VW Has Spent Two Years Trying to Hide a Big Security Flaw
bloomberg.com
bloomberg.com
It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasing order of likelihood: status quo, where they just "fix" the bugs as they hit the news; some sort of massive push towards real computer security, in this and other industries; or a massive reduction in features to avoid the flaws.
This is really just another symptom of the current state of computer security, best described as "a joke." My guess is in 50 years we'll have decent computer security. There's nothing that precludes it in theory. But it's going to be an ugly, ugly couple of decades while we pay off the wave of computer-security-debt that we have been riding.
Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.
We’re not talking about a website here.
Nope. Just a high-gain antenna.
> Couldn’t the car start blaring an alarm or something in that case?
It could. But that might not help.
For example: you're driving your Mazerati down the road when it suddenly stops and the alarm goes off. The next day you get a letter saying, "If you don't want yesterday's little incident to become a regular event, send BTC500 to the following address...."
I had it happen without me leaving the seat (e.g. my wife has the keys in her bag/pocket, I had been driving, and she gets off the car to unarm the home alarm). The car is turned on by pressing a button, not by turning the key.
That's true. On the subject of movies, though, a plot point based on an actual vulnerability would be way better than typical Hollywood hacking.
You can make up for car thefts with dollars.
So there's no discernible event from the fob, as far as I can see. It's just a "this is me" signal.
You're right, that might be it.
the unlock button was on the fob rather than on the car door
Let me clarify: the fob does have buttons for lock, unlock, panic, and open trunk. But I don't normally use them. My normal usage is as I described: just walk up with the fob in my pocket, and press the button on the door handle.
The attack works by overhearing the exchange between the car and the key fob, and then doing an somewhat brute-force analysis to calculate what the secret key on the fob must have been.
I tried reading the paper (not an expert). In the recommendation section, it does not suggest implementing a delay either. Is it just not physically possible with RFID?
I mean, a 4 digit pin with a 5 second delay would take 14 hours for all combinations (better than the half hour with Megamos)???
I have to be missing something.....It can't be this easy.....
My guess is that they're then doing the brute-forcing "offline", not against the vehicle's system. If you know the algorithm and the keysize, and you can see one successful authentication, you could ship the work of workig out which key replicates the authentication you just saw off to AWS or custom hardware (I wonder how readily Bitcoin mining ASICs can be tweaked to attack embedded or IoT authentication?) (Though it seems there's flaws somewhere in the crypto anyway - they somehow broke a 96bit key with under 2^18 attempts...)
Security is about trade-offs, after all.
Stranded in hostile environment (middle of nowhere in the arctic or a desert) could be a death sentence.
I think a more realistic exploit would be a corrupt tow-truck driver / mechanic targeting an area where tourists stop.
2 communications isn't much at all. Getting something from your car and locking it back up is all it takes.
Even worse, they get it down to 48 bits.
Mechanical locks imply that each individual thief needs to learn how pick locks. With computerized locks, you only need one hacker to crack the security for each model of car, and then a bunch of two-dime thugs will only need to download the app and get going in with the car-thief franchise.
Where every single thief had to be a skilled lockpicker before, now you just need a few specialized crackers and then you can mass-produce user-friendly hacking devices or even downloadable software.
Where a thief had to spend several minutes in a compromising pose near the car, often carrying suspicious tools, now he can just sit on a bench nearby, wait for the magic click and then choose the right moment to stroll in. A passerby might as well think he's the owner.
A couple of weeks ago I saw someone using a slimjim, and I did nothing. I have never done anything in reaction to a car alarm. I'm not sure that thief's pose is sufficiently compromising.
Only one of those three is the correct answer, and it is the third one.
Your car does not need a wireless network - since you have a newer, nicer one in your pocket every 18 months.
Neither does your refrigerator nor your smoke detector.
These are self-inflicted problems and they're easy to solve - just remove the gratuitous complexity.
I'm not surprised in the slightest, I think this sort of news will keep popping up all over the place and manufacturers will keep trying hard to suppress it. We know it will never end: good crypto is hard and inconvenient, so it's unlikely that car manufacturers will ever implement it properly. Bad guys get all the info they need, eventually, so it's just a matter of time before any digital lock is broken.
I know it sounds stupid but I remember seeing it on HackerNews a while back. I'm not sure if it was debunked or not.
http://www.networkworld.com/article/2909589/microsoft-subnet...
Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it. Otherwise live with the consequences.
