How the Apple AirTags were hacked

แชร์
ฝัง
  • เผยแพร่เมื่อ 26 พ.ย. 2024

ความคิดเห็น • 1.7K

  • @EpicLPer
    @EpicLPer 3 ปีที่แล้ว +4448

    Next thing to do: Get the AirTag to RickRoll you via its speaker.

    • @SaiCode
      @SaiCode 3 ปีที่แล้ว +58

      Yesss Please

    • @steve_1507
      @steve_1507 3 ปีที่แล้ว +28

      That would be a very nice joke

    • @TravisStamper
      @TravisStamper 3 ปีที่แล้ว +22

      This just won the internet!

    • @PiduguSundeep
      @PiduguSundeep 3 ปีที่แล้ว +9

      Exactly my thoughts after watching this video.

    • @micahrogers7536
      @micahrogers7536 3 ปีที่แล้ว +8

      Or have it open the rickroll youtube url via nfc

  • @robinator18ps3
    @robinator18ps3 3 ปีที่แล้ว +228

    The real skill show here is not your hardware hacking (which is REALLY cool).
    The real skill here is the way you can simplify everything enough for most people to understand without sacrificing details for the ones that can appreciate it.
    THIS is how you get more people into a field.
    Keep sharing and encouraging people to follow up on their curiosities to find out how stuff work!

  • @mikeak7331
    @mikeak7331 3 ปีที่แล้ว +4624

    “Be careful when you try this at home” because I understand all of this technical stuff completely... haha. Great video.

    • @gh8447
      @gh8447 3 ปีที่แล้ว +14

      @@francoisdang Just reported his post for 'Unwanted commercial content or spam'. Post gone (for me at least)! 😄

    • @NathanaelTan
      @NathanaelTan 3 ปีที่แล้ว +23

      @@gh8447 Can confirm whatever you reported is indeed gone 🙃

    • @ImPattMan
      @ImPattMan 3 ปีที่แล้ว +9

      I mean, they did all the hard work, and basically wrote a guide on what you need to do. So I'd venture many people could repeat this at home if they work on their soldering skills a bit!

    • @fanuchman
      @fanuchman 3 ปีที่แล้ว +2

      I will definitely be trying this.
      A little searching and you too can understand all the content in the video.

    • @Custmzir
      @Custmzir 3 ปีที่แล้ว +2

      @@gh8447 which comment? What was it about?

  • @hellschatt
    @hellschatt 3 ปีที่แล้ว +206

    I'm not involved much in hacking but that skip of the debug check with the voltage is mindblowing to me. Didn't know this was possible, and didn't know that people implement a debug mode like that in such chips.

    • @theairstig9164
      @theairstig9164 ปีที่แล้ว +1

      Have a look at security testing if hardware under the Common Criteria

    • @SloppyPuppy
      @SloppyPuppy ปีที่แล้ว

      Very common in embedded devices, wanna see more of this voltage glitching action, search for "How I hacked a trezor wallet worth $2 million.

  • @devinmarx5032
    @devinmarx5032 3 ปีที่แล้ว +8145

    It would be hilarious for you to go back into the Apple store and tell them your AirTags aren’t working only for them to get Rick rolled!

    • @spectraljake9056
      @spectraljake9056 3 ปีที่แล้ว +426

      This is how you get kicked out.

    • @missingno2401
      @missingno2401 3 ปีที่แล้ว +48

      good idea

    • @_BangDroid_
      @_BangDroid_ 3 ปีที่แล้ว +568

      @@spectraljake9056 That would be an honour. I've never set foot inside an Apple store, getting kicked out my first time would be the best

    • @colt5189
      @colt5189 3 ปีที่แล้ว +46

      @@spectraljake9056 Would that be a permanent kicking out? Or just to leave for the day?

    • @liucyrus22
      @liucyrus22 3 ปีที่แล้ว +60

      @@colt5189 they can’t force you to give them your name. They can probably take pictures of you though.

  • @shrubfromtomorrow
    @shrubfromtomorrow 3 ปีที่แล้ว +250

    I don't understand anything but I watched every second and nodded my head like it made sense

    • @centinstudios
      @centinstudios 3 ปีที่แล้ว +1

      Because of the German accent? XD

    • @shrubfromtomorrow
      @shrubfromtomorrow 3 ปีที่แล้ว +2

      @@centinstudios no, I dont understand circuitry at all

    • @RusselGuinarez
      @RusselGuinarez 3 ปีที่แล้ว

      same here bro

    • @MovieCaveDave
      @MovieCaveDave 3 ปีที่แล้ว

      Annnnd that was me as well…

    • @fitybux4664
      @fitybux4664 3 ปีที่แล้ว

      This is basically a case of "security by obscurity". Nordic Semiconductor (nRF) engineers would say: "we never expected anyone to do that...". They could probably protect the next generation of chips by having some internal capacitance to make it harder to glitch externally.

