7 ms·
> In the video it appears that Peter was using the Flipper Zero to wireless turn the power meter on and off, which also controlled the power to a large AC unit.
by diftraku 3y ago
> In the video it appears that Peter was using the Flipper Zero to wireless turn the power meter on and off, which also controlled the power to a large AC unit. Eventually switching the meter on and off while under a heavy load resulted in the meter self destructing and releasing the magic smoke.
Calling out Flipper Zero for someone (ab)using the meter's remote control features cuts me the wrong way: you could've done the same with any other SDR, not just the Flipper Zero.
It's not even a surprise this happened, the cut-off is not meant to be operated constantly to cut heavy loads. Similarly you should not use a breaker to turn off heavy (or any, in that matter) loads as you're needlessly wearing down the protective device, instead of a separate cut-off switch that's designed to be replaceable. Especially since it can be positioned downstream from the protective device.
It all boils down to which part of the circuit you can easily repair in case of a fault, in this case the meter is by far the least accessible.
- wilg 3y agoI got the vibe they were treating it as a cool hacker tool not calling out the Flipper Zero. But I don't know what any of this is really. I'm just some guy!
- deleted 3y ago[deleted]
- rocqua 3y ago> you could've done the same with any other SDR, not just the Flipper Zero. The specialness of the flipper zero is not that it can do more than any other SDR. The specialness is how easy it is to use. The question is what you can do in that 'easy mode'. That, in the easy mode, you can do this kind of realistic and meaningful damage is noteworthy. Because this potential is brought to the masses. It probably won't be the start of widespread SDR-based cyber-crime, but that brings it one step closer. That is why I consider this noteworthy news about the flipper zero specifically.
- pftburger 3y agoThat said, it’s also important to demand device makers build better protections into their software (like rate limiting) in the same way they do for the hardware. Otherwise it leaves the door open for legislature trying to ban screwdrivers (tools)
- mozman 3y agoAbsolutely not. It should obey the law and nothing more. We do not need to be saved from ourself. Let stupid run.
- dismalpedigree 3y agoStupid does run… the govt, and they will make stupid laws against devices unless there is a level of self imposed responsibility.
- nine_k 3y agoYou mean, the meter should have stopped switching on until cooled, instead of frying? That might make sense. Trying to outlaw adversarial devices will not work though.
- cesarb 3y agoThe Flipper Zero is already banned in Brazil by Anatel (the Brazilian equivalent to the USA FCC): https://www.techtudo.com.br/noticias/2023/03/anatel-barra-flipper-zero-no-brasil-aparelho-clona-nfc-e-rfid-edmobile.ghtml https://www.techtudo.com.br/noticias/2023/03/anatel-barra-fl...
- anilakar 3y ago> The specialness is how easy it is to use. Citation needed. Since the advent of cheap SDRs and TI CC1100 devkits it's been a case of "grab code off Github and go do shenanigans". The only specialness here is that it's battery powered, but even previously you could have been running a laptop and HackRF in your backpack.
- aaron695 3y ago[dead]
- diydsp 3y agoIt used to be grab code, laptop and backpack... a modest barrier to enty. Now any jamoke can dl a firmware and conceal this in a pocket and go wild. That's "easy to use."
- closewith 3y agoFor a Linux user, you can already build such a system yourself quite trivially by getting an FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem. From Windows or Mac, this FTP account could be accessed through built-in software.
- hexfish 3y agoWrong thread?
- wongarsu 3y agoIt's the top comment from Dropbox's announcement thread on HN, 15 or so years ago. It has become meta-commentary both about HN's cynicism, and that you don't need to do something novel to create a new product category, it's enough if you just make it a lot more convenient than anything before.
- vhcr 3y agoThis reads like the infamous Dropbox comment, with the Flipper Zero you don't even need to grab code off GitHub, you just have to open a menu and press some buttons.
- salawat 3y agoI hate these types of arguments, as they boil down to "I'm afraid of what you'll do with $nice_thing. I don't want to live in a world of max pessimum.
- rocqua 3y agoI'm not arguing the flipper shouldn't exist. This kind of potential ruin will be required to get manufacturers to wake up to the risk of bad radio security. I was arguing that this real-life example of impact is actually important for showing the impact of bad radio security, by putting dangerous tools in the hands of the masses.
- PietdeVries 3y agoWhy would a power meter allow an unauthenticated client to turn the thing on and off wireless?!? Sure, if you flip a switch handling a large current often enough, something will break (and I am impressed it's not the AC in this case). But why does the power meter accept commands from something 'outside', something untrusted?
- number6 3y agoBlaming this on any device other than the smart meter is disingenuous.
- bayindirh 3y agoWe don't know whether the meter accepts every command, or the device has a fixed security protocol reverse engineered and known by researchers. These protocols exist to get current readings from meters for data retrieval ease, and generally have a combination of security through obscurity and simple authentication to enable mass readings (by authorized people) easier. IIRC, these things can talk P2P in densely populated areas, and you can get all meters' readings in mere minutes, tops. In any way, after and initial PoC, the rest of the video gets into territory of equipment abuse, and I got angry and sad while watching it. You can do it, OK, then why damage things which are not yours? Document your findings and leave.
- ziml77 3y agoThat also made me angry to watch. He knew what he was doing and got the result he was hoping for. I hope his electric company is aware of what happened. The serial number and electric company name are both clearly visible in the video.
- pixl97 3y ago>can do it, OK, then why damage things which are not yours? Because your a terrorist or an AI looking to destroy mankind? You're drifting off into is/ought territory in why people do things and that is something that is very difficult to predict and control.
- deleted 3y ago[deleted]
- AviationAtom 3y agoSome very cool videos from lineman showing high voltage air switches opening under even a reduced load. I think most folks don't understand electric components don't like being manipulated under a load.
- diftraku 3y agoAt the same time, I'm in awe and in horror of seeing those high current, high voltage disconnects being opened only to end up with a few meter high arc of current jumping through the air between contacts. I was taught the procedure of disconnecting a 10/20kV disconnect for an on-site transformer (alas, only an old one that had been decommissioned) and that thing scared the crap out of me when I first heard the spring loaded high voltage disconnect actuate. Having a 3 meter fibreglass pole to actuate the thing, just incase, tells you there is a real risk of the thing blow up in your face, on a good day.
- dreamcompiler 3y agoFor any remotely-controllable power meter, its contactor switch should have been designed to sync with the zero crossings of the AC waveform. That would have completely prevented this damage. I know it would have made the meter more expensive, but it was absolutely forseeable that a wild RF signal could have induced repeated contactor reclosings. They should have built it properly.
- weare138 3y agoExactly. They probably could have done the same thing if they just kept throwing the main breaker.