I won't be surprised if there's another, even more serious vulnerability in Volkswagen locks. The security researcher who found it probably sold it to the bad guys, totally understandable after reading how Volkswagen handles security reports.
If really the problem was relatively trivial, VW should have warned me on how to avoid it, and they didn't. It can't be a simple amplifier: it's not just proximity, you actually have to press a button on the dongle to open a door, so whatever they were doing, it wasn't just repeating an existing signal; and as I said, I can tell you that making sure the car is locked has become a nightly ritual.
Whether my locks open with an easily-spoofable RF signal or with a bruteforceable key, the bottom line is still that they are not doing good crypto in situations where it's clearly necessary.
I can imagine a design where the RF signal is being generated on a very low voltage/low power device that's always/permanently on, and pressing the button enables an integrated antenna that suddenly boosts the signal to a usable signal strength.
In that case, the attacker just has to simulate a increase in signal strength if they are already tapping your signal.
Electronic design doesn't follow the same rules as physical device designs - for example, that power button on your PC, it doesn't really close any circuit! It just tells the motherboard that it's ok to let voltage through a certain electrical pathway, the computer is already permanently on and is trickling power from AC / Mains.
You can use software to tell the motherboard to activate the same way that "pressing the button" does - ie remote server control over pxe, etc.
Most cars are always on trickling power from their battery waiting to hear that signal, I wouldn't be surprised if dongle design follow the same principle.
http://www.theguardian.com/technology/2013/jul/30/car-hackin...
> The research team first took its findings to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013. The car-maker filed a lawsuit to block the publication of the paper - arguing that its vehicles would be placed at risk of theft - and was awarded an injunction in the U.K.'s High Court.
But then they don't detail the legal situation that led to the two years of litigation and the eventual release, so I don't know who to be mad at..
the fact you weren't affected is just because stealing a car is not the hardest part of the ordeal.
And getting back to the original point: I'd want to see some coverage of how this disaster happened in the UK courts.
Hence, to answer to the question posed "So how many vulnerable cars are on the roads of the world right now because the UK High Court wanted to "protect consumers""
I would answer 'possibly zero, BECAUSE of that' and once they are manufactured and sold they exist regardless of the owner, till they are destroyed.
I merely countered the plight of old VW owners with that of new VW owners.
Public release of the general problem is still worthwhile as information, but there is a net "security" loss here.
And it's not like regular people are going to turn into car thieves because this exploit has been made public. Not even house burglars will turn into car thieves. I would guess that car thieves are very specialized due to the seemingly complicated logistics behind these operations, so it's unlikely that they weren't aware of this exploit.
I'm far from being an expert on the subject, but I don't see how this is a net loss. I see very little potential for a spike in thefts and a high probability of VW finally facing the problem.
> Meanwhile VWs are still being stolen using this exploit
Holy fucking [CITATION NEEDED] batman!
Now, after lengthy negotiations, the paper is finally in the public domain - with just one sentence redacted.
"This single sentence contains an explicit description of a component of the calculations on the chip," Verdult said, adding that by removing the sentence it was much more difficult to recreate the attack.
The bigger mistake than sourcing imperfect components is the attempted cover-up and I am positively surprised that this is even reflected in the headline. (at least theoretically: the first glance takeaway message for this story will always be "security hole in car!", no matter how much the author tries to put the cover-up in focus)
They got an injuction so that's a pretty public way to go about trying to do a "cover-up".
"Cover up" sounds accurate to me.
Unless they advertised the car as being unstealable or anything close there's not even a marketing point that's not working as one could reasonably expect. Carmakers call this a theft-deterrant feature, they don't even call it anti-theft or similar.
The immobilizer is not as secure as one would hope, but nobody ever promised you anything here in the first place.
What keeps your car from being stolen is not the immobilizer. The government and laws are what keep your car from being stolen.
Other companies have been known to do voluntary recalls defective locks, why is VAG exempted in your mind?
"It barely can even be considered an immobiliser" is almost certainly contrary to reasonable consumer expectations, and it wouldn't surprise me if the EU, at least, had laws regarding this kind of issue.
It wouldn't fill me with warm and fuzzies if I were sold a high-end door lock / alarm system / safe that was only exploitable with 'special gear and know-how far outside the realm of the typical thief.'
Then you'd better never buy a high-end door lock / alarm system / safe, they all have that in common.
The issue with electronic exploitation is that the know-how component is relatively trivially automated. Script kiddies, etc.
