Transcription
[Music]
So, they turned on the microphone. I guess that means it's my turn to start, right? Thanks everybody for being here. This is a lot more people than I expected. People tell me, "Oh, yeah, Flipper Zero is so last year." But I don't know, maybe not. Um, all right. So, let's get started.
Number one, this is the only time I'm going to ask anything of the audience. Who here brought a Flipper Zero with you?
>> Me.
Well, you better get spamming. There's got to be iPhones around here somewhere. All right, here we go.
So, welcome. My name is Gray Fox. I am a retired Air Force. I started out doing signals intelligence and whoops and digital network intelligence. Um, after a while I got pulled into the dark side and did special operations work and that what taught me about offensive security and some other interesting things that you can do with wireless. When I'm not working, I'm a huge fan of messing with wireless technology. When the Flipper Zero came out, um, it was great. It was like, man, it's a Swiss Army knife of like all these things that I can use and it replaced a whole bunch of bigger equipment that I had to carry around for a really long time. So, I uh developed some training courses and training scenarios with the Flipper Zero. What we're going to look at is one of those training scenarios. Um, I uh, yeah, that's that's pretty much me in a nutshell.
I also spent a lot of time doing things overseas, so I can't stand the sun. I can't stand a beach. It's just not my thing. I was recently at a pool party, took my shirt off, and someone says, "Holy crap, man. I took a look at you and now I have to have cataract surgery. You know, that's what happens when you don't spend any time in the sun." But anyway, so let's get into this.
Here is your mission. A local diplomatic office just got tipped to the presence of two hostile individuals in a nearby hotel. The high value individuals, HVI. You're not going to get that many acronyms, and if you do, then I'll explain them. Match the names of two known criminals, Vera Unabite and Augustus St. Cloud, with histories of attacking Allied forces. The host nation status of force agreement prohibits operations without approval based on evidence. Therefore, the HVI's identities must be confirmed without overt military action. You, all of you, with your Flipper Zeros out there are the only signal specialists close enough to act before a suspected attack is executed.
But here's the problem. We're not going to make this easy. In true international airfare form, you probably spent 18 hours on an airplane, you landed, they lost your luggage. But if you're like me, you carry a Flipper Zero around with you and a whole bunch of other goodies. If you want to come uh come catch me after this, I'll show you what I carry in my uh portable sig box. But you still have to accomplish the mission. One of the things that we learn in the military is if you can't accomplish the mission, then you're not really worth much. So, you have to improvise. And what do you improvise with? Well, whatever you have in your pockets. You no longer have any of your kit. So, can a Flipper Zero do all this stuff? Well, maybe it can. Maybe you can gather what you need to get evidence to be able to see if the people you want are actually around.
Um, Flipper Zeros can do a lot of good sub-gigahertz. That's everything that's below 1 GHz. I'm not going to go through a whole explanation of RF. Hopefully, you're following. Um, but you can also with a couple of extras do Wi-Fi with a Flipper Zero. You can do Bluetooth, you can do infrared, you can do NFC, RFID, a whole bunch of things. Does it do all of these things? Well, h, that remains to be seen, but at least you have some capabilities. So, let's put it to work.
So, a couple of things that we need to make clear here. Now, this is meant to be a training scenario. I typically use this as a two-hour workshop, but I reduced it down to what we have here. And then that being the case, we need to go over a few caveats. Caveat number one, the Flipper Zero is not always going to work. You may try to do things and it's just not going to function. It could be because of firmware. It could be because of the environment, but either way, don't expect magic out of it. Um, but you can always try your hand and a lot of the time you'll see some success. But the Flipper Zero can only do what the Flipper Zero can do.
Um, if any of you try to copy your hotel keys and you'll, you know, and it's a Myfair Classic key and you try to crack keys to be able to emulate it, the Flipper Zero can do that, but it takes five days. Whereas, if you have a computer, you can do it in a few minutes. Maybe I'll show you how to do that, maybe not. I don't want to get arrested while I'm here.
