The tech used here is the popular Flipper Zero, an ethical hacker’s swiss army knife, capable of all sorts of things such as WiFi attacks or emulating NFC tags. Now, 404 Media has found an underground trade where much shadier hackers sell extra software and patches for the Flipper Zero to unlock all manner of cars, including models popular in the U.S. The hackers say the tool can be used against Ford, Audi, Volkswagen, Subaru, Hyundai, Kia, and several other brands, including sometimes dozens of specific vehicle models, with no easy fix from car manufacturers.
Weren’t Kia Boys stealing cars with literally just a USB cable since it physically fit to turn the ignition behind the key cylinder?
That doesn’t require buying a special device, it was mostly crimes of convenience. I doubt the Flipper Zero will ever get that widespread.If you can hack a car with a flipper zero, then the car manufacturers failed to implement the most basic security protocols. Complain to them, and demand a fix.
Fucking real! My car (2016 Toyota Avalon) uses a rolling code for the transponder! It’s like one of the most basic things any manufacturer can do to avoid this shit! And it can’t be more than a few dozen lines of code (I’m no expert so this may be an exaggeration)?
It is almost like their should be something written down somewhere. Like a guideline or rule or something…
Oh that is right, it is called a regulation requiring basic wireless security for extremely expensive consumer items.
Nope can’t do that.
Won’t someone think of the multi billion dollar corporations‽
It is true that this device can be used nefariously. But it’s just a computer with a wide variety of very basic and common communication methods along with software to exploit them. There are many other computers like it that are just less popular. And to ban it is to ban said basic communication hardware like radio, WiFi, NFC, etc.
The solution is to mandate companies to provide a minimum level of security. Even giant companies with good reputations have giant security holes, like Apple or your bank, implementing mandatory SMS as 2FA. That shit should be illegal.
Fear of the Flipper Zero is fear of people having direct control of consumer grade radio hardware. “You can’t let people have universal TV remotes, what if they push the buttons?!”
The people who write the laws specifically like that exploit.
Huh?
SMS 2fa. The feds love that shit and would never let a law requiring something better to pass.
Oh, haha, I bet.
Oh, you sound so optimistic, my bank has a mandatory 4 digit code as login with 2fa sms for new devices. I sometimes consider going to shoot the cto there but I don’t own a gun.
You can’t switch banks?
Or buy a gun?
The real issue here is that the systems that car manufacturers use for their vehicles are insecure and outdated. The Flipper Zero is just exposing their bad design decisions.
“We’re seeing an increase in new care purchases” “What changed?” “We made them super easy to steal”
And here I am just using my flipper zero to turn my fan on and off since the remote that came with it sucks.
Using NFC amibo codes for freebies in switch Zelda
Same. This whole time I could be driving a new car each day. What a waste.
I use it at work to clone a customer’s proximity card when I work in their building so they don’t have to leave me theirs to get around. The one legitimate use I found.
I guess being able to trigger the customer service announcement without having to find a button in a store is nice.
That’s … not a legitimate use.
That’s the definition of a legitimate use.
Cloning keycards temporarily with permission (until new ones are made.) Breaking into your own or a friend’s car because the keys were left inside (until you get the keys back)
Cloning a TV remote just to lower the volume to a sane degree and turn it off (until they get a new TV, remote or find the old one).
Legitimate is a anything that you’re allowed to do. It’s a simple process to test legitimacy:
Did someone ask you if you can help?
If yes, did you tell them what you’d do?
If yes, did they agree?
And once you did whatever it was they agreed to, did you keep your ability to do the same thing in the aim of doing something they didn’t consent to (once you cloned their car key, do you plan on stealing the car? Or once you cloned their remote, do you have an insatiable urge to fuck with them by abusing the remote?)
If you answer “yes” to all except the last one, the use is legitimate in 99.9% of cases.
The only reason this may be considered a non-legitimate use would be if you attached the exclusive economic right of making repairs or new keys to the OEM, which isn’t how a sane world works.
<hr>
And besides, tools like the Flipper truly are hacking tools. Today hacking has a bad rep, and the word used to mean more like hack something together.
Imagine Bob who is a DIY type of guy. His TV starts falling apart because the plastic casing broke. Bob takes some duct tape and glues the casing together. As the TV stand is also a bit wonky, he takes some screws as well just to be safe. He doesn’t plan on keeping it for too long, just until he can find a fitting replacement that’s not too expensive. Most likely, he’s bound to keep it until the next Black Friday.
Bob just successfully hacked something up to keep his TV from falling apart.
That’s the origin of the word “hacking”. “To hack up” got shortened by attaching a new meaning to the verb, without bothering with the entire phrase, and making it relate only to electronic/digital hacking. So the TV example isn’t hacking, but it is hacking up. It means “to make some temporary fix until a proper one isn’t found”.
