Flipper Zero can spam nearby iPhones with Bluetooth pop-ups
techcrunch.com
techcrunch.com
At least for magnetic stripe keycards, you'd need actual physical access to the card for a second; with many contactless ones, a tap on somebody's wallet/pocket is enough.
Actually secure keycards only cost fractionally more; even classic Mifare (which has been thoroughly hacked) would offer better security than this.
Most keycards I've tested don't even register on my phone, meaning that they're using something pre-ISO-14443 (which very likely does not support any real cryptographic authentication).
I don't know what it's like globally, but around these parts it is way more common to encounter one of these "legacy" systems than any of the modern stuff. Many large campuses were early adopters of fob-based access and upgrades are prohibitively expensive.
One of my favourite attacks against the existing HID-card based systems is... once you scan a card, the 24-bit identifier is split between an 8-bit facility ID and a 16-bit card ID. If you encounter a door that won't open with the card you have, start decrementing the card ID; many of these places assigned card IDs sequentially and by trying smaller IDs you're trying cards for employees who have had longer tenure at the company.
Anthony must be the only person knowledgeable of analog electronics design on planet earth then. Security through ignorance.
The problem with this particular hack is (like with many others where flipper zero is mentioned) that you might just use some 10 BLE micro controller to achieve the same thing.
Usually the things that were glued together in the flipper are never used together for a complex use case. Not sure about what Apple does here, though, so I might be wrong.
Anyway, the cases where you can employ IR, BLE, RFID and the flipper's custom radio in some useful combination seem to be rare and it usually always seems to make more sense to list the needed components for the hack instead of giving some folks finally a (destructive) use case for their expensively acquired gadget.
Of course the idea of delivering the solution as software/declaratively is the interesting part. But applications are rare and seldom new (at some point replaying your old garage door might only deliver so much long term motivation)
But the main issue isn't the component cost, it's just how much I'd pay for something like this. Here in Spain it's a lot of money. It's as much as my current smartphone cost.
This is why I was hoping for clones :)
There is no security for these tags, so if you can speak to them you can write to them... thus if you had a flipper, one could erase/fake payload on the tag...
The problem is that one doesnt know what the tag data corresponds to in the inventory systems - so the worst one may do is scramble all the tags such that a valid reader would never be able to determine what was in the containers... and one could use a flipper on a drone to fly over a supply bulk of containers and render finding supplies via RFID impossible - or one could copy and paste data from crates, thus making all reads wrong....
You can be an arsehole with a megaphone too if you want, but please don't be an arsehole.
One is hardware-based Denial-of-Service, and the other is software-based?
We do live in a world where expecting people around you to not be arseholes is a reasonable strategy.
The only real difference here between this and people playing loud shitty music on their phones or whatever is that it's harder to locate the source.
Later I might take my "child mauler" (dog) on a walk.
For a site with "tech" in the name, I expect significantly better than this nonsense. Flipper Zero is a nice packaging of dev tools but nothing fundamentally new. If it makes the author feel better, we can repeat the attacks with a simple esp32 and save a whole bunch of money - though we'd lose out on the cute animations.
I think it’s fair to characterise it as a “hacking device”. As long as we keep in mind that these specialised devices have legitimate uses also.
> Thanks to a popular and relatively cheap hacking tool, hackers can spam your iPhone with annoying pop-ups
Because it seems to place blame (possibly unintentionally) on "a popular and relatively cheap hacking tool" rather than "an individual's choice to annoy the shit out of others".
I agree there are uses of the word hacker that don't mean to exploit, but the author here is not using the term in a positive sense. The author is clearly using it in the perjorative.