>> The target has a say. If you're using any equipment against an adversary, they're going to do things that you don't expect. And they may do things that aren't going to be, I, I guess, like cooperative with the tools that you have. So again, you need to improvise. RF is also finicky. Let's say that you're using Wi-Fi and you're streaming something and then somebody turns on the microwave. Well, if you're on 2.4 GHz, so is the microwave. Your Wi-Fi may not work or maybe degraded service. These things happen. Radio frequency environment is, it's wireless. You don't have control over that.
SUccess depends on adversary error. I say this because during training scenarios, I don't want to make the barrier to entry for learning way too high. So I make the adversary do things that typical adversaries wouldn't do so that the training experience is not going to be cheapened. So while we're going through this, you may be like, "Well, why would they do that?" Wow, that's a crazy training scenario. So what we're going to look at here is in the realm of the possible. What can your Flipper do in a perfect world? What would your Flipper be able to give you if you had this kind of training mission? So, can we do it in 1 hour? Well, let's see. If I go over time, then maybe. But expect those gimmies and let's go on.
So, what we're going to use here is going to be a Flipper Zero. The Flipper Zero is half-duplex. Your Wi-Fi dev board that you can plug into the GPIO pins is also half-duplex. What that means is you can have transmit and you can have receive on different frequencies, but you can't have both going on at the same time. And then I also like to use external sub-gigahertz antennas. And that's what you see all the way on the right. And it just extends the range of picking up radio signals, IoT signals, car fobs, TPMS, all kinds of things that operate below one gigahertz.
So before we start, and I got to say this, and I say this for a reason, if you find me somewhere around here after the talk, ask me why, and I'll give you a couple of really fun stories. But the FCC is a thing. So if you're going to play with radio signals, make sure you're doing it in a controlled environment. Make sure you have permission. Make sure you know what the outcome is going to be. And if somebody complains about it, take those complaints seriously. Are we good?
All right, hotel lobby. Remember, you just landed. It was an 18-hour flight, but it is 1630 hours. The first thing that I would do if I were trying to locate an adversary is go to Wi-Fi because everyone likes to get on the Wi-Fi. Now, there's no guarantee that you're going to get anything, but this is a good first step. And, you know, we're already like coming in hot with a Wi-Fi dev board on a Flipper Zero. If you don't have experience using Wi-Fi dev boards on a Flipper Zero, I highly recommend it. It's an extremely good capability. But immediately we find Vera's iPhone and that's pretty fantastic. One of our targets' names is, you know, their first name is Vera. So this to me is an essential element of information. I'm going to record this and I'm going to try to see if maybe I can confirm which individual we see in the hotel lobby is Vera. So I record that and then I take that MAC address. That MAC address is meant to be, not always, but it's meant to be a unique identifier. That unique identifier is something that I can use in the future. Once we grab that MAC address, then I need to do a few other follow-on things to see if I can, um, I can confirm that this is one of my high-value individuals.
One other thing we can do is we can look for probes. How many of you turn your Wi-Fi off when you're not using it?
>> All right.
I said I was only going to ask one thing of the audience. I'm a liar. You can accuse me of being a liar, but yeah, a lot of you raised your hand, but some of you didn't. When your Wi-Fi is on and you're not associated with a wireless network, your phone is going to keep beaconing out to all the networks that you've ever joined. It's a quality of service thing. You want to join automatically so you don't have to keep on putting in your password every single time. That being the case, everywhere that you go, you're blasting out beacons. "Hey, are you my Wi-Fi? Are you my Wi-Fi? Are you my Wi-Fi?" If I can collect these, then I can take that information and I can look at some open-source stuff like Wigle.net, which is an extremely cool website, and I can see if any of that Wi-Fi has been seen anywhere else. You can probably imagine what we can do with this information. But if I take that, the Wi-Fi I got from you, all those beacons of no networks you've been associated with, and I put it on a map, then that gives me a pattern of life or a pattern of travel. I can see hotels you've been to. I can see houses you've stayed at. I can see restaurants you've been to. This is the RF hackers village. These things are going to happen. But anyway, so you can see what the intelligence implications are going to be of something like that. And this definitely can be useful to us.
