this post was submitted on 10 Feb 2024
132 points (97.8% liked)

Canada

7185 readers
465 users here now

What's going on Canada?



Communities


🍁 Meta


πŸ—ΊοΈ Provinces / Territories


πŸ™οΈ Cities / Local Communities


πŸ’ SportsHockey

Football (NFL)

  • List of All Teams: unknown

Football (CFL)

  • List of All Teams: unknown

Baseball

Basketball

Soccer


πŸ’» Universities


πŸ’΅ Finance / Shopping


πŸ—£οΈ Politics


🍁 Social and Culture


Rules

Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage:

https://lemmy.ca


founded 3 years ago
MODERATORS
 

cross-posted from: https://lemmy.world/post/11789263

Canada declares Flipper Zero public enemy No. 1 in car-theft crackdown

top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 84 points 9 months ago (2 children)

Sure, let's ban everything we don't understand and every tool that can be used to break into something. Next we'll be banning rocks because they break windows and crowbars because they can be used to jimmy locks.

[–] [email protected] 44 points 9 months ago

I think this is the first shot in the open war on technology, there has been a quiet push for years.

Automakers blame an RF toy for their own disgustingly poor security measures, and the government jumps to ban the toy. What happens when Bell declares that only criminals need a VPN to hide their traffic, or Rogers decides that only a hacker would ever need to have server in their home? How about a more general case, cordless angle grinders and sawzalls are the fastest way to steal catalytic converters from cars, how long before they are subject to a ban or can only be sold to "approved" persons?

[–] [email protected] 6 points 9 months ago (2 children)

There's unironically been calls to ban pointed knives in the UK because they get used in crimes.

load more comments (2 replies)
[–] [email protected] 59 points 9 months ago (8 children)

Let's instead declare public enemy number one as the asshat marketers that took away our physical keys and forced us to use poorly secured dongles.

[–] [email protected] 5 points 8 months ago* (last edited 8 months ago)

Its really no worse than it was with keys. The flipper zero only works on very cheap, corner cutting simple systems. A lot of cars (and all cars should) use non-repeating codes so a simple interception is useless. That doesn't make them invincible of course.

Those cars would, back in the day, use simple corner cutting keys to be secured. There were quite a few cars back in the day that would have only a very small number of keys meaning there was a mon-trivial chance of you running into a car that you could open that wasn't your own. There are countless stories of people accidentally unlocking and getting into cars that are not there's.

Here's a concrete example, there are only about 5000 different keys for some brands of Toyota. A car thief could get 10keys and try 10cars a day (and remember this would take a minute or 2 and not really look suspicious) and successfully steal a car every 2 months or so. A dongle pretty decisively kills this avenue of attack. But like all things shitty engineering opens up new attacks, although on the whole it's a lot harder to steal a car today than before dongles.

[–] [email protected] 4 points 9 months ago* (last edited 9 months ago)

Agreed! It's actually pretty easy to make a car not start - that is in fact the default behavior for a large chunk of metal. ~~The fact they will start given whatever fixed input is incredibly unnecessary.~~

Edit: Apparently they don't? It's in the article. This announcement is just totally misaimed.

load more comments (6 replies)
[–] [email protected] 44 points 9 months ago (2 children)

Smh... Lol this is how you end up with widespread vulnerabilities in everything.

[–] [email protected] 6 points 9 months ago* (last edited 9 months ago) (2 children)

Seems more to me like vulnerabilities are widespread in everything, and this thing ended up being made to exploit them?

*edit
Wait, did you mean the same thing I said? Phrasing wasn't clear to me.

[–] [email protected] 6 points 9 months ago* (last edited 9 months ago) (3 children)

This is made to exploit them in the same way a knife is made to cut. It can be used for harm (although is a very weak, outdated tool for it that intentionally knee-caps this use) or it can be used for good, where it is a basic, unspecialized option that anyone can make or aquire. Like if the government tried to stop violence by banning knives, a ban would have little impact except on the least committed individuals (IE not organized crime) while being an annoyance to normal people by focing them to sharpen their own metal plates rather than buying them pre-made.

