MicroPython on Flipper Zero
lab.flipper.net
lab.flipper.net
* Opened my friend's Tesla battery charge hatch from a distance for fun (it closes again on its own after maybe 30 seconds)
* Recorded a lamp's IR remote on/off/up/down toggles and used the Flipper to turn on the lamp, rather than using the IR remote, to try to debug whether the remote was going bad or if there was a problem with the lamp (it was the lamp itself)
And I tried, unsuccessfully, to:
* Read my dog's microchip data
Otherwise, I haven't found any use for it. I really wanted to like it. I did a search to see if there was anything interesting to do with it that I was missing, and basically it's what I did (or failed to do) above. Some people also use it to change TV channels at restaurants as a prank it looks like.
(Not for nefarious purposes, but just in case I can’t find my keys.)
What ever device you’d want to use as a backup would need to capture information sent from the vehicle during the last unlock.
Also there are ways to desync/resync your key so you might be able to “add a key” with the flipper with certain firmwares.
Cloning the current key and using it can desync it from your car. Super annoying. Be careful
That phrase is doing a lot of heave lifting there...
(This is only what I've read, but as i understand it many rolling code keys can be broken by recording three button presses while the keyfob is out of range of the car, then brute forcing the seed.)
The whole microchip registry thing is a mess, though. There's no authoritative database and I'm certain that the database entry for my cat is at some shelter where he was briefly held. I have no way of updating this data without paying a subscription fee, so that's out of the question.
Outside of IR remotes and popping tesla ports, I have used it to emulate RFID tags. I don't have enough free time to really utilize it appropriately.
Cat tax: https://i.imgur.com/8vAabRM.jpeg -- He is sleeping where he really should not be sleeping.
https://old.reddit.com/r/orangecats/
Here's a ML problem for someone to consider tackling ... given a cat picture, identify all of the relevant cat subs that it might get posted in. This could be applied to dogs too... but cats rule the internet ( https://en.wikipedia.org/wiki/Cats_and_the_Internet )
I'm fairly certain that there are an infinite number of cat subs, so this task is impossible!
Its one of the "this might be a fun thing to do if you're playing with a ML image classification problem."
I've got a Mac and so https://developer.apple.com/documentation/createml/creating-... has tempted me on occasion to see "how much can this thing do?"
https://everything2.com/title/halting+dog+problem
There's also the incomplete dog issue... https://everything2.com/title/Dog+incompleteness
That is, unfortunately, correct ^^^ I went through this with my dog. I was told to find out which services your local animal control and humane society use, and make sure your pet is added to those registries. Yes, some charge $$$, but the registries recommended to me were free.
If your pet ends up with animal control, and they can't find the chip registration, getting your pet back can be a nightmare.
It's a great idea, in theory, but it's opened up a world where the possibility of scam registries can exist.
I've considered the challenges of an open and public registry, but allowing the public to access it is problematic as there is no way to validate the entries and you would be handling people's contact information. It might be an actual use of a distributed blockchain / public ledger.
Single resource. Any vet/shelter/guy with a RFID scanner can report found pet with this barcode at approximately this location. If you know this pet, contact us here. Presumably only vets and shelters would be adding to the database, so all of the contact information is already public. People who have lost their pets can then monitor this location/sign up for alerts after you lose Fluffy.
Not as great as being able to immediately lookup the owner, but eliminates some privacy concerns.
The simplest way to do this would be to use the random data for an EC25519 private key, which would be used to encrypt the data[1] and then sign the encrypted blob plus an unencrypted timestamp. The registry would be a mapping of public keys to encrypted records. Updates could be accomplished by sending a record with a greater timestamp, which would then be propagated to other nodes.
You could also put a DHT on top of that to minimize storage requirements, perhaps also a PoW scheme for sibil resistance.
[1] EC doesn't technically do encryption, but that can be worked around by attaching a public key for an ephemeral keypair for your message, doing a DH against the two keypairs, and using the resulting secret as a key for symmetric encryption.
Yeah it is a mess, but my vet told me they use this to search across the dozens of registries in the United States: https://www.aaha.org/for-veterinary-professionals/microchip-...