  • @MisterLiker
    @MisterLiker 3 ปีที่แล้ว +2053

    Apple: "The AirTags are totally safe."
    Stacksmashing: _"Hold my Raspberry Pico."_

    • @xtreme571
      @xtreme571 3 ปีที่แล้ว +36

      Right? He's like "normally you would use an FPGA" and throws a Raspberry Pi Pico at it.

    • @kylemwalker
      @kylemwalker 3 ปีที่แล้ว +57

      I mean, your airtags are safe unless someone physically gets their hands on it, breaks it open, solders wires to it, etc. The airtag is still safe from remote hacking

    • @zornsllama
      @zornsllama 3 ปีที่แล้ว +32

      @@kylemwalker yes, this is way outside the threat model. Air tags are still safe in the sense Apple meant :)

    • @keiyakins
      @keiyakins 3 ปีที่แล้ว +24

      Unless you don't own an Apple device with which to use their warning thing. Then they're a stalker's wet dream, and frankly criminally negligent to release.

    • @zornsllama
      @zornsllama 3 ปีที่แล้ว +15

      @@keiyakins I’ve done some quick reading and it seems you’re right, the current firmware leaves a fair bit to be desired. Hopefully they fix this. It’s worth noting that I can buy a 4G-enabled chip that could do something similar with zero restrictions for not a lot of money from aliexpress.

  • @orion10x10
    @orion10x10 ปีที่แล้ว +41

    You're like the NileRed of hardware hackers, I'm almost done with my 2 year degree in Cybersecurity and this video is teaching me a lot.

    • @stacksmashing
      @stacksmashing  ปีที่แล้ว +11

      Now that's a compliment! Thanks! Glad you enjoyed it!

  • @KyleAwsm
    @KyleAwsm 3 ปีที่แล้ว +1416

    I am continually blown away by your videos, how you lay everything out so clearly, and the skill with which you do all that you do. I strive to be able to do things like this. Great work, man!

    • @stacksmashing
      @stacksmashing  3 ปีที่แล้ว +95

      Thank you so much! I'm glad you enjoyed it :)

    • @esotericsean
      @esotericsean 3 ปีที่แล้ว +6

      Hah, funny seeing you here! Love this guy's videos too :)

    • @CMAC86
      @CMAC86 3 ปีที่แล้ว +3

      @@esotericsean hey Sean do you not create videos anymore on TH-cam? Loved some of your original vids.

    • @esotericsean
      @esotericsean 3 ปีที่แล้ว +3

      @@CMAC86 I plan on returning soon! Just had some big (really good) life changes this past year :)

    • @watchlistsclips3196
      @watchlistsclips3196 3 ปีที่แล้ว +1

      @@esotericsean @James Reaction @ stacksmashing
      Wow.I am seeing one great youtuber loving videos of an awesome youtuber who is blown away by other mind blowingyoutuber. You three are awesome.You are providing amazing content.Love you three.

  • @rowans.corner
    @rowans.corner 3 ปีที่แล้ว +97

    5:01
    Other channels: Don't try this at home!
    Stacksmashing: Be careful if you try this at home.

    • @chronophagocytosis
      @chronophagocytosis 3 ปีที่แล้ว +3

      That's because the justice system in USA is so messed up that you have to include silly disclaimers and warnings on everything. The rest of the world developed in a different direction. If you screw up, it's your own fault and and can't sue anyone for it. The best thing you can do is to look in the mirror. In America though... oh it got pretty wild and that's why the "don't try this at home" slogan even exists.

  • @hydejel3647
    @hydejel3647 3 ปีที่แล้ว +213

    Every new video of yours potentially extends lifespan of these devices by a lot. Your research is ground breaking every time!

  • @eric-id6bk
    @eric-id6bk 3 ปีที่แล้ว +69

    I'm actually pretty surprised that I understood most of this, I've got very limited hardware / low-level experience. Awesome video!

  • @philrod1
    @philrod1 3 ปีที่แล้ว +220

    All the way through this video I was thinking "This is cool, but what's the use?" 8:03 answered that question beautifully :D

    • @stephenfgdl
      @stephenfgdl 3 ปีที่แล้ว +3

      I think it's a little obvious you can spy on someone and not get their information .... hahaha

    • @TheDanm22
      @TheDanm22 3 ปีที่แล้ว

      Still no clue.

