Thieves boosting signal from key fobs inside homes to steal vehicles
cbc.ca
cbc.ca
In addition, you can make it so that the car doesn't unlock due to proximity with the fob, but rather, it only unlocks if you push the unlock button on the fob.
I imagine an smartphone with touch sensor + car remote app would be even safer than what we have now.
If that functionality was encapsulated on a smart phone, that would be fine too.
I'm not sure why we are going backwards in the security department here. Seems like a lot to give up just to not have to stick the key in or press the unlock button.
Consumer products nearly always go features that have whizz-bang "it's so convenient" demo value, until a problem like this becomes prevalent enough to end up on everyone's nightly news.
I do have auto-closers on the garage doors, however, because my kids do have a habit of leaving them open otherwise. Of course, they also keep leaving the man-doors unlocked all day as well.
He then added "It's good that I always lock the door in the garage too".
For many people, there's no need to unlock the front door because it's never locked. Having to lock your door just means you're living in a terrible neighborhood.
Because of that, we had an additional safety feature, you couldn’t open the door from outside!
This doesn't make much sense from first principles. I assume everyone agrees that theft is equally unwelcome regardless of whether the door was locked. But the additional damages from breaking into a locked home are pretty minor compared to the damages of the theft. Why would there be a large difference in punishment?
Interesting. Is that an American thing? I do recall that most of my American friends don't lock their doors, whereas I can only think of a handful of people not locking their doors in Europe - and those live in remote outposts, where people are scarce and deer are unlikely to use the door handle.
Unfortunately, that would be vulnerable to theives unlocking your car and taking everything in it. For me, the biggest convenience of fobs is the ability to start the car and have AC on so that the car isn't burning/freezing when I get to it
The old ignition hole was the perfect solution. You had a dedicated spot for your keys, you always knew where they are, were unlikely to forget them in the car, and it also happened to start your engine. Perfect
Maybe it has something to do with the additional battery consumption that doing this incurs, probably something like double/triple consumption, with the hashing.
We should just go back to traditional keys if this is the case.
I want key holes in all doors. I want to insert a key to start the car.
I'm not sure if it's been from rust, lack of use + time, or ice, but unused or backup keyholes on vehicles seem to fail far more often than those used for normal entry.
"I'm lucky" is not quite the same as "that's a nonexistent problem".
Source: worked for a valet company
It still leaves a small window of opportunity for abuse, but seems like a decent middle ground.
My personal solution is to not drive often, and when I do it's a 1996 Subaru. ;)
But, he may be saying he's vulnerable for long periods because the idle timer won't kick in for him.
I'd much rather have a solution that precludes relaying; maybe something that involves a precise turnaround time in the radio signal between the car and key, and so the key physically can't work beyond some relatively short range.
As well as taking away much of the convenience advantage that passive fobs have over active-only fobs (most fobs already can be actively used, as well as passively.)
I think the over-the-air updates is one of the big advantages that Tesla has right now. They can respond quickly to critical vulnerabilities like that.
I wonder how fast other car manufacturers are going to catch up? Volvo recently announced that they are working on an Android based system, but it's not going to be rolled out before 2020.
Or maybe where the Tesla auto drives itself to the nearest repo-man?
Yes, reverting from passive-supported to active-only remote entry/start would eliminate the attack by eliminating the feature on which it is based. OTOH, the handsfree nature of passive remote entry is a major selling point.
There is a general trend that car electronics is increasingly acquiring behavioral features that annoy me, that cannot be disabled. This is all across the board; if you don't like it, you have fewer and fewer options: pretty soon, you will have to drive a used old beater if you don't like what new cars are doing.
If they are, just do a stakeout and then replay it later in the day to gain access.
Fly the drone into gated estates, or better yet a country club drive-up near the valet and record many high-value signals.
They are laying on a desk or in a drawer and are not being touched/moved for extended periods.
Maybe a simple mems step counter could help activate them for a short period of n seconds/minutes.
The clock has to be pretty fast, but you can get a secure time of flight measurement, so you can absolutely know the distance of the radio signal path.