Let's say that I did pick up something else from this preferred network list. Let's say that I get "Chateau St. Cloud." I also know one of my HVIs, their last name is St. Cloud. This is what we in the industry call a clue. Now I have another clue. So I can record this and I can keep on going.
All right. Now if I want to confirm whose device that is, I can't just scream out, "Hey, who's Vera?" and hope for a raised hand. It doesn't really ever work that way. Well, maybe it will. I don't know. Just, I wouldn't try that. But what you can do is you could have a little bit of fun with stuff that might get you arrested by the FCC. Now, if any of you are connected to Wi-Fi and suddenly that Wi-Fi goes away, you get disconnected from the network, you might get a little bit mad. What I'm hoping for is by disconnecting my target from Wi-Fi, they'll have a reaction. And then that reaction will show me who that person is. It's a hope. It's not always going to work, but if I see somebody madly typing into something, looking at their phone, jamming their finger into it, trying to reconnect to Wi-Fi, then that may give me some kind of an indication that they're offline, they're getting mad, that is my person. Now, I have somebody that I could, I could take a look at. I could put a face to a name or a face to a device. And I think that's fairly valuable. But patience is key. This stuff isn't always going to work. You may be sitting there for a while doing these de-authentications. It's something that we can use. It's something the Flipper is capable of.
So if I were not following those rules, those status of force agreements, and I was going to get offensive, and I said, "Oh, screw the law. I don't care. Let's go for it." I could try a karma attack. How many of you are familiar with karma attacks? Adversary in the middle for Wi-Fi.
>> All right, a few of you.
So essentially, you're doing an evil twin attack. You spin up a Wi-Fi network that looks just like a Wi-Fi network that your target is beaconing out for from that preferred network list. You produce more power than any other Wi-Fi around. And you depend on that device to automatically connect to that Wi-Fi. And when it automatically connects, now you're a proxy and all their traffic is going through your proxy. In this way, I might be able to collect credentials. I might be able to see some traffic. There's a whole number of things that I can do. Um, it is not necessary for me to do because that is not what I'm here to do, but the Flipper can do that using Evil Portal. Um, it is not hard to flash your Wi-Fi dev board with these things. It is not hard to accomplish this kind of karma attack. If you choose to do it, just remember that warning. Somebody somewhere may know you're doing it and you run afoul of the law, but it's still a lot of fun.
All right. So, we're going to keep on going. Now, let's say that the HVI needs to move because, well, the Wi-Fi sucks in the lobby, so let's go somewhere else. So, if they're going to get up and we're still on our our little clandestine mission over here, I think we're going to try to follow them. Now, you don't want to be too obvious when you're following, but you know, you want to make it look like you're a hotel guest. Again, don't scream out, "Hey, Vera, where you going?" and then hope for him to turn around. That's not what we're here to do either. But if you keep on scanning access points, because now we have Vera's iPhone, then if that person gets up and moves, you can follow them and you can see if you still have that same power level for what you just picked up. The key point is you have a MAC address. You've collected it. Now you have something that you can follow. As that device moves, it's going to leave a trail. So if you're in an elevator, by the way, elevators are like big Faraday cages. When you're in that elevator and you take readings and it matches your MAC address, then you, you got your target. If you get MAC addresses or any other signals that don't match it, you have more clues. You can record them, too. You may have to go back to your drawing board, but it's just more information than you have.
So, let's say you're in the hallway now. Your HVI is going to go into their room, and you're going to try to do your best to maybe confirm the MAC address or confirm the Wi-Fi that you have. Don't make it look conspicuous. Don't follow them. Don't stop and look in their room. Don't do any of those things. That'll give you away. So instead, you keep on walking. And then when you're walking, you take a look down at your device. And if you see that you have a received signal strength that increases as you go to that room and then you pass that room and it decreases, that's great. You're picking up the RF where it's strong. And that gives you confirmation that that device is actually in that room. Now, you saw the person go in that room, so you don't necessarily need this, but this is more evidence. Remember from the mission statement, we need evidence that we could present in order for us to be able to get these HVI rolled up by host nation law enforcement. So, this is just more stuff that you have, more evidence. You could even note the, the room number so you know what that is. You can note the time of day that they were in the lobby that they went back to the room. All these things, it's your preponderance of evidence. You're putting together a characterization of your target.
