Live data from Hacker News

Trying Out Flipper Zero

twitter.com

31–40 of 109 posts

Re: Trying Out Flipper Zero

#31
post #28

People and companies that are attacking the device because it makes unlocking certain things easy should realize that the issues is not the device but the antiquated vehicles/door locking system that basically uses obscurity for it's security. If you can unlock your car with the flipper zero you can also do it with a ~100 USD SDR and an old laptop.

Honestly it's a bit of both in this situation : they are good RF protocols that are secure enough (e.g. Calypso has not been broken yet) but they are not used by vendors since the insecure version is "good enough". Now that Flipper Zero exists, they have to adapt. However, there is an ongoing discussion about offensive security tools such as Flipper Zero, IMSI-catchers, phishing frameworks, meterpreter lookalikes, et…

That "ongoing discussion" is largely a small group of extremely loud people in the defensive tooling space who keep getting clowned on that their expensive products don't work.

While the offensive side keeps innovating and improving, defense seems to have stopped bothering and instead is resorting to twitter trolling, pissing, and moaning.

Re: Trying Out Flipper Zero

#32
post #19

Hey @antirez, if you're in the comments here I have a little question. I see someone asked about availability, since it's currently Sold Out. How often did you hit the Store before a unit was available? And was it a really narrow window of availablility? I'm wondering if I should write a little script that'll fetch the page, check availability and send me a notification or whether I should just remember to check the…

There's new units on sale every week. Alternatively, buy a second-hand one.

Re: Trying Out Flipper Zero

#34
post #15
post #7

Are any more Flipper Zero units coming into the US? I heard that a shipment was seized a couple months ago, maybe due to national sanctions. (I have a Flipper Zero, but no time to play with it. Wondering whether I should sell it, or hold onto it because I won't be able to re-obtain one later.)

Mine was held up by the seizure. I got an email about it, but they were able get it out a month or so later. They were able to work around it, but I don’t recall the details. I think they had a blog post about it.

Mine was too. The seizure had more to do with the war (as the devices come from Russia and are explicitly labeled for hacking) - my package got to me fine, looks like it wasn’t tampered with or anything. I think business is as usual for the Flipper folks.

Re: Trying Out Flipper Zero

#35
post #28

People and companies that are attacking the device because it makes unlocking certain things easy should realize that the issues is not the device but the antiquated vehicles/door locking system that basically uses obscurity for it's security. If you can unlock your car with the flipper zero you can also do it with a ~100 USD SDR and an old laptop.

Honestly it's a bit of both in this situation : they are good RF protocols that are secure enough (e.g. Calypso has not been broken yet) but they are not used by vendors since the insecure version is "good enough". Now that Flipper Zero exists, they have to adapt. However, there is an ongoing discussion about offensive security tools such as Flipper Zero, IMSI-catchers, phishing frameworks, meterpreter lookalikes, et…

Responsible disclosure exists for serious exploits, and it sort of works.

Auto makers had ample time to learn that their current radio-operated locks are insecure by design. They had years while everybody even slightly interested knew e.g. how a replay attack can be done. Did they need any more responsible disclosure time in order to act?

BTW there's no need to radically invent anything in that space; say, SSH offers a working example of a tamper-proof, eavesdropping-proof establishment of a secure connection (after a secure initial pairing, expected between a key and the car anyway).

Re: Trying Out Flipper Zero

#36
post #25
post #23

Earlier quoted context omitted.

Yeah, I noticed it being available for a day or so a while back, but didn't click... :)

Sounds like we just need to check every day or so. Fingers crossed you manage to get one!

I’m speaking from 6 months ago. My hacker (vuln researcher) friend just convinced to buy one, I went to the store and bought one. Probably just an uptick in sales right now because of similar blog posts and the current HN hit.

Re: Trying Out Flipper Zero

#37
post #33

Honestly, this devices just misses a speaker and a microphone. It would make for the best phone ever.

But does it not have a BT radio to connect a hands-free set?

It might need a phonebook app though :)

Re: Trying Out Flipper Zero

#38
post #10

People and companies that are attacking the device because it makes unlocking certain things easy should realize that the issues is not the device but the antiquated vehicles/door locking system that basically uses obscurity for it's security. If you can unlock your car with the flipper zero you can also do it with a ~100 USD SDR and an old laptop.

Do those arguments really hold up though? I get that these devices are sort of the “messenger” in “don’t shoot the messenger”, but still. Security is about appropriate security. A general teenager or thief wanting to cause issues would not know what to do with an SDR and laptop, versus something like the Flipper making it point and click. So now that something is made so readily available, we need to increase the cos…

There are a bunch of semi-easy tools for lockpicking too and a good percentage of American locks are reeeally bad at thwarting even a novice picker. In worst cases you just need a flat piece of metal.

Too many fancy electronic locks can be bypassed with a single magnet placed correctly.

https://www.youtube.com/@lockpickinglawyer

These devices are the electronic equivalent of a lock-pick. They still need skill and intent to use, by itself they shouldn't be illegal. They should motivate companies to make proper security measures.

You can grab a $10 ESP32 and a battery pack, load some ready-made software on it and flood everything in a 50 meter radius with so many fake Wifi-APs most devices will go offline. Or you can deauth every wireless device within range.

The tech is available and doesn't require much skill to use.

Re: Trying Out Flipper Zero

#40
post #25

Earlier quoted context omitted.

Sounds like we just need to check every day or so. Fingers crossed you manage to get one!

I’m speaking from 6 months ago. My hacker (vuln researcher) friend just convinced to buy one, I went to the store and bought one. Probably just an uptick in sales right now because of similar blog posts and the current HN hit.

Ah I don't imagine there are any physical stores by me that would stock this. That said I did a google search for "flipper zero site:cz" and it seems there's sometimes second-hand ones listed on ebay-like sites, so that's an option.
Post reply on HN