I did research in this area a few years ago. Here's a research paper [1] from 1993 that goes into more detail about this type of "distance bounding" solution (i.e. authenticating received signal only if 1) it is received within a few nanoseconds AND 2) the decrypted received signal contains the previously sent random number) in order to defend against "relay attacks". The paper discloses many variations to this general solution as well.
[1] Brands and Chaum, "Distance-Bounding Protocols"
edit - thanks for the link, having a read through.
Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way."
Sure enough, enough, key fob attack and theft. Caught on their video cameras. Filed the police report, claimed insurance, cried internally about the loss of a gorgeous vehicle. In all seriousness though, it's just a car, so no big deal, but nothing will fix the violation you feel, and the fact that you were being targeted.
If I were the insurance companies, I'd be putting pressure on the car companies, but hey, maybe it's just the cost of doing business for them. Better to pay out for a vehicle theft, vs. actual injuries from a collision. That's probably why there's little incentive to fix it, especially if fixing it makes your product less convenient.
Once they got very far away from the house, the car should shut off. Or so I would think.
This is why every car company has examined it and chosen to not do it.
This feature actually saved huge inconvenience for us once. While visiting the other coast for wife's mom in the hospital, we used one of her parent's cars to drive to the airport with her brother to drive it back. We get out at the airport, get luggage, hugs, bye, head into terminal -- with the key still in her purse. Car running, doesn't notify him until too late to chase. If it stopped after 2min, he'd be stuck somewhere outside an airport 100mi away from anyone he knew. Instead, he just drove it home, got & used the other key for a few days, and we mailed back the first key when we arrived.
Things that seem reasonable at first....
It means the key has to he inserted somewhere. That makes it both safe and predictable.
(& yes, I still start my car with a key that is inserted, and mine also has a clutch & manual H-pattern 5-speed)
The way it works is reasonable. Maybe tighten up the proximity. But honestly, I miss my classic keys.
Mine will beep for a bit if I leave the car with the key. But the vehicle also works when the fob's battery is depleted (it has an RFID tag and an embedded physical key for the door). Having the car randomly shut off based on something so potentially flakey seems like a worse idea.
In the event that the actual owner of the car left their fob at their previous stop and discovers this fact 40 miles down the highway later, if the car were to stop, the driver is now stranded with a car that won't start. As it is now, as long as there is enough gas in the tank, the owner can just drive back and get it.
I've declined this but expect that insurers will push for it to become mandatory. They would love to be able to charge unsafe drivers more money, and in the abstract I don't have a problem with that, but the tracking is creepy.
This is why I am not going to get one, nor a “smart” water or electricity meter: give more data to corporations, and you can be sure that they will use it against you.
And also give car owners an incentive to keep their keys safer, given how many vehicles out there are vulnerable to this. Just fixing this for new cars is only half the solution.
I remember back in the 80s my parents got a discount on their insurance for installing a third brake light in the back window of their old Camaro. If my insurance gave me a discount, I'd get a faraday cage for my keys. I'm considering doing it anyway, even though my house is pretty far from my driveway, and we have cameras.
I've searched for nice-looking faraday cages but haven't found anything good. I think there's a market for fashionable key/phone faraday cages, between this car theft issue and the push to digital detox.
EDIT: curious why this is downvoted? I'm not saying that this shouldn't be fixed by car manufacturers going forward, but we need to do something about the millions of cars on the road already. Is there another solution that would make more sense? Or is there something I'm missing here?
If anyone knows how much leakage there would be for fobs/phones, and whether it makes a difference for this application (where the sniffer/attacker would be 10+ feet away), I'd love to know it!
I just completely wrapped my remote with one layer of aluminum foil and that was enough. A small gap on side was enough for the car to detect it.
Of course this only foils overnight theft. I imagine it would be trivial for someone to follow me from a car park to a public location and sit next to me to get the key signal from my pocket.
Then just a metallized flap for extra protection.
Leakage is fine. As long as it’s in the right direction.