So, you wait a little while and then you see >> that your target leaves the room and you notice that the target has a duffel bag and they have a room key and they have a key fob that they're just displaying out in the restaurant. Again, it's a training scenario. There are going to be some gimmies. Would any of us leave these things out on a table? No, probably not. But this gives us a little bit more options. It is a training scenario. What I can do with the room key and the key fob is I can go to NFC and I can see what I can collect. Now, these are more selectors that I can use to try to get at my targets. So, with NFC, you go to read and as soon as you read that card, you're going to get some information. I mentioned room key cards before and you can have a lot of fun with this. Now, this caption, if you read it, it's Washington D.C. It's a hotel that's five blocks from the Capitol. And this is what I was able to do with a Flipper Zero in a place where you would imagine that things are supposed to be safe and secure.
There's no audio, so if you don't hear anything, that's perfectly fine. But this is me using my Flipper. I think a lot of you with Flipper Zeros have already seen this. You've already done this, but for the benefit of the audience that maybe have not done this, this is how easy it is to copy a card. This particular card was a little bit more complicated. It's a Myfair Classic card. Myfair Classic is pretty secure. They have a lot of encrypted sectors on it. So, it can't be copied like this. But if you go online and you find these Myfair Classic keys that are able to decrypt the sectors on your card, then well, you can do this with your Flipper. Now, notice that I'm recording this inside the room. And notice that I'm making a very deliberate effort to show you that I'm doing this from inside the room. If this video were to get out and somebody saw me doing this from outside the room, then there's no reasonable expectation that it was my room. Remember, don't be a criminal. And there you go. I emulate it and the door opens. This is five blocks from the Capitol.
Anyway, so remember that we also saw a car key fob. So, let's have a little bit of fun with that. If you do basic signals analysis with a Flipper Zero, you'll be surprised that you have a lot of re-really useful tools that you can use. In general, whenever I'm doing any signals analysis of a piece of hardware, I want to find an FCC ID or something that's an equivalent because that'll allow me to do web research to see, well, what frequency are we actually going to find when we test out this equipment? Most car key fobs that are out nowadays are going to operate on 315 MHz, 433 MHz, or somewhere in the lower range of 900 to 915 MHz. So, it's a pretty good guess. The way that the way that I would test out a key fob would typically be by changing the slide. There we go. Would be by using a, a spectrum analyzer. Now, a Flipper Zero, the stock firmware, doesn't have a spectrum analyzer, but you can download it, and I'll show you how to do that. And a spectrum analyzer is basically a window that shows you which signals are strongest in a graphic manner. If I activate the lock or the unlock of a key fob and I see a spike come up, well, that's the frequency that I want. And now I have three frequency ranges that I could focus on. So, that makes my life a little bit easier with a spectrum analyzer. And I'll show you how to do that.
>> You can see spikes of a whole bunch of other things. But if you take a key fob and you hit the lock frequency, you can see where those spikes are. And the Flipper Zero will show you what the frequency is of those spikes. You can also adjust it to be a little bit more narrow. I was started out at broad. I found the spike and then I went to more narrow and even more narrow to get a more precise signal. The more precision that I have, then the better signal I'd be able to capture. Now, when you have that signal, your next step is going to be to mess with it. So, I'm going to read that signal and I'm going to try to record it. And the way that you would do that, especially with a key fob, because the signals are a bit more complicated, is you just record the raw signal. That is me recording a lock. And now I can send that signal. And if I send the signal, it's going to reproduce it. I'm not going to try to get answers because there's a lot of people here and there's a lot of extraneous noise. But I would normally ask a class, "What would you expect to happen if you were to hit the lock on a key fob?" Well, you'd see the car flash. You would see the lights flash, right? If you were to simulate that signal or emulate the signal with a Flipper Zero, you would expect the same kind of reaction from the vehicle, right?
