5 ms·
I got one not too long after the official launch and I've used it a decent amount (granted I am in cybersecurity and have a more real-world use cases then the a
by tkems 3y ago
I got one not too long after the official launch and I've used it a decent amount (granted I am in cybersecurity and have a more real-world use cases then the average person). My favorite use case is the IR remote since phones no longer have IR blasters. It's saved me twice so far in having to buy/find a remote for something.
One thing people don't realize is that the custom firmware [0] that you can run allows you to receive and transmit on a wide range of frequencies under 1Ghz. Lots of things use that range (garage doors, gates, fan remotes, etc.) and are not very secure. I think that this will be a time looked back on where it's possible to interact with those devices without having to buy a custom PCB transmitter or somewhat expensive and complex SDR.
[0] https://github.com/DarkFlippers/unleashed-firmware https://github.com/DarkFlippers/unleashed-firmware
- dheerajvs 3y ago> phones no longer have IR blasters Plently of phones still do [0]. I've configured mine to operate all my devices at home. [0] https://www.gsmarena.com/results.php3?nYearMin=2023&chkInfrared=selected https://www.gsmarena.com/results.php3?nYearMin=2023&chkInfra...
- BossingAround 3y agoIn other words, Chinese brands still have IR blasters. I don't know I would trust Chinese-brand of phones though.
- sofixa 3y agoWhy not? Most phones are manufactured in China anyways, and Xiaomi, OnePlus, Honor, Oppo are major and very widely popular and used brands all over the world (outside of the US which is allergic to Chinese brands unless it's for cheap crap or to outsource manufacturing to).
- dangus 3y agoOutside of the US is a problem when it comes to availability and usability. I’m not going to buy a phone that doesn’t play nicely with my carrier or receive regionally relevant support. OnePlus is the only brand on that list that makes sense buying in the US. (Personally I can see why the IR blaster was removed as a feature in US phones. I can’t think of a time I wanted or needed it. How often are y’all losing remotes? My current remote doesn’t even really use IR for anything since the streaming box is controlled by Bluetooth and connected devices including the sound system are controlled by HDMI-CEC. My phone already controls the entire setup via a remote app that utilizes WiFi/Bluetooth).
- Telemakhos 3y agoI don’t have a television, and I haven’t owned anything with an IR port since the 2012 MacBook. I have zero use cases for IR blasters.
- devilsAdv0cate 3y ago[dead]
- hythythythyt 3y agoI've always liked Xiaomi. At home, we have several of their phones, a vacuum cleaner, and some shoes (yes, shoes!). But a few months ago, my Chrome homepage changed to a Chinese search engine, and after looking online, it seems it was a Xiaomi error that affected quite a few people. Also, they include ads in their customization layer. This will be the last Xiaomi device I purchase.
- chpatrick 3y agoIn terms of functionality they're night and day compared to Western brands which seem to just enshittify their devices while raising prices. They're all made in China at the end of the day.
- JKCalhoun 3y agoYou just need a small Bluetooth-enabled box sitting on your coffee table near the TV that has an IR transmitter and a paired app on your phone that can send commands to the box. Edit: I had only search and one did appear: https://www.amazon.com/PUCK-Smart-Universal-Remote-Model/dp/B07HB4PF9S https://www.amazon.com/PUCK-Smart-Universal-Remote-Model/dp/...
- copperx 3y agoUniversal remotes are still a thing, and much cheaper than that or a Flipper Zero.
- dylan604 3y agoyeah, but you have to be line of sight for a universal remote to work. the app enabled IR box means you can be anywhere within range. that does have its advantages. also, being in the kitchen while the remote is near the couch when your streaming platform of choice asks "Are You Still There?" means you can answer from the kitchen.
- dzhiurgis 3y agoSeems much cheaper than "infrared blasters" used for home automation
- CraigJPerry 3y ago>> or somewhat expensive and complex SDR I don’t think that’s as accurate today as it used to be. On the hardware side there are tons of options very cheaply available - iirc the flipper uses the c1100 (or a number like that) it’s a popular cheap chip and it’s well documented and interfaces easily with arduino. More accessibly, lime mini SDRs are cheap but there’s quite a few alternatives too. On the software side GNU Radio is free with decent tutorials - we’re not talking anything like blender levels of difficulty to adopt even if it is a complex domain. Although on the more accessible side, urh is incredibly powerful given how easy to use it is https://github.com/jopohl/urh https://github.com/jopohl/urh I used the latter to tap into a 2 channel wireless bbq thermometer via a $10 rtl sdr and that was a breeze, an absolute walk in the park compared to when I reverse engineered the flysky telemetry system.
- ale42 3y agoGNU radio is free, but what about the hardware you need if you want to transmit an actual signal?
- tiagod 3y agoAn HackRF clone is quite a bit cheaper than a Flipper, and it's a full-blown SDR with TX capability
- TeMPOraL 3y agoIt's not the TX hardware part that will be expensive - but rather bespoke encoding and crypto. Not prohibitively expensive, just annoyingly expensive in money and/or time - enough to prevent anyone except criminals from tampering with those devices. Or worse, vendors will use it as an excuse to make their products cloud-dependent, with strong cryptographic auth and actual processing done on the other side of the world. (And with that enabling the rent seekers their recurring revenue, we arrive at the reality foretold by IIRC Philip K. Dick, where you have to subscribe to your own apartment doors.) (EDIT: the more IoT embraces actual security, the more I feel that US gov had a point in classifying cryptography as munition. Perhaps there ought to be legal limits on using crypto against other people.)
