8:56 PM - 14 Feb 2015
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.