BMW, Audi and Toyota cars can be unlocked and started with hacked radios
telegraph.co.uk
telegraph.co.uk
Side note: if you have a great infosec podcast to recommend, please share!
For me the earlier stuff from SN was far better, but now it is mainly adverts and talk about non security stuff.
There are a few others out there but none worth mentioning.
EDIT: As pointed out in a comment elsewhere in this thread:
> The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.
Don't Have Keyless Entry.
It's getting to the point where I don't think I'll ever buy a car made after the early 2010s.
All jokes aside (although it's true about my car), it just seems like a fundamental truth that digitally-secured systems always provide convenience at the cost of, well, security.
The wireless bit does seem like a big regression over non-wired digital security, though.
Window smashing is still an option, though!
Personally I had seen this twice in action. First was back in the early nineties I could unlock my friends Escort GT with my key and he could unlock my EXP. Neither could start it. Now my Aunt and Uncle had a Ford Windstar and Mercury Sable. The Sable key could start the Windstar but not unlock it. My Aunt found this out the hard way after a trip to the store where she could not get back in the car.
Now my BMW motorcycle uses a keyless ignition but you have to stand so close that I am not sure how well the hack will work. As in close I mean nearly rubbing up to it and only from the left side, from the right if they key is in the pocket away from the bike it won't recognize. There is an emergency key which is an little plastic type that has no power of its own, you can start the bike provided you find that magical point near the dash it actually works; by that I mean it took me and the dealer five minutes to get it to work
Car door locks are immaterial anyway, since any thief is just going to break a window. The immobilizer matters, certainly, but even an immobilizer vulnerable to sophisticated attackers is doing two orders of magnitude better than purely mechanical security.
[1] http://www.nytimes.com/2014/08/12/upshot/heres-why-stealing-...
[1] wear made left pedal unscrew itself over time, I couldn't ride single legged anymore so I took the failing pedal, the seat and went to my appointment.
I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.
https://farm4.static.flickr.com/3277/3011586006_42403e0788.j...
It was a folkie punk band ;) With that promotional sticker. I had one, but didn't put it on my bike.
I must say, however, that after my new (expensive, and lovingly customized and maintained) bike was stolen, I did fantasize about remote-controlled explosives. But then I just filed an insurance claim, and replaced it ;)
Still, I wouldn't personally ever stand up to pedal on an SA 3-speed unless I personally owned it and knew its maintenance condition...
It's no wonder they don't want to import a bunch of foreigners. I can just imagine how their society would be completely ruined if they allowed millions of Americans to move in. Bike theft would be the least of their problems.
My own country(Poland) had mandatory bike registration 30 years ago(during communist rule) and no, it didn't stop bike theft.
the cheaper the stuff, the healthier the aftermarket, if it's a mass produced item. people who buy cheap stuff want to buy even cheaper stuff parts when the stuff breaks.
1. It operated on mechanics that I could see and touch and fix with a wrench, as opposed to opaque black box computers. I did not need a code reader to diagnose problems.
2. Thanks to point #1, I had the confidence in the knowledge that it was maintained correctly, the parts were good and soundly installed, that every bolt was tightened to the right torque specification, because I did quite a bit of it myself, and could visually inspect any work that someone else did.
3. Points #1 and #2 let me learn a hell of a lot about car maintenance and how everything works than you can with today's computers-with-wheels.
4. It was built years before every manufacturer decided to make their cars look like identical bars of soap, so it had a distinctive '80s look that you don't see much of anymore.
Sadly, the state of California decided that the car had to meet emissions standards that were far stricter than anything the original manufacturer ever dreamed of, so it eventually became impossible to smog. I had to sell it to someone outside the state and I'm currently driving a boring bar of soap.
There's nothing wrong with it, i'm not sure why i'd want a newer one.
For my own personal, and endless, amusement: I paid more for my phone than I did my car.
I'm naive but it doesn't seem trivial to me.
Also, the link ought to be fully authenticated and end-to-end encrypted. And one could require the user to press a button on the key fob.
Fobs could require a 'wake up' key press after a certain duration of inactivity.
Fobs could have a physical switch on them, enabling an airplane mode.
These ideas all give up some manner of ease-of-use.
Once in pairing mode, the physical key and ECU use standard public-key crypto (ala SSL) to setup a secure connection, then exchange keys.
In theory you could allow boot-strapping another key so long as an existing paired key is present which would make the procedure above your failsafe for when all keys are lost/destroyed. If you wanted to take things a step further you could use a form of distributed Kerberos where the manufacturer sets up a physical key with a ticket allowing access to one (or a set) of allowed cars but that makes the manufacturer's systems a massive target for hacks/social engineering which is a problem because thousands of dealer technicians need access to those systems... that's the point of the delays and short acceptance windows above. An evil tech or hacker can't pre-create a bunch of keys on the sly.
To unlock or remote start, the key broadcasts a HELLO message, encrypted with the ECU's public key. The ECU responds with an ACK+nonce encrypted with the physical key's public key. The physical key decrypts it and replies with an ACK+nonce encrypted with the ECU's public key. Congrats, you now have a reasonably secure system that prevents replay attacks.
Ultimately it would require embedded software engineers and company management who a) understood security and b) gave a shit. Both are in extremely short supply.