    • @TheDanm22
      @TheDanm22 3 ปีที่แล้ว +2

      Iphone users will buy anything.

    • @RadDadisRad
      @RadDadisRad 3 ปีที่แล้ว

      @@TheDanm22 nah, you just believe they will.

    • @TheDanm22
      @TheDanm22 3 ปีที่แล้ว

      @@RadDadisRad you are 10ply.

  • @JamesReaction
    @JamesReaction 3 ปีที่แล้ว +870

    I don't even know why I'm watching..... But I am.. 😅

    • @abellthomas1978
      @abellthomas1978 3 ปีที่แล้ว +4

      maybe to react to it😂

    • @apu_apustaja
      @apu_apustaja 3 ปีที่แล้ว +5

      I know exactly what you mean. Let me tell you why you're here. You're here because you know something. What you know you can't explain, but you feel it. You've felt it your entire life. That there's something wrong with the world, you don't know what it is, but it's there. Like a splinter in your mind, driving you mad. It is this feeling that has brought you to me. Do you know what I'm talking about?

    • @__Pre
      @__Pre 3 ปีที่แล้ว +9

      Kinda weird how people automatically like a comment from a verified person without having a single reason to

    • @gjkrisa
      @gjkrisa 3 ปีที่แล้ว

      Let’s you know what can be done and how they do it. Your iPhone security if they have direct access they can use these techniques to find what on the phone although would take much longer to do and probably are other better ways in but just another tool in the tool box

    • @highstereolove
      @highstereolove 3 ปีที่แล้ว

      @@__Pre or they genuinely like and agree with the comment? 😑

  • @joshuavincent7884
    @joshuavincent7884 3 ปีที่แล้ว +93

    Concise, informative and entertaining...what more can we ask?

  • @whytushar
    @whytushar 3 ปีที่แล้ว +4

    Saw your tweet and was impressed, watched your video and I'm in awe. Good job, man!

  • @Qsie
    @Qsie 3 ปีที่แล้ว +63

    Never considered doing this myself, but just the _idea_ that this works is both extremely entertaining and rather educational 😄

  • @paulgray1318
    @paulgray1318 3 ปีที่แล้ว +9

    Love the brute force loop - automating the grind out of the fun, smashed it.

  • @marsanmarsipan
    @marsanmarsipan 3 ปีที่แล้ว +124

    Bitcoin Mining on AirTags incoming

    • @stacksmashing
      @stacksmashing  3 ปีที่แล้ว +21

      This is the way

    • @densho9057
      @densho9057 3 ปีที่แล้ว

      @@inkybz but not my phone please

    • @mrgw98
      @mrgw98 3 ปีที่แล้ว +5

      @@inkybz Yet another reason I like that Android gives you the option to turn off NFC.

    • @Adaephonable
      @Adaephonable 3 ปีที่แล้ว

      @@inkybz botnet sure, mining cluster would be useless. Phones are a terrible choice for miners.

    • @yDeathAngely
      @yDeathAngely 3 ปีที่แล้ว

      @@Adaephonable Yes but if you place one of this airtags at an airport or so you can get a lot of phones and this can add up. One phone isn't gread but 1000 or 10,000...

  • @jesseshakarji9241
    @jesseshakarji9241 3 ปีที่แล้ว +150

    I'm a computer engineering student and I'd love to get better at understanding hardware hacking. Your explanation of "glitching" was really good. Is there any resources or other videos I could check out to learn more about hardware hacking like this?

    • @joeds3775
      @joeds3775 3 ปีที่แล้ว +9

      Look at the sites this guy reccomends.
      Do the same for them. Eventually you have a bank of experts you can trust and learn from.

    • @joemck85
      @joemck85 2 ปีที่แล้ว +7

      There's also a bunch of good stuff in whatever-number-C3 talks. Notably ones revealing some new flaw found in some game console to allow homebrew often contain some serious hardware hacking talk. "Nintendo Hacking 2016" and "Console Hacking 2016" come to mind, and tend to be a mix of super low level hardware hackery such as MITMing a PCIe bus or using external hardware to dump RAM chips of a live system, and software analysis.

