Flipper Zero: Multi-Tool Device for Geeks
flipperzero.one
flipperzero.one
One thing people don't realize is that the custom firmware [0] that you can run allows you to receive and transmit on a wide range of frequencies under 1Ghz. Lots of things use that range (garage doors, gates, fan remotes, etc.) and are not very secure. I think that this will be a time looked back on where it's possible to interact with those devices without having to buy a custom PCB transmitter or somewhat expensive and complex SDR.
Plently of phones still do [0]. I've configured mine to operate all my devices at home.
[0] https://www.gsmarena.com/results.php3?nYearMin=2023&chkInfra...
OnePlus is the only brand on that list that makes sense buying in the US.
(Personally I can see why the IR blaster was removed as a feature in US phones. I can’t think of a time I wanted or needed it. How often are y’all losing remotes? My current remote doesn’t even really use IR for anything since the streaming box is controlled by Bluetooth and connected devices including the sound system are controlled by HDMI-CEC. My phone already controls the entire setup via a remote app that utilizes WiFi/Bluetooth).
Edit: I had only search and one did appear: https://www.amazon.com/PUCK-Smart-Universal-Remote-Model/dp/...
I don’t think that’s as accurate today as it used to be.
On the hardware side there are tons of options very cheaply available - iirc the flipper uses the c1100 (or a number like that) it’s a popular cheap chip and it’s well documented and interfaces easily with arduino.
More accessibly, lime mini SDRs are cheap but there’s quite a few alternatives too.
On the software side GNU Radio is free with decent tutorials - we’re not talking anything like blender levels of difficulty to adopt even if it is a complex domain.
Although on the more accessible side, urh is incredibly powerful given how easy to use it is https://github.com/jopohl/urh
I used the latter to tap into a 2 channel wireless bbq thermometer via a $10 rtl sdr and that was a breeze, an absolute walk in the park compared to when I reverse engineered the flysky telemetry system.
Or worse, vendors will use it as an excuse to make their products cloud-dependent, with strong cryptographic auth and actual processing done on the other side of the world.
(And with that enabling the rent seekers their recurring revenue, we arrive at the reality foretold by IIRC Philip K. Dick, where you have to subscribe to your own apartment doors.)
(EDIT: the more IoT embraces actual security, the more I feel that US gov had a point in classifying cryptography as munition. Perhaps there ought to be legal limits on using crypto against other people.)
Also, while I like the RTL-SDR (and the price tag!), you can't transmit with it. While this isn't a deal breaker to everyone, if you'd like to clone a garage door remote, for example, you need to be able to transmit. While you could use something like a raspberry pi and rpix [0], but I think it is more work than it's worth for many. Also, multiple RTL-SDRs are required for higher bandwidth applications like ASTC TV or trunked radios.
With the flipper, I think the main draw for most is the point-click-done nature. Include the Android/iOS app and it makes it easy to configure on the go without a computer. The expandability is one of the main feature that will increase adoption over time compared to the HackRF+PortaPack which, from what I saw in the past, lacked longer-term support and regular updates and new features.
A reason why I have switched to NiMH rechargables. They leak less often. I've also grown tired of recycling spent alkaline batteries. Also Energizer has no leak guarantee on some of their batteries. I've got the green ones, Recharge Universal.
https://www.energizer.com/about-batteries/no-leaks-guarantee
Using it as a remote seems so cool, esp bc I lost my roku remote not so long ago so if you have any resources that could help I'd appreciate it.
The documentation I've seen so far seems far and scattered and it seems people are more scared of being implicit in illegal activities based on their resources.
I've had good luck with the basic universal remote when I'm in a pinch. Also, you can create custom IR files, but it can be a pain with encoding. The flipper forums are a good resource too [1].
[1] https://forum.flipper.net/t/is-possible-to-convert-irplus-fi...
https://en.wikipedia.org/wiki/Rolling_code I didn't know this wasn't secure enough. I thought this was the basis of most modern vehicle keyless entry too?
It is hard for me to not think of the Flipper Zero as a script-kiddie tool to do super illegal things like open your neighbor's garage illegally.
Also, are attacks like this real/common/easy to pull off? https://youtu.be/1SUGf6OwRzw Where the signal is amplified from the key inside the house to the car. How does the car/keyfob not detect it's signal/noise ratio or time for roundtrip is all messed up distance wise?