The companies could even give away nice-looking faraday boxes that cost them next to nothing to make, and which would probably have decent adoption among people who have requested them. That would cut the hard costs to be very low, and give them a branding/perception benefit.
Imagine seeing "Mercury Insurance is giving away a Fob Box to any customer who wants one." It wouldn't make me switch to Mercury, but it would make me think more highly of them. And if I were just out of college and choosing my first insurance company, I'd undoubtedly choose them.
Given the spate of thefts and the likelihood that it continues, a promo like this could resonate for a long time and get mentioned in lots of news stories.
Why is it always up to us to deal with the consequences of all this poorly thought out new crap?
It sort of reminds me of the way they want us to believe that "identity theft" should be our problem to clean up, when its really caused by banks poor security practices.
What do you mean? It's not as if anyone will be driving less... the insurance company will pay for a new car, the family will buy a new car (presumably they need it), and still be just as statistically likely to collide with the new car.
Oh please, this is Ontario. The auto insurance companies main innovations have been:
1) getting caps on benefits
2) creating new driving violations to jack up your premiums (eg: non-criminally blowing over 0.05, but less than 0.08)
Neither resulted in lower premiums for anyone else.
Free cars?
Whats the yield on the secondary markets for these hot vehicles since the VIN is compromised, a new license plate is needed and a thorough scrubbing has to happen
Some luxury sellers are actively making it difficult to buy for export to arbitrage this.
Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.
Tesla is using an NXP Athena OS based smartcard that uses the Java Card 2.2 platform for it's NFC Key on the Model 3.
Edit: there's a discussion down the page somewhere. The issue seems to be that (for power reasons) they use low-freq radio, on which it's hard to get timing accurate enough for 10m distance changes.
To think of it another way: before keyless entry was a thing - how many people were thinking 'damn I wish I didn't have to get these annoying keys out of my pocket?'
To think of it yet another way: How many people buy the upgraded trim on their car mainly for the keyless entry?
(Not having a go - genuinely curious)
I used to have a car without this feature and it was sort of annoying for 5 seconds each time I have to unlock the car. I do get annoyed when I get a rental without this feature too.
Additionally, this also helps when I am carrying bags or other large items with two hands. I can simply make a kicking motion at the bottom bumper of my car and the trunk will open automatically instead of me having to put the bags down and fish for my keys.
I agree that it is minor and not a real deal-breaker, but it is a nice to have.
More efficient for the car to estimate the distance and power of the transmitter.
These thefts have been going on for years and they will not stop until key-less go is dropped or changed such that the key requires interaction (like every higher security transponder has for, like, always).
It also depends on the reliability. You could also say that you can't just shut the engine off if the electrical contact in the keyhole is wonky.
And the challenge-response pair must be different for every transaction, otherwise the thief can easily grab a SDR with tx capabilities, get to the car and ask for a transmission, record the spectrum, then go near the car owner door, transmit the car challenge and record the key fob response, go back to the car, wait for another challenge transmission and time the response accordingly. Not even need for a second thief.
An added bonus, it also makes the keys much more comfortable to have in a pocket, holds them in a fairly flat orientation - and stops them from scratching a phone!
The smallest ones I could find would actually hold two fobs, but when filled were large and uncomfortable enough in my pocket that I preferred to just keep the fobs naked.
I still haven't found a good solution that actually works for keeping passive fobs secure while they are actually in my pocket.
Why is it transmitting without the user pressing a button? Is that a feature? As you walk up to the car it automatically starts like magic? I'm not familiar with these newer cars.
The really nice feature is when you walk away (a few seconds after you're out of range), the doors automatically lock. However, the downside of this feature is my wife's car does not have it -- and so at least half of the time when I am driving it I forget and leave it unlocked in parking lots.
This is the problem with a lot of the newer tech in cars like backup alarms. You become used to various features in your own car and when you rent a car you need to consciously remember that the vehicle doesn't have $FEATURE. Effectively, cars are becoming a lot less standardized. A car I rented a few weeks ago beeped at me a couple times and it took a while before I realized it was the lane departure warning triggering on a couple turns.
