top of page

The Radio Didn't Get Stronger. The Operator Did.

Sometime in the late 1960s, a man discovered that a plastic whistle packaged as a prize in a box of breakfast cereal produced a tone at exactly 2,600 hertz.

That number mattered. AT&T's long-distance network used in-band signaling - the same channel carried your voice and the commands that controlled the switches. A 2,600-hertz tone told the system a line had gone idle. Blow the whistle into a handset at the right moment, and the network believed the call had ended while the connection stayed open, waiting for instructions.


The vulnerability was not new. Telephone engineers had understood in-band signaling for decades, and a small number of people with the right technical background had been exploiting it quietly for years. What changed was that the knowledge got small enough to carry. First a whistle. Then a handheld box that generated the tones on demand - including a run built and sold out of a garage by two young men who would later start a computer company.

The phone network's weakness didn't change that decade. The population of people who could exploit it did.


I keep coming back to that story, because I think we are watching it happen again - and, as usual, the interesting risk is not inside either technology. It's in the seam where two of them meet.


What Actually Changed


In March, a developer released an AI companion for the Flipper Zero. The app runs on an Android phone, connects to a language model, and talks to the Flipper over Bluetooth. You speak, type, or point a camera. It translates what you said into device operations across the Flipper's sub-GHz radio, infrared, NFC, and USB subsystems, and reports back. Pair it with smart glasses and you never touch the device at all. A researcher demonstrated it identifying and taking control of a connected lamp through conversation.


The hardware did not improve. The radio transmits at the same power it did last year. Every physical constraint remains exactly where it was.

What improved is the thing directing it.


The project's own documentation makes the point better than any critic could. It lists among its features: instant expertise - don't memorize SubGHz protocols or IR formats. That is an honest description of what it does, and it is precisely the risk. Historically, a person standing in front of an unfamiliar reader, remote, or sensor needed protocol knowledge, documentation, and a lot of patient trial and error. Now they can photograph the thing and ask.


Novices can borrow expert-shaped judgment. Temporarily, imperfectly, but well enough.


From Universal Remote to Adaptive Operator

The deeper shift is structural.


Operating a Flipper manually is a series of discrete human choices: pick an app, capture something, look at it, decide what to do. The human is the loop. Every step passes through a person who has to at least form an intention.

An agentic layer changes the shape of that. Sense, classify, act, observe the response, adapt, repeat. The device stops being a Swiss Army knife and becomes a pair of hands attached to a decision engine. The operator states an objective; the system works out the sequence.


That is a different kind of tool, and we do not currently govern it as one.

I'd call the resulting exposure Proximal Agentic Exploitation - an AI system perceiving, interpreting, and adaptively interacting with nearby wireless, embedded, access-control, or cyber-physical systems through a portable hardware interface. Flipper plus AI is simply the first version visible enough to argue about. The real subject is what happens when agents acquire portable senses and hands in the physical electromagnetic environment.


Prompt Injection Grows Legs


This is the part that should keep architects awake.

If an AI companion is permitted to interpret what it sees and reads - QR codes, device labels, NFC records, Bluetooth device names, captured text, files on removable media, community-contributed signal descriptions - then all of those become inputs. And inputs can carry instructions.

We have spent three years learning that text a model reads can hijack what a model does. We have treated that as a web problem, a document problem, an email problem. Attach the model to a radio and a camera, and the injection surface becomes the room.


Adversarial object, AI interpretation, trusted hardware action.

A sticker in a stairwell. A device label in a supply closet. A crafted filename on a shared SD card. None of it looks like an attack, because none of it is aimed at a human.


The Data Leaves the Building


There's a quieter exposure that matters more in our sector than in most.

When a companion app sends context to a hosted model, that context travels. Depending on implementation, it might include badge identifiers, reader characteristics, equipment photographs, remote-control codes, serial numbers, frequency observations, location, and images of the space the user is standing in.

The person believes they are testing a local device. They may be building a cloud-resident reconnaissance record of a facility.


One capture is noise. Hundreds of correlated captures, held by a third party, describe equipment families, security architectures, facility patterns, and operational dependencies. That is a data-provenance and aggregation problem before it is a hacking problem, and in the Defense Industrial Base it lands directly on CUI handling, export-controlled technical data, and the boundaries we are contractually obligated to defend.


A Tuesday Afternoon in an Engineering Bay


Now put it in a real building.

A contractor employee brings an AI-connected handheld into an unclassified engineering area. He is not malicious. He is annoyed. A vendor-supplied wireless sensor stopped responding, the vendor's support queue is four days deep, and he wants it working before the design review.