- 3y ago
- elliottcarlson 3y agoThe batteries died in my bedroom TV remote a few nights ago, it wasn't until I went to replace them did I notice that one of the batteries had leaked and seems to have caused some corrosion on the contact, so until I clean it up I've switched to my Flipper Zero as the remote for it (just need power and audio control, rest is via a Roku stick). Never thought this would be my use case for it, but it worked out perfectly.
- petre 3y ago> one of the batteries had leaked and seems to have caused some corrosion on the contact A reason why I have switched to NiMH rechargables. They leak less often. I've also grown tired of recycling spent alkaline batteries. Also Energizer has no leak guarantee on some of their batteries. I've got the green ones, Recharge Universal. https://www.energizer.com/about-batteries/no-leaks-guarantee https://www.energizer.com/about-batteries/no-leaks-guarantee
- bookmark99 3y agoA friend got this for me, but I'm struggling to put it into any useful purpose, any pointers with things I can experiment it. Using it as a remote seems so cool, esp bc I lost my roku remote not so long ago so if you have any resources that could help I'd appreciate it. The documentation I've seen so far seems far and scattered and it seems people are more scared of being implicit in illegal activities based on their resources.
- spacecadet 3y agoGreat tool for learning Bluetooth Pen-testing. I run BTCTF-Infinity on an ESP32, powered through the flippers GPIO. It creates the BTCTF environment and I use the flipper to crack the examples. Kinda like a self-contained gaming handheld for BT practice.
- sbdaman 3y agoYou can buy a Roku remote for like $5.
- tkems 3y agoFor IR remotes, there are a few ways to go about it. If you have a remote you want to clone, you can just use the flipper to clone and map buttons to a custom remote. If you don't have the remote and have a common device (like TVs), I would check this repo on Github [0] and see if you can find a compatible IR file. Note, you need a micro SD card in order to move the files onto the flipper, but a small one works fine. I've had good luck with the basic universal remote when I'm in a pinch. Also, you can create custom IR files, but it can be a pain with encoding. The flipper forums are a good resource too [1]. [0] https://github.com/Lucaslhm/Flipper-IRDB https://github.com/Lucaslhm/Flipper-IRDB [1] https://forum.flipper.net/ https://forum.flipper.net/
- bookmark99 3y agosweet. thank you
- rft 3y agoSeems like there is at least a bit of interest [1] to convert lirc definitions [2], which is great, because there are so many of them. There even is a definition for my about 30 years old hifi! A really nice hack I saw is to send the code via something that reads lirc and capture it with a flipper in learning mode [3]. [1] https://forum.flipper.net/t/is-possible-to-convert-irplus-file-to-ir-flipper-zero-format/13650 https://forum.flipper.net/t/is-possible-to-convert-irplus-fi... [2] https://lirc.sourceforge.net/remotes/ https://lirc.sourceforge.net/remotes/ [3] https://github.com/Lucaslhm/Flipper-IRDB/pull/294 https://github.com/Lucaslhm/Flipper-IRDB/pull/294
- MuffinFlavored 3y ago> Lots of things use that range (garage doors, gates, fan remotes, etc.) and are not very secure. https://en.wikipedia.org/wiki/Rolling_code https://en.wikipedia.org/wiki/Rolling_code I didn't know this wasn't secure enough. I thought this was the basis of most modern vehicle keyless entry too? It is hard for me to not think of the Flipper Zero as a script-kiddie tool to do super illegal things like open your neighbor's garage illegally.
- tkems 3y agoWhile rolling codes can be secure (KeeLoq [0] is a more secure example but has it's own issues), this [1] is an example of some of the weaknesses that can happen if a rolling code algorithm is broken. I have personally been able to capture, decode, encode, and transmit garage door codes using that python script and a HackRF (which can also be done with a flipper and custom firmware). [0] https://en.wikipedia.org/wiki/KeeLoq https://en.wikipedia.org/wiki/KeeLoq [1] https://github.com/argilo/secplus https://github.com/argilo/secplus
- MuffinFlavored 3y agoCan you help me understand why rolling code attacks aren't broken on most cars but are broken for garages? Also, are attacks like this real/common/easy to pull off? https://youtu.be/1SUGf6OwRzw https://youtu.be/1SUGf6OwRzw Where the signal is amplified from the key inside the house to the car. How does the car/keyfob not detect it's signal/noise ratio or time for roundtrip is all messed up distance wise?
- tkems 3y agoFrom what I understand, cars are a bit more complex now then garages. KeeLoq, from my understanding, is not 'breakable' like garage doors. It does have weaknesses, but more related to the raw cryptography/math. Since KeeLoq is a cryptographic function, it can be broken by brute force or by gaining access to the manufacture key. For the amplification attacks, my understanding of them is that the key fob and car may be able to detect this kind of attack, but require more logic/software to do so. Also, most of these attacks use high frequency 'backhaul' wireless networks (key fob at 3-400Mhz, backhaul at 2.4-5 Ghz Wifi with lower latency) to prevent such timing/signal-noise from being detected. If I had to guess, most key fobs/cars are more focused on making sure the key fob works at range or in hard-to-detect environments and not focused on preventing such relay/amplification attacks. Also, some similar attacks to what you linked could also be done against Bluetooth (I think Tesla had this issue in the past few years) with a simple Bluetooth range extender/relay setup. (Note: without one of those devices, most of this is just guesses/what I've seen is possible/theoretical in terms of attacks)
- devilsAdv0cate 3y ago[dead]