A reasonable person would probably have turned around and exchanged the car with the rental company at this point.
I am not a reasonable person.
Instead, I headed directly to a truck stop and purchased a heavy-duty power inverter, dropped the back seat, and crammed my portable PA speaker into the trunk, connected to the car's trunk-mounted battery through the inverter and to my iPhone through a shielded audio cable run from the trunk to the front seat.
The result sounded far better than it should have, and what it lacked in convenience (I had to pop the trunk to power it down) and channel separation (one speaker = mono), it more than made up for in dB SPL.
(for the record, I've also repaired eBay purchases that arrived in worse-than-advertised condition rather than returning them, for no other reason than that learning how to fix things is more fun than going through the hassle of returning them)
My brother in law did this on a ski trip with a borrowed Range Rover. It was only at the end of the week he realised he'd left his keys in a jacket pocket in the car the entire time and it had been sitting unlocked in the car park half a mile down the road from the apartment. Thankfully it was fine but stealing it would've been a case of getting in, pressing the start button and driving away.
It's not transmitting anything, it works pretty much the same way NFC works. Both the key and the car have their own public/private key pairs(which were obviously set by the manufacturer) and when you touch the handle the car transmits an unlock request to the key, encrypted with the car key's public key(this is going to get confusing lol) - when the key receives the message, it decrypts it using its own private key, if it's correct then it replies with an "ok" message encrypted with the car's public key. When the car receives that it decrypts it using its own private encryption key and opens the doors. Simple, and in theory unbreakable. The issue is that the car doesn't measure how far away from vehicle the key is - it only relies on the fact that the transmitters used by the car and the key are super-low range(like, within 50cm). Which is obviously defeated by using signal boosters.
In typical designs, the car continually transmits a low-frequency (e.g., 135 kHz) radio signal to wake up any wireless keys within range. When a key receives this signal, it replies with a VHF (e.g., 315 MHz) signal, and the car unlocks or starts when a door is opened or the start button is pressed.
The reply signal, at least, is uniquely coded to the car. The attack is to extend the range of the LF wake-up signal, causing a key stored away from the car to transmit a valid reply.
In some models, besides the transponder described above, the key also has a passive RFID tag, which works with a reader in the car to allow starting even if the battery in the key is dead.
(The article is wrong about the broadcasts, by the way; if the key transmitted continually, its battery wouldn’t last long.)
Could you just record the relay signal and play it back whenever, essentially replicating the key?
It is pretty much standard across all cars now days, except maybe the very bottom of the line models.
Newer vehicles are already mitigating this attack, eg by measuring signal timings. Signal relay introduces a delay which can be identified and rejected.
- Low appeal to thieves interested in stealing the vehicle itself, due to the hardware (locks and whatever else) being exceptionally difficult to deal with
- Some sort of secure/hidden compartment for concealing valuables (I know, I know, don't keep anything valuable in your car, but let's say it will still be more secure than keeping it outside of the car)
- Following up to that, an especially secure trunk (if such a thing exists)
- A wagon or smaller, so no minivans/crossovers or anything bigger
- Under $25k used for something recent, maintainable (was looking at Audis but I don't want to risk maintenance issues), and with low mileage, which puts Teslas out of the picture (sadly)
The convenience here is that the system requires no confirmation from the driver, no physical interaction with buttons, handles, keys, etc. The driver just opens the door and starts the engine. This allows for a trivial remote sniff-and-replay attack, not unlike copying a key temporarily.
I bet not having a lock on the door would be even more convenient. But for some reason it's not widely practiced.
It's a poor design for the system to take any access-escalating action without an explicit command from the user that initiates a secured transaction that is resistant to MITM.
It's poor design to assume that the range is based on raw signal strength; it should use round-trip-time measurements (for packets exchanged with MITM resistance).
Requiring user iniciation seems like the adequate solution here...
You don't need complexity in the FOB; the car starts the clock, sends the signal, measures the time taken to reply. If it exceeds some threshold ignore the response.
