Today I want to talk about a hot topic that has been on the rise in regards to Cyber Security news lately, even prior to its official announcementโฆ THE BANNING OF THE FLIPPER ZERO!
๐ Article ๐ Glossary ๐ Catalog ๐ Home ๐ Search ModeToday I want to talk about a hot topic that has been on the rise in regards to Cyber Security news lately, even prior to its official announcementโฆ THE BANNING OF THE FLIPPER ZERO!
I'll be discussing the following topics in order: ๐ Premise ๐ What is the Flipper Zero? ๐ Banning it prevents it? ๐ Itโs not the Flipper Zero, Itโs our lack of Security ๐ Cyber Security Is A Game of Chess ๐ How to prevent automobile theft via the Flipper Zero (IN THEORY) You can click on any of the topics to simply check that one out if it interests you! NOTE: Articles are read from LEFT to RIGHT via 2 columns! Read the first column all the way down and then move to the next one!
Here's a quick run down on all the main links that are in the article in case you want to check them out first. ๐ LinkedIn Version ๐ CTF Server ๐ Hack5 Tool
Itโs no speculation that a lot of the news surrounding it lately was going to lead to its inevitable ban in the U.S. The tool is so popular in regards to what itโs being used for, that it could potentially be banned on a global scale, as itโs also in the process of being banned in places like Canada that also see it as a threat.
For those that donโt know, the Flipper Zero Tamagotchi is being used for motor vehicle car theft. The tool is so seamless and easy to use that even people that donโt understand anything about hacking could pull it off, hence its ban being set into motion. Butโฆ What if I told you itโs pointless to ban it?
I want to talk about why itโs pointless to ban the Flipper Zero, as well as some basic things that could be done to prevent motor vehicle car theft with it, as well as other methods similar to it.
I also want to talk about how Cyber Security is a game of chess, and how it is meant to be played to deter Cyber threats.
The Flipper Zero Tamagotchi is a multi functioning tool that is able to intercept, clone, and replay various data communication methods specifically tailored to Radio/RF and RFID/NFC. This allows it to clone any form of authentication credentials that might pertain to the end user, allowing a threat actor to bypass security and access the system.
In simpler terms, itโs able to clone the unique signature and data that is exchanged via remote control, such as a automobile car remote that unlocks the car door for you, or via RFID/NFC device tap, which exchanges data when you tap things like your ID badge to access a control room for example. It can even be simpler things like the NFC chips that are installed on our debit/credit cards, or our phones when we โtapโ it to make purchases on a regular basis or access various facilities like storage units. An attacker could use this to: break into your car, purchase things on your behalf, access control systems and authenticate as if they were you, and a lot more. The list goes on!
This technique is also what is known as a Replay Attack, which is commonly used to intercept crypto keys in order to perform a Wrapping Attack that allows an attacker to man in the middle and change the overall contents of the data that is being exchanged as if they were the original sender, while using the key to peek and do so each time.
If you ban the Flipper Zero then you have to ban every hacking tool that exists
There are a ton of hacking tools on the market, even ones from Hack5 that also can do what the Flipper Zero does. To ban the Flipper Zero, means to ban all these tools as well.
Take For example the HackRF One which can also analyze RF frequencies for various purposes like the Flipper Zero and imitate them. Itโs been around long before the Flipper Zero was ever made and it has yet to be banned. The only difference between the two, is that one is more accessible than the other. If thatโs the case, then we need to upgrade our security so silly stuff like this DOESNโT happen. Rule of thumb, IF A SCRIPT KIDDIE CAN PWN IT, ITโS A PROBLEM!
Besides, itโs easy to make your own Flipper Zero if you're skilled enough to do so. You can even name it whatever you want and bypass the ban. The Flipper Zero isnโt anything we havenโt seen before, itโs just cute and popular!
The problem isn't the Flipper Zero, itโs our lack of proper understanding of security practices that can be used to effectively neutralize the threat.
Itโs no shocker that the implementation of Cyber Security practices are just now becoming a standard, with legal aspects cracking down HARD and punishing infrastructures for not implementing it, via fines and other means. This is because we are moving closer and closer to a more digital landscape where everything is connected, which is good news for hackers, since it extends the scope and range of what they can target now more than ever.
Security has been one of the many things ignored for far too long. Itโs the main reason why we have so many security breaches. Most systems, even basic stuff like web applications, donโt factor security in terms of overall design. Itโs our job to ensure that anything and everything is properly secured regardless of what format said technology comes from. This also includes automobiles, which is the main topic for today since it relates to the Flipper Zero Tamagotchi.
The problem now is that we are just now catching up, while hackers have already done their homework and pretty much can stay ahead of the game. We need to do the same!
Cyber Security is a game of chess. What do I mean by that? I think the best example would be the classic one I provide a lot in my articles, my CTF server, โFutabaโs Playgroundโ.
When I made the CTF server I basically had to โplay this game of chessโ, where I had to think several steps ahead of the player as they progressed throughout the game as if they were a โrealโ adversary. I had to think of all the possible variables of what the player could do to bypass my security and cheat the game.
For example, I ran into an issue where the player could easily access critical files on the server that would allow them to capture flags in unintended ways. This could easily be done via the browser, as well as ssh shells which are intended for the player to progress. This is a HUGE no go, so I needed to put a stop to that pronto.
My thought process to upgrade security was to figure out how to block easy web application access to the files, while also blocking ssh system command access to the files, and on top of this, I needed to make sure the server account hosting the web application could still read the files, while also ensuring the player could progress. Still with me? I know, this was a major headache for me too and took a lot of trial and error until I got it right!
The remedy for this was to: set the files on the server to ownership of the main account that reads it, that way only it and root users can access it. Root access can only be done on the final stage of the game, so by the time the player manages to get to all the files it will already be too late. See what I did there? I did a lot more, but of course, NO SPOILERS!
In theory, and itโs quite simple, the best way to prevent automobile theft with the Flipper Zero is to implement the same methods that prevent Replay Attacks in general: splitting the data channels so that authenticated credentials to unlock the motor vehicle are not sent alongside each other. You can even layer frequency randomization on top of that much like with wireless access points to throw the tool off, that way it misses its target. These little things can hurt the effectiveness of the tool greatly.
I donโt specialize in motor vehicle security, but Iโm pretty sure there are a ton of other methods that can prevent the Flipper Zero from hacking into car systems. We just need to implement the security in place to do so!
If you have any other ideas that could improve motor vehicle security, feel free to drop your thoughts bellow in the comment section. Iโd love to hear your own thoughts on the matter?
If you enjoyed this post give it a thumbs up! Iโll be keeping track of whose reacting from now on as there is a โspecialโ reason for it. Just know the more you support my content the more there is in stored!
- The Hacker Who Laughs ๐ธ๐ธ๐๐ธ๐ธ