
ESP32 security research: getting started lawfully
ESP32-based research hardware is cheap, capable, and legal to own almost everywhere. It's also the category where "curious" and "criminal" are closest together, so it's worth being precise about the lawful-use boundary before you power anything on.
What these tools are for
A modern ESP32 deck — sub-GHz radio (CC1101), 2.4 GHz (nRF24), NFC (PN532) — is a general-purpose RF laboratory in your pocket. Legitimate uses are broader than most people assume:
- Auditing your own systems. Testing whether your garage door, gate receiver, or building access system uses a fixed, replayable code. If it does, you now know to replace it.
- RF protocol research. Capturing and analysing ISM-band traffic on frequencies you're licensed to use or that are unlicensed and low-power.
- NFC/RFID inventory and tag exploration on tags you own or are authorised to test.
- Educational demonstration of why rolling-code systems exist at all.
The legal boundaries that matter
Laws vary by jurisdiction, but the recurring principles are consistent across AU, NZ, US, and UK:
- Authorisation. Test only systems you own or have written permission to test. "It was unlocked anyway" is not authorisation; it's the definition of unauthorised access under most computer- and communications-crime statutes.
- Spectrum rules. Transmitting on sub-GHz ISM bands is legal at low power in most jurisdictions; transmitting on licensed bands (mobile, emergency services) is not, regardless of intent. Know which band your firmware is keyed to before you press transmit.
- Cloning vs research. Capturing a signal to understand a protocol is research. Replaying a captured credential to open something you don't own is an offence nearly everywhere, independent of any hacking law — it's typically dealt with under general theft or fraud provisions.
- Possession with intent. In some jurisdictions, possessing a device with intent to commit an offence is itself an offence. Your notes, logs, and documented research projects are, practically speaking, your best evidence of lawful purpose.
A sane first setup
Start with a device that exposes everything through open-source firmware (Bruce is the usual choice) so you can read exactly what each radio does. Learn the capture-and-analyse workflow before anything transmit-heavy: a good first month is entirely passive — capture, decode, understand. Keep a lab notebook. Test your own doorbell. Read the ACMA (or your regulator's) low-power device class rules; they're short documents.
Why we build these the way we do
Every StealthOz deck ships with upstream open-source firmware from pinned Git tags, verifiable via SHA-256 against a signed manifest. That's not just a supply-chain guarantee — it's a lawful-use affordance. When the software is inspectable, the boundary between "audit tool" and "attack tool" is visible in the code, and your use of the device can be explained by what you chose to run.
These are general-purpose research tools. They don't come with permission to break the law, and they don't need to: the interesting, publishable, career-building work in RF security is overwhelmingly done against your own hardware. Stay there and this hobby stays legal.