19 ms·
Edit store price tags using Flipper Zero
- voidUpdate 5mo agoI still don't think I've seen an actually useful application for a Flipper Zero. It's all just "use this to change store price tags" or "here's how to disconnect all bluetooth devices", but also "don't actually use this, because it would be illegal, this is just for educational purposes"
- cucumber3732842 5mo agoIt's useful for dealing with the industrial equivalent of IOT garbage
- avian 5mo agoThis one provides the source and asks you to build it yourself so at least it has some credibility for the "education use only" claim. I've seen similar things posted on here before that had a binary build only and zero technical documentation. It was really hard to see any kind of research or education value in those.
- rjh29 5mo agoTurns out it's what they said it was all along, an educational device.
- rickdeckard 5mo agoBeside of how the media often tries to present it, the value of Flipper Zero is not for everyone to "become a hacker with this simple app". Its value is to provide a standardized hardware platform for (white hat) hackers for probing, prototyping, refining and sharing of security research in the fields its hardware supports (Sub-GHz RF, NFC, IR, and custom external boards via simple Input/Output pins). Prior to that, everyone who wanted to research e.g. RF security had to either build/assemble something custom or buy much more expensive equipment. This created a barrier to collaborate on research, as everyone had to buy/build the same setup. On top of that, Person A researching some RF topic selected an RF-transceiver from Company X, Person B used a component and a proprietary SDK of Company Y, so consolidating both work streams for a better foundation for all RF-related research required alot of time and effort from someone, breaking workflows of at least one group of researchers, etc. In contrast, security research which utilizes Flipper Zero can be reproduced and built upon by everyone. All the work is harmonized on the same Hardware architecture, so it's easy for someone familiar with the platform to dive straight into a new idea without having to build a new breadboard, select a chipset, buy additional probing equipment etc.
- kotaKat 5mo agoI'm tired of the "security research" angle when it's all just kids playing with ESP32 deauther attacks presented to them on a silver platter. I should not have to put up with children going "JUST SECURE YOUR NETWORKS BRO" because they spent $30 on some eBay "maurauder" dongle to be a pissant.
- StingyJelly 5mo agojust secure your networks bro
- lan321 5mo agoIt's probably good to have kids with no big plans messing with your security now and then. Keeps you on your toes, and you can't really pass it off as an act of god if a teenager pwns you.
- rft 5mo agoAnd a minority of those kids will get curious about the How and Why. Those are the security nerds of the future securing the networks against both the kids they were themselves and actual malicious actors. Source: Early interest in wifi security, including in other people's networks, lead me down an education and career in security
- gausswho 5mo agoHacker News. Where you either die a pissant or become the villain with a fistful of RSUs.
- kotaKat 5mo agoI sure wish I was wealthy and had a fistful of RSUs. You wanna send me some? I make 5% over my area's 80% median income and I can't even get housing because I "make too much money" despite being $3000 too rich. I'm pretty tired of being the network guy in the field playing remote hands having to be on the front lines of all of this bullshit having to explain to decision makers that a bunch of shitty kids are running around and there's no real solution that we can just "fix" this with. I'm tired. If they're not deauthing our networks they're breaking into rooms with the goddamn card copying and fuzzing functionality and stealing shit.
- OuterVale 5mo agoI use mine for all sorts. I volunteer at a second-hand shop so use it to set up remotes for donated media devices, I've used it to run scripts to apply the same changes to many computers that aren't on a group policy via BadUSB, I've used it for toys-to-life games, and very much more. There are plenty of genuine uses if you're cluey.
- imp0cat 5mo ago[flagged]
- master-lincoln 5mo agoAs if devices created in Russia would all be "useless" or only for illegal purposes. I smell prejudice
- imp0cat 5mo agoWhat? Obviously, they are not useless, it's just that it's way easier to skirt the law there. And when I say skirt the law, I mean blatantly ignore.
- estimator7292 5mo agoCool racism bro
- vbezhenar 5mo agoYeah, I bought it and it collects a dust since then. Fun device but I have no idea how to use it in my life.
- tamimio 5mo agoIt’s been very useful to me in so many ways, from fob management, to one IR, to rf scanner and other stuff, it’s useful if it fits your needs, just like anything else out there.
- hughNala 5mo agoYou just aren't being creative enough, I use mine daily: 1. TOTP generator 2. As an extra garage door opener to let guests in from my desk 3. To avoid typing my long WiFi password in while setting stuff up (ducky or qr code) 4. Wrote a custom app that suggests meals/ restaurants so when the wife asks what we should eat this week I can just rattle off the random suggestions Not to mention other random things on a less often basis
- bombcar 5mo agoThis right here would be useful once these price tag things start being thrown away. Times change and systems get updated and if you keep your eye out you’ll likely be able to get a handful cheap.