The only way to secure against the described exploit is to measure round-trip-time from the car -> key -> car and ensure it's under, say 5 light-meters: aka 16 nanoseconds, plus the carefully calibrated time it takes the key to compute its response.
16 nanos is a very short amount of time, and it'll be tricky to measure that reasonably accurately.
The real solution is to require the user to interact with the key in some way, like pressing a button, or perhaps moving it around (as would happen as you walked with it in your pocket).
>A PKES car key uses an LF RFID tag that provides short range communication (within 1-2 m in active and a few centimeters in passive mode) and a fully-fledged UHF transceiver for longer range communication (within 10 to 100 m). The LF channel is used to detect if the key fob is within regions Inside and Outside of the car. Figure 2(b) shows the areas in proximity of the car that must be detected in order to allow a safe and convenient use of the PKES system. The regions are as follows. [1]
1. http://www.syssec.ethz.ch/content/dam/ethz/special-interest/...
Yes, the actual key itself is located by the car based on Low Frequency RFID.
The attack described is a relay attack, which means that the key can be spoofed in real time by relaying short range radio transmissions to two locations.
The mistaken assumption of the security system is that the short range communication protocol used by the car and the key requires the key to be in close proximity to the car.
Since the communication may be relayed, the range assumption is invalid. The main suggestion is to use high precision timing to determine the range, as it is very difficult to cheat on the speed of light.
I agree that "signal strength" is not the best way to phrase the above in a technical discussion.
I have not seen any indication that triangulation or any other physical location system is used in vehicle PKES.
One attack vector is stealing cars out of a supermarket parking lot. You just wait for someone to drive up in the model car of your choice and have your accomplice discreetly follow them into the store. When your accomplice texts you that they are at the bread aisle/back of the store you can just steal with impunity knowing that a bystander will see no difference between the actual owner who has the key in his pocket and you with your relay device in your pocket. You also know that your victim is in the back of the store and that they can't get within sight of you before you're already long gone.
Wikipedia has an article with links to research:
My friend (who's not particularly technical and probably didn't know what a faraday cage was previously) told me that's what we has doing with his Prius key after it had been broken into with no sign of forced entry twice.
I get that regular keys could be copied and locks picked, but I feel that if you can't securely do wireless unlock and keyless start, then don't put it in.
The car industry has a lot to learn about security. I almost refuse to believe the stories where hackers take over the onboard computers via the entertainment systems in a car, because I can't believe that anyone would be stupid enough to link the two system. Yet, companies like Jeep seems to believe there's a reason that the computer running the GPS and radio needs access to the breaks.
Not only security; with GPS and radio having access to the breaks, the car industry has a lot to learn about safety.
The entire industry that allowed this kind of terrible design needs to study the lessons of the Therac-25. Nobody seems to understand what "fail safe" means anymore.
Proxying the radio signal over this link introduces a req/res delay. The handshake starts when the car detects fob proximity but there is still a communication with the key for authentication (otherwise you could have a replay attack). So if the car side is programmed to be strict about req/res timing you can defeat a proxy like this (in theory at least) at the expense of a higher false-negative rate.
Every x milliseconds, probably ;)
This article isn't very good.
1. http://www.syssec.ethz.ch/content/dam/ethz/special-interest/... See page 13: Part Providers
To be secure against this type of attack, such a device has to be designed assuming the adversary controls the nearby radio spectrum and can do relaying and MITM.
To control for distance, a speed of light based latency limit might work, though I don't know how cheaply it could be implemented. Laser based distance meters are cheap now, and light travels just 30cm per 1 GHz clock cycle...
edit: Although his car was still eventually stolen when the thieves used some kind of specialized tools to bend his car's hood. The tool allowed them to bend the hood without triggering the alarm somehow and cut the power sources to the alarms. Then they put it on a repo/tow truck and drove away. I guess he showed his alarm to the wrong hot girl he would always bring around when we all hanged out.
When the police found the car everything was gone except for the car's frame and bent hood.
So here is what you do, amplify the key ping coming from the house, that gets you into the car. Plug this black box into the ODBII and program a new key. Now you've gone around the alarm, and the immobilizer. And the car is yours.
Remote control key : you push a button on your key (the transmitter), it sends a signal to a receiver in your car, your car authenticates the key (probably a request/response challenge involving some crypto), and opens the door.
Now if you swap the transmitter and the receiver : you put the transmitter button in your car door's handle, and you move the receiver to your key: you have your magic key fob.
From what I understand, the security relies on the fact that the power of the radio signals emitted by the transmitter and receiver are very low, so the range of usage is limited to a few meters. The thiefs and researchers exploited this by amplifing the radio signals of both communicating devices to extend the range up to 90+ meters.
I really wish car manufacturers would not rely on security through obscurity for these systems though.
2) breaking a window creates noise, usually.
3) it still takes time to start the car after you break into it. not so when you hack the radio.
all in all, this hack turns something that would take minutes into something that takes a couple of seconds and leaves the vehicle intact, i.e. beyond suspicion.
Even on the infinitesimal chance they steal the car itself, you have car insurance. It doesn't really matter aside from the inconvenience, and the odds are so low it seems like a silly thing to be an absolute deal breaker for anyone.
Even if they mean "switch on the electronics which control the motor" - I find that hard the believe. There's nothing on the key fob which can do that.
And, even if they did, the battery use of a parked car is negligible.