There is no way to spoof this if the request/response itself is using proper cryptography.
But there are better solutions. I've heard about a car maker (I think it was BMW, but don't quote me on that) that put an acceleration sensor in the key fob. It would only broadcast the signal while the key fob is moving.
I see I made a naive statement here. Let's consider the access-reducing action of the vehicle locking itself when the fob becomes distant. That is also open to exploit; if the attackers boost the signal when they spot a driver walking away from the car, then the locking neglects to take place as the driver enters a building and goes out of sight.
However, auto locking a car based on proximity is justifiable as a fall-back measure to explicit locking with a button. The rationale is that if the user forgot to lock, it is probably better to do it for them than to do nothing.
I just want an off switch in my fob, so i can disable it at night. More fancy solutions would be a motion sensor on the fob to only power it when had recently moved, or for retrofits, this technology in a battery?
And it‘s only disabled temporarily. As soon as you press any button on the key again (e.g. open the car), keyless-go will be activated again.
They have to have a mandatory recall if your Audi accelerates quickly by itself (that was in the early 80's i think), but no recall for a possible vulnerability in a jeep where someone can hack into the machine and control the acceleration (and other items).
This would be worse with centrally controlled autonomous vehicles, they are always sending and receiving data. Image the firmware on your car not being updated after 2 years and being stuck with the still open vulnerabilities.
It is kind of an apples to oranges comparison, but nonetheless it gets the point across.
What a coincidence.
Jokes aside, this is bound to happen.
It’s disturbing that a vulnerability like this isn’t caught as a show-stopper before the technology is sold to consumers.
All you have to do is keep the fob inside a shielded case at home and you're fine.
Because we all have Faraday cages in our homes, and I'm sure the salesman who sold the car also made the customer aware of this vulnerability. /sarcasm.
Yes, most people who own cars new enough to have this vulnerability own microwave ovens.
Everyone knew about this for many years. Interactive transponders are quite old (late 90s? early 2000s?) and were designed to mitigate attacks like this one (because the user has to interact with the transponder, i.e. press the button it has for it to work, all passive attacks fail).
My car is unlocked at night but in my garage. If they got in my garage somehow and had the signal repeater they couldn't drive off unless I pushed the keyfob button. In the morning I just have to push it once to go. You can also en/disable auto door lock if you walk away.
Of course a general solution that blocks signal repeaters would be best. Tesla has so many fun tweaks it's truly the programmer's car.
Center "touchscreen" consoles with awful usability, shifters that are not obvious (coupled with people that are too lazy to pull the parking brake) and now this
Voice can be sort of ok, as long as your speech models are locally stored (no internet blackspots), but deny access to those who cannot talk, or for whom you haven't bothered to build a speech model that matches their language/accent.
>"They do that for safety so that if you lose the key fob or if it loses signal the vehicle doesn't shut down while you're driving, but that right there is part of the vulnerability."
Anecdata, a few years ago my wife had a Renault "Megane" that used a sort of "card" that worked with proximity. She opened and started/drove it without ever taking the card out of her bag.
A couple of times I was driving it with her in the passenger seat, we arrived to a shop, she got down in front of the door and went into the shop while I was going to park it when the car some 20-30 mt away "locked itself" (cannot remember if it stopped or just didn't allow more than - say - 5 km per hour) with the display saying it couldn't find the card.
When she changed cars, her new Renault (using the same kind of card, at least visually, but a different car model) had to be inserted in a slot to allow the Start/Run button to operate.
But do they really transmit all the time, or do they contain accelerometers or something to prevent battery from being wasted?
in other words, requiring a button press.
> But do they really transmit all the time, or do they contain accelerators or something to prevent battery from being wasted?
I'm curious about this as well. A family member has an older Nissan with a keyless fob and I don't recall them ever having to replace batteries/keyfobs.
Something you know: numeric unlock code.
Unlocking the doors could be 1FA, but moving the vehicle should require 2FA.
Were these types of immobilizers never a thing here?
