N.O.V.A. is a proof-of-concept prototype built for educational and portfolio purposes. It is not a production security system. Please read the limitations below before using any part of this system in a real access control deployment.
The following are documented, understood limitations of the current prototype:
| Limitation | Severity | Production Mitigation |
|---|---|---|
| NFC UID cloning trivially bypasses NFC factor | High | MIFARE DeSFire EV2 mutual authentication |
| Optical channel is vulnerable to replay attacks | High | TOTP-based rolling frequency keys |
| NFC UIDs stored in firmware plaintext | Medium | NVS encrypted key storage |
| Only 3 optical frequencies (brute-force surface) | Medium | Expanded frequency space with encoding |
| No failed-attempt rate limiting beyond a fixed delay | Low | Exponential backoff with alarm |
For a detailed threat model, see docs/SECURITY_MODEL.md.
If you identify a security issue in this repository's code:
- Do not open a public GitHub issue. Use private disclosure.
- Email the repository owner directly (see GitHub profile).
- Provide: description, steps to reproduce, and potential impact.
- Allow 14 days for a response before public disclosure.
Security issues in the Edge Impulse generated library should be reported to Edge Impulse directly.
| Version | Supported |
|---|---|
| v1.0.x (when released) | ✅ Yes |
| v0.x.x (pre-release) | ❌ No — prototype only |