Today, hacking has been conflated with exploiting and breaking digital locks, which is not what the original phrase meant.
That’s probably debatable, if they have permission. They probably shouldn’t have been given permission, but that’s a separate issue
Ideally, there should be a visitor card available to be used, with its clearances configured as appropriate for the visitor in question. Having a person hand over their own card (and PIN, if applicable) isn’t a great idea either, but it’s far better than copying that card, with or without permission (probably without, if we’re being honest).
Oh, absolutely. It’s not something which should be encouraged, and against a well designed modern system it probably isn’t possible (there must be some challenge-response type NFC systems on the market).
I’m just saying it isn’t unambiguously “illegitimate”
there must be some challenge-response type NFC systems on the market
There are. Hotels use them for door key cards so they can’t be cloned.
Unfortunately… I was trying to clone a room key to my phone so I could just tap to enter when I stay 10 weeks in the same room.
I usually do it when we take over a customer’s access control system and we we have half their doors on the new system and half in the old still and are migrating them over. I’m an electronic security tech, this is what I do for a living.
le·git·i·mate adjective /ləˈjidəmət/
- conforming to the law or to rules.
“Do what thou wilt shall be the whole of the law” - Aleister Crowley
seems legit to me…
If you’re using Crowley to support what’s legitimate, you’re gonna have problems.
that’s the only thing i use from him…
You don’t do sex rituals to summon the antichrist? Lame.
Oh I think I used it to unlock some extra characters in Skylanders at some point too, but I don’t really play those types of games anymore.
I like to hijack the robot vacuum when I go to DnD and ring my parents doorbell when I visit.
I’m fond of skipping Kid Rock songs on the local dive bar’s touchtunes.
I would let all the power go to my head with that one. Not that I go outside, let alone to bars.
Sometimes you gotta do what you gotta do, unless you want to hear Kid Rock butcher Sweet Home Alabama (which itself butchered Werewolves of London, and was only still good because you can hear Van Zandt drop his donuts, goddamn, in the back of the track) for the fourth time tonight.
I tried deciphering this sentence with Dungeons’n’Dragons and Do Not Disturb and neither makes sense
The physical IRL location where I show up to play Dungeons n Dragons, and not in game. DM’s got a robot vacuum.
You can get devices that connect to home assistant for that too! (Just a comment, not a suggestion that you are doing anything wrong.)
deleted by creator
I do the same with mine. 😜
Thought cars were bad, not sure many people have an understanding of how our emergency broadcasts and alerts work. US needs some huge infrastructure updates.
Can you be more specific? It’s not like you’re the first person to think about the nefarious uses of emergency alerts.
I dont want to be too specific, there is a reason, I work with radio infrastructure quite a bit. A lot of these systems hide behind obscurity alone. Not great against national actors that may want to do harm.
Wow yes you’re very smart for knowing that unencrypted radio is unencrypted.
To be clear, the flipper is just a Girl Tech IM-me with an NFC chip. If it lets people do a thing, that thing has been possible for decades. Just wait until someone makes a popular device based on a cheap fully featured wideband SDR like the AD9363 or LMS7002. Shit is gonna get fucking wild.
It’s like how people think the Raspberry Pi is the only single board computer.
Lol yeah a very cheap rtlsdr with a chip for transmission can do the same as a flipper. Flipper just makes it easy.
I kinda want to see if this would work on my car since the proximity detection of the keyfob only works about half the time anyway.
Securtiy by dysfunction!
Really? I see these fairly often on local fb marketplace. I was tempted out of curiosity to get one but I dont have a use outside of mucking about.
outside of mucking about.
The best use case of all.
They don’t really have many legitimate, practical uses for most people. They’re ideal for pentesters.
Prentending to be hackerman is a legit usecase IMHO. They do seem like fun, but I personally can’t justify the cost.
I would definitely play with one if I had one
Yes let me stalk someone to steal their car temporarily. Honestly this thing is kinda a toy on par with my rooted LG V20 with its IR blaster and USB C port that I can plug anything into or my HP stream with a software defined radio I played around with. These people are kinda making software for the wrong type of devices to be frank with ya and I cannot wait until someone makes some weird app and USB C dongle for an android phone to replace the Flipper Zero with. You don’t even need to have root access for this as apps can just take over the USB port anyway on your phone.
I think you’re missing the point this article is trying to make… It’s not an advertisement for Flipper Zero, it’s a scare piece implying the devices’ existence is bad
SDR devices with usb support and controlled by android apps is very much already a thing.
Yeah exactly no root access required.