<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Flipper Zero in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61237#M864</link>
    <description>&lt;P&gt;On any communications channel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;About the time my phone got a NFC reader, I was looking at my door badge and learned that when in a "wireless charging" field, it simply starts transmitting a non-changing string one-way. Not much different than the magnetic stripe on a credit card.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The credit card companies have addressed this risk with tap-to-pay.&amp;nbsp; As I understand it, they effectively do a DH key exchange, then allow the terminal to use the session key after your badge has left the field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Somewhat wryly, I have occasionally realized I could improve my door security by making my employees tap-to-pay $0.01 to enter the building.&amp;nbsp; Then, PCI and EMV controls would protect my door, but I would owe everyone a $3.65/yr raise.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 21:56:04 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2023-07-27T21:56:04Z</dc:date>
    <item>
      <title>Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56235#M728</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something is happening on TikTok and it is going viral, be aware and ensure you understand its capabilities:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www-wired-com.cdn.ampproject.org/c/s/www.wired.com/story/what-is-flipper-zero-tiktok/amp" target="_blank"&gt;https://www-wired-com.cdn.ampproject.org/c/s/www.wired.com/story/what-is-flipper-zero-tiktok/amp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The $200 device is called Flipper Zero, and it’s a portable pen-testing tool designed for hackers of all levels of technical expertise. The tool is smaller than a phone, easily concealable, and is stuffed with a range of radios and sensors that allow you to intercept and replay signals from keyless entry systems, Internet of Things sensors, garage doors, NFC cards, and virtually any other device that communicates wirelessly in short ranges. For example, in just seconds, I used the Flipper Zero to seamlessly clone the signal of an office RFID badge tucked safely inside my wallet."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remember the "Lost in Space" Series - Danger Danger Will Robinson etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cautim_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:24:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56235#M728</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56258#M729</link>
      <description>&lt;P&gt;Here's a tidy little compilation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=u1GDUapHdUw" target="_blank"&gt;https://www.youtube.com/watch?v=u1GDUapHdUw&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's really incredible, and alarming.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 14:19:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56258#M729</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2022-12-26T14:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56299#M730</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;Yes it is cool, dangerous do you want to shoot the next person who has one of these?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now think how you can protect yourselves and your organisations against it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 23:40:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56299#M730</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-12-27T23:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56300#M731</link>
      <description>&lt;P&gt;The most alarming thing I can think of is door access.&amp;nbsp; I've personally seen collisions happen at card readers far too often for me to have a lot of faith in those devices, let alone this tool which can copy a card easily.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 00:30:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/56300#M731</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2022-12-28T00:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61214#M860</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An update on Flipper Zero, it now has a App store for third party applications.....&amp;nbsp;&amp;nbsp; Even though Amazon has banned it, it is still available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/flipper-zero-now-has-an-app-store-to-install-third-party-apps/" target="_blank"&gt;https://www.bleepingcomputer.com/news/security/flipper-zero-now-has-an-app-store-to-install-third-party-apps/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 05:47:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61214#M860</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-07-27T05:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61221#M861</link>
      <description>&lt;P&gt;I find it increasingly difficult to blame the bad actor when simple replay attacks succeed.&amp;nbsp; &amp;nbsp;Replay is a well-known attack vector (ca &lt;A href="https://en.wikipedia.org/wiki/Ali_Baba_and_the_Forty_Thieves" target="_blank" rel="noopener"&gt;1717&lt;/A&gt;) with established and long-available defenses (Asymmetric encryption/signatures (ca &lt;A href="https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exchange" target="_blank" rel="noopener"&gt;1976&lt;/A&gt;), salting (c.a. &lt;A href="https://en.wikipedia.org/wiki/Crypt_(C" target="_blank" rel="noopener"&gt;1973&lt;/A&gt;)), 2-way confirmation, etc.).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 14:20:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61221#M861</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-07-27T14:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61229#M862</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;On access systems and doors?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 20:18:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61229#M862</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-07-27T20:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61237#M864</link>
      <description>&lt;P&gt;On any communications channel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;About the time my phone got a NFC reader, I was looking at my door badge and learned that when in a "wireless charging" field, it simply starts transmitting a non-changing string one-way. Not much different than the magnetic stripe on a credit card.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The credit card companies have addressed this risk with tap-to-pay.&amp;nbsp; As I understand it, they effectively do a DH key exchange, then allow the terminal to use the session key after your badge has left the field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Somewhat wryly, I have occasionally realized I could improve my door security by making my employees tap-to-pay $0.01 to enter the building.&amp;nbsp; Then, PCI and EMV controls would protect my door, but I would owe everyone a $3.65/yr raise.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 21:56:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61237#M864</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-07-27T21:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61240#M865</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;&amp;nbsp; The price of protection and peace of mind is priceless &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 02:25:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61240#M865</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-07-28T02:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61246#M866</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;are there transaction fees on a penny?!&amp;nbsp; Inquiring minds want to know!!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 13:11:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61246#M866</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-07-28T13:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61247#M867</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;are there transaction fees on a penny?!&amp;nbsp; Inquiring minds want to know!!&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I do not have factual knowledge, but I do suspect it would be something "small", like $0.30 plus 3%.&amp;nbsp; :-).&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 14:22:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61247#M867</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-07-28T14:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61298#M870</link>
      <description>&lt;P&gt;So that's roughly going to be $0.32 every time someone badges in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BOOP in the morning... *cha-ching*&lt;BR /&gt;BOOP returning from lunch... *cha-ching*&lt;BR /&gt;Dentist appointment at two?&amp;nbsp;&amp;nbsp;*cha-ching*&lt;/P&gt;&lt;P&gt;Restroom breaks?&amp;nbsp;&amp;nbsp;*cha-ching* and&amp;nbsp;*cha-ching*&lt;/P&gt;&lt;P&gt;Left my umbrella in the office on a rainy afternoon?&amp;nbsp;*cha-ching*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Payment Card Industry really put themselves in the correct place.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 12:56:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61298#M870</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-07-31T12:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Flipper Zero</title>
      <link>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61304#M871</link>
      <description>&lt;P&gt;Yep.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At some point, there will be a major vulnerability; management will ask for a solution.&amp;nbsp; That's when I will pull out the "PCI got it right" card and let them work through the exact same realization that Eric did --- security costs money and outsourcers don't work for free.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I honestly believe leveraging PCI this way is the right solution?&amp;nbsp; No.&amp;nbsp; Do I believe we ought to be leveraging their pocket-to-terminal data protection expertise in other areas?&amp;nbsp; Yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 17:29:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Flipper-Zero/m-p/61304#M871</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-07-31T17:29:02Z</dc:date>
    </item>
  </channel>
</rss>