So, that being the case, and I told you I would, I would uh show you how to like download these things if you had just had a stock Flipper Zero and you didn't have a spectrum analyzer. If you have a phone or a laptop, you can go to lab.flipper.net and you can download any one of these things. And you can see under the sub-gigahertz setting, you have spectrum analyzer right there. When I'm using stock firmware, it is the first thing that I download because I use it so much for signals analysis. And there are your references in the bottom corner. If anyone wants to take a photo of this slide, please feel free.
All right. So, here we are in the parking lot because I just copied that key fob and I want to identify which vehicle is attached to this key fob because for me, that's just more evidence that I can gather. It's a vehicle. It's something they're going to use every day. We live in a world where license plate readers are everywhere and where there's a whole bunch of other signals that are coming out of your vehicle. So, if I can, if I could identify my HVI's car, I can use that and I can send it back to whatever backup that I have, they could take a look at whatever collection we have from that car from license plate readers and I can get a pattern of life. I can get a pattern of travel. It's extremely valuable. So, send a signal sub-gigahertz under the read raw. I have a save signal and then I hit send and then bam, I see some lights on a vehicle. I could record the tag. I could record the make and model. I could even record when the vehicle is coming and going if I had the time to do that kind of reconnaissance.
Key fobs are, they've drawn a lot of eye from the international community because a Flipper Zero can copy your key fob. It can open up a car. Canada banned a Flipper because of these things. You see videos all the time of Teslas being messed with by a Flipper Zero. The reality is when you're conducting an investigation, when you're doing intelligence, you're not looking to break and enter. You don't want to steal stuff. That's not what you're about. You're not a criminal. You just want to identify things. So, we're only sending a lock. We're not sending an unlock. And I want to make that distinction because once again, we don't want to be a criminal. Also, fun story. When I started experimenting with these things, I have very, very good friends that trust me and they're like, "Yeah, man. You could practice your Flipper Zero on my car." Older vehicles, you can copy a signal and then you could send it and it unlocks the car. It's fantastic. But if your vehicle is manufactured 2013 and newer, depending on the make and model, if you send that signal and you don't have the key fob present, you don't have all the multi-factor authentication that you need. And sending a fraudulent signal will actually break the remote entry. And then you have to drive to a Volkswagen dealership and spend $300 to get it reprogrammed. Ask me how I know.
All right. Being a civilian is great, but I really miss having a backup. I really miss being able to send stuff to people and they tell me, "Oh, yeah. This is what you got. Go forth and conquer." But my intel team did get back to me. Remember, it's a training scenario. Our device MAC is matched to our HVI. So, great success. We found the right person. We have the information that we need. Automatic license plate readers, and I probably got that acronym wrong, showed that this vehicle was in the vicinity of a whole bunch of soft targets that we have in this host nation. That's great. That's more evidence that we have if you're assuming that the vehicle and the driver belong to each other. And then that device MAC also shows me the BDL. BDL is bed down location. It means that's where they sleep. Yes, I use a lot of acronyms.
All right, we have other options. Remember that that duffel bag was at the table, too. The cool thing about a Flipper Zero is that if you are willing to lose it, you can turn it into something like an AirTag. So now you can track the Flipper Zero wherever it's going. If I had the time, if I had the wherewithal and the resources, I might do that because now I can track to see where that person is going, provided that they have their duffel bag with them, whether they walk around, get in the car, go to a different room, and that's extremely useful. But remember, all my luggage was lost. All I have is my Flipper Zero. I have to do that risk analysis on the ground to see, well, am I, do I want to lose my Flipper because I want to turn into an AirTag? No, I still need to use it, but it's an option. The best thing about working operations like this is that if you have options, then you have different courses of action that you can take. And I really, really like options. But for this one, the risk analysis didn't work out. I'm not going to use an AirTag. But it's possible. And that's why I like the Flipper so much.
