[0] https://www.home-assistant.io/voice_control/worlds-most-priv...
479 karma · joined August 22, 2016
[0] https://www.home-assistant.io/voice_control/worlds-most-priv...
I would guess that the cert pinning would prevent such MITM attack, but I could be wrong. I'm not a huge fan of Chamberlain and myQ since they are so against 3rd party use of their products [0].
[0] https://www.home-assistant.io/blog/2023/11/06/removal-of-myq...
I've also used it as a universal remote more than a few times on devices that didn't come with a remote. The App running on a phone makes it somewhat easy to transfer new remote templates to the Flipper over Bluetooth.
It also comes in handy as a serial adapter as it has GPIO pins you can connect to things (UART headers).
The RF transceiver is also cool to capture RF remotes (garage doors, overhead fans, etc.) and replay them.
I think more time needs to be spent looking into these commonly used, cheap IoT devices and educating consumers on the risks of using a poorly secured device on their network.
The upside of these vulnerabilities is that you can run your own code on these! 'Declouding' is great as it can extend the lifetime of these devices and make using them more private.
I did some research on them and found that they are completely wireless (cellular network most of the time) and powered by a 65w solar panel. Since they capture every license plate that passes by, I wasn't thrilled it was a private company keeping the data, even if they say they only keep it for 30 days.
I did a FOIA request with my city to see how many are in use and their locations to share with my community. I also plan on asking why my city thinks it is a good use of tax dollars. I think it should be a requirement for cities to disclose their use since it is a private company installing private equipment (and a camera at that!) on public land to monitor the public.
We have solutions to most of the phishing attacks, but most people find them hard to use or don't want to use them as they are seen as not important. I've made comments to several companies that SMS or TOTP based MFA is not phish-proof and that they need to implement something stronger, but it often is ignored.
I linked this in a sub comment, but the largest garage door maker in the US is Chamberlain [0] (which owns a ton of other brands) and uses known rolling code algorithms that can be decoded. [1]
[0] https://www.chamberlain.com/ [1] https://github.com/argilo/secplus
Also, why do I seem to always get spam from a few providers? And why aren't we holding them accountable?
I think the FCC needs to step up and have a hard deadline for STIR/SHAKEN with fines for operators who don't comply. That is the only way, IMHO, that the VOIP operators will take it seriously.
<tinfoil hat> I wonder if the ransomware incident last year played a role in this decision? [0] I'm guessing they wouldn't announce it for fear of boycott, but who knows. </tinfoil hat>
[0] https://www.cnbc.com/2023/09/14/caesars-paid-millions-in-ran...
Also, what is this Core Technology Fee for all apps? Maybe Apple has been losing money on the App Store infrastructure so they want to make it up? Or is this just a bid to try and keep as much control as possible? Seems that Apple wants to go into this kicking and screaming...
As someone in cybersecurity, I understand the need for secure apps, but I think Apple has been going about it in the wrong way.
For the amplification attacks, my understanding of them is that the key fob and car may be able to detect this kind of attack, but require more logic/software to do so. Also, most of these attacks use high frequency 'backhaul' wireless networks (key fob at 3-400Mhz, backhaul at 2.4-5 Ghz Wifi with lower latency) to prevent such timing/signal-noise from being detected. If I had to guess, most key fobs/cars are more focused on making sure the key fob works at range or in hard-to-detect environments and not focused on preventing such relay/amplification attacks.
Also, some similar attacks to what you linked could also be done against Bluetooth (I think Tesla had this issue in the past few years) with a simple Bluetooth range extender/relay setup.
(Note: without one of those devices, most of this is just guesses/what I've seen is possible/theoretical in terms of attacks)
Also, while I like the RTL-SDR (and the price tag!), you can't transmit with it. While this isn't a deal breaker to everyone, if you'd like to clone a garage door remote, for example, you need to be able to transmit. While you could use something like a raspberry pi and rpix [0], but I think it is more work than it's worth for many. Also, multiple RTL-SDRs are required for higher bandwidth applications like ASTC TV or trunked radios.
With the flipper, I think the main draw for most is the point-click-done nature. Include the Android/iOS app and it makes it easy to configure on the go without a computer. The expandability is one of the main feature that will increase adoption over time compared to the HackRF+PortaPack which, from what I saw in the past, lacked longer-term support and regular updates and new features.
I've had good luck with the basic universal remote when I'm in a pinch. Also, you can create custom IR files, but it can be a pain with encoding. The flipper forums are a good resource too [1].
To get started, the basics are: low freq (LF) is usually around 125khz and is rarely encrypted (HID Prox is the most common in the US). The data is often encoded in Wiegand format for access control systems (something to keep in mind when reading the raw data).
High freq (HF) (aka NFC) is ~13Mhz and is readable by most Android phones with NFC. Not all tag data can be read however. HF cards support a lot of different options including data storage (normally in a block layout with permissions to read and write depending on keys) and encryption (iCLASS and SEOS being the HID offerings and very common). Some can be cloned (like hotel cards) while others (like SEOS) require a downgrade attack to work correctly (SEOS -> normal SEOS reader -> Weigand data -> older style card like HID Prox).
[0] https://github.com/RfidResearchGroup/proxmark3
[1] https://github.com/RfidResearchGroup/proxmark3/blob/master/d...
Most people don't need a full SDR like a HackRF in order to explore their RF devices and a Flipper gives that too them without the headache of software and the bulk of a full PortaPack.
(I love my HackRF and PortaPack for the record. The Flipper can't complete with the features and low-level access when you need it)
[0] https://hackaday.com/2015/06/08/hacking-the-im-me-to-open-ga...
For the price, it is great for more complex attacks and almost has all the features of a full Proxmark RDV4 (minus BLE and a battery).
[0] https://proxmark.com/proxmark-3-hardware/proxmark-3-easy