I built an encrypted BLE dongle for pasting stuff to air-gapped devices
Details
- External ID
- 48789152
- Source
- HN
- Company
- —
- Product
- I built an encrypted BLE dongle for pasting stuff to air-gapped devices
- Website domain
- github.com
- Launched
- July 4, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.1081242532855436
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Definitely one of those "20 minute adventure gone wrong" projects where all I wanted initially was a quick wireless rubber ducky for bitlocker keys and the like and then I kept adding stuff like AES-256.....Currently working on adding WebAuthn/FIDO support because the hardware is already there and scope creep is a lifestyle at this point.Would love feedback, especially on the security side. Repo and PCB files are fully open source.
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Hardware & robotics
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- encrypted ble dongle for air-gapped devices
- Manually corrected
- False
Could you build this?
No Creating custom physical BLE dongle hardware with encrypted air-gapped keystroke injection (BadUSB/HID) and WebAuthn/FIDO firmware demands custom PCB design, embedded C/Rust, and hardware cryptography.
What it would actually take: Building this device requires custom PCB design (KiCad), microcontroller selection (e.g., nRF52840 or ESP32-S3), and low-level firmware development in C or embedded Rust. The hard parts include USB HID stack emulation, Bluetooth Low Energy security pairing, AES-256-GCM hardware crypto integration, and implementing the FIDO2/WebAuthn CTAP2 protocol. This necessitates hardware engineering, embedded systems development, and hardware-level cryptographic expertise.
Discussion
6 comments analyzed.
Competitors mentioned: InputStick, ShareToInputStick (Android F-Droid app)
Concerns raised: AES key stored in browser IndexDB vulnerable to dumps, Password length leaked via keystroke-by-keystroke BLE packets, Missing replay attack protection, Lack of session-specific key negotiation, Insufficient documentation on security implementation
Feature requests: FIDO support, Argon2id password derivation instead of Argon2, Obfuscated packet sending with random padding, Per-session ECDH key negotiation, Commercial hardware assembly/sales option
Competitors
Other products that read as similar to this one — 175 launches clear the similarity bar, closest 8 shown.
Attention rank: #161 of 176 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 247 days after the earliest competitor.
- 8cryptdo · github · 2026-09-26 · 11 upvotes · similarity 0.50
- Ellipticc Drive · hn · 2025-10-30 · 21 upvotes · similarity 0.45
- Brute · github · 2026-09-18 · 8 upvotes · similarity 0.42
- List stuff to borrow for your people, anonymously · hn · 2026-08-12 · 5 upvotes · similarity 0.42
- Portable Secret · hn · 2026-02-26 · 5 upvotes · similarity 0.42
- CambiOS · hn · 2026-06-11 · 8 upvotes · similarity 0.42
- cve-2026-41940-PoC · github · 2026-09-16 · 528 upvotes · similarity 0.41
- Sidebar · hn · 2026-08-07 · 16 upvotes · similarity 0.41
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a hardware & robotics tool for Horizontal yet.