For the amplification attacks, my understanding of them is that the key fob and car may be able to detect this kind of attack, but require more logic/software to do so. Also, most of these attacks use high frequency 'backhaul' wireless networks (key fob at 3-400Mhz, backhaul at 2.4-5 Ghz Wifi with lower latency) to prevent such timing/signal-noise from being detected. If I had to guess, most key fobs/cars are more focused on making sure the key fob works at range or in hard-to-detect environments and not focused on preventing such relay/amplification attacks.
Also, some similar attacks to what you linked could also be done against Bluetooth (I think Tesla had this issue in the past few years) with a simple Bluetooth range extender/relay setup.
(Note: without one of those devices, most of this is just guesses/what I've seen is possible/theoretical in terms of attacks)
I done a worse "hacking" actions when I was 12 and I were grounded without any access to any electronic device outside TV at lunch/dinner
I'm guessing not.
No matter how you paint it, this was probably rather excessive on the part of the police.
Looks like they still can call the “emergency” given the police was there after.
When I was a teacher some time ago some kids did a dumb things as well – they "hacked" schools' computers by putting some really sticky putty under keyboard keys. I wasn't allowed to punish these kids by ordering to clean it after themselves and parents agreed to pay for a new keyboards after weeks of "discussions" with lawyers involved.
For other readers, I’d be curious the jurisdiction.
The specific app that can turn off iPhones requires the “unleashed” firmware I believe.
Also, regarding legality, if you are DoSing cell phones, you are creating a hazard where users are no longer able to contact emergency services, and this is the most likely avenue of charges, as opposed to FCC fines (if in USA) for using locked spectrums.
This is why attempted murder, kidnapping, etc is a charge. We do not yet have a charge of "attempted mass personal device disablement". and there is no reasonable case for......"manslaughter" of a device.
Being "realistic"/less analagous; Your mobile device is the most important inanimate object to you in every single category imaginable. And this is the case for most of humanity for some time now. If someone knowingly removed my access to my personal device maliciously, I would suddenly start caring very much about seeing that persons freedoms taken away.
Edit: after rambling I wanna reiterate my first bit....intent is 99 percent. In this case, it's a kid. The law has context, and I think they should of course be lenient.
The kid should be told not to do it again. And no law enforcement should have ever been involved in the first place. Otherwise we are teaching those children to distrust authorities, that authorities are unjust and unfair. Thus undermining the rule of law.
All their classmates are also involved and watching the outcome of the situation. Some might end up seeing the "system" as being unfair and are not going to think twice before stealing or committing some other crime, e.g. fraud.
What do teachers use their phones for during class that they would have noticed this?
Genuinely intrigued as you never caught a teacher on their mobile phone in class when I was in school.
In the words of Governor William J La Petomane, one of Mel Brooks' characters from Blazing Saddles, "We have to keep our phony baloney jobs gentlemen!"
I wouldn't be surprised nowadays they would just start a rumor about the teacher's sexual misconduct or grooming of the students, in response, instead. And the accusation could spread and escalate, completely destroying the life of the teacher.
A certain percentage of the population will just make stuff up if they have the opportunity to do so, and "juicy" gossip can spread virally. So if they ask for "witnesses" to come forward, they will. Sex offenders are hated so much in society, they get beaten and abused in prison all the time, so it's essentially torture in the end.
One cool thing is that you can talk to it serially. I pretty quickly had it organized with an IoT temperature sensor so that it could send commands to my ceiling fan given the temperature in my office.
I have also used it to capture the NFC code on a hotel card key so that I could still get into my room even after my key was inevitably "damaged" by nearness to other fields.
Some parts of it are silly, like the Tomagachi type game with the dolphin. Doesn't add value for me, but I can see how it might be something for someone.
There is also growing awareness with agencies about its flexibility, some apocryphal stories of them being confiscated by TSA checkpoints have come in.
Writing your own apps for them has a fairly high learning curve.
The device itself is fantastic though. Gives me some real Pebble vibes in all of the best ways. It’s very hackable and even though I don’t do crazy pentest things with it, it’s just an overall fun device.
