Radio Attack Lets Hackers Steal Cars with Just $20 Worth of Gear
wired.com
wired.com
The range with normal usage is very short though. If I'm on the driver side of the car, it doesn't work on the passenger door, and vice versa.
I still can't really fathom starting a car if I dont turn the key manually... I guess its like you say, silly until you use it
Have you tried electronics? 5,000 RPM should do the trick. 7,000 RPM for those extra-tough jobs.
And I've heard it's much easier to make it happen in ehm... older cars.
Edit: after reading some Mazda forums, it looks like you can just hold the shift button (if you have an automatic) while on park to make the radio stay on, no need for neutral or other gear. You might want to try that.
Physically pressing that button and hearing the click is enough for me. It takes some training, but it works quite well. So maybe it's your rental but most cars with the keyless entry have thought about this.
There's an edge case where if you unlock the car, the mirrors unfold, and if you don't open the door within 60 seconds, the car re-locks itself, but the mirrors do NOT fold. So you might think it's unlocked when it's not, but you won't think it's locked when it isn't.
My Prius has the "pull the door handle to unlock" method, and a push button to lock. But while opening the passenger door or trunk will unlock all doors, opening the driver door only unlocks that door. There is no way of automatically unlocking all doors from the driver side (other than the interior lock button).
Many cars unlock the driver's door only by default (assuming using a keyfob) but have the option of setting it to unlock all doors.
One neat thing about VW group cars (VW, Audi, etc) is the ability to use VAG-COM to reprogram a dizzying array of car functions. Other vehicles have this ability (BMW comes to mind) but require extremely expensive dealer-only tools to do it.
My problem was that I kept my key in my pocket, sat down, the key slid out onto the floor, I drove around which i could still do because the key was in the right area, but then I had a heck of a time trying to find the key so I could lock everything when I got out.
This is the same behavior I've used on all cars I've owned that have (push-button remote) keyless entry for, I don't know, decades?
1. Lock the car using the fob (which sounds the horn)
2. Unlock the car using the fob, and then lock it using the door button.
3. Pull on the handle.
This is one of those cases where I wish all products had open firmware, so that you can install a best-of-breed user interface on all cars (not to mention, have my car fob also work on multiple cars from different manufactures, and also on the my house door lock).
I quickly get used to it, but it's a bit of a barrier every time. But the problem is really around rental cars more than the feature being a bad idea.
"One hacker holds a device a few feet from the victim's key, while a thief holds the other near the target car."
While this isn't awesome, it certainly limits the effectiveness. You would have to have someone waiting in a parking lot to follow the person, then another person waiting by their car.
I do have a question though...I assume these things work on challenge/response schemes. That means that even if the car is started and stolen, it could never be started again without someone tailing the owner 24/7, which makes this a neat but nearly useless hack. Am I wrong in assuming this?
Sell for parts, program a new key, replace the key, replace the computer, etc. There's lots of room for profit on a $40,000 vehicle.
This is worse in the UK, as we have much less space, so things are much closer togeather (ie. the car, and the keys (where they are left overnight).
[0] https://www.amazon.com/gp/product/B01HETGX00/ref=oh_aui_sear...
https://m.youtube.com/watch?v=8pffcngJJq0
The West Midlands Police may want to ask you some questions.
Trying to start it again and set off the alarm? No worries! Take as much time as you need to disable the alarm before trying to start it again. After all, no one is around to stop you.
Making car keys an IoT endpoint on a cell network strikes me as one of the worst ideas ever. It is begging for exploits and failures.
Imagine the joy the first time the owner drives outside of cell tower data range and tries to re-start the car.
I am a he, btw.
Oh, thank goodness! My faith in ycomb hackers is restored!
Now, I'm off to go work on my reading comprehension skills...
“Mr. Danev said that when the teenage girl turned on her device, it amplified the distance that the car can search, which then allowed my car to talk to my key, which happened to be sitting about 50 feet away, on the kitchen counter. And just like that, open sesame.“
https://www.nytimes.com/2015/04/16/style/keeping-your-car-sa...