- paradox460 5mo agoI use mine as a presentation remote, and as a USB interface for some micro controllers. Sure, I could buy a dedicated remote, or a bus pirate or other programming device, but I already have the flipper, so it suits me fine
- stavros 5mo agoI am overjoyed to see this story here, we haven't gotten a lot of these hacks lately. Well done!
- encom 5mo agoHacks? In my Hacker News? The nerve!
- weli 5mo agoThis is pretty dangerous. At least in my country the displayed price must be honored and they cannot refuse the sale.
- rickdeckard 5mo agoUsually the advertised price must be honored, because it may have brought the customer to your store. For prices displayed on the shelf-label inside the store the law is usually not that strict (YMMV), as a shop-owner can refuse sale on check-out (otherwise I could put a pricetag on e.g. a shopping-basket and the shop-owner would be legally required to sell me the basket...). Besides, most shops I've seen (in Europe) already moved from Infrared communication to RF (NFC or proprietary), for centralized shelf-label management without handheld devices. So all this study (and the underlying reverse engineering of the IR-protocol) might do is probably accelerate the transition from IR to RF-based ESL...
- rimunroe 5mo ago> Usually the advertised price must be honored, because it may have brought the customer to your store. This is not the case for groceries in Massachusetts at least. If there’s a discrepancy between the tag’s price and the scanned price the store must charge the customer the lowest of the two: https://www.mass.gov/price-accuracy-information https://www.mass.gov/price-accuracy-information
- stevekemp 5mo agoI recently learned that in some cases fines of mispriced goods were very low, leading to companies repeatedly failing tests - and over/undercharging their customers. https://www.theguardian.com/us-news/2025/dec/03/customers-pay-more-rising-dollar-store-costs https://www.theguardian.com/us-news/2025/dec/03/customers-pa... That seems shocking to me, but I guess I live in a country where the prices on the shelves are "final" (with no need to add taxes) and I think it would be immediately obvious if I'd been charged the wrong price for goods.
- devilbunny 5mo ago
- Aboutplants 5mo agoI was in college when self checkout became a thing and it took us all of about 45 seconds to realize that you could just check everything out as bananas. Steak was weighed and priced at 4011 (banana code) as the stoned teenager cashier paid no attention. Everything on the receipt was literally Bananas
- stavros 5mo agoCouldn't you also not just check stuff in? These are all obvious drawbacks, it's not really a high-scrutiny environment.
- manarth 5mo agoMost self-checkouts I've come across have weight validation – "Unexpected item in the bagging area". Categorising things as "bananas" tricks the checkout into accepting the weight of an item, and you pay the appropriate price per bananagram.
- junon 5mo agoThis is a more expensive form of shoplifting though, idk why even bother with the banana thing, as hilarious as it is.
- manarth 5mo agoPresumably there's a slightly lower risk of getting caught, as casual observation suggests a normal shopper paying for their groceries.
- stavros 5mo agoAgreed, but there's nobody looking if you're putting the items in the bagging area or not. You could simply leave an item last, pay, put it in the bag, and go. They do have (prominent) cameras over the tills I've seen, though, not sure if that's just "we see you" or if they're doing some item recognition with that.
- 5mo ago
- comrade1234 5mo ago[flagged]
- DoctorOW 5mo agoI wonder if since IR is invisible you could theoretically, in an intellectual exercise, blast IR light in a room and mass change them surreptitiously if that was your goal.
- ac29 5mo agoFrom the upstream project: > Can I change the display of all ESLs in a store at once ? No. For two reasons: Unlike radio waves, optical communication must be line-of-sight. Even from wall and ceiling reflections, an unique transmitter has no chance of reaching all of the hundreds or thousands of ESLs in a store. Each ESL has an unique address which must be specified in update commands. There's no known way to broadcast display updates.
- sva_ 5mo agoNot bringing politics into every discussion challenge: impossible
- petterroea 5mo agoIt's always funny when people publish source code and have a disclaimer saying "You CANNOT use it for bad!". When is the last time a criminal read such a disclaimer and thought "Oh right, guess this isn't for me"? Sure, at least the developer can say they did say so, but it doesn't matter. To me it seems more like avoiding responsibility. You published the tool, and by doing so you changed the world, even minutely, and in ways you cannot predict. As hackers we bear the responsibility of tools we publish. Even if you believe knowledge is the most important and that everything _should_ be published, we should at least be well aware of the consequences. Great power, great responsibility.