I do have one, I think it’s a fun thing to have in my bag, but haven’t had any luck finding forums of responsible adults, or even just adults, discussing development or things to do with it. Even the “adults” who post about it inevitably do something like get fired because they take it to work and try to clone their own badges and the enter their work with the flipper.
Sorry for the rant.
... But after owning one? I dunno. It's a neat gadget but to be honest about the only practical thing I've got out of it is cloning our apartment keyfobs and duplicating hotel cardkeys. Otherwise it's kinda fun opening up tesla charge doors and messing with iphones using Bluetooth LE. Somebody somewhere was starting a project to add CANbus support, which would be a perfect fit for the device.
I feel like the ecosystem needs a better way to add "apps" to the device. I might be missing something but it doesn't really have any official app registry or anything. Something like you'd see for npm, pypi, or platformio.
A large volume of the stuff you can do with it is just spoofing a USB keyboard and running console commands. You could do that for years with tons of existing microcontrollers the price of a hotdog, but suddenly script kiddies have taken notice and are willing to pay 100x for the ability.
It quickly became pal of the child.
Friend told that is one in top 5 toys of the child now :)
I hope this pushes more manufacturers to switch to rolling-code algorithms (like the key fob your car uses), in place of simpler, less secure codes that can be captured and replayed.
In the 90s my brother had a portable TV/Radio which we managed to tune into cellphone conversations.
Those were the days you could still telnet 25 to send emails with whatever sender you wanted. I used to send Christmas greetings from Santa to my colleagues at uni.
Did it?
IIRC, the biggest thing to fall out of that is the US government banned scanners that could pick up the frequencies commonly used by cordless phones.
I recall that. I think the age of SDR's made such a ban (law?) almost impossible to enforce.
OP stated the existence of SDRs now would render such a (new) ban (on scanners) wouldn't work.
Being an elementary aged student poking around, I realized I could use the tuner to listen in to telephone calls somehow. Granted, I lived on a farm and there were probably only two dozen houses within a mile radius of our home; the nearest being a quarter mile away. I had a small rabbit ear antenna on the back of my CRT TV that could have been plugged into the VCR.
I don't recall the actual hardware I had.
I never figured out if I was listening to cordless phones (seems they would not be powerful enough to reach me), cell phone signals (there were few cell phones in my poor rural community I assume but I guess there could have been travelers on a nearby highway), or CB radio signals from truckers on the highway (these seemed like mundane person to person conversations; not trucker conversations). Perhaps it could have been long distance HAM operators though they didn't seem to use any HAM protocols while speaking.
[1]: https://www.telecomtrainer.com/amps-cellular/
[2]: https://en.m.wikipedia.org/wiki/Pan-American_television_freq...
Flipper Zero can be used to crash iPhones running iOS 17
https://news.ycombinator.com/item?id=37919396
Apple Shuts Down Flipper Zero's Ability to Shut Down iPhones
https://news.ycombinator.com/item?id=38656607
Flipper Zero banned by Amazon for being a ‘card skimming device’
https://news.ycombinator.com/item?id=35481580
UK airport confiscates passenger's Flipper Zero
But it's also from Twitter so take it with a grain of salt.
An investment in something like HackRF+PortaPack clone is far better, IMHO.
Most people don't need a full SDR like a HackRF in order to explore their RF devices and a Flipper gives that too them without the headache of software and the bulk of a full PortaPack.
(I love my HackRF and PortaPack for the record. The Flipper can't complete with the features and low-level access when you need it)
[0] https://hackaday.com/2015/06/08/hacking-the-im-me-to-open-ga...
It's a decent multitool. :-)
- Cloning weird ceiling fans/lights. Apparently I've bought horrible remotes but this helped.
- Used this as a nightstand clock while traveling.
- Used the authenticator app as a backup Yubi key
- Mouse jiggler to keep a computer awake
- blasting tvs at restaurants is a ton of fun and my kids like that.
- And the IR functionality for Nerf Laser Ops Pro (IR laser tag) is an absolute blast - the actual Nerf guns have a delayed trigger, but with Flipper there is no delay or need to "reload" so you are an unstoppable beast.
You can likely still buy those "every TV" $5 power/volume remotes that fit on a keychain, if they're asking for their own.
I'm not an expert at NFC but after playing around with Flipper I've learned that there are different types of NFC devices and they aren't at all interchangeable. They aren't just dumb devices but actual computers that power up and do shit (I think).