    • @RafaelKarosuo
      @RafaelKarosuo 2 ปีที่แล้ว

      @@joemck85 I remember seeing one of those talks in hackaday a while back, but never thought about the nC3 thing, until now that I didn't understand the reference and had to look for, simple details silly me 😆

  • @marcmiyamoto
    @marcmiyamoto 3 ปีที่แล้ว +48

    In Apple headquarters: *nervous sweating*

    • @musteycraft
      @musteycraft 3 ปีที่แล้ว +7

      Cant wait to apple to make a v2 wich is glued down

  • @M_tch311
    @M_tch311 3 ปีที่แล้ว +18

    Learned more about reverse engineering than any of my classes, thanks!

  • @Phroggster
    @Phroggster 3 ปีที่แล้ว +8

    Nice work! I tend to avoid all products designed in Cupertino because they tend to only function with other products designed in Cupertino, but now it might be worthwhile thanks to you!

  • @sanches2
    @sanches2 3 ปีที่แล้ว +8

    There is a thing called brown out reset. You can check for that flag during the debug lock procedure. If the flag is risen at all :) Great video and a presentation, thank you!

  • @BaumInventions
    @BaumInventions 3 ปีที่แล้ว +229

    You got featured at "TechLinked" in the "If you cant buy a graphics card" episode at around 4:20 ... noice.

    • @stacksmashing
      @stacksmashing  3 ปีที่แล้ว +65

      Ohh cool, thanks for letting me know! :)

    • @bhavyakabade
      @bhavyakabade 3 ปีที่แล้ว +11

      @@stacksmashing yeahhh Techlinked got me here

  • @jpjapers
    @jpjapers 3 ปีที่แล้ว +16

    Just wait til they start filling the casing with resin now.

  • @bryteklabs1855
    @bryteklabs1855 3 ปีที่แล้ว +14

    I just saw Hak5 coverage for this and was looking for the video! Great timing and good job.

  • @siegmundeurades5753
    @siegmundeurades5753 3 ปีที่แล้ว +3

    Things like these are why I'm studying electronics. Great work man!

    • @rahatpreo3209
      @rahatpreo3209 3 ปีที่แล้ว

      Studying Electronics is supper fun.

  • @4pThorpy
    @4pThorpy 3 ปีที่แล้ว +67

    I occasionally read through the "discovery" page on my phone (that page on android shows me targeted news) and yesterday while pooping I read the title "somebody has already hacked apples airtags"...should have known it'd be you.

    • @davidplenderleith4176
      @davidplenderleith4176 3 ปีที่แล้ว +1

      I did it ages before you but don’t show or accept praise

  • @DEJS3
    @DEJS3 3 ปีที่แล้ว +1

    You explained the concept so elegantly that it made me realize the RGH (Reset Glitch Hack) hack for the Xbox 360 used a very similar methodology to achieve code execution.

  • @o0julek0o
    @o0julek0o 3 ปีที่แล้ว +55

    Well that took like a week. Very cool.

  • @Scrogan
    @Scrogan 3 ปีที่แล้ว +3

    Very good work! I wonder about what the apple IC is doing in there, considering the NRF is already an onboard microcontroller and it doesn’t exactly need tons of processing power.

    • @StuartZiane
      @StuartZiane 3 ปีที่แล้ว +1

      UWB - Ultra WideBand radio. I won't explain what it is and how it works, but the AirTag and compatible devices use UWB radio to measure how long it takes radio signals to travel between the devices - i.e. "Time Of Flight (TOF)". This allows the devices to measure the distance between themselves.

  • @josephdlist
    @josephdlist 3 ปีที่แล้ว +7

    I read an article on Ars technica about this and couldn’t wait for the video.

  • @ahtoshkaa
    @ahtoshkaa 3 ปีที่แล้ว +9

    I have no idea what Airtag is, i have no idea what you were talking about, but i watched the whole video from start to finish and it was mesmerizing!

  • @MartinDerTolle
    @MartinDerTolle 3 ปีที่แล้ว +554

    Now all that is left to do is amplify the nfc so you can rickroll everyone in your surroundings

    • @theterribleanimator1793
      @theterribleanimator1793 3 ปีที่แล้ว +39

      what kind of VILE, UNSPEAKABLE EVIL CREATED YOU, MONSTER?

    • @WalterMan
      @WalterMan 3 ปีที่แล้ว +13

      Is that even possible? lol

    • @kenopyowo
      @kenopyowo 3 ปีที่แล้ว +6

      @@WalterMan yeah i'd like to know too

    • @theterribleanimator1793
      @theterribleanimator1793 3 ปีที่แล้ว +13

      @@kenopyowo probably not, probably wouldnt be legal either. Too much of a nuisance

    • @kaukospots
      @kaukospots 3 ปีที่แล้ว +38

      @@WalterMan absolutely not, NFC is powered/initiated by your phone not the device itself

  • @drchopsticks
    @drchopsticks 3 ปีที่แล้ว +1

    Due to the TH-cam algorithm I found your channel and am I sure glad I found your channel. The stuff you do is just so interesting

  • @electricketchup
    @electricketchup 3 ปีที่แล้ว +5

    You never give up, and you never let me down.