- kimos 5mo agoI think it’s trying to demonstrate intent. “This is cool and hacking is fun” vs “Here is a tool to do bad things”. I don’t think it would much protect you from consequences, but it can change perception of the intent of the project.
- petterroea 5mo agoI think you are right, it just feels useless.
- kimos 5mo agoMaybe! It won’t change liability. But perception is important too.
- hrimfaxi 5mo agoWhat would you prefer they say?
- estimator7292 5mo agoPresumably they want nobody to ever publish or even explore "bad" things. Because as we all know, if something "bad" is possible, but no one has published a GitHub about it, no one will ever be able to do the bad thing! Society is saved at last!
- fennecbutt 5mo agoLmao more flipper zero crap. I'm sorry, but I'm so sick of seeing "omg hacker man" mystique surrounding flipper, which is exactly what they want because it drives sales. Ofc you can muck about with open and unsecured stuff...like duh. But it annoys me to no end when I have reasonably intelligent friends parrot claims like "flipper can clone the nfc in your credit card and you can steal people's money wow much hack!"
- jlongr 5mo agoThat's just you, bud.
- fennecbutt 5mo agoNot your buddy, pal. ;3
- madebysnacks 5mo agoNot your pal, friend
- imp0cat 5mo agoInfluencers gonna influence.
- mswphd 5mo agokind of a circular argument though? the reasonable definition of "unsecured" is "stuff you can't muck about with". That might change over time as attacks/exploits are developed though.
- HoldOnAMinute 5mo agoI'd like to buy some of these tags and use them as displays around my house.
- jmux 5mo agoLook into openepaperlink. It’s an open source project that integrates with home assistant, and lets you control multiple tags over WiFi with just one device. you can create custom display setups in yaml to show anything you want. my favorite that I have set up is a tag in my bathroom that shows me today’s weather and chance of rain when im brushing my teeth - I haven’t been caught by surprise in the rain since :)
- ornornor 5mo agoVery neat! Where did you acquire the tags and for how much?
- data-ottawa 5mo agoI’m very surprised here. I worked in retail many years, including doing store shelf tear downs and replacement and night shift stocking. Back in the day we would get our planograms from HQ, then we’d print out all the labels on perforated paper, and walk the shelves moving product and updating the price tags, throwing out the old. The epaper tags are very clearly an improvement to that process in both time and waste. We would also check the prices using a Motorola price gun and do our fixes manually and then print out new tags or update the counts. I’m surprised these tags are just IR blasted with no security. I would have expected they’d need some sort of code and you would simply save the code on your gun, pop a tag in front of a product, scan the product, then pair the tag all on your price gun in like 3 actions. I also would have thought in these days we’d use Bluetooth beacons to triangulate the shelf slot too so that HQ could have a realtime map against their planos (it was not uncommon a product’s size would change and the layout would have holes or products that don’t fit on your real shelf). Anyways, neat project! Triggered a walk down memory lane for me.
- ssl-3 5mo agoIt doesn't really change anything. Previously, a criminal could just print their own shelf tags. They'd probably do this somewhere other than in the store to get the details right, but it was doable. (We've all probably seen rolls of blank shelf tags sitting around at the store, and thermal printers are inexpensive. So what if it's two crimes instead of one?) And then, in the store, they could just switch out the shelf tag(s) and try to play their little scam. Now with this new development, a criminal still needs to get the details right. Like a blank paper tag, the little screen is also a blank slate. It's just eraseable and rewritable in-situ. The scam is the same. It's just shaped differently. --- I do understand why the tags are simple to write. Maintaining some kind of revolving, PKI, or multi-factor auth would be harder than doing nothing, and probably slow. Fixed, basic auth would just get leaked (probably first by Home Assistant tinkerers who find some discarded electronic shelf tags somewhere and want a new display for their house). One-way jnfrared is cheap and low-power compared to anything with RF. And resets would be a pain in the ass if things were forever associated with a certain product, or a certain place in the store. The way it's implemented now, on reset (yay new planogram!): All the tags get pulled and put in a pile. And then: One by one, they're removed from that pile, put on a shelf, and programmed. That's fast and flexible, and therefore inexpensive. Inexpensive is good. If there's one thing that all retail establishments hate most, it is their labor expense. It does fail to prevent obvious-scam from happening. But it'd probably cost more to do it "right" than to eat the losses when the scam actually works.
- HDBaseT 5mo agoThey are incredibly easy to break with your finger. We do not want a world full of hyper-dynamic pricing, we should destroy these.