If I bought an $80k Porche, I'd be bit miffed that it could be stolen from a parking lot in the time it took me to have a sit-down lunch.
I don't think Porche et al are under any illusions their windows are rock-proof. ;)
If you bought an $80k Porshe you knowingly bought something you know will be a target for theft, and probably have enough money to have anti-theft insurance and be able to afford the inconvenience which would be your car vanishing. Yes apparently the ease of it being stolen is slightly greater than you thought when you bought it. But if not having your car stolen was a top priority for you then you would not of bought a car which people would want to steal as much.
As they mention in the article this would of been a difficult thing to fix on existing models, they did however change the system so it doesn't apply to new models.
As always, relevant XKCD: https://xkcd.com/538/
See http://krebsonsecurity.com/ for plenty of examples.
Otherwise they've just delayed the information getting out which seems pointless?
What a nightmare. Car manufacturers have to design more resilient systems.
Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side.
If so, they will also have to think about a quick way to deploy security fixes remotely. One way could be working with connectivity solutions for Embedded Systems (e.g. SigFox).
All messages on the CANBUS are securely signed, there are multiple rings of security where data can always pass only in one direction, etc.
The only thing this exploit enables is that if you already have the car, managed to break the steering wheel lock, managed to replicate the magnetic signature of the key, and managed to start the motor, that you can circumvent the immobilizer that comes after that.
This is a pretty minor flaw compared to the "full control via radio" that competitors had.
And the fact that the car has a steering wheel lock (the steering wheel is locked in the right-most position) is also standard.
According to my knowledge, keyless entry is even illegal in Germany. (But I am not a lawyer, so I do not know if that applies at all, or if the legal situation just ends up stating that drunk people owning a car with keyless entry may not be close enough to their car that the immobilizer is deactivated)
On most cars, you'll never notice the immobilizer as it's RFID based, passive, and requires no batteries. The only way you'd find it is if you take apart the key fob or have to service the ignition lock, at which point you'll find the RFID antenna ring around it, or if you try to get the key replaced.
So will some cars produced before 1998. The Audi S2 (listed in the article) is one of those, and was built from 1990 to 1995.
Depending on how the car manufacturer spec'd the engine<->skim handshake, you might get as lucky as to just be able to isolate the offending skim/rke unit and MITM/replay its messages. If the rke and skim units are separate, there's an outside chance that the beacon that is sent after remote-start that lets the engine know not to turn off doesn't contain a secret key itself and can be replayed. In any event, I'd assume that physical access to the vehicle means that a kit could be deployed in minutes to steal the vehicle without any fuss.
Bosch recently published how their variants are used to prevent stuff like break-in through the radio.
The system is safe against replay attack (by prepending a timing signal to the encrypted message), has seperate rings of trust (so your gas pedal can control acceleration, but your radio can’t), and is in general quite safe.
And, well, with a physical kit you might be able to start the kit, but the steering wheel lock can not be unlocked without a physical key. And even if you break through that, you need to stop the immobilizer.
So you end up breaking open the door, breaking with large tools a part of the steering wheel lock, (hoping the car does not have an anti-intervention system, usually a cat jumping onto the car already starts a loud alarm), then you have to actually start the car and run this 30-min brute force attack against the immobilizer, after having sniffed the owner before.
It’s theoretically possible, but it's not really a practical attack.
You break door lock, get inside, pop the hood. Alarm starts, you spray polyurethane foam into alarm loudspeaker and it shuts up. You close the hood and go away for 10-20 minutes keeping a lookout on the car. You come back, swap computers, turn on the car and drive away.
I'm sure the time to fix is also made more problematic by the need to fab new chips.
Mechanical keys have the "photograph" problem (i.e. a single photograph can be used to reproduce them). Wireless start has the wireless hacking problem (i.e. if you broadcast, that can be intercepted/manipulated/etc). Digital keys have neither of these, and can utilise real challenge/response protocols since the keyfob can be powered by the car while authenticating.
I will say I don't know if wireless entry will ever be secure. Too many technical problems to overcome, soon we'll be reproducing the military's channel hopping.
Right, what could possibly go wrong?
Something tells me giving the car's immobilization system a routable IP address is not the best way to "fix security"
They captured 2 uses of the RFID-based immobilizer. That gets used every time you start the car, regardless of how you unlocked the car. It's completely separate from the UHF-based keyless entry system which you use to unlock the car.
The paper makes this distinction in the first paragraph, but of course the article fails to distinguish.