  • @TechNo1geek
    @TechNo1geek 3 ปีที่แล้ว +13

    "So be careful when you do this at home"
    I'm not even rich enough to get a TAXI to a Apple store

    • @SF-eg3fq
      @SF-eg3fq 3 ปีที่แล้ว

      underrated

  • @sahbibg9680
    @sahbibg9680 3 ปีที่แล้ว +7

    Fantastic job dude ! Too much experience went into this short explanation

  • @Cobrass2
    @Cobrass2 3 ปีที่แล้ว +2

    Im not a hacker but keep doing what you do man, people like you in the end do magic to the world of tech! Also even i understood the video, you are a born teacher!

  • @williambrasky3891
    @williambrasky3891 3 ปีที่แล้ว +8

    Definitely looking forward to getting one of those pico based tools. You are awesome! Thanks for sharing all of this with us!

  • @suyashdongre
    @suyashdongre 3 ปีที่แล้ว +1

    Did I understand what you did: No
    Did I enjoyed the video: Yes

  • @Jayanky
    @Jayanky 3 ปีที่แล้ว +71

    Can’t wait to play doom on an airtag

    • @kekc2181
      @kekc2181 3 ปีที่แล้ว +1

      nah skyrim would be released before doom

  • @ichderarnd
    @ichderarnd 3 ปีที่แล้ว +1

    So, if it‘s possible to change firmware of an Airtag, it would be possible to use it as an Ultrawideband controller for an RPI Pico or ESP32. The goal is to have the „find“ and „distance“ functions not only accessable from iPhones. It could be usable from microcontrollers too. That would be a nice project...

  • @rootshell101
    @rootshell101 3 ปีที่แล้ว +87

    let's hope that TH-cam will not delete your video aas they did with the "Nintendo Game & Watch" one.

    • @flippa4220
      @flippa4220 3 ปีที่แล้ว +19

      One giant corporation shielding another giant corporation while lawmakers bow down before them…we really live in a dystopia

    • @brandontechnerd
      @brandontechnerd 3 ปีที่แล้ว +3

      it's on my PC btw

    • @TattiePeeler
      @TattiePeeler 3 ปีที่แล้ว +1

      You know it's just a matter of time.. a gang of mealy-mouthed so and so's.. use youtube-dl, yt-dlp etc.. to preserve it offline.

    • @gamechep
      @gamechep 3 ปีที่แล้ว

      What was wrong with it?

    • @TattiePeeler
      @TattiePeeler 3 ปีที่แล้ว +2

      @@gamechep, Nintendo got TH-cam to take it down. Nintendo generally don't want people hacking their hardware and will gladly harass, lodge DMCA requests for the mildest of reasons.. In this case, the Game & Watch hacks were a full dissection of the device, at a software and hardware level, greatly extending the device's potential and use.

  • @purerizzo
    @purerizzo 3 ปีที่แล้ว +4

    Thanks for showing your "draft soldering", now I know it's not just me!

  • @ProjectV95
    @ProjectV95 3 ปีที่แล้ว +4

    Wow. Amazing work! Had been watching your videos for a while now, this gave me a great reason to subscribe and follow your work! Great job!

  • @Vidsandso
    @Vidsandso 3 ปีที่แล้ว +1

    So realistically you could give someone a hacked airtag and have them install a compromised app that talks to the airtag and use the accelerometer as a microphone?
    How much memory is there on an airtag? I mean how long could the airtag record before it would need to talk to a phone to upload the recording. You could have airtags recording and acting as bugs and only download the content when the memory is full.

  • @IamTheHolypumpkin
    @IamTheHolypumpkin 3 ปีที่แล้ว +6

    Whenever I see you upload, I konw it will be fun entertaining and a bit out of the ordinary.

  • @aSingularPhoton
    @aSingularPhoton 3 ปีที่แล้ว +5

    I find it comedic that apple released a product that’s being used as more of a test board then it’s actual intended purpose

  • @peir5074
    @peir5074 3 ปีที่แล้ว +7

    When you talked about the rickroll part I laughed out loud. Amazing man, thanks for making this.