I shut it off, exited the vehicle, re-locked it, and saw that my own car was actually the next one down the row. There are only so many combinations of pin heights in a car lock.
I have been paranoid about not keeping valuables in my vehicle ever since. That door lock is only keeping someone out for a few minutes, at best.
And if you lose your key? $$$ to get a new one. Want a copy for safekeeping or because you have additional drivers for the car? More $$$.
If someone wants to get into your car they will. They will just break a window. If they want the whole car they will get it. The only person who is having a more difficult time is the owner.
Edit: some / all of the power drain would be offset because the RF transmitter would be off while the sensor is on.
Years ago, McDonalds was handing out pedometers[1] which had a year+ battery life along with a display in a package smaller than most key fobs.
If the speed of light is to fast, maybe using sound could work.
That said, the fob is much more battery-constrained than a watch that you charge on a daily basis.
Here's the patent: https://patents.google.com/patent/US8930045
[1] https://www.google.com/search#q=speed+of+light+%2F+2+ghz
With measuring the time, however, presuming that radio signal will travel on the order of one foot per nanosecond, you have much less of a threshold tolerance. If the unlock takes place within two feet of the car, that is two nanoseconds. If the key sits 20 feet away, that is a 20-nanosecond one-way travel. So this solution would need to be able to distinguish between a four nanosecond gap (round trip time) and a 40-nanosecond round-trip time.
Add to that the turnaround time in the car CPU which I would imagine to be some number of milliseconds, would 10 ms be reasonable?
Thus, the electronics in the car needs to distinguish between 10ms + 4 ns vs 10ms + 40ms. And given jitter in any modern CPU/memory/OS/electronics device, I would bet that the jitter totally swamps that.
(Keep in mind that this is a BOEC https://en.wikipedia.org/wiki/Back-of-the-envelope_calculati...)
The only true solution is to stop using transmitter power as a proxy for proximity when houses/etc are not opaque to that signal.
Instead, use something that the house is effectively opaque to for the distance part of it.
IE include an ultrasonic receiver in the keyfob, transmitter in the car and require it output the distance to the car.
(or something, i'm just spitballing)
The problem is almost certainly the power requirement.
https://www.urbandictionary.com/define.php?term=Boosting%20C...
(wireless) Key fob capturing and replaying require far more equipment than NFC PVC card (credit card) cloning.
Your original comment is that cloning is nearly if not entirely nonexistent. Of course it has advantages. But it's difficult and doesn't happen in the real world. What happens is replaying. Which isn't difficult.
I used to lease a 2015 Toyota Auris(facelift). One year into the lease someone broke into it smashing the rear-left window and just drove away.
I know late 2000s Rav4s could be stolen by thrusting a wire through the left-front mudguard and disconnecting something(not sure what) inside this way. There's a clip of a Russian demonstrating this technique somewhere on youtube.
All I found was shattered glass from the window.
So besides relaying the key, you can just hack via the CAN bus. There's also a trick to use a second ECU to bypass the immobilizer, but that's probably too time consuming.
Many manufacturers (inc. Toyota) also allow bypassing immobilizers and other features using TechStream and a maintenance tool. If they claim you have to buy a new ECU if you lose your master keys, call bullshit: https://attachments.priuschat.com/attachment-files/2015/10/9...
Manufacturers really need to hurry up and implement more accurate timing detection in the keys - it should be absolutely trivial to detect how far away the key is based on the response time, but for some reason manufacturers don't do this yet.
Edit: I also know people who take the exact opposite approach with their expensive vehicles - they leave the key in plain sight near the front door, so if someone wants to steal the car using this method they can do so without entering the house or if they do break in they will(hopefully) take the key and leave, without threatening and possibly harming their family. I'm not sure which way is better - preventing the thief from stealing your vehicle and risk that they will then decide to break in and get the key from you, or let them steal it and just deal with insurance later.
Is that true? Accurate, very low power distance detection has a lot of potential applications (e.g. your phone straying too far away) but BLE (for example) doesn't really work for measuring distance--through signal strength--at all. If it's possible, I'd be very curious how to build such a distance detector.