- Remote central locking via UHF
- Immobiliser authentication via RFID (this is what is vulnerable)
- Key for the ignition barrel or manual unlocking of doorsBut anyone waiting to spend 30 minutes with an electronic crack is also smart enough to use liquid nitrogen to crack this too.
The difference is that a keyless hack can look natural since there is no physical force for entry or ignition. A funnel and chisel would raise some eyebrows.
The full paper here: https://www.usenix.org/sites/default/files/sec15_supplement.... has a lot better detail.
For affordable options, I have no idea.
Until then, buy a Lada Niva. No one will want to steal it and it doesn't have anything complicated in it that can be hacked.
Get an old American junker.
There are very high-end car thieves who want flashy cars, but the vast majority of car theft is about 1) ease and 2) what the parts are worth.
Radio keys should be OK although they have their own security risk.
No one is going to crack that but a guy with the right piece of plastic can still take down a window, get in, and steal the car. If someone wanted to murder me, they'd need physical access to the car to mess with it.
So...yeah. No situation is 100% safe or secure. However, pretty much anything wireless pretty much guarantees any criminal can just make a kit to do X and sell it to actual car thieves claiming he thought they were [legal profession like car repo].
Sort of like how people sell malware/"security tools" now. "Oh, I sold it to a criminal. HOW COULD I HAVE KNOWN?" :p
If you're worried about safety, buy a car with a good crash safety rating. You're far more likely to get into a normal crash due to bad human drivers or mechanical failures than you are to be hacked.
If you're worried about the financial loss from a crash or theft, your best protection is good insurance.
Not for long.
But I really doubt that all the thieves out there will learn fancy technology so they can steal newer cars. A few will, but most will find other things to steal.
Right now, popular new cars are stolen in amounts of hundreds per year in the US. Older cars (like the Honda Accord) are stolen by the tens of thousands. That's not because older cars are more valuable, it's just because it's a lot easier.
By saying a thief would have to understand how a computer exploit works, it's saying a thief needed the equivalence of an engineering degree to drive away with a car before computers entered the equation. Exploit discovery, maybe, but it doesn't take much to execute packaged tools you bought on the blackmarket.
Whatever the reason, stealing newer cars is harder. That increased difficulty translates into decreased theft rates.
For now. Once they get out of circulation only newer cars will be left and at that time it might be that thieves could buy devices to hack into these cars just as you can rent botnets today.
Pro-Tip: If you're chaining your bike up, make sure the chain can't touch the floor.
It has been this way for about two decades. It is much easier for thieves to slice-and-dice a common vehicle into hard-to-trace parts, since the hot parts will disappear into a sea of legitimate used and reconditioned parts. High-end cars are comparatively rare, and thus harder to dispose of discreetly.
Things started improving in the 90's (falling from 143m to 115m). In 2000 it was at 112m. 2008 saw the sharpest decline - down to 78m. In 2012 it was 65m.
The difference between 112m and 65m is staggering - and is largely due to newer, safer cars being on the road.
All figures above are driver deaths per million for registered vehicles taken from: http://www.iihs.org/iihs/sr/statusreport/article/50/1/1
E:
Although Subaru has a good track record of safety. I just think the fear is misplaced. For most people driving older cars, I'd be far more scared about my safety during a crash than my safety from a potential hacker.
Both are of concern, of course.
That biggest change since 2012 has been increased roof strength requirements. This was driven at least in part due to the popularity of top-heavy, rollover prone vehicles.
Meeting these requirements have required cars to get heavier and incorporate massive roof pillars. This negatively impacts gas mileage (relatively minor concern), but, far more importantly IMO, means that nearly every new car out there has awful rear visibility. So we've bandaided that by requiring backup cameras, but those don't help when you're moving in traffic. We've created a situation where most new cars on the road have huge, terrible blindspots by trying to make the cars safer.
Again, better safety is a good thing, i just think that we just need to do a better job of balancing it with the usability of the vehicles.
Interesting, though. I had noticed this trend - coming from a 2002 Outback, most of the ZipCars I drove seemed to have terrible rear visibility. Now I know why.
I am actually curious because this is the only part of this whole thing that does not make sense to me. Even if I disagree with Volkswagon's decision to not notify existing owners that there was a vulnerability known or eventually provide them with a fix, the decision at least makes sense because it probably was deemed more profitable for VW.