  • @markuss.7798
    @markuss.7798 3 ปีที่แล้ว +1

    Can you also try it with the Samsung Galaxy SmartTags pls

  • @TheFerdi265
    @TheFerdi265 3 ปีที่แล้ว +4

    Great Video!
    I especially love how pretty much all of your recent hardware hacking videos can theoretically be replicated if you just have a Raspberry Pi Pico, some level shifters, and a breadboard.
    I haven't tried any of it yet (and to be frank I don't understand too much about low-level electronics, my understanding more or less starts at logic gates), but the fact that it doesn't need super fancy equipment makes it so much more accessible!

    • @stacksmashing
      @stacksmashing  3 ปีที่แล้ว +6

      Haha thank you! It's funny, cause at first I was like "Why do we need Pico", and now I love it.
      And I think it's important to show that you don't need the highest-end devices to do cool things!

  • @armandolios4561
    @armandolios4561 3 ปีที่แล้ว +2

    Man you are a Genius!!!!, this video was great.
    I only understood 5%, but I watched all.
    Congrats.

  • @jamin959
    @jamin959 3 ปีที่แล้ว +5

    This is was great too learn about! What would you use a hacked/jailbroken AirTag for?

    • @DeanCollinsVideos
      @DeanCollinsVideos 3 ปีที่แล้ว

      The first time i saw it i thought.....hmmmm free data :)
      Start deploying IOT data that gets delivered for free?

  • @RustOnWheels
    @RustOnWheels 2 ปีที่แล้ว

    This is simply satisfying to watch. Great work (and I really appreciate people mentioning sources). Way to go!

  • @postbreak
    @postbreak 3 ปีที่แล้ว +12

    Very nice! I'd love to see someone build a "jig" that you can just place the airtag into to jailbreak the device without having to solder to the pads, like a modchip. Also is that an external antenna port I see on the PCB?

  • @MenacingMika
    @MenacingMika 2 ปีที่แล้ว

    To be fair, I understand nothing in this video, however this guy is very very invested in it, and it really shines through to the point where I actually don't mind watching it..

  • @GameMuse
    @GameMuse 3 ปีที่แล้ว +5

    You have immense skill. I'm glad you share it :)

  • @dribal
    @dribal 3 ปีที่แล้ว +16

    By getting access to the firmware couldn't you bypass apple's anti stalking mechanics making it an even bigger threat?

    • @cakearmy_maxgaming6346
      @cakearmy_maxgaming6346 3 ปีที่แล้ว +4

      No, thats done on the iphone side. The airtag just says hi, and the iphone determines location, whether to broadcast, etc.

    • @Elliandr
      @Elliandr 2 ปีที่แล้ว +1

      The anti stalking feature has the side effect of making it useless for what I'd actually want to do : track my car or backpack in case it is stolen without alerting the thief that they are being tracked. The anti-stalking feature also makes it impractical to so one of these into your child's clothes to be able to track them in case they are ever kidnapped. Anyone who is riding with the child would essentially be notified that there is a tracking device.
      I wonder if maybe there would be a way to get the device to present itself as a different device periodically so as to throw off the anti-stalking detection of the phones.

  • @izerpizer
    @izerpizer 3 ปีที่แล้ว +4

    I LOL’d at the Rick roll part. Absolutely genius. I love it all.

  • @bmilejski
    @bmilejski 3 ปีที่แล้ว +3

    Hey @stacksmashing! Very nice video. I'm actually trying to reproduce your glitch on another device that has an nRF52832 for a master's thesis. Now I'm wondering: How did you identify the external decoupling capacitor (and its test point) on the airtags? Would you have a keyword for me for follow up research?

    • @undergroundradio11
      @undergroundradio11 ปีที่แล้ว

      Mostly you can find the pin connected to the capacitor in the datasheet. They will call it core-vcc for example. (I did not check how it is written in the nrf datasheet).
      Ps. I just read that you comment is one year old. I hope you could found it out on time ;-)

  • @mhe123321
    @mhe123321 3 ปีที่แล้ว +4

    why is the debugging an option that can be enabled on products that are shipped?
    I mean wouldn't it be more secure for them to exclude that?

    • @gyroninjamodder
      @gyroninjamodder 3 ปีที่แล้ว +2

      It's easier / cheaper to make a single version than a development version and various locked down versions for each chip. These development features are useful, and it may be desirable to use the same chip for development and production instead of just hoping they work the same.