>Our team was originally formed in Neuron Hackspace by collaborating with industrial design and manufacturing experts Design Heroes.
A quick Google search for Neuron Hackspace and Design Heroes shows their location as Moscow. I'm inclined to believe the detailed report from that blog post and am glad I did not end up buying the device.
I'm still not aware of it after reading the post. Pointing out that some of the people on the project were members of a hackerspace in Moscow at some point in the past is not remotely sufficient to substantiate that there exists any current connection between the project and Putin's regime.
As far as a connection to Putin's regime, you should read up the thread and note that nobody here mentioned that. Regardless of their supposed affiliations or lack thereof, I'm not interested in sending money to the Russian economy by purchasing a product from a Russian company. It's that simple. I think others would want to know that same information so thanks to pnw for mentioning it.
Stop trolling.
1. Flipper Devices Inc. is registered in USA as their main office, but no development or business is done at that address. The address belongs to a ”mailbox” company. 2. A majority of registered staff on LinkedIn were until recently registered in the Moscow region, (but suddenly moved to Tbilisi, Georgia according to their LinkedIn profiles.) - No developers remain in Russia according to LinkedIn.
3. TZOR and Neuron Hackspace shared the same address during the period of 2012-2013. (Neuron Hackspace used the address before TZOR was founded.) The Company of the founder of Neuron Hackspace, Esage Lab/TZOR, is placed on US sanction lists due to the DNC hack 2016, under the claim that the company provided tools to the Russian intelligence GRU and FSB. The attributions were validated both 2017 and 2020.
4. The Company and founder of Neuron Hackspace, Esage Lab/TZOR, had contracts with at least two companies that delivered services for the Russian government, FSB and the Russian military.
5. The founder and CEO of Flipper Devices Inc., has been involved in activities, such as running the DDOS site putinvzrivaetdoma.org, that could have attracted the attention of Russian security services.
6. The founder and CEO of Flipper DevicesInc., has been involved in activities since he moved to Moscow that can be interpreted as actively supporting the authorities in Russia, like trying to sabotage Alexei Navalny’s blog in 2014 and building a tool, Zaborona_help, to circumvent Ukrainian blocking of the Russian websites
The assessment is that there is an even chance that Flipper Zero has links to Russian Intelligence Services. The founder and financier of Neuron Hackspace was placed under US-sanctions due to providing tools to FSB and GRU related to the DNC-hack. The validity of the investigations behind the US-sanctions has been confirmed in 2017 (Intelligence community assessment) and 2020 (Senate Intelligence Committee). Pavel Zhovner’s past activities and that he seems to have been an early member of Neuron Hackspace contribute to this assessment.
It is at the same time likely that Russian authorities are well aware of the distribution of Flipper Zero and monitors the situation for opportunities to gain other types of benefits, either in form of influence over the hacking community, recruitment of talented hackers for similar projects or even attacks of infrastructure or other targets in the future.
It is also likely that Russian authorities will remain to have a substantial influence or control over this hacker community and could benefit from the future possibility to recruit talents with some form of combined security and IT background or even to blackmail foreigners that have been connected to this community.
Also made some far fetched connections of Flipper Devices to companies owning the hackspace Pavel Zhovner worked in, and attributed his trolling and making anti-censorship tools "as actively supporting the authorities in Russia". lol.
> send money (indirectly) to Russia
Even the report mentions the team members moving to Tbilisi, Georgia. Afaik Pavel moved to Dubai and still has Ukrainian citizenship. So I doubt a significant portion of company's money ending up in Russia, maybe except salaries of a few engineers. But it's pennies compared to how much the regime is paid for the resources, if that's what you worry about.
The report mentioned that their LinkedIn profiles changed from showing Moscow to Tbilisi. I'm sure I could also change my location to Tbilisi on my LinkedIn profile. How is that a meaningful argument? I don't want any amount of my money going to the Russian economy if I can avoid it, even if it's merely pennies as you say.
Why do you care to defend them so much?
Using a legal entity in a more convenient country for a startup seems like a common practice, including listing the address of such entity on the website. You'd be surprised how many companies are incorporated in America, pay taxes there, but have founders/employees/contractors elsewhere around the world.