If they actually want to stop these crimes, more reasonable courses of action might be tracking what is shipped, acting on reports of stolen property, trying to impede large-scale organized crime when it is found, or requiring that vehicles maintain security protocols that take into account the existance of computers outside the vehicle.

load more comments (3 replies)
[–] [email protected] 3 points 9 months ago (1 children)

Wow, I check back to see if clarification is available and now I have downvotes? People really are getting meanspirited on here.

[–] [email protected] 6 points 9 months ago (1 children)

Yeah I've started to notice people are engaging in less good-faith conversation than when I first joined Lemmy last summer.

I think a lot of ex-reddit users, after the initial excitement and novelty of the migration to Lemmy, eventually slipped back into their bad habits from reddit. Reminds me of this this blog post denouncing the unhealthy behaviours that are all too common of online discourse.

[–] [email protected] 6 points 9 months ago (1 children)

There's a reason hackernews just straight up denies you from downvoting direct replies... and it's to discourage a knee jerk reaction to downvote anyone who disagrees with you.

[–] [email protected] 2 points 9 months ago

Maybe lemmy should count loading a comment as an upvote

[–] [email protected] 4 points 9 months ago

Yeah, that's the bright side here. If they try to control everyone by banning science, bitch, I've already got it!

[–] [email protected] 32 points 9 months ago (2 children)

So basically, the government doesn't care about the issues and doesn't plan to do anything about it.

[–] [email protected] 22 points 9 months ago (1 children)

Nah, the politicians asked around, the automaker lobbyists blamed the device, some intern-slave wrote a halfass bill, and no one cared to stop fundraising as little power prostitutes long enough to question it.

[–] [email protected] 6 points 9 months ago (1 children)

Thats just what I said, but with more words

load more comments (1 replies)
load more comments (1 replies)
[–] [email protected] 17 points 9 months ago (1 children)

Of course, they don't work on vehicles with rolling codes like, you know, all of them since the 90s. But don't let the facts get in the way of a good do-nothing press opportunity.

[–] [email protected] 3 points 9 months ago* (last edited 9 months ago) (1 children)

How are people even stealing cars by fob, then?

Edit: It's in the article. By using the fob + an amp or cracking the codes like big boys, neither of which this can do. Flipper Zero should sue the government for defamation.

[–] [email protected] 2 points 8 months ago

Yah, they just repeat the signal from a fob near a wall to hit the vehicle, which is now set to always open if the key is near enough. It's a stupid setup that's ripe for abuse like this, instead of just having the user press a button like they did before. That would have been impossible to exploit, but convenience always trumps security.

[–] [email protected] 16 points 9 months ago (2 children)

Canadian Prime Minister Justin Trudeau has identified an unlikely public enemy No. 1 in his new crackdown on car theft: the Flipper Zero

What a fucking ignorant, dickless, corporate cock-sucking, asshat.

The flipper is no different than any laptop or phone + an SDR, it just has an extra spicy collection of software available by default. Literally anyone can assemble the hardware and software needed to duplicate the functionality of the Flipper for a fraction of the price using off the shelf parts.

[–] [email protected] 14 points 9 months ago (1 children)

Honestly they just need an enemy to distract from real potential solutions because solutions are hard. They did the same thing with firearms.

What an asshat indeed.

[–] [email protected] 2 points 9 months ago (1 children)

Yeah, they should definitely have targeted vulnerabilities instead. Human skin should not be so easy to pierce with bullets...

load more comments (1 replies)
[–] [email protected] 4 points 9 months ago

I mean, that's typical politician behavior. let's not pretend the other options are different. This is the shit you have to do to get morons to vote for you.

[–] [email protected] 14 points 9 months ago

Ima just leave this here...

https://www.cbc.ca/news/politics/cbsa-investigators-auto-theft-1.7108145

Yes yes it's the flipper's fault /s

[–] [email protected] 11 points 9 months ago (1 children)

So they are saying I need to invest in one of these devices? I didn't even know it existed but after seeing what it can do I want one, thanks Canadian government.

load more comments (1 replies)
[–] [email protected] 9 points 9 months ago (3 children)

Aw fuck. I should've bought one as soon as I heard about the device.