- deleted 5mo ago[deleted]
- renewiltord 5mo agoI use a similar trick with most software. Instead of buying the online one, I get it on The Pirate Bay. These days even open source software you can simply just apply Claude and get a different version. People online will kick up a fuss about GPL and shit but in real life no one bothers. Shoplift. Close an OSS project. Who cares. Sometimes I even ride without a ticket. In Europe/Asia especially if you act like clueless American they’ll let you off every time. Done it so many times haha. Some of these places even they will put fruits outside. You can just take extra and hide it. They can’t tell. One time on drive to Bury St. Edmunds small town in the UK I saw a little farm shop with some sign saying to leave payment there. Zero enforcement. I just took the fruits. No flipper zero needed. Good life hack. Social hacks like these are not so common but if you’re clever you can get a lot.
- zbentley 5mo agoIn some specific instances, this approach is clever. Taken as a general philosophy, it’s regrettable, harmful, unethical. https://en.wikipedia.org/wiki/Tragedy_of_the_commons https://en.wikipedia.org/wiki/Tragedy_of_the_commons
- renewiltord 5mo agoYou can't Categorical Imperative me. I'm a hacker.
- zbentley 5mo agoyou kant hack me, I don't use computers
- uhfraid 5mo agoMore often than not, they’re aware but let it slide because they pity you
- renewiltord 5mo agoYeah, that's the social engineering part. It's a hacker trick. "Cmaan, I'm a little guy I'm a little birthday boy" https://x.com/eshear/status/1941696051884458278?s=20 https://x.com/eshear/status/1941696051884458278?s=20
- xkcd-sucks 5mo agoA lot of discussion about self-checkout fraud, but these tags are only for shoppers' convenience and don't control pricing - One tag goes in front of that SKU on display so you can see the price. At checkout, a barcode or plain old paper tag / printed barcode on the item itself gets scanned and that's where the price is looked up.
- F7F7F7 5mo agoYou've never been to a grocery store and had something incorrectly 'rung up'? It's happened to me more than a few times and I've never had a problem getting a "price check" and having the item adjusted according to the shelf label. It's typically in-store policy. Is Best Buy going to let you walk with a $10 Sony FX3 camera? Probably not. Are they going to fight you over a $10 difference in posted vs look up? Probably not. From what I remember Connecticut laws used to require retailers to charge the lowest advertised and/or physically labeled price.
- invalidSyntax 5mo agoThis is cool and all, but how am I supposed to test it? Get permission at a local store? No way they will let me do it.
- jeroenhd 5mo agoYou can buy tags like these from the internet, either via shady second hand stores or directly from the same Chinese resellers supermarkets probably use.
- chithanh 5mo agoIt's interesting how the README.md basically states in every other paragraph how you should not use this without authorization. The term (un)authorized and variations appear 18 times in there.
- traceroute66 5mo ago> Usually the advertised price must be honored, because it may have brought the customer to your store. No. In most jurisdictions this is covered by Contract Law 101 that lawyers learn in year 1. A contract only forms when you have an offer, acceptance, consideration The price on the shelf (or shown on the website or in a catalogue) is known as an “Invitation To Treat”. “Invitation To Treat” means you are inviting the customer to come to you and make you an Offer. There is no obligation on the business to sell. In the case of a supermarket in the context of this discussion, the agent scans the barcode, and the "real" price is displayed on the screen and added to your bill. This is the "Offer", the business is saying "we are willing to sell you this Tomato at this price, take it or leave it". If you don't say anything and pay and leave, then "Acceptance" has occured and the "Consideration" is the act of payment itself. (N.B. IANAL, so my description might not be precicely textbook, but that's the broad concept).
- tylervigen 5mo agoThat is common law, but many jurisdictions have specific regulations related to this. E.g.: https://www.nist.gov/system/files/documents/2017/04/28/US-Pricing-Laws-All-States_2.pdf https://www.nist.gov/system/files/documents/2017/04/28/US-Pr... I don't know whether "usually" is accurate though; it may be that common law prevails as you say in most transactions despite the states with regulations.
- traceroute66 5mo ago> it may be that common law prevails as you say in most transactions despite the states with regulations As already mentioned IANAL, but I would take an educated guess as follows: The specific regulations to which you refer are in effect consumer protection regulations. Ergo, they are there to protect the consumer against malicious behaviour by unscrupulous traders such as false or misleading information. Any reasonable judge in a courtroom will likely agree that incorrect display of pricing on a shelf (or website or catalogue) is (in the absence of evidence to the contrary) likely to be an inadvertent error with no malicious intent. And therefore the common law would prevail.
- Cluelessidoit 5mo agoI knew this was coming. It was a huge topic on r/hacking for a lil bit
- deleted 5mo ago[deleted]