That form is able to find my cat's microchip information in both the registries I have her on, for example. But yes, I was surprised the pet microchip scene isn't more consolidated. Like bicycle registrations are, where the two major U.S. players are https://bikeindex.org and https://project529.com
EDIT: But I was unable to read my cat's microchip with my Flipper Zero, even though my vet confirmed it's still readable using their more appropriate tool for the job.
I used to have an LG G4 android phone with a TV remote app built in- with just the TV manufacturer information, I could change the channel / volume in all sorts of useful places (the gym, etc.). I miss this feature often.
"Flipper Zero has a built-in library of signals for common TVs, ACs, projectors, and stereo systems brands. This library is regularly updated with new signals, thanks to the Flipper Zero community's active contributions to the IR Remote database."
(from the flipper zero homepage)
I've successfully used mine as a "TVbGone", switching off all the TVs in a bar...
The wifi board is fun to play with to learn about how some of the more common/basic SSID spoofing and broadcast spam attacks and similar things work. There are some fun HID device attacks you can check out too that are pretty cool. I also used it as a jumping off point to dabble with programming in C and using gdb and stuff like that.
I created a very simple attempt at an oscilloscope type program ( https://github.com/anfractuosity/flipperscope ).
Otherwise, it's kinda fun for scanning credit cards, pet microchips, maybe the occasional NFC or RFID tag. It can clone most hotel keycards, at least to the level required to open your door, although the parking gates tend to use better security.
It can also emulate an AirTag, at least on the bluetooth beacon side, which is kinda funny.
But yes, mine mostly lives in a drawer.
I've also used it as a universal remote more than a few times on devices that didn't come with a remote. The App running on a phone makes it somewhat easy to transfer new remote templates to the Flipper over Bluetooth.
It also comes in handy as a serial adapter as it has GPIO pins you can connect to things (UART headers).
The RF transceiver is also cool to capture RF remotes (garage doors, overhead fans, etc.) and replay them.
Do you mean the non IR kind?
It can receive and transmit from about 300MHz to 930MHz (with a few gaps in between).
I've used my Flipper to sniff the signals for my wireless controlled projector screen, projector, and home theatre amp. I then used the data I sniffed to program an ESP32 with a CC1101 module attached, so I can roll down the screen and turn on the project and amp via wifi (with Homebridge and iOS Home app).
I later sniffed my garage door opener, added that into the ESP32/CC1101 gadget. I needed to add a better antenna to make sure it reliably had range to get to the garage door, but it now works more reliably than the keychain fob, and I can use an "arrived home" automation to have the door open without me needing to stop the motorcycle and take off my gloves and get the key fob out of my pocket. I may replace this with an Arduino/CC1101 triggered by the hi beam switch.
The Flipper Zero is a super useful tool when having ideas like this, but like most tools, it really does sit in the drawer most of the time. But I'm glad it's there, I don't regret a cent of it's purchase price.
I have a few ideas to make it more useful, but every time I try to get into developing an app, I get frustrated and give up. It is probably the worst codebase I have ever seen. Just walls of strangely named function calls with no code comments and no documentation whatsoever.
If you want to see my lousy code I wrote, you can see it here: https://github.com/Jestzer/Flipper.AC/blob/main/ac_app.c
You can still find earlier firmware versions that do the old thing but you have to hack the hell out of anything to make it useful.
Then I went to go sell it and found out you can't list them on eBay or FB Marketplace. Not sure how to go about selling or trading one beyond those types of places, either, so I basically have a pricey dust collector in a drawer.
I would have expected the Flipper to be pretty good at that, but it manages to crash while emulating the key fob like a third of the time.
https://download.rockbox.org/daily/manual/rockbox-sansaclipz...
They're fairly durable other than the headphone jack and the clip from what I've seen
I spent a weekend not long ago upgrading a broken Sansa Clip+ with a new battery, RockBox, and a USB-C port - first one with USB-C AFAIK. Oh and I replaced all the SMD buttons too while I was at it.
I’m very happy with how it turned out! I only wish I knew how to do something more advanced like adding Bluetooth audio capability that doesn’t just hook into the DAC output and sound terrible.