Now, let's go back inside. I know the vehicle. I know the room. I know the MAC address. I know the Wi-Fi SSID. I know so many different things. But we have another individual that came in. And this other individual might be somebody of interest, too. Now, you can tell from the scenario that this person is pissed, probably because his partner has been spending all day in a hotel just messing around, basically getting pawned by the opposition, and that's me. So, what do we do? Well, it's a training scenario. We see what the adversary is doing. They leave a credit card. That credit card is then taken by somebody that works at the restaurant. And this restaurant, uh, you know, waiter, waitress, whatever. They're not very good with their PCI DSS standards. So, they leave the credit card just sitting around doing nothing. So, what do I do? I use my Flipper Zero. And again, you can use NFC and you can read what the credit card says. One fair warning though, a credit card is not, it's not as powerful as you think to have a Flipper with a credit card. You may have seen some TikTok videos, YouTube videos about, "I can copy a credit card and now I can do point-of-sale stuff." No, a Flipper can't do that. But what a Flipper can do is it can get you a credit card number. It can get you an expiration date. It can give you a name. And it can give you a whole bunch of other unique identifiers. Now, you've already seen from the wireless activity that we've done that a unique identifier is very valuable because I can send this back to whatever support that I have and they can use whatever, whatever means we have necessary to try to correlate these numbers with purchase histories or, uh, withdrawals from an ATM if it's an ATM card, something like that. So even just being able to copy the information and not being able to emulate it to make a purchase, it's still extremely valuable because we're not looking at criminal activity now. Now we're looking at it from a national security lens. And this is why I put all of my credit cards in these copper sleeves and I make my life extremely inconvenient because of things like this. So the Intel team can definitely use this.
But we've reached our hour. What do we got so far? The Intel team got back to me. That credit card number matches Finn's collection for Cloud St. Augustine. That's a known alias for the guy they were looking for. It's a good possibility that new person that came in is Augustus St. Cloud. An FBI report came back saying that that credit card was used to buy some really horrible things over on eBay. So, I think that's some pretty good evidence and I think that we can probably consider this done and we were able to do that only in an hour. So, we have that evidence. Let's keep on moving forward. By the way, financial intelligence is what FINT is. Again, I just really like acronyms.
So, where do we go from here? You collected all of your evidence because a Flipper Zero is able to store. You've done Wi-Fi. You've done NFC. You've done sub-gigahertz. You probably could have used infrared if you wanted to turn the TV off, too, to get a reaction. I love doing that in restaurants, but it's getting more dangerous. People are starting to figure out that I can do this stuff. It's like I can't eat out anymore. Um, you also have all the PCAPs that you've collected and you can do some really good stuff with this. If you do a deauth attack with a Flipper Zero and that deauth is collecting all of the reauthentication packets and that gives you something we call EAPoL, it's Extensible Authentication Protocol over LAN, something like that. You guys are more nerdy than me, you know what that breaks out to. But essentially what it means is these packets contain the password for the Wi-Fi. And that's why I like doing deauth and collecting the PCAPs because now I have more options. If it's an adversary network that I want to get on, then I have that kind of incidental collection that would be able to get me onto that network. And I think that's really valuable.
You also have all of those other MAC addresses that you collected, whether it's Wi-Fi, Bluetooth, or some other radio frequency. You can use that to set up what we in the industry call a SIGINT tripwire. Now, let's say you have an ESP32 chip. It puts out 2.4 GHz, whatever signal that you want. You can program it to detect a whitelist of MAC addresses and I can put that anywhere. Now, from the license plate reader data that I got from this vehicle, I know the pattern of life and the pattern of travel. I also have data from the, uh, preferred network list which gives me Wi-Fi where this person used to be. That's valuable. I can program some kind of wireless detector and I could use them as leave-behinds along the route and that gives me just another option of if that Wi-Fi or that MAC address is detected, it'll alert me and it's almost like near real-time tracking. So, it's extremely valuable stuff.
