The Canadian government plans to ban the Flipper Zero and similar devices after tagging them as tools thieves can use to steal cars.

18 points

If you can steal a car with a Flipper Zero, then this is definitely not the fault of the Flipper Zero.

permalink
report
reply
15 points

Solving the problem forever!

permalink
report
reply
62 points

Lol. You better just ban all programmable boards then, because the Flipper doesn’t have any special proprietary or differential tech in it. It’s just a clever collection of already existing hardware and software. Someone will just make another immediately. Idiots.

permalink
report
reply
1 point

If they knew that, they wouldn’t be banning the device instead of going after the car makers to make the cars more secure

permalink
report
parent
reply
12 points

I don’t disagree with your point, but the flipper zero for sure lowers the bar of entry. Before the flipper came out the, “You must be this tall to ride” required some pretty good knowledge of microcontrollers, hardware peripherals, and software engineering. The people that had that sort of knowledge tended to actually have paying jobs, which is like the biggest factor in not being a street criminal.

The flipper made the barrier of entry at about the level of being able to operate a TV remote which any dipshit can do. However, the fact that the flipper exists at all means that the cat is out of the bag. As you said, someone else is just going to come along and release a similar product. You can’t just ban the flipper and expect it to have any impact. My concern is they will decided to make certain code illegal, which gets really stupid.

permalink
report
parent
reply
8 points

Barrier to entry to do what? They can’t be used for vehicle theft because you can’t replay attack a rolling code, which is what all vehicles use.

The current attack is to use a repeater to amplify a fob that’s close enough to an outside wall to hijack and open these “get close enough and the doors open” locks.

permalink
report
parent
reply
2 points
*

Ask Kia/Hyundai owners how it can’t be used. There’s for sure cars that are susceptible to this attack still driving around, and the barrier to entry for executing the attack was lowered substantially. It’s like if you made an out of the box pentesting tool that was highly effective at breaking into vpns, identifying high value targets, and downloaded those high value database’s data at the click of a button.

https://nvd.nist.gov/vuln/detail/CVE-2022-37418

https://www.caranddriver.com/news/a43941743/hyundai-kia-vehicle-theft-settlement/

https://www.theverge.com/23742425/kia-boys-car-theft-steal-tiktok-hyundai-usb

permalink
report
parent
reply
1 point

The Flipper is literally just an ends to a means. An easily accessible action for hardware. Nobody is stopping any random person from buying a number of $3 dongles for their laptop and using it in the exact same way.

permalink
report
parent
reply
0 points

Yes but the flipper requires zero base knowledge to use it whereas setting up the hardware, installing the software, and troubleshooting any issues takes about the same amount knowledge as a helpdesk gig in IT. Again, I don’t think making them illegal does shit. I do think it’s rather obstinate to not acknowledge that the barrier for entry to execute those attacks was lowered substantially by the flipper though.

permalink
report
parent
reply
-2 points

Bar for entry wasn’t really that high to begin with. There were already a collection of tools that did the same thing, and could be had for a couple thousand bucks. Yeah, a price point 1/10th the older option is more accessible, but it’s not like criminals are hurting for money just because they are criminals.

permalink
report
parent
reply
1 point

I’m onboard with that but putting it at the level of operating a tv remote really casts a wider net. You essentially have to be barely literate to use the thing, where before you had to at least be able to read and execute some walkthroughs. Also you had to kind of be in the security/tech scene to even understand that it was an option, where the flipper has, for a lack of a better word, popularized the attack.

There’s a reason that when you go on sites like exploit db well over half of the exploits require some fiddling to make work. Metasploit is similar as well because it requires you to actually be able to use a cli on some level. While that isn’t a huge bar of entry, it’s still keeps the riff raff out for the most part. The flipper pretty much said fuck it, and let not only the skiddies in, but any dipshit with $80 buy a car stealing autopwn.

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
reply
2 points

I’m definitely getting one. Canada is overreacting as most cars use rolling codes, but I have a shitty old aftermarket system and it should be possible to either A) Use it to unlock my car outright or B) program my car to accept it as a second remote. My car locks itself while running if you close the door, with this, I could (hopefully) heat up my car in the AM before driving to work, then just use this to unlock it! And if my fob’s batts die it’s less inconvenient until I can get the stupid AAAA batt or whatever it takes. Also gonna test my mom’s garage door and use it if I can, and find out if my RFID blocking wallet works, and who knows! Might fuck around with some RFID too, gonna check my pet’s tags, they might tell me my cat’s temps!

permalink
report
parent
reply
17 points

Fucking Canadian Idiots.

permalink
report
reply
2 points

Laughs in healthcare

permalink
report
parent
reply
1 point
*

We’re not keeping that advantage for long. Conservative provincial governments all over Canada are working to turn our healthcare into the privatized US system, and they’re about to have allies in the federal government.

permalink
report
parent
reply
-2 points

Laughs in MAIDS.

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 12K

    Posts

  • 554K

    Comments