Live data from Hacker News

Flipper Zero – Portable Multi-Tool Device for Geeks

flipperzero.one

221–230 of 267 posts

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#221

Just got mine a few days ago (EU based). Well built, works as promised. But I find that it mostly works for simple things like controlling lights, tv etc. Most interesting targets use proper encryption (mifare classic for example) so I had no luck accessing my company badge. Mifare Desire data cannot be read properly at the moment it seems, but I'm sure that will be fixed. Fun little tool, will probably end up in a d…

MIFARE Classic support is quite good : the device will search through its (somewhat exhaustive) list of known keys, to attempt to unlock your badge.

If keys aren't found, you can perform a "Reader Attack" - take the nonces from the log during a sniffed authenticated exchange, place them in a MF32Key tool (there are online versions as well) - and this will calculate the key.

The device doesn't have enough computational power to crack on board (for that you need a Proxmark / iCopy-X) - but the team has roadmapped a tethered mode for performing these cracks.

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#222

Cool piece of hardware, however their software TX lock is bullshit. They didn't claim development platform exemption with the fcc like with a hackrf, ettus, etc. Users are forced to use custom firmware to unlock the full potential of the hardware. The support person astra on their web forums goes around telling people its illegal to discuss things involving TX'ing and capturing rolling codes of a keyfob. I can't tell…

Their original firmware is open source? Or is custom firmware a hassle?

Everything is open source. For the GP, there are unrestricted FW releases as well.

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#223

I love how movies show hacking devices as super serious futuristic goggles the open 6 different terminals that patch you through sockets on satellites, but the best thing in real life is a dolphin tamagotchi.

Which in turn may be a reference to the time when a movie showed an actual dolphin as a hacking device: https://m.youtube.com/watch?v=F7OM59U4-z0

It's a reference to the story that inspired the movie.

> The prototype of our character is the cyborg dolphin Jones from the story "Johnny Mnemonic" by William Gibson.

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#224
post #219
post #193

Earlier quoted context omitted.

Hm, feels like I could have used this with my Gen 1 Phillips Hue, shouldn't have thrown that away I guess.

Weren't these already using ZigBee? Does anyone know whether the Flipper can handle those frequencies as well?

ZigBee, Thread and a few others use IEEE 802.15.4 which allows three bands: 868/915/2450 MHz. According to the FlipperZero homepage, it supports two out these three bands: 868 and 915 MHz. So depending on your device, it might work with them too.

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#225
post #176

Earlier quoted context omitted.

AND you can support small enterprises of people who did take the time to make something work well for you to hack around with. We need MORE flipper zero type projects!

the only way you get more flipper zero type projects is if some subset of people actually do the ordering from Ali Express...

The only way you get more such projects is if some people order from AliExpress and some people do not.

This goes for every facet of the economy and is called 'specialization'. :)

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#226
post #159

Earlier quoted context omitted.

I'm more concerned about why you would need a remote for something that depends on you being there...

From a security point of view, it sure makes for an interesting attack surface

You have to look out for backdooring though.

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#228
As a Kickstarter backer residing in Europe, I can say that the quality of the product has exceeded my expectations. In the meantime, I've been experimenting with different versions of the firmware and discovered that an attempt to clone my access badge did not succeed, most likely because of the additional security measures in place. The SD card I bought on my way to work necessitated a double-check.

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#229

As an aside, I'm curious about wireless hacking but don't know whether or not I possess the necessary expertise. Can someone with no prior knowledge of pen testing or wireless networks benefit from this?

Yes. But you'll have to learn a bit or two to make use of the more advanced stuff. It is indeed a great learning tool, as it offers almost everything you need to delve in.

There's good lectures out there, explaining the things you might not yet know and most of it is fun stuff to learn. Very much worth your time & effort. Hope you're fine with some advanced math concepts, though!

Re: Flipper Zero – Portable Multi-Tool Device for Geeks

#230

Cool piece of hardware, however their software TX lock is bullshit. They didn't claim development platform exemption with the fcc like with a hackrf, ettus, etc. Users are forced to use custom firmware to unlock the full potential of the hardware. The support person astra on their web forums goes around telling people its illegal to discuss things involving TX'ing and capturing rolling codes of a keyfob. I can't tell…

Its liability avoidance.
Post reply on HN