Flipper Zero – Portable Multi-Tool Device for Geeks
flipperzero.one
flipperzero.one
What is also amazing is the community, there are already custom firmware, extension and guides
You can find a list here: https://github.com/djsime1/awesome-flipperzero
If you're familiar with arduino/esp* programming, you can get the components (eg. esp32, cc1101, nfc reader, and infrared transciever) for a lot cheaper on aliexpress or your local reseller, and all of those things are in stock.
(or in other words, if you're one of those people who buy stuff like this, play with it for 2 minutes and then put it in a drawer, and now you're in the middle of thinking about how you could open your neighbours garage to mess with them... well, you can do it chaper)
This device lowers the entry barrier into hardware for software people.
We need MORE flipper zero type projects!
This goes for every facet of the economy and is called 'specialization'. :)
> I realize it's internet fun to point neon arrows at people seeming outrageously wrong in the past, but the truth is that people aren't reading that comment accurately and there's a huge dose of hindsight fallacy here.
The full comment by dang has more context: https://news.ycombinator.com/item?id=27067281
People make fun of this post on account of Dropbox having been a commercial success, but the first points are still valid (and even more true today, with modern tooling) that FOSS self-hosted solutions are far better, more flexible, and serve as a learning/building opportunity - something the 2022 world of vendor lock-in, dumbed-down "user friendly" solutions, and vast data collection sorely needs more of.
> without charging users for the service, is it reasonable to expect to make money off of this?
Dropbox was initially pitched as a free service, which was absolutely not sustainable, and someone would have been right to be very skeptical about the underlying business model. People might not have been quite as enthusiastic if they'd said from the beginning "oh, and it'll be $100/year for the rest of your life, or until you get your shit together and move your data elsewhere".
The relevant bit to this is the “quite trivially” do X, Y, and Z non trivial thing.
Technical people often underestimate the value of good UX, generally there’s a lot of demand for it. That’s also where a lot of the value is in making something good. He also acknowledges as much in his reply to Drew.
In this case the “main benefit” of the flipper being ease of use, software, and hardware vs. some random components off of Ali express just reminds me of that.
This is like the usual flame war about macbooks vs everything else.
https://create.arduino.cc/projecthub/mike-murray2/homemade-t...
If you want to open garage doors, you just need a cc1101 and an esp8266
https://github.com/gusgorman402/RFmoggy
If you want to clone rfid cards, you need one of the cheap readers, an empty card an an arduino
https://github.com/miguelbalboa/rfid/blob/master/examples/RF...
Yes, it's ugly, but it's cheap.
More than a nice hacking tool, this is a pollution and waste of resources tool. There is nothing positive about that.
"It's hard to believe, but lots of kids today ONLY know how to buy prepackaged molecules."
You're right that one could put most of the functionality together, but not in a package that you're gonna toss in your pocket for EDC.
I'm curious to know what it would take to hack my garage door or key fob for my car
New building opens up, vendor screws up and the control panel in stall #1 is programmed to control the Washlet in stall #2. Cue the predictable (and hilarious) email thread on #<building>-misc, along with a whole lot of memes.
"Read RAW" does exactly what it says on the label: Captures a raw stream, based on the specified frequency and demodulation.
"Read" captures, decodes and attempts to interpret the signal capture. The FlipperZero has a large built in database of brands + models of RF devices, and a database of KeeLoq master keys.
For rolling remotes that are KeeLoq based, with known keys, the Flipper can most definitely decode / decrypt rolling codes, and generate the next in the sequence.
TL;DR: Handles fixed + Rolling codes, via built in database of keys + models.
I'm not convinced that there is a 'non destructive' method to find that out though.
There’s a pairing mode you put the car in and it accepts the new keyfob and probably records it’s seed / counter / etc at that point.
> The prototype of our character is the cyborg dolphin Jones from the story "Johnny Mnemonic" by William Gibson.
Seriously Keanu Reeves ins't a bad choice for a technological automaton representation, being Johnny Mnemonic and Neo and all. Though I guess dolphins in general are much more conciliatory on IPs, trademark and copyrights issues.
We need to put Keanu Reeves in the public domain!
I participated in the crowdfunding campaign and I must say it was one of the best run campaigns ever; the team was super transparent and took a lot of time communicating all the behind-the-scenes of developing the product; their updates were very interesting. Can’t wait to see what they do next.
