| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take security seriously. If you discover a security vulnerability, please report it responsibly.
Please DO NOT open a public GitHub issue for security vulnerabilities.
Instead, report privately via:
- GitHub Security Advisories: github.com/tworjaga/flipper-rf-lab/security/advisories
- Or email: security@tworjaga.dev (if available)
When reporting a vulnerability, please include:
- Description: Clear description of the vulnerability
- Impact: What could an attacker achieve?
- Steps to Reproduce: Detailed instructions
- Affected Versions: Which versions are vulnerable?
- Mitigation: Any workarounds you've identified
- Your Contact: How to reach you for follow-up
| Phase | Timeframe |
|---|---|
| Initial Response | Within 48 hours |
| Assessment | Within 1 week |
| Fix Development | Depends on severity |
| Public Disclosure | After fix is available |
- Critical: Remote code execution, data breach
- High: Local privilege escalation, significant data exposure
- Medium: Denial of service, information disclosure
- Low: Minor issues, hard to exploit
This application can transmit RF signals. Users must:
- Comply with local regulations regarding RF transmissions
- Use appropriate power levels for the frequency band
- Avoid interfering with emergency services or critical infrastructure
- Obtain necessary licenses if required in your jurisdiction
- All captured data stays on the SD card
- No cloud connectivity or telemetry
- No automatic data transmission
- Users have full control over their data
The application respects hardware limits:
- GPIO current limits enforced (max 20mA per pin)
- No overclocking or voltage manipulation
- Temperature monitoring
- Safe RF power levels (within CC1101 specifications)
- Physical Access: Anyone with physical access to the device can access captured data
- SD Card: Data on SD card is unencrypted - protect physical access
- RF Eavesdropping: Captured signals could be replayed if not properly secured
- Physical Security: Keep your Flipper Zero physically secure
- SD Card Encryption: Consider encrypting sensitive captures
- Responsible Disclosure: Report vulnerabilities you find in other devices responsibly
- Legal Compliance: Always follow local laws regarding RF analysis
This tool is designed for legitimate security research:
- Device Testing: Test your own devices
- Authorized Testing: Only test devices you own or have permission to test
- Responsible Disclosure: Report findings to manufacturers
- Education: Use for learning RF security concepts
The application includes security analysis features:
- Threat Modeling: Identifies vulnerable protocols
- Entropy Analysis: Detects weak encryption/static codes
- Fingerprinting: Identifies specific devices
- Vulnerability Scoring: Rates security risks
These features are for defensive purposes - identifying weaknesses in your own devices.
This application uses:
- Flipper Zero Firmware SDK (official)
- FreeRTOS (embedded in SDK)
- FATFS (embedded in SDK)
All dependencies are part of the official Flipper ecosystem.
Security updates will be:
- Released as soon as possible
- Documented in CHANGELOG.md
- Announced via GitHub Releases
- Backported to supported versions when feasible
We thank security researchers who responsibly disclose vulnerabilities.
Hall of Fame (researchers who reported valid security issues):
- None yet - be the first!
For security-related questions:
- Security Advisories: GitHub Security
- General Questions: GitHub Discussions
Last Updated: 2024-01-XX
Policy Version: 1.0