If you just simply add distance to the system with no additional overhead. The time it takes for the ack should go up in a measurable amount of time.
And if you did anything more -- like some of the system do today -- where they make a generic pipe that pipes it over the internet via LTE and back -- then for sure we would have a ack way out of the time tolerance.
Method 1
(car){signal amplifier}<-------->{signal amplifier}(keyfob)
Method 2
(car){transceiver}[LTE]<-------->[LTE]{transceiver}(keyfob)
To my knowledge most of these systems work but using some sort of out of band transmission over other wireless means such as WIFI/LTE/or simply another band.
The second method they use has to do with rolling codes. Where they jam the signal and intercept your keyfob code, preventing it from reaching the car. They store this and when the target realizes they did not actually lock/unlock they car they attempt to unlock it again. This time they jam the signal from the keyfob to the car, but replay the code they intercepted the first time, and saving the last code sent from the keyfob for later when the target is not around. This method works for more than just cars, it can be used for most rolling code systems.
[1] https://locatify.com/blog/in-practice-precise-indoor-locatio...
Perhaps if the keyfob needs to do some additional conditioning on the data (eg some decryption+encryption), or is very slow, the extra overhead of the relay is small in comparison.
I don't know how the keyfob conserves power, but I guess some kind of duty cycling the radio, in which the first wake-up latency of the keyfob is not necessarily know beforehand. But, just send a few packets back and forth and get the overall latency and it should be able to determine if a relay is used.
This seems like the best strategy to me. If you have a desirable vehicle and someone decides to break into your house to get hold of the keys they're going to turn the place upside down trying to find them. If you're in at the time you're also putting yourself in a lot of danger.
Just leave the keys by the front door and let the insurance deal with it.
People who's threat model does not include home invasion can generally leave their keys wherever is convenient in your home with immeasurably little additional risk. If you feel your threat model includes home invasion then where your keys are if the least of your issues.
It turned out that the patient had committed a home invasion, only to be greeted by a homeowner wielding a replica katana. The invader tried to defend himself by holding the blade...
I can easily see that situation becoming lethal to the invader if the homeowner really wanted it to.
It's not possible. A keyfob has a relatively slow R/F communication channel, less than 1 Mbit/s (at best) because it's constrained by power. Thus the "length" of a bit transmitted over the air is 300 meters or more. The receiver needs to demodulate "300 meters" of R/F signal to recover a single bit. A difference of +/- 10 meters when these thieves boost the signal across your front yard is therefore indistinguishable from R/F noise and not demodulable by the receiver. You can visualize this as a 300 meter bit that has a noisy beginning and a noisy end.
That's why the distance-bounding techniques (term we use in the field) used by car manufacturers are instead pretty primitive, such as measuring the strength of the R/F signal (which is easily defeated by a proper signal booster.)
I'm just trying to think of any reason the keyfobs NEED to use low frequencies, and all I can come up with is cost
Use those and you can base your distance estimation on time measurement, rather than signal strength. Amplifiers won't help.
Their ranging algorithm critically depends on the receiver time-stamping the "leading edge" of the first bit of the first byte of the PHY header. This bit is either always 0 or always 1 (it's part of the 802.15.4 data rate field), so an attacker can easily cheat by preemptively sending a 0 or a 1 just before the signal booster can relay the first legitimate bit from the keyfob. This legitimate bit will be received (by the booster) while the preemptive bit is still being transmitted, so the booster can smoothly transition to sending the subsequent legitimate bits, and the receiver will have been completely fooled that the keyfob is nearby.
DW1000 is nice but it only works in scenarios where both transmitters and receivers are being honest to each other.
Could you Honeypot the cars wake up signal? If the car detects a delayed broadcast of it's wake up signal it could trigger an alarm or at disable keyless entry. The high frequency signal will have lower tolerances for a timing check.