If keys aren't found, you can perform a "Reader Attack" - take the nonces from the log during a sniffed authenticated exchange, place them in a MF32Key tool (there are online versions as well) - and this will calculate the key.
The device doesn't have enough computational power to crack on board (for that you need a Proxmark / iCopy-X) - but the team has roadmapped a tethered mode for performing these cracks.
It's also available on F-Droid: https://f-droid.org/en/packages/at.zweng.bankomatinfos2/
My front gate, my parents front gate, and any other front gate (check your local laws before doing this).
Controlling a lamp I have (works with any device I've tried that uses 433mhz)
Backup remote for my TV (the Flipper infrared UI is kinda clunky but it works)
Backing copies of NFC cards
And most importantly, you can use it to turn the pages during a PowerPoint presentation
Ah, so it's a business expense!
Once you know the frequency one option is to just take a raw sample at ____megahertz and play it back on demand. This doesn't work for some radio signals because they use rolling codes and it's also a bit inefficient (be VERY VERY careful using a Flipper with a car key fob, because they can sometimes go out of sync and you can't open your car afterwards)
The good news is, for many types of radio signals, the flipper can also determine the protocol and what digital data is being sent- so instead of playing back a 2 second sample of me holding down the "power" button on my lamp's remote, it knows it can just broadcast 0x1234 using protocol XYZ.
NFC and RFID devices are basically plug & play, although only a subset are supposed.
FYI many cars with "keyless" entry have a traditional keyhole hidden under a piece of trim around the door handle and a key (sometimes plastic) hidden inside the fob; sometimes the key is part of the ring for a keyring, and can be released by pressing on the manufacturer's logo or inserting a paperclip in a hole.
(Except for that suspiciously cheap gadget you got from AliExpress which shows up in the FCC database as an iPhone 4S...)
Remote door controls are painfully dumb and relied on the absence of affordable software-defined receivers and especially transmitters. With most of them you can set the code via binary DIP switches at the back and that's it. No replay protection, no nothing, if you're lucky the receiver has a brute-force detection.
There's a small group in the US that does this kind of thing: https://en.wikipedia.org/wiki/Grindhouse_Wetware
haven't explored anything else
> Low-frequency proximity cardsThis type of card is widely used in old access control systems around the world. It's pretty dumb, stores only an N-byte ID and has no authentication mechanism, allowing it to be read, cloned and emulated by anyone. A 125 kHz antenna is located on the bottom of Flipper — it can read EM-4100 and HID Prox cards, save them to memory to emulate later.
And
> Flipper Zero has a built-in NFC module (13.56 MHz). Along with the 125kHz module, it turns Flipper into an ultimate RFID device operating in both Low Frequency (LF) and High Frequency (HF) ranges. The NFC module supports all the major standards, such as NXP Mifare.
Curious to see what uses I can find for this, most likely it will end up in a drawer sooner rather than later, but I can see this be very useful on holidays ;)
Edit: According to their forums, "There are no US region (R02) flippers in stock at the moment."
https://forum.flipperzero.one/t/unable-to-place-order/4251/4
From the shop page:
Shipping in August 2022. Currently available only for: Andorra, Austria, Belarus, Belgium, Bosnia & Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, French Polynesia, Germany, Greece, Vatican City, Hungary, Iceland, Ireland, Italy, Kazakhstan, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey, United Kingdom
Yes I live in Switzerland but it's not at the edge or the world. Most have received theirs already but Swiss people had to wait a while...
I was confused by this until I saw you were Swiss. Then I realized it was just a bit of involuntary yodeling.
I've waited for 2.5 years, so what's a few weeks more =)
Hope you get it soon.
I can't even recount how many times I've wanted to order something, and not until the final step before doing the payment they put up a "Sorry, we only accept orders within the US & Canada".
Do these same fraudsters hit other EU online sites as much as they hit US based sites?
---
Shipping in August 2022. Currently available only for:
Andorra, Austria, Belarus, Belgium, Bosnia & Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, French Polynesia, Germany, Greece, Vatican City, Hungary, Iceland, Ireland, Italy, Kazakhstan, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey, United Kingdom
More countries coming in September.
The web is funny tho - an order page is just an order page - if it was built by a trillion dollar company or a startup barely paying rent - we go in with the same expectations.
