Live data from Hacker News

Trying Out Flipper Zero

twitter.com

71–80 of 109 posts

Re: Trying Out Flipper Zero

#71
post #49

Earlier quoted context omitted.

> everyone installs pick resistant locks instead of cheaper alternatives. What geographic area? In the northeast US I've noticed that the cheap, easy to pick locks seem to dominate.

How would you even tell? Is there some kind of independent certification of pick resistance? Of course all lock companies will say that their lock is secure.

> How would you even tell?

It’s pretty easy to tell if you know what you’re looking for. Most reputable quality pick resistant locks use a different style key or are a specific identifiable brand.

Re: Trying Out Flipper Zero

#73

Earlier quoted context omitted.

All the car locks can be opened by force using hammer, and in theory it should be equally illegal to force open as to use flipper. But in practice it gives plausible deniability if say a kid could use a toy like thing with some script downloaded from internet versus a guy breaking car window. Flipper kind of looks like a learning tool used for hacking, while SDR method seems like hacking tool that could be used for l…

[flagged]

A bit aggressively stated, but I agree with your overall point. Every few years, a piece of tech comes along and clobbers older tech. This is how security improves.

Also, in the write context, it is already illegal to send raw TCP packets. Laws around port scanning are pretty ambiguously defined, and inconsistent across states. While generally harmless, a poorly placed SYN can get you in some serious trouble.

Re: Trying Out Flipper Zero

#74
post #49

Earlier quoted context omitted.

> everyone installs pick resistant locks instead of cheaper alternatives. What geographic area? In the northeast US I've noticed that the cheap, easy to pick locks seem to dominate.

How would you even tell? Is there some kind of independent certification of pick resistance? Of course all lock companies will say that their lock is secure.

You're thinking too hard. Most locks aren't anything more complicated than a simple pin and tumbler setup, so anything more than that is more secure. Who cares if a Schlage Primus key is better or worse than some medico lock, you've successfully made it more annoying to break into your house/office/warehouse.

Re: Trying Out Flipper Zero

#75
post #69

Earlier quoted context omitted.

if your security model can't stand up to teenagers with plenty of time, it might be time to reconsider it.

I was more addressing the idea that the Flipper device, while cool, seems to stand to do more harm than good by making its functionality so readily available to a wide class of people. Yes, it is generally a good idea to not oversupply teenagers with things that do things they otherwise couldn't but do harm. Cars are trivially broken into. Increasing the safety of the locking mechanism would do some good but not prev…

> There is a lot of security that relies on things simply being inconvenient.

Remember how in the mid-00s it was pretty trivial for any nerd with a Linux laptop to sniff traffic on a WiFi network and intercept passwords? For years the security-aware community was making a point of this, but major web sites just kept using unencrypted HTTP for their logins and such.

Then someone released a Firefox extension which made it literally point and click for almost anyone on any OS to capture and reuse passwords over the air. Suddenly it went from trivial for nerds with the right tools and a bit of training to trivial for anyone who wants to try, and very soon after that we started seeing the "HTTPS Everywhere" movement explode in popularity, sites like Facebook locking down at least their login endpoints if not the entire site to only work over HTTPS, etc.

Insecure communication was always a problem, but it took the combination of popularity of WiFi and point-and-click tools to make the world care enough for the problems to get solved. Until that happened, those with the ability to solve it didn't care enough because it didn't impact their bottom line because not enough of their customers cared.

Re: Trying Out Flipper Zero

#76

Earlier quoted context omitted.

> tons of tech now relies on radio garbage for no reason, especially car keys. I'm curious what you mean by "radio garbage" and "for no reason."

For instance, car keys.

I'm confused about the "for no reason" part then. I get a lot of value from not having to physically approach my car and use a key to unlock or start it.

Re: Trying Out Flipper Zero

#77
This is a brilliant wrap up, but the real gem is the accompanying app ProtoView.

> "The secondary goal of ProtoView is to provide a somewhat-documented application for the Flipper [...] ."

Having a well-documented, not too complicated and somewhat canonical beginner application is so important.

Re: Trying Out Flipper Zero

#78
post #10

People and companies that are attacking the device because it makes unlocking certain things easy should realize that the issues is not the device but the antiquated vehicles/door locking system that basically uses obscurity for it's security. If you can unlock your car with the flipper zero you can also do it with a ~100 USD SDR and an old laptop.

Do those arguments really hold up though? I get that these devices are sort of the “messenger” in “don’t shoot the messenger”, but still. Security is about appropriate security. A general teenager or thief wanting to cause issues would not know what to do with an SDR and laptop, versus something like the Flipper making it point and click. So now that something is made so readily available, we need to increase the cos…

> A general teenager or thief wanting to cause issues would not know what to do with an SDR and laptop, versus something like the Flipper making it point and click.

This is where the story falls apart. I own both a HackRF One and a Flipper. I thought it would be a great teaching tool for my kids to show them physical world insecurities. While it's a great device it's nowhere near as potent as the HackRF as a real tool. And straight out of the box the Flipper does very little from a nefarious point of view.

The "influencers" did a great job of hyping it up on YouTube and Twitter. And my guess is that the majority of the devices sold will be used to pop Tesla charge port doors for giggles. I've gone through a few different firmware and repos and you've got to have just as much interest to learn and use compared with an SDR. And in fact in many cases the Flipper is harder to use because it's limited by its physical footprint.

It's a fun little tool but it's not making much "point and click" besides a handful of known replay attacks that shouldn't have existed in the first place. If anything I hope the Flipper pushes the likes of physical access systems manufacturers / integrators to be questioned on why their systems fail to authorize access correctly against trivial attacks. This is not the fault of tools like Flipper.

Re: Trying Out Flipper Zero

#79
I have never seen a tool that really does so little out of the box (notice most people only talk about cloning IR remotes) be worried over so much. SDR, key relay and other radio based attacks were happening before flipper and will continue.

Anyone who wants to do real harm with flipper will have to learn a lot, and when they do flipper won't be the tool they stick with. It is limited compared to something like hackrf.

Criminals can buy all kinds of turnkey kits to do crime, flipper isn't one of them.

Re: Trying Out Flipper Zero

#80
post #15
post #7

Are any more Flipper Zero units coming into the US? I heard that a shipment was seized a couple months ago, maybe due to national sanctions. (I have a Flipper Zero, but no time to play with it. Wondering whether I should sell it, or hold onto it because I won't be able to re-obtain one later.)

Mine was held up by the seizure. I got an email about it, but they were able get it out a month or so later. They were able to work around it, but I don’t recall the details. I think they had a blog post about it.

I purchased two of them, recently. I bought one in December from an authorized reseller and received it within 2 weeks. Ordered another one direct from the official Flipper website in late December as a gift and received that one within 1 week. They're easy to get at this point.
Post reply on HN