Nicholas TongFlipper Zero
46 / 46
the toy that makes the front page, the tools that make the breach
The demo that sold me was not the TV rebooting. It was the door. A colleague held a chunky white plastic thing with a dolphin on the screen up to our office badge reader, pressed a button, and the reader blinked green and the door clicked. Not the real door, to be clear. The conference room door, guarding a whiteboard with a lunch order on it. The room did not contain a single secret, and the green blink made everyone in it nervous anyway, which is the whole review.
Here's the thing. The Flipper Zero is a $199 multi-tool for radio protocols: RFID, NFC, sub-GHz, infrared, Bluetooth, GPIO pins, all in a case with a screen and a battery. It is fun, it is well built, and it has become the prop the news reaches for whenever a story needs a hacking gizmo. Canada proposed banning it in 2024 over car theft, then walked it back toward banning the use rather than the tool, and device-shaped panic has been trailing it since. Meanwhile almost nothing it does is new, and the actual breaches I have worked this year were committed with a laptop, a phishing kit, and patience. The panic is pointed at the wrong object.
what it actually is
A pocket penetration testing toy with a mid-range microcontroller, a monochrome display, and a dolphin that levels up when you use it, which is the least important and most-discussed feature. The radios are the substance: a 125 kHz RFID reader for the old clamp-on badges, NFC for cards and tags, a sub-GHz transceiver covering the 300 to 900 MHz bands where garage doors, gate remotes, and some sensors live, infrared for TVs and AC units, and a GPIO header for real hardware work. Stock firmware plays by conservative rules. The custom firmware ecosystem, Momentum and friends, is where the capabilities get spicier, and the community was the engine of its early charm, with new capabilities landing almost weekly the first year I owned it.
Battery life is genuinely good, the build is better than the price suggests, and features grow through an app store without flashing anything. I bought mine at the official store in 2023 for $199, the same price it lists at today.
the part everyone gets wrong
The wrongness has two poles. The first pole is the news version: this thing steals cars. Mostly no. Modern cars with rolling codes are largely out of reach, the Canadian government's own clarification moved the target from the device to its use, and Flipper's public response pointed out that the tool cannot do what the panic said. Rolling-code replay is old science, and the hardware that actually does car theft is not a $199 dolphin toy with a retail warranty.
The second pole is the homelab version: it is a security professional's daily driver. Also mostly no. It is a demonstration and learning device with radio front ends that are fine and not amazing. The rolling-code work people actually do in this space runs on hardware with better receivers, and the access control audits I have watched used a programmable tag and a laptop. The Flipper's real function is making the invisible visible. You can read the card in your wallet and see, in one moment, that it is a 2010-era low-frequency credential with no encryption, copyable in a second. Reading that on a screen does more for a client's security posture than any report, because executives do not fund remediation for paragraphs. They fund it for the green blink.
I want to be careful here, because none of this is permission. Cloning a badge you do not own is a crime in most places, and the device does not care whose door it is. Your own lab, your own door, or written permission, and nothing else.
the mechanics, in ops terms
Everything the device does maps to one of a handful of protocols, and the workflow is always the same: read, store, replay or emulate. Read a 125 kHz badge, it stores the ID, and from then on the Flipper can present itself as that badge. Capture a sub-GHz signal, it stores the waveform. That is the whole game, and it teaches the shape of physical-layer security by touching it, which no amount of blog reading replaces.
The GPIO pins are the underrated half. Pair it with a Wi-Fi devboard and you have a small test rig; plug in sensors and it is a lab instrument. Mine sniffed a weird RS-485 line at a client site last spring, a two-minute job that would have meant digging out a serial adapter and a laptop console.
Where it gets genuinely useful is the boring assessment angle: walk a facility, count the readers that accept a 2010-era unencrypted credential, and hand the list to whoever owns the budget. It turns "your badge system is old" from an opinion into an inventory.
where it breaks
Range and fidelity, first. The radios are adequate, and adequate means a sub-GHz capture sometimes takes several tries, and NFC reads want the exact right distance and a steady hand. Pricier hardware does these jobs with fewer retries.
The hype cycle, second, and this is the expensive one. Resale prices spiked absurdly in 2023, then came back down as supply caught up, and a chunk of the community that arrived for the meme left for the next meme. What remains is the people who actually like radios. Treat any listing above the official price as a tax on attention.
The legal gray zones, third. Owning it is legal in the US. Using it is a different question per state, per country, per door. Canada's proposal and walk-back made the uncertainty permanent: the rules are about use, use is contextual, and context is exactly what a pocket device strips away. Carry one to a client site and expect questions at the lobby desk, because the dolphin now has a reputation.
And the false confidence, last, which is the failure mode that matters to me professionally. A week with a Flipper teaches you that badges are weak, and a week is not enough to learn that fixing that costs a re-badging project nobody wants to fund. The tool shows you the hole. It does not show you the nine months of procurement that filling it takes. I watched a client get a demo, panic, and buy a stack of new readers that stayed in boxes for a year because the migration plan was a blank page.
what to do
- Buy it to learn, at the official price, from the official store. If the point is showing off, it becomes a drawer occupant.
- First weekend, read every card in your own wallet and your family's wallets. Write down which ones are ancient low-frequency tech. That list is your real security finding.
- Use it on your own door or lab, with permission documented for anything else. The tool makes the crime easier and the evidence more obvious.
- Join the community firmware conversation only after a month on stock, so you know what you actually need.
- If you own a facility, skip the device and schedule the credential audit. Same finding, and you will already own the remediation budget.
One useless detail to end on: mine has a screen protector applied in 2023, slightly off, so there is a two-millimeter sliver of exposed glass across the top edge that I notice every single time I pick it up. The device has been dropped twice on carpet. The protector has a scratch. The glass underneath does not, as far as I can tell, and I am no longer sure what the protector is for.
The admission I keep circling: the Flipper has found exactly one real problem in my professional life, the badge inventory, and that finding paid for it twice over. Everything else it has given me is understanding, which pays in a currency my timesheet cannot record.
The scary gadget was never the problem. The unmanaged radio protocol running your front door was, and it does not care what tool knocks.