Hacker News new | ask | show | jobs
by afvictory 2160 days ago
It's been a while since I have worked in this space but the underlying protocol (AIS) is incredibly lacking in terms of security due to the nature of plain text transmission & lack of authentication. I'm not sure if these issues have been addressed but below is some great research from 2014 on the matter [1][2].

[1] https://www.blackhat.com/docs/asia-14/materials/Balduzzi/Asi...

[2] https://www.youtube.com/watch?v=5rt9dzu3I7U

1 comments

The payload length for a single AIS slot is 168 bit. So there is really no room for any kind of security headers.