FindMy Flipper – AirTag and SmartTag Emulator

  • very interesting project, but one of the downstream dependencies used here is insecure by default:

    https://github.com/biemster/FindMy/blob/113ebf4017729b92a381...

    Seems to be auth lib for iCloud.

    Also seems to hard code a MacBook device agent in order to associate the generated keys with a device.

    As with anything in the centralized world, I wouldn’t use this on an account with a high number of services/digital assets tied to it. I wouldn’t be surprised if Apple bans accounts that use this.

    Wouldn’t be difficult to find out either given the unique “adsid” code that is required to login.

  • This concept would possible be used to get around the stalking features that Apple et al has implemented.

    Ex: Get N donor tags. Have it cycle through the N tags every 24/N hours. Therefore, to apple (/ device tracking), the "stalkee" is never being followed by a single tag for an extended period of time.

  • Still using flipper a few times per week. Looking forward to the next edition with Wi-Fi and other frequencies.

  • Has anybody tried this to see how the "Find My" app reacts to seeing the "same" tag in more than one location?

  • I use this and it's great. Consumes basically no power, too. I'd like it if it could talk to Google's "Find device" network, but it's already working really well with Apple's network.

  • It would be nice if this can be ported to a low cost BLE device such as the ESP32-C3. Using a flipper as an airtag is a bit expensive.

  • Sadly this requires a "donor" tag to impersonate (which then can't be used for as long as you want this to work), or using OpenHaystack which requires using a Mac in order to get the data.

  • The README.md could use a link to know what this is talking about: https://flipperzero.one/

  • What Android app do I need to use this? Preferably one that does not require Google Services?