Disclaimer: I know some of the employees at Flipper. And a few Russian backers who still didn't get their device.
For general hardware hacking I'd get a pirate bus ($30), and a saelae logic clone (cheap). Maybe a nice cheap oscilloscope (but they go for $300+), but logic clone can get you mostly there.
hantek handheld for 190.
At worst if you wanna try it out without spending so much money you can try out the bus pirate from dangerous prototypes it’s only ~27.
It's great for beginners as it has a huge and friendly community behind it and you can easily work your way up from beginner to more intermediate/advanced.
Next it's fun to mess with the screens at the pub.
Somewhere along the way, realizing that someone out there has the remote you lost long ago and all you really want is an on/off button and now you can get one.
For me so far it's a universal remote with a kind of weird interface.
There's good lectures out there, explaining the things you might not yet know and most of it is fun stuff to learn. Very much worth your time & effort. Hope you're fine with some advanced math concepts, though!
Such as what, out of curiosity?
LinkedIn indicates 15 of their 16 employees are based in Russia.
You aren't in control of your own net access?
> LinkedIn indicates 15 of their 16 employees are based in Russia.
What difference does it make? According to Linkedin I live in Falklands, that doesn't mean anything.
src: personally know the lead guy.
The support person astra on their web forums goes around telling people its illegal to discuss things involving TX'ing and capturing rolling codes of a keyfob. I can't tell if it's plain stupidity or gas lighting...
I hadn't actually written an original line of C code since the 1980s. After a couple evenings of following one of the tutorials, I was able to create some new functionality to a button that currently doesn't do anything.
At least one person on the Discord (Flipper Devices, I think) watches when someone mentions how they think it would be cool to make changes to the firmware, When that happens, they upload a PDF of the K&R book "The C Programming Language" to the chat.
e: it can read but can't yet emulate, given how niche it is outside of JP I doubt it'll ever support it.
Context: I have a flipper zero and have been thinking about testing for amateur radio licenses.
With this number of radios, does it need to be FCC certified?
As a side note, in some of the promo images, the battery gauge is at 52% (or 73%), yet its icon shows a full battery... I guess it's fixed in the real implementation.
Just simple things like copying a garage opener. I tried it a few times and couldn't work it out. I think It looks like I got it to capture something, but then nothing happens when I send it again. Makes me feel a bit dumb and haven't touched it since.
Garage Door openers aren't as easy as they sound. Try the infrared remotes first, you'll have better likelihood of doing something useful in a few minutes.
I encourage you go to this young man's main page and buy him a coffee (not me nor anyone I know, apparently I was the first person to actually use that button)
I found it interesting that their Careers/Jobs page is in Cyrillic. Flipper Devices is not looking for me. https://www.flipperdevices.com/jobs
That said, there was a post on Reddit of a EMT driver who used theirs to clone dozens of remotes that the ambulances need to open the gate to bring in a patient.
Update: Flipper says they'll be back in stock for US, Canada, and Australia in September but did not provide a mechanism for getting alerted when this happens.
And I agree, the build quality is really nice - just wish they sold the screen protector during the kickstarter - I have the silicon protector and wifi dev board but my LCD screen is scuffed from carrying it around in my pocket.
As I was writing this, it occurs to me that you could might be able to capture a bluetooth signal with one, sent it via radio to another that might not be in line of sight, then retransmit from another.
The limit on what you're thinking is that the devices inside this are NOT the latest and greatest.
Bought it anyway in the hope of someone more talented than me manages to make an expansion board :D
Looks weird, spends tons of time to promote the dolphin angle and the use cases are all shuffled together.
perhaps a different reward tier for the kickstarter? it was a massive success. if you check the comment / karma history for people saying they have them they're not fake accounts.
Later on, they had some sporadic availability, got my second one ordered and it has arrived in the last week or two.
So far it's mostly a clunky universal remote but I've started relearning C so that I can write firmware customizations.
You can also buy it in EU from an official reseller, with same day shipping depending on your location: https://lab401.com/products/flipper-zero
I dont know what happend with the shipping management, I hope I will receive my device soon.
It's open source and it was started on Kickstarter before even having a website.
Who? And what are they claiming. It does seem like flipper zero enables mischief but a honeypot?
I have used it successfully in the past to place and receive three different orders of flippers and accessories.
Can you point out even one?
I'd also like a citation.