    • @TheRailroad99
      @TheRailroad99 3 ปีที่แล้ว

      it IS disabled. however he manages to disrupt the CPU so it executes a dead if-branch.
      Of course this most likely needs to be timed down to the microseconds

    • @soggytoast111
      @soggytoast111 3 ปีที่แล้ว

      Removing all the debug features in the hardware and software might introduce more bugs - so then how do you debug the device if you as the developer are locked out of all of your diagnostic tools?
      It's simply a bad idea to make significant changes to the device between development and production. There needs to either be a developer backdoor or kill switch so that you can essentially test on the same device that you intend to sell.

  • @kyonru
    @kyonru 3 ปีที่แล้ว +1

    I kinda understand the logic and programming and circuits, but I have no clue about how to get from zero to that point. Amazing video!

  • @MikeTrieu
    @MikeTrieu 2 ปีที่แล้ว +9

    What's fascinating is that now that you have the firmware dump and verified that the AirTag allows for unauthenticated firmware writes, you could theoretically overwrite any arbitrary AirTag with custom firmware for nefarious means. Disassembling and reassembling an AirTag would not show any obvious signs of tampering, so you could totally perform an evil maid style attack on one and the mark would be none the wiser.

  • @thatdude5104
    @thatdude5104 3 ปีที่แล้ว

    Nice job man, already really enjoy your Twitter feed, looking forward to what we can further get out of this!

  • @nillhari
    @nillhari 3 ปีที่แล้ว +21

    "Please be carful while trying this at home" - Got your sarcasm

  • @MikeDamewood
    @MikeDamewood 3 ปีที่แล้ว +1

    What's the URL that it normally sends you to? does it contain variables like the device or name?

  • @thevideoman12
    @thevideoman12 3 ปีที่แล้ว +14

    I've read about this. Gut gemacht!

  • @Ghost-jx2dj
    @Ghost-jx2dj 3 ปีที่แล้ว

    Wow I am noob but 1 year back I thought about this fault injection now I am seeing you actually doing it made my day love from 🇮🇳

  • @Carterthielftw_
    @Carterthielftw_ 3 ปีที่แล้ว +5

    Holy crap, youve earned a sub.

  • @samk9799
    @samk9799 3 ปีที่แล้ว +1

    Hey, can you make software to turn an action camera to a dash cam. Like make it start recording when turned on and stop recording when turned on. Also make it delete old footage while recording new footage. Thanks

  • @MrMesVentes
    @MrMesVentes 3 ปีที่แล้ว +4

    As someone who've designed multiple PCB, I must say I'm impressed with the voltage glitching technique. I've never heard of that and I wouldn't have thought of this to make the ucontroller jump instructions. Great video!

  • @jonathanriggins5451
    @jonathanriggins5451 3 ปีที่แล้ว +1

    You did an amazing job explaining what you did and with my background understood completely. Great video!

  • @NeoRazor
    @NeoRazor 3 ปีที่แล้ว +4

    Apple: "New for 2021, we are releasing these homing devices to keep track of your location at all times. But don't worry, they're totally safe."

    • @maximiliandeisz2961
      @maximiliandeisz2961 3 ปีที่แล้ว

      if you don't happen to have an android
      because if so well get stalked by people that just slip it somewhere lol

  • @LazyBunnyKiera
    @LazyBunnyKiera 3 ปีที่แล้ว +2

    This is pretty cool. I didn't even know Apple Airtags were a thing. But i think it's pretty neat you were able to hack them and i can imagine you can have a lot of fun with these. I wonder if you can write a program to wirelessly program them now.

  • @superhero1
    @superhero1 3 ปีที่แล้ว +10

    Nicely done! One of the many things I would like to reproduce one day :D

    • @gammoron
      @gammoron 3 ปีที่แล้ว +1

      Yeah we would all like to reproduce someday

  • @OllAxe
    @OllAxe 3 ปีที่แล้ว

    Wondering if this could be used to give the tracker some sort of compatibility with Android, even if not through the Find My network

  • @EpicLPer
    @EpicLPer 3 ปีที่แล้ว +8

    Ready to Rick-Roll people!

  • @83daaj
    @83daaj 3 ปีที่แล้ว +1

    I’m not sure what just happened but I liked it. Great job !

  • @spiderhaz_
    @spiderhaz_ 3 ปีที่แล้ว +16

    When they tell you to turn it off and on again and you enable debugging mode instead xD.

  • @Patrik2166
    @Patrik2166 3 ปีที่แล้ว +1

    Will this make the AirTags unsafe from now on? I mean someone could dump the firmware and modify it so a nearby device won't tell potential victims of the location of the airtag (Apple claims that these can't be hidden and used to track people so this could open that.... Right?)