So, I personally wouldn't count it as active effort of "trying to hide" or "trying to mislead".
> The report mentioned that their LinkedIn profiles changed from showing Moscow to Tbilisi. I'm sure I could also change my location to Tbilisi on my LinkedIn profile. How is that a meaningful argument?
Again, not sure why assume malice intentions. I also updated my Linkedin location when I left Russia, is that surprising?
> Why do you care to defend them so much?
Pavel pays me 15 rubles per comment of course! (tbh not sure why I waste time on this :D)
Only you are saying anything about malice. Everything is easily explained by greed (or the desire to simply gain if you prefer softer language).
Anyway, seems like you made up your mind and there's zero point debating it with you.
I didn't know about M5 before and now I'm hooked exploring M5's store, so I appreciate OP's pointing me there!
That actually sounds really cool...
r/ZeroPhone: ZeroPhone - a Raspberry Pi smartphone
You can check firmware version and device status, update it, have access to file manager, can backup keys, read logs, reboot, speed/stress test, and probably do a lot of other things that I am not aware about.
If you want to interact with the software on flipper zero you have to use the "remote" app (or whatever) on the phone. It kinda sucks though because it literally acts just like the physical device. If you wanna type a filename out and think having a full keyboard like on your phone would make that task easier... it doesn't. You are stuck using the fake "buttons" to move the cursor around to each letter just like you would on the device itself.
It's the same thing with the raspberry pi, sure you can get some cheap clone off less than ideal places, but you're gonna pay with your time. That's basically it.
Biggest level up was just lightly dusting anything with a starch or flour (lentil flour is awesome) and then a few light sprays of olive oil.
Two different models microwaves cook pretty differently from each other. Especially if they have differing wattage.
But then again, cooking is poor man's process engineering - what you do when you don't particularly care about quality and consistency, or at least don't have access to hardware and methods to ensure them.
It's a little different: from when the rPI first came out the price was a big driver of it's popularity. It started with the Model B at $35 (with the Model A at $25 "later this year") and this was so much cheaper than other options at the time. Look over threads from the time [1][2] and you'll see things like: "I teach middle school programming/computer classes. I cannot wait to get my hands on one of these. Right now it's cheap enough that I can tell the parents to buy one for their kids without a problem, and out of pocket it for those few of my students whose parents won't be able to afford it." and "The pricepoint is simply revoultionary. I intend to make a few amateur home automation gadgets with this."
For the price, it is great for more complex attacks and almost has all the features of a full Proxmark RDV4 (minus BLE and a battery).
[0] https://proxmark.com/proxmark-3-hardware/proxmark-3-easy
To get started, the basics are: low freq (LF) is usually around 125khz and is rarely encrypted (HID Prox is the most common in the US). The data is often encoded in Wiegand format for access control systems (something to keep in mind when reading the raw data).
High freq (HF) (aka NFC) is ~13Mhz and is readable by most Android phones with NFC. Not all tag data can be read however. HF cards support a lot of different options including data storage (normally in a block layout with permissions to read and write depending on keys) and encryption (iCLASS and SEOS being the HID offerings and very common). Some can be cloned (like hotel cards) while others (like SEOS) require a downgrade attack to work correctly (SEOS -> normal SEOS reader -> Weigand data -> older style card like HID Prox).
[0] https://github.com/RfidResearchGroup/proxmark3
[1] https://github.com/RfidResearchGroup/proxmark3/blob/master/d...
Too bad. I was sincerely hoping nobody would buy anything from them so they would die.
OT but if you found it for $8 on Temu, then you can most likely find the exact same device on Aliexpress for $1 - $2. Don't feed Temu - their ads are clogging up my feeds :)
Had it a few years and the whole Tesla port trick gets old quickly.
Losing your job is never a favour. Would you prefer termination if any issue was found with your work place?
you could be getting attention of all kinds and not even know it.
Just as this meta-voting-post of mine should :)
My comments got more than 200 downvotes and ban in discussion about physics about decade ago, but I nailed the problem. Also, I receive downvotes from Russian imperialists at constant rate just talking about history of Russia and Ukraine, because real history of Russian Federation/Russian Empire is well guarded secret in Russia.
