FindMy Flipper – AirTag and SmartTag Emulator
github.com
github.com
https://github.com/biemster/FindMy/blob/113ebf4017729b92a381...
Seems to be auth lib for iCloud.
Also seems to hard code a MacBook device agent in order to associate the generated keys with a device.
As with anything in the centralized world, I wouldn’t use this on an account with a high number of services/digital assets tied to it. I wouldn’t be surprised if Apple bans accounts that use this.
Wouldn’t be difficult to find out either given the unique “adsid” code that is required to login.
Hold short, so you don't need an iOS device technically to onboard AirTags, any Apple device is sufficient? Why in the name of everything that is holy does Apple not support this officially, just to push sales for iOS devices or what?
(Angry rant of someone who bought an extra used iPhone despite owning like 5k in Apple desktop/mobile gear, just to be able to onboard some AirTags)
No. They deliberately do this for gatekeeping. That's what I'd expect from a company forcing you to own a Mac in order to develop for iOS, by license terms.
If it's just technical issues Apple usually do have more helpful alternatives, for example you can only request password reset for your Apple ID on an Apple device (because they can throttle and potentially ban a threat actor trying to stuffing, I guess?), but they invite you to go to an Apple Store and use iPad in the store to do it if you happen to not have one.
You answered your own question ;).
My best guess (assuming it wasn’t malice/greed): not many people have access to an NFC/RFID reader and it’s Apple. So it has to be soft locked somehow behind the Apple Wall. So, in order to provide that “just works” experience. It’s better to advertise iPhone method as a way to get the tags registered.
Other methods exist, but your mileage varies. Also, Apple may change the APIs at any time and break that process. Thus, no support provided.
https://github.com/biemster/FindMy/blob/113ebf4017729b92a381...
I would never consciously integrate a library from a third party. I am in the middle of scanning every single release of 'VenToy' into virus scanners, awaiting for the moment when an NZ-type vulnerability proves true.
Its not that Apples payment stream depends on this, its their subscription model.
Beware of offering a feature free that Apple thinks is interesting, they will lock you out, and start charging people for it.
Doubly beware of p*ssing off geeks, the will go to bed on Friday, in an angry state, and fervently work all weekend both to black box your product, but to trivialize the implementation of it. Now those are the really scary people.
Ex: Get N donor tags. Have it cycle through the N tags every 24/N hours. Therefore, to apple (/ device tracking), the "stalkee" is never being followed by a single tag for an extended period of time.
IIRC this came up in the context of tracking shipments with expensive equipment, where it can be in transit for many months. The tags are so power efficient that they work for ages on a large battery, existing GPS solutions just didn't cut it.
I'm not sure how apple could ever patch it. If you were willing to add a power-cycling microcontroller to your airtag, it wouldn't be that much effort to also add a bank of airtags to cycle through, which would make the apparatus totally indistinguishable from a group of airtags coming in and out of range constantly.
If you have to cycle the tags constantly, couldn't you just physically follow the person and spend less effort/money at that point? Or get a GPS tag that doesn't use the AirTag "network" at all, no cycling needed.
the anti-stalking features make airtags less useful for anti-theft (or theft discovery), as any aware thief can just disable the tag due to the anti-stalking feature (apple does note that its not designed for anti-theft purposes). But if one can defeat the anti-stalking feature, it makes it much more practical for this.
Personally, I wish Apple allowed one to permanently put their air-tag into law enforcement mode, which would prevent you personally from tracking it (and remove it from stalking alerts), but would provide legally recognized law enforcement the ability to request the tracking record (i.e. same process that they might use for requesting cell phone location data).
> provide legally recognized law enforcement the ability to request the tracking record
Where do you live where law enforcement cares about stolen property? 1985 America?
And in other places you can probably bribe them to do it.
ex. You notice your bike is stolen. immediately turn on law enforcement mode. The anti-stalking notifications are disabled but the owner can no longer track the airtag. However, after alerting the police, they could access the location of the device and investigate or recover the bike.
Umm, where do you live that the police give a hoot about a stolen bike? Maybe Japan?
- My family’s old subhz car keys are dying so I cloned it & use the flipper when the real one doesn’t work. It’s a car from before the 2000s so no security whatsoever.
- Apartment, lift, gym rfid. Don’t need to bring multiple sets of cards
- IR is also helpful as a backup while I procrastinate going out and buying batteries for some remotes.
For NFC/RFID it depends entirely on the card. You can easily clone Mifare Classic, but on newer ones there's no way I know of, and the software does not (yet) have support for Legic (which has been broken for over a decade).
Other hotels have an iPhone app you can use to unlock your door. That's another nice backup, but I've found I can have my Flipper out and the room door open faster than I can open my phone, find the app, launch it, inevitably have to log back in because it's been more than 30 seconds since I last opened it, etc.
Also give it for my kids to play instead of letting use the phone and browse random stuff on youtube.
The original one was funnier because you could change the config for the different weapons.
[0] https://github.com/seemoo-lab/openhaystack?tab=readme-ov-fil...
[1] https://github.com/seemoo-lab/openhaystack/tree/main/Firmwar...
Basically I was able to pass email and phone number verification, but then "Continue" button on the "Apple ID & Privacy " page doesn't work and you can't get around it. No error or description whatsoever, just internal server error in the browser's console.
Turns out it's a known problem and the same button works perfectly fine when pressing it on an Apple device. I haven't tried it in a macOS VM though, but presumably Apple flags such accounts anyway.
Related thread: https://www.reddit.com/r/applehelp/comments/17zawel/continue...
If you want, I can create an account for you on my Mac, email me (email in profile).
But what Android app can actually "find" it? I don't have an iPhone or Samsung device.