<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Amged</title>
    <description>The latest articles on DEV Community by Amged (@amgedi).</description>
    <link>https://dev.to/amgedi</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4174540%2F4a5f6a14-5f43-42c5-bce3-80616b449c5b.jpg</url>
      <title>DEV Community: Amged</title>
      <link>https://dev.to/amgedi</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/amgedi"/>
    <language>en</language>
    <item>
      <title>Threat-modeling the LAN sync in my wildlife app (as a beginner)</title>
      <dc:creator>Amged</dc:creator>
      <pubDate>Sat, 10 Oct 2026 04:34:28 +0000</pubDate>
      <link>https://dev.to/amgedi/threat-modeling-the-lan-sync-in-my-wildlife-app-as-a-beginner-43j0</link>
      <guid>https://dev.to/amgedi/threat-modeling-the-lan-sync-in-my-wildlife-app-as-a-beginner-43j0</guid>
      <description>&lt;p&gt;I'm new to programming &amp;amp; have been teaching myself security by building things and then poking at my own assumptions. This is a simple threat model for one feature of &lt;a href="https://github.com/amgedi/Wildlife-Incident-Handoff" rel="noopener noreferrer"&gt;Wildlife Incident Handoff&lt;/a&gt;, it's an opensource Windows app for recording wildlife incidents and handing them off between people.&lt;/p&gt;

&lt;p&gt;Now the feature is &lt;strong&gt;LAN sync&lt;/strong&gt;: I wanted to make it so two paired devices on the same local network can exchange incident records directly with no cloud involved. It's opt in and still experimental although &lt;strong&gt;It has not been independently reviewed&lt;/strong&gt;, so this post is "how I designed it and where I know it's weak," not "it's secure."&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'm protecting
&lt;/h2&gt;

&lt;p&gt;Incident records. They can include sensitive animal locations and private contact details, which shouldn't leak.&lt;/p&gt;

&lt;h2&gt;
  
  
  What could go wrong, and what I did about it
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Threat&lt;/th&gt;
&lt;th&gt;In plain English&lt;/th&gt;
&lt;th&gt;My defense&lt;/th&gt;
&lt;th&gt;Known gap&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Eavesdropping&lt;/td&gt;
&lt;td&gt;Someone on the same wifi reads the data&lt;/td&gt;
&lt;td&gt;Data is encrypted (AES-256-GCM) with a key both devices agree on (P-256 ECDH + HKDF)&lt;/td&gt;
&lt;td&gt;Keys are long-lived, so there's no forward secrecy unless I rotate keys or re-pair&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impersonation&lt;/td&gt;
&lt;td&gt;Someone pretends to be my other device&lt;/td&gt;
&lt;td&gt;Each install has its own keypair and a fingerprint you can compare&lt;/td&gt;
&lt;td&gt;On a hostile network, it only works if people actually compare fingerprints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Stolen pairing code&lt;/td&gt;
&lt;td&gt;Someone learns the code and tries to pair&lt;/td&gt;
&lt;td&gt;The first device has to manually approve every request&lt;/td&gt;
&lt;td&gt;A human has to read the prompt carefully&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Replay&lt;/td&gt;
&lt;td&gt;Someone records a message and sends it again later&lt;/td&gt;
&lt;td&gt;Each message carries a counter, and old counters are rejected, even after a restart&lt;/td&gt;
&lt;td&gt;Limited testing so far&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Strangers reading data&lt;/td&gt;
&lt;td&gt;An unpaired device asks for records&lt;/td&gt;
&lt;td&gt;The sync endpoint rejects untrusted devices&lt;/td&gt;
&lt;td&gt;A tiny "ping" endpoint still answers for discovery (it returns no incident data)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;"Disabled" isn't fully off&lt;/td&gt;
&lt;td&gt;Sync is turned off but something is still listening&lt;/td&gt;
&lt;td&gt;Pairing and sync requests are rejected when sync is disabled&lt;/td&gt;
&lt;td&gt;The network listener stays open while the app runs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What I haven't covered
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;A device that's already trusted but compromised&lt;/li&gt;
&lt;li&gt;Attachments (they don't sync)&lt;/li&gt;
&lt;li&gt;Wide testing across different routers, VPNs, and corporate networks&lt;/li&gt;
&lt;li&gt;An outside security review&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What I learned
&lt;/h2&gt;

&lt;p&gt;Writing this made me notice that "disabled" in my app means "refuses requests," &amp;amp; not "stops listening." Those aren't the same thing and I want to fix it so the listener only runs when sync is on&lt;/p&gt;

&lt;p&gt;If you find a hole please report it through the repo's &lt;a href="https://github.com/amgedi/Wildlife-Incident-Handoff/blob/main/SECURITY.md" rel="noopener noreferrer"&gt;SECURITY.md&lt;/a&gt; instead of opening a public issue.&lt;/p&gt;

</description>
      <category>security</category>
      <category>opensource</category>
      <category>rust</category>
      <category>beginners</category>
    </item>
  </channel>
</rss>