If coercion was going to ever rule the world someone would have accomplished it fully already as many have tried. Yet here we are still free to say nearly whatever the fuck we want in the free world thankfully.
I had perhaps foolishly hoped to at least get a fun universal remote out of it, and it’s somewhat possible yet the software just isn’t there to bring a robust family of device RF and Bluetooth commands together. It’s no harmony remote.
I recently discovered this, which I want to try: https://electroniccats.com/store/flipper-add-on-magspoof/
If that's not the case I really need to do this because having it handle my tv's, ceiling fans, and garage door would be a nice trick.
Not sure which specific garage opener my apartment building has. But the fob controller the leasing office gave out is way too weak, so i have to sometimes press it many many times and wiggle it in multiple ways until it triggers the garage door. With flipper, it works on the first try.
A funny anecdote: after using my flipper for about a year, I encountered another flipper user in my apartment elevator (the elevator requires a keyfob to go to any floor except the ground floor). I talked to him for a bit. Turns out, he manages a bunch of boat storage units here (in Seattle) that all use different keyfobs. So for him, it is just pure convenience to carry a single flipper device as opposed to always having a lot of different physical keyfobs on him, and then shuffling through them in his bag to get the right one.
The WeWork key-fob uses rolling codes so couldn't use it for that...
One interesting capability that this unlocks is that battery powered, offline readers (think apartment door that uses the same fob as the lobby) can write out things like battery state so that apartment maintenance knows when it's time to swap out batteries.
They cost $15 and were hugely controversial.
>Digging Deeper::TV-B-Gone Device Shuts Public TVs Down
https://mediashift.org/2006/04/digging-deepertv-b-gone-devic...
This isn’t a thing in other countries, it’s part of American culture.
It's one thing to block ads when they have been loaded into your web browser that is in your room (completely morally and ethically fine). It's a completely different thing to go into someone elses space and start making decisions about what is or isn't running on a tv there.
I like ads as little as you so what I can do is just boycott that restaurant or bar entirely or ask the staff to turn it off. I think it's part of being a well adjusted adult to know what you want or don't want and go about it in a reasonable way (such as asking staff). It's immature though to just do that forcibly.
It is however not my duty to teach you that, so let's leave it at that.
Turning off a TV is also morally and ethically fine. I don’t see the big deal. Nothing is happening “forcibly”, I’m just sending out some IR. Nobody’s hurt or damaged.
Thankfully culture has adjusted some and those conditions aren’t as common as they were.
I was able to copy my work NFC badge, but I'm not really interested in trying it out.
It's handy as a pocket spectrum sniffer, but I don't have much day-to-day use for it outside of that. I'm glad it was given to me because I learned a lot. Potential future use for me might be an amiibo emulator, but I've grown out of those sorts of things.
This is already Western centric, but even here there are a ton of older static and fixed frequency systems still chugging along.
Of these rolling code systems most are not difficult to crack, especially those more than a decade old (and which are still sold today)
Question: how many times would you have to press the button on the remote for it to get so far ahead of what the receiver looks for that the remote no longer works without reprogramming the receiver?
This also means if you manage to clone a remote, you can just abuse humans. If you opened the door with your clone, the next time the original remote sends its package the sequence number will be too low and the controller will ignore it. But what do you do if your remote didn't work? You press it again, this time the sequence number matches and things work as they should.
For cloning you need to reconstruct the initial seed for the PRNG that is used to create the ciphertext based on the sequence number. Based on how little resources these remotes tend to have, more based on cost than battery life etc, and that some vendors design their own crypto, this can actually work. If you know the algorithm and the seed is only 32 bit, you can easily brute force it.
Couldn’t find a ceiling fan remote one time ( I have 3 with the exact same remote ) and used it to manage fan speeds
Still doesn’t justify the cost but I guess it’s like my leatherman. Hardly use it but handy when I do.
I actually bought it when seeing the pwnagotchi comparison and expected functionality from the wifi/marauder dev boards to be included. Meaning I got my flipper in the first batch for my country but couldn’t get a dev board even months later
That said, I knew very little about UART communication or SPI until I started playing with this and an ESP32 device. I also knew very little about bluetooth, RF, and RFID/NFR type stuff until I started exploring the world with this. It's been a fun journey that's rapidly advanced my understanding of quite a few things.