He photographs the sensor and asks the companion to identify it. The system correlates the image against public documentation, infers a likely protocol, starts a passive capture, and proposes a short list of tests. He approves the batch. He does not register that one of them transmits.

The transmission reaches the sensor he's troubleshooting. It also reaches several neighboring devices running the same legacy protocol. The agent observes the responses, adjusts, and continues. Photographs and captures go to a hosted model for analysis.


By close of business, without a single malicious intent anywhere in the chain, the organization has: unauthorized RF transmission inside a controlled facility, interference with operational equipment, potentially sensitive imagery outside approved boundaries, identifiers collected from adjacent systems, and no reliable record of which actions a human chose versus which the model chose.

Nothing in that story requires future technology. It requires common wireless weaknesses, a conversational interface, unbounded authority, and a competent employee trying to fix something.


Who Authorized the Machine to Act?


This is where it joins the rest of my work, and where I think the governance question actually sits.


A human pressing a button on a Flipper exercises visible agency. An agent selecting among scripts, frequencies, formats, and retries exercises delegated operational judgment. Somebody authorized that delegation - usually nobody in particular, usually by installing an app.

The companion app does have safety architecture. It risk-classifies operations, requires confirmation for destructive ones, and locks system paths. That's real engineering, and it's more than many tools ship with.

It also offers to let you auto-approve by risk tier so you can move faster when you trust the workflow.


Read that again with a governance eye. The approval gate is the control. The convenience feature is a switch that turns the control off, offered at the exact moment the operator has decided the tool is reliable - which is precisely when automation bias is strongest.


And even with the gate on, a confirmation prompt is only a control if the person can evaluate what they're confirming. If a user cannot tell whether an approved action listens or transmits, their approval is a signature, not a judgment. That is the human-in-the-loop fallacy in a new package: presence treated as comprehension, comprehension treated as authority.


What to Do Before This Is Policy


Five moves, none of which require waiting for a standards body.

Inventory the seam, not the tool. Your device policy probably names Flipper Zero. It almost certainly does not name "phone application that translates natural language into radio-frequency actions." Write the capability, not the brand - the brand will change by fall.


Extend Agentic Role Mapping to the physical layer. Same questions we ask about software agents: what may it perceive, infer, transmit, retain, and send offsite? Who owns each consequential action? What proof survives it? An agent with a radio is still an agent.


Fix the systems that trust proximity. This is the durable work. The enduring weakness has never been the handheld tool - it's the large population of building automation, legacy access control, industrial remotes, and wireless sensors that trust nearness, obscurity, static identifiers, or replayable signals. Those systems were exposed before AI arrived. AI just widened the pool of people who can find them.


Treat captures as regulated data. Signal captures, facility photographs, and equipment imagery from a controlled space are not scratch files. Decide, in writing, whether they may reach a hosted model, and know what your vendor retains.

Watch for the cognitive indicators. Approvals granted faster over time. Auto-approve enabled and never revisited. Operators who can't explain what an approved action does. Actions with no attributable author. These show up before the incident does.


The Part We Got Right Last Time


AT&T did not solve phone phreaking by confiscating whistles.

They rebuilt the network. They moved signaling out of the voice channel, so a tone in the audio path could no longer command a switch. The exploit didn't get harder to perform; it stopped meaning anything. They fixed the trust assumption instead of chasing the tool.


We are about to spend a lot of energy arguing about whether a particular handheld device should be legal to own. That argument is a decade old and has not made a single door reader safer.


The device is not the problem. The trust assumption is the problem, and it is sitting in tens of thousands of buildings, quietly accepting whatever it hears.

The whistle was always going to get smarter. The question is whether the lock was ever going to.


Cyber Explorer Field Question

Walk your own facility and find one wireless system that trusts proximity - a reader, a remote, a sensor, a gate. Then ask: if an unskilled person with a conversational interface stood next to it for ten minutes, what would they learn, and what would we know afterward?


Follow Allen Westley and Cyber Explorer for continuing research on Cognitive Security, AI decision authority, Agentic Role Mapping, and the protection of human judgment in high-consequence environments.

Boundary note: This article reflects Allen Westley's independent Cyber Explorer research lens and is based entirely on publicly available reporting and project documentation. It is intended for educational and governance purposes, contains no operational guidance, and does not represent the position of any employer, customer, government agency, standards body, or partner.

Recent Posts

See All

Comments


2023 by Cyber Explorer Team. Proudly created with Wix.com

  • Medium
  • LinkedIn - Black Circle

Follow me on social netwroks

bottom of page