  • @weshuiz1325
    @weshuiz1325 3 ปีที่แล้ว +36

    Lets count how many hours it take for apple to send a false copyright strike

    • @weshuiz1325
      @weshuiz1325 3 ปีที่แล้ว

      @Kent talks tech ninndo does it all the time, every time the see a modding video

    • @weshuiz1325
      @weshuiz1325 3 ปีที่แล้ว

      @Kent talks tech never say never

  • @pierce8308
    @pierce8308 3 ปีที่แล้ว +1

    How does this voltage fault injection really work ? I mean to skip instructions the Instruction pointer register must be incremented significantly to skip the debug routine. But after we cut the power we basically disallow the IP to increment at all, so what gives ?????

  • @AshokKumar-jv6wk
    @AshokKumar-jv6wk 3 ปีที่แล้ว +33

    i didnt understood anything :(
    but this was cool:)

    • @maicod
      @maicod 3 ปีที่แล้ว

      huh he expains it SO clearly

    • @BradK02
      @BradK02 3 ปีที่แล้ว +5

      @@maicod if it's not your field of interest, you still won't understand. I have no clue also, but understand that it's well explained. 🤣

    • @maicod
      @maicod 3 ปีที่แล้ว +1

      @@BradK02 ok you got a point there

    • @TimberWulfIsHere
      @TimberWulfIsHere 3 ปีที่แล้ว

      Invest more skill points in IQ

  • @syke384
    @syke384 3 ปีที่แล้ว +1

    Hey...I am trying to learn this subject right now and i was wondering if you have any recommended learning resources that i could follow. thank you so much!!❤️

  • @hammerfix7241
    @hammerfix7241 3 ปีที่แล้ว +6

    gonna watch this before its gone :D

  • @patrikcath1025
    @patrikcath1025 ปีที่แล้ว +1

    I have no idea what is an AirTag but I like this

  • @20_percent
    @20_percent 3 ปีที่แล้ว +19

    The only usage for me is going to be my airport checked in bags, so I can track the distance between my seat and the bag :D

    • @hunterwilhelm
      @hunterwilhelm 3 ปีที่แล้ว

      And if it shows nothing, and your bag at your destination isn't there, then you know it got left behind

  • @ZackHab
    @ZackHab 3 ปีที่แล้ว +1

    The rickroll was genius I subbed

  • @gudenau
    @gudenau 3 ปีที่แล้ว +4

    I'm surprised you can just flash it like that, you'd think Apple would have picked something you can lock down more.

    • @turolretar
      @turolretar 3 ปีที่แล้ว +2

      I guess they got tired of the lockdown..

    • @relt_
      @relt_ 3 ปีที่แล้ว

      i am 100% sure they forgot

    • @UCXEO5L8xnaMJhtUsuNXhlmQ
      @UCXEO5L8xnaMJhtUsuNXhlmQ 3 ปีที่แล้ว

      Couldn't flashing it with something run the risk of bricking it and void the warranty on it? The way i see it apple gets to sell more

  • @fevermeds
    @fevermeds 3 ปีที่แล้ว +1

    Fantastic video. Your explanation of the chip and attack was extraordinary. You made a complex topic approachable.

  • @abhishekkamlesh1751
    @abhishekkamlesh1751 3 ปีที่แล้ว +6

    Your videos are extremely overwhelming🙂

  • @Jukehere
    @Jukehere 3 ปีที่แล้ว +1

    I dont know which is better, hacking the airtags,
    or rick rolling the one who finds your item

  • @krzbrew
    @krzbrew 3 ปีที่แล้ว +4

    Now, you need to connect two GameBoys via Airtags

  • @UCXEO5L8xnaMJhtUsuNXhlmQ
    @UCXEO5L8xnaMJhtUsuNXhlmQ 3 ปีที่แล้ว

    I really have no idea what you said or did but the idea of jailbroken air tags is really awesome and i can't wait to see what people do with them

  • @Fireboy-ym9yx
    @Fireboy-ym9yx 3 ปีที่แล้ว +3

    i like to pretend i understand what hes saying

  • @chasesimmons1418
    @chasesimmons1418 2 ปีที่แล้ว

    These are the videos worth millions of views

  • @jimmiethesainttech
    @jimmiethesainttech 3 ปีที่แล้ว +6

    Sweet!

  • @tahirkassam3962
    @tahirkassam3962 3 ปีที่แล้ว

    Good work, kudos to you mate. Just curious, is that Segger j-link original or a clone ? If so, where'd you get it from ?