Others have said its overpriced or that you can build your own or whatever, but it's actually just the right price for a cool little educational tool that also works beyond the educational stage. It may even inspire me to build my own advanced version at some point.
If you're already a hardware hacker or EE, this is probably not much more than a toy for you. If you've always wanted to explore some of these topics but had no idea how to start, the Flipper is a good introduction. I immediately flashed it with custom firmware and it was easier than flashing my BIOS.
Edit: oh! I used it today to snap pictures with my phone every second for photogrammetry work, that was neat! Wish I had gotten better point clouds out of Gaussian splatting though
Of course, it wasn't useful to do, but hey it worked!
* Stingy => security protocols that I agree with in sentiment but unfortunately I need to let my pet sitter in and it's nice to allow them to keep the keys as I travel frequently and key exchanges are less than optimal for my spouse and I
I'm not competent of interested enough to make full use of them but I get the impression that they still have a lot of use in a large part of the world where simple RF is used to open gates and garages.
And of course you can copy and store RFID but you still have to get your hands on the tags. And that's where it falls down in certain more developed countries because they've mostly moved to RFID.
It's rubbed me as thoroughly dishonest and fraudulent.
I know this is currently a minority position, that's why I took the time to state it.
Because of the popularity of the device, there are third parties, some less reputable than others, trying to ride their coattails. Perhaps that's what you're reacting to?
If you really need a tool that can do them all, though, I can't really argue with the utility; but I do kind of agree with the GP comment that Flipper didn't exactly do anything that hasn't been done before.
This approach isn't a cheap cop out, it is serving a genuine utility and bridging the technology to more people.
Front page, nothing about their copy or their website says what you think it says.
They created a fast-food substitution product and have been trying to pass it off as the real thing. It's a hardware script kiddie device and that's exactly how their videos depict it.
I was always turned off by their approach since first seeing it in 2019. I've played with the device, get their facebook ads all the time, tried to change my mind about it but 5 years later I keep coming back to the same animosity towards it.
These are all easy to teach things and this thing shrouds that fact through product alienation intentionally distancing the user from any real hacker education and replacing it with animations and theatrics.
I'm cool being dismissed as a crank. They're obviously successful millionaires and I'm not.
I tried repeatedly to sell mine there, because I'd see some auctions for them complete. Then they told me it was definitely banned, because it could be used for (IIRC) RFID hacking.
(Fair enough. I ended up having to sell mine locally, for a lot less money than what the occasional auction would complete for on eBay. And finding a buyer locally was harder, and with much higher rate of flaking. As someone with deep frugal influences, who likes to save money when buying things, and to sell things once not really needed, I really like eBay when it works OK.)
Apple Shuts Down Flipper Zero's Ability to Shut Down iPhones - https://news.ycombinator.com/item?id=38656607 - Dec 2023 (26 comments)
Tiny device is sending updated iPhones into a never-ending DoS loop - https://news.ycombinator.com/item?id=38125426 - Nov 2023 (108 comments)
Probably Buy a Flipper Zero Before It's Too Late - https://news.ycombinator.com/item?id=38025786 - Oct 2023 (27 comments)
Flipper Zero can be used to crash iPhones running iOS 17 - https://news.ycombinator.com/item?id=37919396 - Oct 2023 (33 comments)
UK airport confiscates passenger's Flipper Zero - https://news.ycombinator.com/item?id=37707486 - Sept 2023 (44 comments)
Flipper-Xtreme-Firmware: Give your Flipper Zero the power it is craving - https://news.ycombinator.com/item?id=37519277 - Sept 2023 (4 comments)
Flipper Zero can spam nearby iPhones with Bluetooth pop-ups - https://news.ycombinator.com/item?id=37397481 - Sept 2023 (44 comments)
Flipper Zero Controlling Traffic Lights [video] - https://news.ycombinator.com/item?id=36756787 - July 2023 (3 comments)