Light can move about 300 meters in one millionth of a second. It's easy enough to find a store where the parking lot is well within that distance from the middle of the store.
So whatever system that goes into place would need to possibly have accuracy down to the 1us level or smaller.
1 nanosecond is about a foot. A 100MHz clock gives us a resolution of 10 ns, which translates to 2.25 meters away by light in air.
As a backup if your fob battery is dead, you could use inductive power in the door, or just use that to begin with (still with distance-bounding).
Here's how I see it: the car broadcasts a (short duration) challenge message on short range (10 meters, say), the key fob, once in range, signs the challenge message, transmits it, the car checks the signature with the fob's known public key, and Bob's your uncle. If the fob can compute a signature of the challenge in 500ms, the window doesn't need to be much longer. Sure, people will likely be able to pull private keys from the fob with some effort, and duplicate it that way, but that's no worse than today. Reprogramming the car wouldn't significantly harder than it is today either.
If we want convenience and security, it seems fine to make the key fob a little more complicated and beefy.
I feel like this is by no means a new idea and maybe I'm missing something.
edit: I was missing something.
The problem has nothing to do with cryptography. Given radio signals can be relayed at will, and there's no way of knowing so (short of a way to measure quite small latencies), there needs to be a proper way to bind the cryptographic exchange to the person pulling the door open. Relay attacks (which do nothing to exploit cryptographic exchanges -- just relay messages fast) exploit that lack of binding.
This isn't about better cryptography. This is about how can the car know that the key is in close proximity to it? We can transmit data long distances.
Timing is going to be the key, how much time is allowed to be passed between sending a challenge and getting a response? Right now there is a lot of "slop" to allow the owner with the key to be turned away from the vehicle and things to still work, or have it in your left pocket versus your right when seated in the car.
My Subaru WRX requires the key to be right next to the middle console, so I can only keep my key in my right pocket. If I have it in my left pocket I can't start my car.
I don't know how much "timing" slop there is though. Could someone relay my keys transmission with a short delay?
https://en.wikipedia.org/wiki/Distance-bounding_protocol
It really is an oversight from the carmaker not to use it in the design of the keyfob.
If the security of the whole system depends on distance, the crypto behind it should verify that distance limit. The same goes for NFC, bluetooth pairing, WPS, wireless credit and debit cards, and apple/android pay. They all have 'nearby' somewhere in their security model, and in no case is 'nearby' actually verified cryptographically.
The key fob can't invalidate signals with the car once it's sent since it's too far away, so even if you have distance-bounding on the key fob, it can't tell the car to ignore an otherwise valid signal.
Given that the speed of light is ~1ns per foot then a total response time greater than (2d + p) where d = max distance in feet, and p = processing time within the keyfob in nanoseconds would provide a bound.
I suspect however that making the keyfob response time consistent might be the hardest part of the check, closely followed by an accurate timing facility within the car.
There is a startup from ETH Zurich [1] which develops technology to make relay attacks impossible. In short, they are developing a method to make the key proove its within a certain distance of the car. Some of the tech behind it: https://arxiv.org/abs/1404.4435
Almost every countermeasure defeats the convenience factor. One proposal was to have the key light up and you pressed a button on it to say 'yeah do your thing' but at that point why not just have the old style push to open fob?
Perhaps something magnetically coupled rather than RF coupled will help keep it reliably a near field sort of interaction but even that is subject to a slightly more sophisticated relay device.
IEEE 802.15.4 UWB (Ultra-Wideband) radios with timestamping functionality allow measuring the time of flight (well, not directly, but it can be inferred from an exchange of messages) of your signal. With some added crypto, it isn't difficult to build a solution which is limited to a specified distance. You can get as precise as ±20cm.
This means that you can build a system which will not work beyond a certain distance, because signals will take too long to travel.
I'm surprised this hasn't been picked up by car manufacturers yet. Perhaps there is too little market pressure.
There are protocols which are though:
Will the car continue to operate once the thief is out of range?
