Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Flipper Zero 'DarkWeb' Firmware Bypasses Rolling Code Security on Major Vehicle Brands

⁨162⁩ ⁨likes⁩

Submitted ⁨⁨2⁩ ⁨days⁩ ago⁩ by ⁨cm0002@lemmy.world⁩ to ⁨cybersecurity@infosec.pub⁩

https://cybersecuritynews.com/flipper-zero-darkweb-firmware/

source

Comments

Sort:hotnewtop
  • can@sh.itjust.works ⁨2⁩ ⁨days⁩ ago

    A significant consequence of this attack is that the original, legitimate keyfob is immediately desynchronized from the vehicle and ceases to function. This could be the first sign for an owner that their vehicle’s security has been compromised.

    source
    • Brunbrun6766@lemmy.world ⁨2⁩ ⁨days⁩ ago

      I think the first sign would be the stolen car

      source
    • IllNess@infosec.pub ⁨1⁩ ⁨day⁩ ago

      How does this work if a family is using two keyfobs? Does each one have its own rolling code?

      source
      • atrielienz@lemmy.world ⁨1⁩ ⁨day⁩ ago

        Technically, the other fob shouldn’t be affected if it works the way I think it does. There’s usually a maximum number of keys synced to the vehicle.

        This attack basically forces the key fob the flipper zero is substituting itself for to fall out of sync because the flipper zero doesn’t transmit the rollover response from the vehicle back to the key fob. So the F0 sends the rolling code it intercepted from the key fob to the vehicle. Vehicle is like, yep, that’s matches, and then it does it’s rollover and sends out the rollover response. The response doesn’t get back to the key because of range etc and then the key remains a step behind the vehicle in the rollover sequence from then on out.

        Technically I think they key could potentially be resynced to the car. (My understanding is that a key of the correct type could be synced to any car that it can be programmed for so long as the key isn’t physically damaged, and the security module isn’t compromised with malicious code that would prevent it).

        source
        • -> View More Comments
      • 9point6@lemmy.world ⁨1⁩ ⁨day⁩ ago

        Yeah I would assume there’s a maximum number of fobs you can register to an individual car and it just keeps the state for all of them individually

        source
        • -> View More Comments
  • aramova@infosec.pub ⁨2⁩ ⁨days⁩ ago

    Until I see proof of concept in action I’m going to be suspicious that this is as bad as the sensational headlines claim.

    Hysterica gets clicks, gets news coverage then turns into nothing more times than not.

    source
    • ArcaneSlime@lemmy.dbzer0.com ⁨9⁩ ⁨hours⁩ ago

      Talking Sasquatch did it to his car on video, it’s on his youtube.

      source
  • ExtremeDullard@lemmy.sdf.org ⁨1⁩ ⁨day⁩ ago

    I have tried to record / replay my FIAT keyfob with my F0, and it did unlock the car once. Then I spend a bunch of having the remote lock replaced.

    I’d like more evidence that this works reliably before attempting the same thing again…

    source
    • ArcaneSlime@lemmy.dbzer0.com ⁨10⁩ ⁨hours⁩ ago

      No, this would still desync your key. You in theory could maybe figure out how to pair it to your car as a spare fob, depending on what rolling codes fiat uses or how that pairing process works on fiats, but you’d have to set it up like that to not desync your regular fob.

      source
    • Typotyper@sh.itjust.works ⁨16⁩ ⁨hours⁩ ago

      So you’re saying if you don’t like someone you can unlock their car once. Sit back as they have a shitty day and are forced to replace their key fob.

      Then you can unlock their car one more time and their shitty day repeats itself.

      source
    • 9point6@lemmy.world ⁨1⁩ ⁨day⁩ ago

      Potentially misunderstanding but that’s exactly what this is, right?

      You recorded the code for a given unlock (I’m assuming out of range of the vehicle), replayed it, the car then rolled the code on to the next one and your replayed code was no longer valid and your existing fob didn’t know to rollover too, so was left out of sync.