Or car makers can provide Honeypot keys. If the key receives a wake up signal it can alert the owner and disable keyless entry. The owner would put the Honeypots where they don't want their keys to activate.
If the repeater is directional / shielded on the side toward the car, I'd think it would be impossible to distinguish echoes of a repeated signal from normal echoes.
They can't even secure the thing that directly unlocks your car and enables thieves to steal it.
It will be interesting to see how legal liability shapes up with self-driving.
Everything else in our lives we've automated using our cellphone and apps. So why not cars?
Bring back the old mechanical coupling method, upgraded for better security in close proximity, and provide a long range automation method via app.
Just like your standard light switch. We have the old mechcanical way of using it, and our new radio based way via app.
The hopping pattern should be derived from a good cryptographic protocol that also contains mutual attestation.
To you and me, changing the batteries in a key fob isn't a big deal. But more than once I've seen people walk into the auto dealer's repair center because their fob stopped working, and all the tech did to repair it is replace the battery.
(If you think that sounds stupid, I work in healthcare, and we have employees who spend a surprising amount of time teaching people how to put AA batteries in their blood pressure and other medical gadgets.)
Coupled with a cryptographic authentication protocol these solve the issue quite nicely.
What I'd really like to be able to do is to wirelessly tether a Tile-like small long battery life device to a band (or watch) I wear with user configurable distance settings but it doesn't look like the tech is quite there today. UWB does seem to be the current approach you'd take though.
I've currently got a blockchain "proof of proximity" idea on one of my back burners.
kids Lunch box would not block, small metal garbage can, would not block, cookie tin would not block. All would block if you lined the edge with aluminum foil before putting the top on.
foil lined Potato chip bag would block.
Wrapping in enough aluminum foil will block the signal
Those faraday bags are convenient, but I park in the garage so Im not that worried. Garage door openers now have lock switches which prevent the door from being opened using any opener.
More info on this? Mine is older and doesn't have anything like it.
Regarding the keyfobs, I've seen demonstrations on video where the RF signal was relayed. I can search for them, but they were in German.
It's convenience factor that makes a big difference for people that tend to get to their car with full hands.
> Whatever happened to key fobs you had to PRESS to open a car?
They still exist, handsfree entry is an upgrade (or an included feature but only on higher trim levels) on many models.
What's considered a safe distance? How far away can they pick up the signal?
But to be honest it’s easier to keep them in a metal box that shuts properly. That’s what i do (although my fob still needs interaction, so i should be a bit safer, in theory).
Also consider that keyless cars actually still have a way to enter, be it physical or remote: garage-supplied universal keys and software. VWs for example have an old-school keyhole under a thin plastic bit on the door, so that garages can access it when you lose the fob.
Or you know, maybe put a button on the fob.
Glad I have a key.
Easy fix: a thing called a "button" that you press before it broadcasts the private key. Even better, also broadcast a different key each minute, like GA
How did they not realize that was a bad idea?
If you need to push the button to unlock this won't work, but they could still smash a window and then relay attack the ignition. Challenge would be determining prior to the break-in if the FOB is close enough to relay. Plus the most vulnerable cars tend to be the most expensive. From the article I'm a little surprised the RAV4 has passive entry.
I have a 2009 car. It'd NOT start if I don't have my key fob inside the car.
I don't hear much about the speed of light being used for security, but it's applications are innumerable.
Triangulating it won’t help. It thinks it’s there.
Relay thefts
According to Bates, many of these thieves are using a method called "relay theft."
Key fobs are constantly broadcasting a signal that communicates with a specific vehicle, he said, and when it comes into a close enough range, the vehicle will open and start.
"The way that the thieves are getting around this is they're essentially amplifying that low power signal coming off of the push start fob," he said.
"They will prey upon the general consensus that most people are leaving their key fobs close to the front door of their home and the vehicle will be in the driveway."
The thief will bring a device close to the home's door, close to where most keys are sitting, to boost the fob's signal.
They leave another device near the vehicle, which receives the signal and opens the car.
Storing the keyfob in a faraday bag blogs the signal and prevents the relay attack from working.