Don't suppose you could tell me the name of the part they use for the headphone jack? I can find loads that look almost right but never the exact model
There’s not a lot of room on the board, so I soldered 0402 resistors directly to the pins on the port to allow it to work with modern PD chargers, and I had to expose a few traces so I could jump the pins since it didn’t align with the mini usb pads. Fortunately I was able to solder its feet to the main structural pads and it’s a good firm connection.
I bought an assorted usb-c port kit from Amazon with something like 10 varieties and chose the port that best fit onto the board. I needed to bend the legs a bit but it worked.
I used a digital microscope and fine solder tips. There’s no “easy” way to do this that I’m aware of, especially since I chose low melt solder to avoid melting the port’s plastic, which meant the jumper wire conducted enough heat to desolder the other connection if I didn’t work quickly!
This experience had me wondering if I could design a little thin adapter pcb to make the process less error prone, but I’ve never done anything like that before…
What’s wrong with your audio port? To find a replacement you might want to get some cheap calipers and measure a bunch of stuff to compare with components on digikey/mouser/aliexpress.
Or you may just be able to repair it instead of replacing it. Could be it just needs its pins reflowed to the board if you haven’t tried that yet. I hope you can fix it - good luck!
The common headphone jack issue is that one of the pins comes loose very easily but that's a very simple fix of adding some extra solder. Beyond that the audio port gradually gets looser to the point headphones will very easily fall out; I think if you just never remove the headphones this will be much less likely to happen.
The main failures I've seen on eBay are: - dead battery (these are often in amazing condition otherwise because they were bought and hardly used) - loose audio jack (simple solder fix but may have the looseness issues) - broken membrane buttons (probably not very fixable?) - faded screen (probably has lots of other issues but generally usable)
Only one button was malfunctioning but I replaced them all since they looked pretty worn.
If you’re thinking of switching to micro usb you might as well try usb-c. AFAIK you’ll still need to deal with alignment issues. The resistors are only necessary if you want to use modern PD chargers - they make little boards with these attached already but it may be impossible to fit one of those.
Could definitely make a decent markup buying broken ones and reselling them all fixed up too; I got seven "broken" ones a few months ago on eBay for $20 and almost all of them just had dead batteries
I'd expect C to run the best due to it being compiled. JS is pretty quick, but we're talking a microcontroller, so any speed you can pickup by reducing computation cycles is a win.
Easiest/better is using what you already know as that'll provide the best speed to MVP. If it's too slow in Python/JS, but it seems like a useful thing, it's probably worth rolling up your sleeves and learning some C. At least enough to build a python library.
I have a weird related question and I am not looking for a full answer, but rather on what/where would be a good resource to find that information as what I have found so far was not super useful.
In short, for the newer employee badges, are there some secret handshake pieces that flipper can't copy? Stuff around the house worked flawlessly, but the moment I tried to play with employee card, I got, um, mixed results.
"Employee badges" can be implemented in a number of ways, from simple broadcasted rfids down to having secret challenge responses that aren't breakable without going down the jlsca route since the secret is on the device and never leaves it.
So, step 1: figure out what exactly the model your 'employee badge' is using and what protocol it uses. There's probably some marking on it that should give you the manufactuerer at least.
One of the best resources is probably the Discord channels. There is the official channel, and the non-official (for non-official firmware). YMMV, but the non-official seems to be more active.
The Flipper is "somewhat underpowered" in terms of hardware for RFID, or specifically 13.56MHz, but makes up for it in a very active development community.
"Access badges" is a fairly vast blanket term. Anything that's not an exhaustive, lengthy breakdown will be inherently over-generalised, but here we go:
125KHz: Low Frequency: _usually_ cards with "just" an ID or very limited memory. _Usually_ much simpler technology. _Usually_ without security, and much easier to copy.
There are multiple encoding and modulation methods in this family, almost all of which are encompassed in a (fairly amazing) tag that can emulate them all - meaning they can be cloned easily : the T5577 chipset.