      So yes I guess there’s the risk it hasn’t been implemented correctly, but adds the necessary functionality you were missing to accomplish this before

      source
  • viking@infosec.pub ⁨2⁩ ⁨days⁩ ago

    And people wonder why I use my key toget into the car.

    source
    • adespoton@lemmy.ca ⁨1⁩ ⁨day⁩ ago

      Why do you use your key toget into the car?

      source
      • four@lemmy.zip ⁨1⁩ ⁨day⁩ ago

        To get to the other side

        source
    • ArcaneSlime@lemmy.dbzer0.com ⁨9⁩ ⁨hours⁩ ago

      Never seen one of these, huh?

      (Amazon link, for those who’d like a warning.)

      source
    • CallMeAnAI@lemmy.world ⁨1⁩ ⁨day⁩ ago

      Because of some potential but low risk attack in the future that would be covered by insurance? Sounds like a posting in the ass for little gain.

      source
      • viking@infosec.pub ⁨1⁩ ⁨day⁩ ago

        I’m not going to deal with insurance if I can prevent a theft in the first place.

        source
  • Semi_Hemi_Demigod@lemmy.world ⁨2⁩ ⁨days⁩ ago

    Anybody know if this disables any fob or just one? I wouldn’t mind using my Flipper for my car, but my wife still needs to drive it.

    source
    • abominablecosmonaut44@lemmy.world ⁨15⁩ ⁨hours⁩ ago

      I would check YouTube to see how complicated pairing a new fob with the car is. Some are pretty straightforward with just a few button presses on the fob and in the car.

      If that’s easy to do I don’t see why you couldn’t clone the original fob and then re-pair it as a ‘new’ key afterwards.

      source
    • mmmac@lemmy.zip ⁨1⁩ ⁨day⁩ ago

      So you’d just carry your flipper everywhere you go? Any benefit to that?

      source
      • ArcaneSlime@lemmy.dbzer0.com ⁨10⁩ ⁨hours⁩ ago

        I do it, my old ass car doesn’t use rolling codes so I use it to keep my car running but locked while I run into the gas station real fast for snacks on break during the winter. Yes this means I’m vulnerable to other people with flippers, but they’d still have to know and sniff my fob’s signal which is easier said than done, and as long as it’s not accessed when I leave it running all they can steal is my jumper cables since I don’t leave anything in the car (theives can also just break the damn window, or use the wedge, inflatable bag, hanger method, they sell the kits at Autozone lol.)

        I can also control some Touchtunes jukeboxes in my area, and any TV I come across; doctors office TV has Fox running? Oh look at that now we’re watching Forensic Files, odd. Some drunk moron played the Kid Rock version of Sweet Home Alabama? Oh no it got skipped! How happen?! Also a wealth of other IR or Sub-GHz signals provided by the IRDB (for IR) and elsewhere on github (for SubGHz), fans, AC, even vibrators, you name it.

        Also it has a wealth of RFID fobs stored, I have access to some gyms and pools that I otherwise shouldn’t, and a rewritable RFID fob on my keys so I don’t have to show the flipper at the door I can just write it to the fob before I exit my car and look like I have an approved fob. Same with NFC.

        Some other cool random things too, ROT13 and Caesar cipher decoders, a key copier, BadUSB, I have a GPIO attachment that lets me trade any pokemon to myself to my GBC, and of course the wifi board loaded with mayhem and evil portal (haven’t played around with flipperHTTP yet, nor the social media app, among others, that use it), it can break into some keypad sentry safes using just the flipper and two wires, lots of stuff! Don’t use much of that very often but I have before and will again.

        source
        • -> View More Comments
      • Semi_Hemi_Demigod@lemmy.world ⁨1⁩ ⁨day⁩ ago

        It’s got a rechargeable battery unlike my car fob.

        source
    • AwesomeLowlander@sh.itjust.works ⁨1⁩ ⁨day⁩ ago

      Just one, there’s no way your multiple fobs could sync with each other to begin with.

      source