Flipper Zero Self Destructs an Electricity Smart Meter - https://news.ycombinator.com/item?id=36253591 - June 2023 (210 comments)
FlipperZero: 1 Month Battery Life with Firmware Update - https://news.ycombinator.com/item?id=35735415 - April 2023 (82 comments)
Flipper Zero banned by Amazon for being a ‘card skimming device’ - https://news.ycombinator.com/item?id=35481580 - April 2023 (133 comments)
Brazil seizing Flipper Zero shipments to prevent use in crime - https://news.ycombinator.com/item?id=35109931 - March 2023 (67 comments)
Hacker Uncovers How to Turn Traffic Lights Green with Flipper Zero - https://news.ycombinator.com/item?id=34872104 - Feb 2023 (4 comments)
Trying Out Flipper Zero - https://news.ycombinator.com/item?id=34215390 - Jan 2023 (99 comments)
Hands on with Flipper Zero, the Hacker Tool Blowing Up on TikTok - https://news.ycombinator.com/item?id=34102109 - Dec 2022 (2 comments)
FlipperZero hardware hacker released for US sales - https://news.ycombinator.com/item?id=33720764 - Nov 2022 (7 comments)
Bad news: US Customs have seized a container with 15k Flippers Zero - https://news.ycombinator.com/item?id=33073141 - Oct 2022 (13 comments)
PayPal blocked Flipper Zero account with $1.3M - https://news.ycombinator.com/item?id=32739950 - Sept 2022 (105 comments)
Flipper Zero – Portable Multi-Tool Device for Geeks - https://news.ycombinator.com/item?id=32166058 - July 2022 (263 comments)
Quick Start Guide for Flipper Zero - https://news.ycombinator.com/item?id=31368209 - May 2022 (137 comments)
Flipper Zero: How it’s made and tested - https://news.ycombinator.com/item?id=27704883 - July 2021 (34 comments)
Flipper Zero: Bringing Cases to Perfection - https://news.ycombinator.com/item?id=27479684 - June 2021 (6 comments)
Case manufacturing behind the scenes - https://news.ycombinator.com/item?id=27155584 - May 2021 (1 comment)
Flipper Zero: Tamagochi for Hackers - https://news.ycombinator.com/item?id=26405919 - March 2021 (48 comments)
Flipper Zero Manufacturing and Shipping Plan - https://news.ycombinator.com/item?id=25870255 - Jan 2021 (14 comments)
Flipper Zero – Tamagochi for Hackers - https://news.ycombinator.com/item?id=23996733 - July 2020 (53 comments)
Show HN: Flipper Zero – Tamagotchi for Hackers - https://news.ycombinator.com/item?id=22941733 - April 2020 (10 comments)
Tamagotchi for Hackers - https://news.ycombinator.com/item?id=22859083 - April 2020 (1 comment)
Flipper Zero: Under Development Multi-Tool Device for Pen-Testers - https://news.ycombinator.com/item?id=21842830 - Dec 2019 (1 comment)
With Flipper Zero I now have backup keys in my backpack, on my dog's leash, in my running belt, and with close friends. It's great.
My new rental only provided us with one garage door remote and it looks ancient. Fairly certain this could an overly expensive extra garage door remote.
As others have said, if you want real capabilities get into SDR. My real kit includes HackRF piped into wireshark.
Lastly, a community that has seen a bump recently, Pwnagotchi. Its worth checking out and to me has alot of potential.
Another one of those "Sounds cool, but not really useful" tools
Probably out of scope, but I hope FlipperOne has a few environmental sensors too. (In a perfect world, it would also have thermal imaging, but these sensors are way too expensive.)
For some reason, many apartment buildings require the use of a little electronic tag not only to open the outside gates, but also to operate the elevator to reach someone's apartment. This also includes trying to use the elevator to reach the ground floor, e.g., when you leave your friend's apartment and you are going home. So you can't leave the building with the elevator without your friend coming out and unlocking it for you. It's madness.
So, I clone my friends' tags (with their knowledge) and come and go as I please.
i buy lots of nerdy toys, but can we all just admit that this is a toy, not a tool?
Their website wouldn't take my credit card. Needless to say, it's a good card and I used it on other sites that same day and after. I wrote to Support.
Three days later, they wrote back and suggested I try a different card. Sorry, Flipper, you lose. Nice idea, but a company is more than a piece of hardware.
1. Relatively small to carry around.
2. Specifically built for one topic of purposes.
3. Can be achieved by a single hacker with on market tools.
What kind of tools have you built for yourself? Here are some examples I have in mind:
Hardware debugging dongles, rom burning boards and of course Flipper zero itself.
Is it as great as it seems?