Is the purpose of this just to get access to your car to steal goods?
Or is this just an extreme demonstration to get automakers to tighten security?
If it was, I could throw my keyfob out of the window on a highway and the car would come to a stop.
You wouldn't be able to start the car again if you turned it off, but by then the car is long gone.
* Is it about making the exchange more computationally complex, so it can't be just replayed? I guess that would require some sort of clock in the key?
* Have 2FA with something like a phone? Like requiring TouchID on the phone to confirm when you press the key.
2FA defeats the purpose, but you could have biometrics directly on the car instead of a broadcast signal.
I think ultimately you would be relying on a 3rd party evaluation of the systems automakers are using because salesmen aren't going to have a useful knowledge of the specifics.
So if you leave your keys in a bowl by the door, they can just extend the range of the key with a relay/booster.
The car will only stop when you turn it off.
Things like this save an infinitesimal amount of time (or sometimes even make actual usage more difficult), and introduce orders of magnitude more complexity ripe for exploitation. All so people can feel like they're magical.
I believe society still have a lot of inertia toward this. I also think video games tapped into this brain subsystem, that IMO was designed as a desire to learn how to master the real world, except now technology can bridge the fantasy
Sure, I would still cope with conventional keys; I wont deny that. Just as my mum coped raising me when she didn't even have a car. But I'm just making the point that this feature isn't just some "juvenile power fantasy" and actually does help make like a little bit easier.
Though frankly, even if it was just a vanity feature then I still wouldn't begrudge anyone wanting it. Isn't that the half the reason people buy nice cars in the first place?
For what it's worth, if this is a feature you have but don't like, then some cars (mine included) do allow you to disable that feature. So it might be worth consoling your manual / checking the in car settings menu.
There is a very slim key that is included in all the key fobs that I've seen.
I have car insurance and zero worries about theft.
Still a button less key .. with a distance based protocol .. I'm no expert but it sounds so naive.
My 15 year old car has this feature!
[1] Light travels at ~30 cm/ns, so a round trip time of 1 ns corresponds to 15cm.
In that case, just make it app-only and have your iOS/Android gps-enabled device(s) be the only keyless entry.
For those who don't know what a Slim Jim is (not the snack):
http://www.autobodydepot.com/AET-SJ2.html?gclid=EAIaIQobChMI...
That's what we're potentially talking about here. Opening, and driving off in, a keyless vehicle literally keyless.
http://www.bbc.co.uk/news/av/uk-42132804/relay-crime-theft-c...
This is very much not an issue anywhere outside the US.
But this attack makes no noise (other that opening and closing the doors, and starting the vehicle), and won't set off the burglar alarm in the house, and probably won't be noticed until the vehicle owners go to drive off.
I was under the impression that this was standard for at least 15 years but since we're talking about automotive industry, some makers may not even be aware of that yet
Maybe this is already a thing?
The potential failure scenarios increase by a huge margin if you require the keyfob to be authenticated with the car the entire time.
We know that computers can't be secured... so it is a little scary to ride in one.
[1]: https://www.newscientist.com/article/2143499-ships-fooled-in...
[2]: https://link.springer.com/chapter/10.1007/978-3-540-30182-0_...
The most practical one, I think, is to make it NFC-near instead of BLE-near. Or, you know, just use a non-contactless one. Or add a button.
The limited performance of the low-power microcontroller isn't the only problem. The R/F signal itself is modulated at a low baud rate. If it's modulated at 1 Mbaud then each bit is sent as an R/F symbol that's 300 meters long in the air. In a sense the R/F receiver needs to demodulate "300 meters of R/F analog data" to be able to decode it to a 0 or a 1. If there is a little delay or noise at the beginning of the 300 meters of data because the signal is being relayed (if you can visualize what I mean), then the receiver isn't going to notice.
The low-power constraint on the keyfob (as it's powered by a small battery that must last years) prevents manufacturers from developing R/F physical layers and chips that are performant enough for precise distance-bounding.