LED Strips - Findings
F-001: Hardcoded XOR Key
CVSS: 9.8 (Critical)
XOR key is hardcoded in the app, identical for all devices.
F-002: Trivial Encryption
XOR provides no real protection:
- Instantly decryptable with known key
- No brute-force needed
- Byte 0 not encrypted (known-plaintext)
Recommendations
- Use real encryption (AES-GCM)
- Per-device keys from pairing
- BLE Security Level 2+