If we have NFC reads like what we got from that credit card, that's really good for ubiquitous technical surveillance because now I have unique identifiers that I can match up against national collection or even breach data if I do this as a civilian. And that breach data will then tell me, well, this is where the credit card was used. This is where, you know, purchases were made. These are online stores where this credit card information is saved. And that all gives me more characterization of where these targets are and who they are. And then lastly, if I have these MAC addresses and I can use that for device correlation, the equipment that we have at hand can't give us that. But I can tell you that our adversaries have all that equipment. We know that Salt Typhoon is sitting in our telecom networks right now. That's why the FBI and NSA said "Use Signal" last year. It's like they are saying "Use Signal." The world was turned upside down. I'm, I'm okay with that. I also teach digital privacy. But all that notwithstanding, it is fairly easy for a nation-state with access to a telecom network to see a cell phone and then correlate that cell phone with all kinds of other information. And that just gives you a little bit more telemetry and a little bit more correlation of who you are and where you've been.
For those people that use multiple cell phones, that's great. It's a good tactic if you want to stay covert. The problem is if you carry all of them with you all the time, you're considered a co-trafficker. And that co-trafficker information would be able to tell me, well, who's Vera Unabubbe's group? Who's his crew? Who are they staying with? Who are they running with? Who was there when they purchased material? Who was there when they were doing reconnaissance on these bases that are in the host country that we think are so, so much of a like so much of a soft target. That's good information for us to use. That's how we would do our social network analysis was based off of this technical data. You got all of it with a Flipper Zero. I think that's pretty amazing.
So, we did it. We did everything that we needed to do. We did a little bit of passive collection and that was just soaking up the Wi-Fi. We did active collection. We did a lot of active collection. Anyone here from the FCC? We did a lot of active collection. It was pretty fantastic. So, we got a key fob. We got a credit card. We got a key, uh, key card for the room. We got a lot of really good things. And we did a little bit of signals analysis. That signals analysis, using the spectrum analyzer, using the, um, using the read function for sub-gigahertz. If we had more time, then we would be able to do a lot more cool things. We'd be able to emulate that key card and maybe try it on some other doors that may have been rooms for suspected HVIs, too. We could have, we could have probably done some Bluetooth soaking and seeing if there was any personal area network, any PAN equipment that we can get into, you know, like headphones or, uh, smart watches, anything like that. And we did a little bit of signal replay, but remember our signal replay, especially for that key fob for the car, it wasn't for breaking and entering. We copied the lock signal, not the unlock signal because we wanted to send it because we wanted to indicate the vehicle. That's all we wanted to do. We didn't want to get into the vehicle. That's a big distinction.
I'll tell you a little bit of a story. So when I was experimenting doing all these things like for the past couple of years, even for older vehicles like from the early 2000s where remote entry was a brand new thing, anytime that you would try to unlock the vehicle, then the onboard system would then sequentially go up to the next code and then to the next code and next code and as long as it was aligned with the key fob, then it would have a, it would unlock at the first try. With older vehicles, I would copy unlock signals into the Flipper Zero without the vehicle being in the vicinity. So, the vehicle wouldn't hear the unlock signals. If I would click unlock five times and record it five times and then go back and play any one of them, it would unlock the vehicle. But then when I take the key fob and I go to unlock it, it takes a few tries to get realigned with the vehicle's onboard security system. That happens. If you do that with unlock with an adversary's key fob, then they go to unlock their car and suddenly the first unlock doesn't do anything, that might be suspicious, especially if your adversary knows what they're doing with vehicle technology or wireless technology. So, when you want to try to use a Flipper to do what we did to identify an unknown vehicle, you want to use the lock because I don't know of anyone that approaches their vehicle and hits lock. Everyone usually hits unlock first, right? So for me that's a little bit of like operational security. I don't want them to know that I did anything. It is what we would call a clandestine action. Clandestine means you're performing an action and you don't want anyone to know. Covert action is when you perform an action and you want everyone to know about it. You just don't want them to know that you did it. So this is clandestine. It's a distinction.
We have a little bit of time left. I know that I kind of flew through this, but I was just thinking that I'd go down a rabbit hole and we wouldn't have enough time, so I went a little bit fast. But if anyone has any questions, this is your opportunity. Before you ask me anything, my hearing is going because I spent a lot of time doing operations and I was very fast and loose with earplugs. So, if you want to ask me something, feel free to come up. I will give you the mic so everybody else could hear you. Plus, this is your five minutes of fame. Go for it.
All right. Thanks very much, everybody. I appreciate it.
[Applause]
Please.