"The scientists wanted to publish their paper at the well-respected Usenix Security Symposium in Washington DC in August, but the court has imposed an interim injunction. Volkswagen had asked the scientists to publish a redacted version of their paper – Dismantling Megamos Crypto: Wirelessly Lockpicking a Vehicle Immobiliser – without the codes, but they declined."
http://www.theguardian.com/technology/2013/jul/26/scientist-...
<rant>As owner of an 1985 Westfalia, I have nothing but contempt for the inconsistent and poor engineering of this beast. Even with the factory Digijet pro training materials and factory service manual and several mechanics later, this thing still won't idle right when cold or warm. Systemically went through each system (fuel, air, electrical, mechanical, vacuum) individually and triple-checked per procedures and looked at general stuff like grounds and wiring too. Maybe the community factor akin to Mini Cooper owners: ostensible value built on hazing by ostentatious, expensive repairs due to substandard engineering. Sure VW has/had the hippie thing too, perhaps also due to them being difficult/expensive to maintain or being less powerful.</rant>
I'm grateful though the beastie doesn't have OBDII or keyless entry. (Like most German vehicles of this vintage, the drivers' side door doesn't lock without the key to avoid locking oneself out.)
The Internet of Things will recapitulate all the painful experience of how this stuff works out we just spent twenty years getting sorted out in the software field.
Whenever anyone says "Internet of Things", reply "unfixable Heartbleed everywhere forever."
Sysadmins will be in work until we're 100 if we want to be, cleaning up after this rubbish. Like elderly COBOL programmers, making the big bucks after retirement.
Shouldn't that be security 101, limiting the rate to a couple per minute, max? Why allow such brute force attacks in the first place?
EDIT:
Or in other words, why is the phrase "brute force password attack" still even heard in 2015?
I do object to car companies knowing about a safety issue & keeping quiet due to it being "cheaper" to accept a couple of deaths than fix it. That kind of thing should be punished with eye watering fines in my view - not to save those 12 lives but to put the message out there that car companies need to get it right instead of playing the odds.
Doesn't sound cost-effective.
"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." ... "A VW spokesman responded: 'Volkswagen maintains its electronic as well as mechanical security measures technologically up-to-date and also offers innovative technologies in this sector.'"
Since they haven't recalled the vehicles and replaced the chips, that would be... not precisely true?
"The transponder uses a 96-bit secret key and a proprietary cipher in order to authenticate to the vehicle."
not sure there's anything more you need to know than "rolled their own crypto"
Start-stop can save significant fuel - 3% - 12% by some estimates, and it comes at very little cost and complexity.
edit: In the past couple of years things seemed to have mixed up a bit in the industry (for example American cars have quite improved in quality). So who knows, maybe today's cars might hold up much better 10 years into their life , than their predecessors. But increasing incorporation of software and electronics into these probably will not help them get there.
It's like switching a traditional light bulb on and off in a continuous way - it won't last years (some 100+ old light bulbs still work fine, but the were powered-off just a handful times).
Yes, that too. Although I imagine it would wear out certain components of the engine (such as starter-motor, and crankshaft?) and battery rather than the engine as a whole.
Total-Cost-of-Ownership-wise, a stop-start might save more in fuel than it would cost in increased repairs (Or it may not, depending on make and model among other things).
http://www.autocar.co.uk/car-news/new-cars/stop-start-long-t...
While a home light bulb may not stand up to continuous on/off cycles, a bulb that's designed to do so (like a low-voltage bulb with a heavy filament) can last for a very long time.
So I wouldn't retrofit an existing car with a start-stop system, but I wouldn't have any qualms about purchasing a car with a start-stop engine as it would have been designed for the purpose.
See for yourself: http://www.nhtsa.gov/staticfiles/nvs/pdf/NASA_FR_Appendix_A_...
If it was the latter case, somebody should really serve them a class action suit. Security by gag is not helping the end customer.
Some of the models on the list feature neither keyless entry, nor are high-end (the Audi A2, for example). While the Audi S2 may be considered high-end, it certainly wasn't available with keyless entry, and I wouldn't be suprised if the Audi 80/90 (which the S2 is based on) were affected, too.
Especially in cars without keyless entry the immobilizer is only one of dozens of mechanisms against theft.
I have car insurance for my Porsche. According to the list it's vulnerable.
Chance of getting stolen? Quite small. If it does insurance pays in my case the full value not the depreciated value (age of car as only one reason). Not something I am worrying about.
How many cars are actually stolen as a result of this flaw?
Just another example of the security industrial complex fanning the flames...