Hacker News new | ask | show | jobs
by filterfiber 923 days ago
Better title: "Apple fixes BLE DOS attack".

I'm tired of media acting like the flipper is some kind of "super special hacking tool", it is very literally getting it banned in some places when all of it's internals are easy and common radios (Not to knock the flipper, it is conveniently well packaged).

You just needed to be able to send crafted BLE packets, this attack doesn't have anything specific to the flipper at all.

It didn't even originate on the flipper: https://github.com/ECTO-1A/AppleJuice

> To run these scripts you need a Linux machine with an internal Bluetooth card or a USB Bluetooth adapter.

Versions also exist that run on the ESP32, android, etc.

4 comments

Portable devices like the Flipper make it very easy to distribute working RF-layer exploits that don’t get hung up on all the non-standard hardware in phones and laptops. And frankly, that’s a good thing! Because manufacturers have, for some reason, decided that if there’s a radio-layer protocol involved somehow they’ll be protected by the obscurity of it. The Flipper lets devs turn those vulns into push-button exploits, which is finally inspiring companies to clean up the crapware in those stacks. (And I bet there is scarier stuff in there that researchers just haven’t found yet.)
Is this really a battle worth picking? Many friends and coworkers are going to bring up the Flipper to you in passing conversation, might as well get used to it.
In my opinion, yeah. If anyone tries to deify or demonize the concept of a Flipper, you just remind them that everyone has a smartphone with even wilder SDR capabilities. The biggest difference is that the Flipper is weak hardware with wide-open software, and your smartphone is strong hardware with weak-ass software configuration.

Reminding people of that is important, even if you don't think the FCC is about to change their mind. Crucify us for being a nerd if you must, but someone has to be the voice of reason and point out that the Flipper is the most optional part of the exploit.

yes, and people shouldnt accept the media do what should be considered grossly lying. and dont forget, they do this, or whats way worse, to EVERY SINGLE article. You know about this because you're in this sphere, but when its about farm animals, you may or may not know, and then people tend to eat it up.

The mainstream media as it is now, and probably has been for a very very long time, is an enemy of the people, and should be treated accordingly

It's like FireSheep. Session hijacking wasn't new but it made easy and something anyone could do.
shoot the messenger.

since you have stocks of the billion dollar message

> since you have stocks of the billion dollar message

I have no idea what you mean by this?

Are you saying I'm defending apple somehow?

Because my point is nearly every phone/laptop could pull off this attack, not just a single "special hacking device". Which I think is worse for them.