Seems like the focus should be on who is allowing and enabling this type of usage. Manufacturers, since they do not act of their own free will, need to be compelled to actually release secure software.
If anything, I love that the Flipper Zero is revealing how vulnerable a lot of this technology is. It hasn't been this easy before to execute radio hacks while mobile, nor in such a game-like/product format. Consequently, I think many people have not realized how secure their devices actually are.
It seems that people are finally becoming aware of how unsafe many of these products are. Unfortunately, they are mistakenly focusing the blame on the wrong party.
Fixing the security holes also protects everything against truly "evil malicious" actors, not just "fun malicious" actors, so it has its benefits to force manufacturers to up their game.
RF spectrum inherently requires rules and cooperation -- if it were a free for all, user beware type of situation, it just wouldn't work.
A lot about order in society relies on most mischievants being actors of opportunity.
I think the brick and window analogy fails here. Thing is, the real bad guys generally already know about the best weaknesses to exploit. I think a better analogy would be pointing out that a storefront in a high-crime area doesn’t actually have glass in its windows. Robbers already knew that. Now the locals are telling the shop owner that they need to install some windows, quickly.
Who are "the real bad guys"? Highly motivated, highly intelligent attackers? That's a valid concern if you're a high value target, but most people aren't. The vast majority of crime is the result of ease and opportunity, not expertise.
I live in a place with high rates of vehicle thefts. Essentially all of them are performed by low skill attackers who use low skill attacks at the physical layer. Carjackers don't care about anyone's rolling code implementation.
I don't think Flipper Zero is anything to worry about, most abuse is probably just going to be edgy kids who are doing annoying things, unsyncing their friend's car keys, etc. But I disagree with the general sentiment that any proliferation of tools that escalates the need for security is always a good thing. Generally, increasing the opportunity and ease of crime is a bad thing.
I genuinely believe that the makers have such devices have coasted way too long on security through obscurity. These weaknesses need to be highlighted so that there's political pressure to fix them. If someone users a Flipper Zero or the like to attack a cochlear implant, they should be punished for it. So should the manufacturer of the implant who released an insecure medical device into the wild. If the Flipper's popularity is what draws attention to the broken medical device, then good for Flipper! Maybe they'll patch the problem before North Korea can use it to launch cyberattacks.
Bad actors are not a monolith. There are many different types of attackers with different means and motivations who will take different actions against different targets and different types of technologies. Threat profiling is a thing for a reason, and it absolutely does matter whether or not a particular threat has the means and/or motivation to exploit a vulnerability. It is the only thing that does matter, outside of a technical academic context.
Yes, security through obscurity is not an rigorous approach to implementing a cryptography system, but it is a completely valid approach in other security disciplines outside of cryptography or digital security. Too many people make the mistake of incorrectly assuming that cryptography security principles apply to the broader practice of security as a whole. Digital security is only as useful as it is to support a holistic model of security. Digital security in isolation is just an academic exercise. It has to be implemented to be useful, and when implemented, operational security and threat modeling are very relevant.
> If a vulnerability is patched, it doesn't matter if there are 1 or 1,000 tools targeting it.
It does matter what the real-world observed rate of patch compliance is, the cost to patch, and whether or not those tools will be used nefariously. If you have an academically obscure remote exploit for a pacemaker, that requires a hardware patch, please don't write a script that makes it easy for non technical people to exploit, and post it on GitHub. While this will certainly encourage a fix to future pacemakers, the cost may not be worth it.
IIRC this is in Canada, but in US (and probably Canada too), FCC has rules against creating harmful interference. Fine + punish the people creating the interference, rather than the tools that people can use to learn, debug + protect these devices that are vulnerable.
Because such a flood is now easy to trigger, phones now implement rate limiting that effectively mitigates the attacks. After all, you're not legitimately going to see 1,000 Apple TVs trying to connect at once, so there's no need to give each one of them personal attention.
For another example of similar politician behavior just look at how LA is handling the graffiti towers. They're driven by concern about being on the national stage and the corruption of the whole system being put on display, not about the graffiti.
This isn't a realistic solution because the difficulty of identifying people abusing these devices is high. The usual US approach is to jack penalties up way high to offset the low probability of capture, which inevitably leads to disproportionate sentences and an even greater erosion of respect for the legal system.
Technology will always develop, it's important to plan and regulate it, sure, but bans are need to be extremely carefully thought out to enforce well.
So are you more forgiving of it now?
The people stealing cars are an international organized group that have managed to exploit holes in the federal government, the railroad companies, and the ports. The way they are stealing these cars is outside of the capabilities of a stock flipper, and requires custom hardware.
Banning the flipper is going to do precisely nothing to increase the friction on the problem they are trying to solve.
Banning the Flipper is a minimal effort way to minimize it as an election issue.
Sport shooters can insert a certain James Franco meme here.
There is something about lowering the bar to disruption, and the possibility of this causing a bit of a reckoning for devices that don't do a good job of "Accepting any interference received"
And they would if it were not in a "bright plastic case"?
I use netcat for legitimate things every day. If someone made an IP server that I could hack with netcat, they should be ashamed of themselves. It's not netcat's fault that their security sucks. Well, same with Flipper Zero.
That's one of the situations where I'd feel justified in taking a device and stomping it to bits, and I'd support anyone else doing the same.
If anyone does encounter this in the wild with Apple devices, first, install your damn updates because I'm pretty positive this is now blocked, but in the meantime turn on Lockdown mode to keep this from interfering with you.
Apropos of anything else, the FCC regs around the 2.4GHz spectrum are pretty explicit, "Part 15 devices ... must accept any interference that may be received". In their eyes, the device that is flawed is the phone, not the Flipper.
As for courts, if this hadn't already been resolved (at least on iOS) I wonder if you could request that jurors and the judge turn their phones on for a demonstration. Given the state of Android updates in the general public, it'd probably still be effective on a significant percentage of people.
After the war there are going to exist a whole bunch of people who know how to deny GPS, defend against drones, build attack drones that bypass primitive countermeasures, spoof mobile networks, monitor the RF space for unencrypted signals, and set up actually secure comms. And not all of them are going to remain completely silent about all of this. Toys like Flipper are going to be the least problematic. Banning it achieves nothing.
BTW, wanna connect to the Apple TV? :D