[–] [email protected] 7 points 9 months ago (1 children)

As far as I can tell, it hasn't been banned yet. So go get one and then don't get caught with it once the toothless ban comes into force.

[–] [email protected] 3 points 9 months ago (1 children)

God damn, I'm going to build a clone from an old laptop and $40 on Aliexpress.

[–] [email protected] 5 points 9 months ago* (last edited 9 months ago) (1 children)

The price is what kept me from having one already. I always wanted a device like this since I was a kid and the idea was still science fiction.

Ironically, I first heard about it from a video review showing it doesn't actually do some of these hacks well or at all, such as opening a garage door by duplicating the code of the remote for the garage door.

[–] [email protected] 3 points 9 months ago

Yeah lol. You can't do much unless you have the original device you want to clone or are lucky enough to be within range and time it right when it's used to capture any signal.

load more comments (1 replies)
[–] [email protected] 8 points 8 months ago

If a car can be stolen with a battery-powered toy of off-the-shelf electronic parts assembled into a cute box, maybe automakers need to modernize their security.

[–] [email protected] 6 points 9 months ago (1 children)

So it's just a small radio? Lol, how the fuck are they going to manage this? Even if they went full North Korea you can make a little SDR from e-waste.

There's a chance they'll take the approach they did with guns and just pick an arbitrary collection of specific products. And if they do, it'll be just as much of a a "dog and pony show". You'll still be able to buy and use radios, including ones that can tune to whatever frequency (probably 13.56Mhz).

[–] [email protected] 4 points 8 months ago (4 children)

It's a bunch of antennas. Low GHZ radio, RFID, NFC, Bluetooth. It will also read/write those button-cell keys. There's also GPIO for you to create your own add-on hardware.

I have no clue how they plan on outlawing them, but it's going to be some reactionary knee-jerk law that does more harm than good.

If the concern is car theft, go after the vehicle manufacturers that aren't using rolling codes and properly securing their vehicles.

[–] [email protected] 2 points 8 months ago (1 children)

Other than the one wire connector and the IR, most phones have all the same hardware and much more compute power, there is nothing stopping a rooted phone from doing the same thing. The Flipper is just an easy UI on a cool form factor.

[–] [email protected] 2 points 8 months ago

My S5 still works and has an IR blaster.

load more comments (3 replies)
[–] [email protected] 6 points 9 months ago

Shouldn't it be the Ontario Conservatives privatizing service Ontario that's enabling all these thefts?

[–] [email protected] 5 points 8 months ago

"California declares new illicit super material called 'porcelain' public enemy No. 1 for car break in crackdown."

[–] [email protected] 5 points 8 months ago

Now about public enemy no. 1 for car theft being car thieves?
After that, negligent manufacturers.

Nah, let's attack tools instead.

[–] [email protected] 3 points 9 months ago

This is the best summary I could come up with:


Presumably, such tools subject to the ban would include HackRF One and LimeSDR, which have become crucial for analyzing and testing the security of all kinds of electronic devices to find vulnerabilities before they’re exploited.

This slim, lightweight device bearing the logo of an adorable dolphin acts as a Swiss Army knife for sending, receiving, and analyzing all kinds of wireless communications.

People can use them to change the channels of a TV at a bar covertly, clone simple hotel key cards, read the RFID chip implanted in pets, open and close some garage doors, and, until Apple issued a patch, send iPhones into a never-ending DoS loop.

The price and ease of use make Flipper Zero ideal for beginners and hobbyists who want to understand how increasingly ubiquitous communications protocols such as NFC and Wi-Fi work.

Lost on the Canadian government, the device isn’t especially useful in stealing cars because it lacks the more advanced capabilities required to bypass anti-theft protections introduced in more than two decades.

The most prevalent form of electronics-assisted car theft these days, for instance, uses what are known as signal amplification relay devices against keyless ignition and entry systems.


The original article contains 617 words, the summary contains 195 words. Saved 68%. I'm a bot and I'm open source!

[–] [email protected] 3 points 8 months ago (2 children)

so uhh.. whats a good place to order from?

load more comments (2 replies)
load more comments
view more: next β€Ί