Home/FAQ

Straight answers

The questions people actually ask

Including the uncomfortable ones. If something here reads like a dodge, open an issue — the Charter records the arguments against every decision for exactly this reason.

What happens if nobody ever meets the recipient?

A carried message expires after ninety days — one fixed window, the same for every message — and you’re told it wasn’t delivered. You are never left believing something arrived when it didn’t.

My radio stopped working during a firmware update. Have I broken it?

Almost certainly not, and the app can finish the job. A radio that is interrupted part-way through an update — it went out of range, the phone was interrupted, the app was closed — stops behaving like a radio and waits to be finished. It is not damaged and nothing is lost.

Open Update a radio over Bluetooth in the app. A radio in this state appears at the top of that screen, by name, with Finish the update next to it. That completes the transfer over the air — no cable, no reset button, and it still works after you have closed and reopened the app.

If the app says it cannot see it, it needs to be within a few meters of your phone. If it stays out of sight, the fallback is physical: press its reset button twice, plug it into a computer, and install the firmware over the cable.

Can I write a message when there is no radio at all?

Yes — on paper. A message can be turned into a QR code or a short link and carried by anything that moves: a photograph, a printout, a screen held up to somebody else’s camera, a note pinned to a board. The person who receives it scans it back into their app and it behaves like any other message.

It is the same sealed message either way — paper is a route, not a downgrade. Nobody between the two of you can read it, including whoever carries the paper.

One message per code, and a long one will not fit — the app tells you the limit before you write, not after.

Doesn’t carrying other people’s messages use my battery and storage?

Storage isn’t capped — messages are small, and the app sets no limit on how many your phone holds. Battery is the real cost, and it is better stated plainly than dressed up: carrying means scanning, and scanning uses power. What the app does guarantee is that peer scanning yields the radio rather than competing for it — it stops entirely while a station firmware update is in flight, and refuses to run whenever it cannot read the radio’s state.

Can someone flood the network?

Copy budgets bound how many copies exist, per-session quotas bound what any one peer takes, and airtime budgets bound each encounter. A stationary node — the one physically capable of the most flooding — is the most tightly bounded of all.

Can I read messages I carry?

No. They’re ciphertext addressed to somebody else and there’s no field telling you who. That’s the point. You can see a blob of a certain size, an opaque identifier, an expiry and a count of how many phones have carried it — and nothing else.

Do I need a license?

MeshDTN runs on license-free bands. Regulations vary by country and are your responsibility — see NOTICE.md, which sets out the relevant regulatory facts with citations and draws no conclusions.

Will it talk to my existing MeshCore nodes?

Yes. A flashed radio stays in your MeshCore network: MeshCore users see an ordinary node and text it the ordinary way, and plain text works in both directions. Carriage — a message waiting for someone out of reach — happens only between MeshDTN nodes. You choose, per contact or per message, whether a message goes the MeshCore way, the MeshDTN way, or Auto.

What each way puts on the air

What’s the range?

Ordinary LoRa range — kilometers, terrain-dependent. But range is the wrong question: a message can cross a hundred miles through five people who never met each other.

Do I need a radio at all?

No. Because BLE and WiFi carry messages, a phone participates fully on its own — carrying other people’s traffic and sending its own. The radio makes you reach further; it isn’t the price of entry.

Is there a server, an account, or a subscription?

None of the three. Linking stations over the internet was considered and rejected: a central service would see every station, every identifier and every timestamp in one place, which reassembles a movement trace of senders in the one component with a complete view. It is also a one-way door — you can add a hub later, you can’t credibly remove one.

There is no MeshDTN company that can go out of business and take your network with it.

Can a station operator refuse to carry certain messages?

No. No allowlist, no blocklist, no operator filter, no content policy, no priority class. It is a written invariant with a test behind it. The property is free today because a carrier can’t read anything — and the only way to lose it is for somebody to add a knob believing it’s a feature.

Is a group chat as private as a one-to-one message?

No, and MeshDTN calls it a broadcast channel rather than a group chat for that reason. Every member can decrypt everything ever sent to the channel, including traffic from before they joined. There’s no forward secrecy and no claim of any. The app shows you plainly which kind of conversation you’re in.

Has the cryptography been audited?

No. Nothing in MeshDTN has been audited, and no security property in this project has been independently reviewed. Until that happens, every security property described on this site is a design target rather than an assurance, and the Charter forbids us claiming otherwise.

That is a statement about scrutiny, not about construction. The primitives come from widely used libraries and the specification is public — but a library’s assurance covers the library, not the way this project combines it.

What cryptography does it use?

Standard, widely used primitives, and nothing invented here. A carried message is sealed with an X25519 key agreement, HKDF-SHA256 key derivation and ChaCha20-Poly1305, with an HMAC-SHA256 tag the recipient uses to recognize it — every primitive from the published cryptography and crypto Dart packages. A message sent the MeshCore way uses MeshCore’s own encryption.

There is no forward secrecy. The key between two contacts is derived once and does not rotate, so anyone who later obtains that key can read earlier messages they captured. That is a deliberate trade for simplicity, not an oversight. Every choice is written down in the Protocol, field by field, so it can be checked rather than taken on trust.

Independent cryptographic review is where outside help is worth the most. The primitives are standard and the specification is public, which makes review tractable. If you do this professionally, we’d welcome your eyes on it.

What do I actually need to get going?

A phone, and a supported LoRa board if you want kilometers instead of a room. Install the app, flash the board the same way you flash any MeshCore board, pair them over Bluetooth, scan a contact’s QR code, and write. If you already own a LoRa mesh radio, there is a good chance you don’t need to buy anything.

Ten minutes, step by step

How do I help?

Range and field data from real terrain. iOS. Cryptographic review — that’s the gap that matters most. And stations: put one on a pole and tell us what happens over a month. If you want to build a second implementation of the protocol, the specification is published for exactly that.

Where help is most useful

Distance is easy. Time is the hard part.