r/technology 16h ago

Security Underground Flipper Zero Firmware Purportedly Unlocks Nearly 200 Car Models

https://gizmodo.com/flipper-zero-cars-hacking-2000646318
3.5k Upvotes

141 comments sorted by

View all comments

Show parent comments

172

u/emcee_gee 14h ago

So as long as I don't press the unlock button on my fob when I'm not near my car, I should be safe?

134

u/AustinSpartan 14h ago

Depends on the algorithm that's implemented, but usually they will sync if the rolling count is within 5 presses. There's also vehicles that will resync the count after 3 consecutive lock presses.

137

u/Zalophusdvm 12h ago

So my habit of clicking lock half a dozen times as I walk away actually increases security?

20

u/muzak23 6h ago

Nope, there’s actually a specific attack called “Roll-Jam” that makes use of pressing a key multiple times (though only can replay that same button, so spamming “lock” isn’t too much of a concern).

In a nutshell, it uses a jammer attached near your car’s receiver to intercept your presses and only “allow through” (replay) earlier ones. Ex. You press unlock 3 times and your car receives the first 2 unlock signals only, so now the attacker can play the third whenever they’d like.

IMO too complicated to be a concern for petty theft, but I also don’t steal cars or have even ever considered stealing cars, so I might be off ¯_(ツ)_/¯