There's much more penetration of these chipsets in non-EU markets (US, Canada, etc). Key brands and tags: HID Prox, EM4XXX, Hitag, etc.
The FlipperZero handles most / if not all of these very well (read / save / emulate / write).
High-Frequency tags (13.56MHz) : encompasses multiple ISO Standards : 14443-A/B/C (lots of access cards), also ISO15693 (Slightly Longer read range, more industrial tags, ski-passes, etc), and EMV (Payment Cards) among others.
There are many sub-protocols and implementations of these higher level standards. But these can be generalised as : small memory units / computing units on a chip. As such : larger functionality, and various security.
The most well-known family is probably MIFARE (1K/4K Classic..). Chances are, if you've got one somewhere. Encryption is totally broken.
Ultralight / NTAG: Cheaper, no / not much security (password + signatures on some tags, and counters). Typically used for ticketing etc.
These are handled in Flipper.
Other implementations: DESFIRE: Uncracked. iCLASS (Commercial Access Control - iCLASS SE / ELITE / SEOS ..). Can be cloned, or suffer from downgrade attacks. Not handled by Flipper by default.
The Flipper has a fundamental 'flaw' with high-frequency tags: it can't handle emulation on chip, and its clock isn't evenly divisible by 13.56MHz, so emulation and some functions are always going to be limited. With that said, the 13.56MHz stack is always improving - the community has done amazing things.
Likewise, cracking (typically: MIFARE) is CPU / memory intensive. The Flipper can limp through some implementations, and can team up with a PC for others.
However, more specialised devices (Proxmark, iCopy-X) pick up where the Flipper leaves off.
In summary, it's a very useful tool for RFID (LF + HF) - can handle most LF operations, and quite a few HF operations - before you have to reach for much more expensive hardware (Proxmark : ~300 EU).
Some people to check out on YT: https://www.youtube.com/@TalkingSasquach https://www.youtube.com/watch?v=VF3xlAm_tdo
Feel free to reach out for more questions.
With that said, if your badge is in tag/fob format, you could clone it onto a card-format. Larger antenna, better coupling.
There are a few suppliers building these devices. The bad uses outstrip the good uses.
>The bad uses outstrip the good uses.
I understand this logic, but I reject it conceptually. This is true for a huge variety of products. At the end of the day, it should be up to the individual to decide this. We survived as a society with substantially higher trust in the past. For example, check fraud is technically trivial and quite common, but did not prevent checks from being an accepted method of payment. Perhaps there is a path back to this in the future, but certainly not if we allow the megacorps and governments to make all technical decisions for the greater good.
I can write more about this but this is not the place or time.
I am only starting my adventure with RFID and there is a lot to learn, but it has been a while since I was this weirdly excited.
Almost everything in the community happens here.
For Mifare Classic: - Nested (Uses one known key to crack others) - darkside (Derives a key with no others. Slower, results are typically handed off to the nested attack to calculate remaining keys..)
For newer versions of the Mifare Classic with better PRNGs - "Hardened" cards: HardNested. Needs one known key.
For cards that provide a static nonce (to try to evade cracking, ie FUDAN) - Static Nested.
For the latest generation FUDAN: Static Encrypted HardNested.
Note, for the nested attacks - if you don't have a known key, these can be sniffed from the access control reader, and then cracked (MFKey32/64).
Flipper supports the MFKey32 attacks, and limited nested. You may bump into limits of your Proxmark clone with hardnested cracking - it's memory intensive, and most of the Proxmark Easy clones have reduced RAM.
There's actually an auto_crack LUA script on proxmark ( Use this fork: https://github.com/RfidResearchGroup/proxmark3 ) which will take most of the hassle out of cracking.
Cracking requires very, very precise timing: In a nutshell, you're trying to predict nonces / PRNG values, by sending very precicesly timed requests, and then later cracking those results.
The Flipper has limited CPU power - its main "attack vector" against MIFARE is a very large keylist / dictionary of common MIFARE keys. It's slow and dumb, but it works for most cases. It can also do limited cracking, depending on the type required.
The Proxmark is built around an FPGA, and can crack much, much more efficiently.
LadyAda of Adafruit got her start with such a device.