In addition, you can make it so that the car doesn't unlock due to proximity with the fob, but rather, it only unlocks if you push the unlock button on the fob.
I imagine an smartphone with touch sensor + car remote app would be even safer than what we have now.
If that functionality was encapsulated on a smart phone, that would be fine too.
I'm not sure why we are going backwards in the security department here. Seems like a lot to give up just to not have to stick the key in or press the unlock button.
Consumer products nearly always go features that have whizz-bang "it's so convenient" demo value, until a problem like this becomes prevalent enough to end up on everyone's nightly news.
I do have auto-closers on the garage doors, however, because my kids do have a habit of leaving them open otherwise. Of course, they also keep leaving the man-doors unlocked all day as well.
He then added "It's good that I always lock the door in the garage too".
For many people, there's no need to unlock the front door because it's never locked. Having to lock your door just means you're living in a terrible neighborhood.
Because of that, we had an additional safety feature, you couldn’t open the door from outside!
This doesn't make much sense from first principles. I assume everyone agrees that theft is equally unwelcome regardless of whether the door was locked. But the additional damages from breaking into a locked home are pretty minor compared to the damages of the theft. Why would there be a large difference in punishment?
Interesting. Is that an American thing? I do recall that most of my American friends don't lock their doors, whereas I can only think of a handful of people not locking their doors in Europe - and those live in remote outposts, where people are scarce and deer are unlikely to use the door handle.
Unfortunately, that would be vulnerable to theives unlocking your car and taking everything in it. For me, the biggest convenience of fobs is the ability to start the car and have AC on so that the car isn't burning/freezing when I get to it
The old ignition hole was the perfect solution. You had a dedicated spot for your keys, you always knew where they are, were unlikely to forget them in the car, and it also happened to start your engine. Perfect
Maybe it has something to do with the additional battery consumption that doing this incurs, probably something like double/triple consumption, with the hashing.
They are laying on a desk or in a drawer and are not being touched/moved for extended periods.
Maybe a simple mems step counter could help activate them for a short period of n seconds/minutes.
The clock has to be pretty fast, but you can get a secure time of flight measurement, so you can absolutely know the distance of the radio signal path.
I did research in this area a few years ago. Here's a research paper [1] from 1993 that goes into more detail about this type of "distance bounding" solution (i.e. authenticating received signal only if 1) it is received within a few nanoseconds AND 2) the decrypted received signal contains the previously sent random number) in order to defend against "relay attacks". The paper discloses many variations to this general solution as well.
[1] Brands and Chaum, "Distance-Bounding Protocols"
edit - thanks for the link, having a read through.
We should just go back to traditional keys if this is the case.
I want key holes in all doors. I want to insert a key to start the car.
I'm not sure if it's been from rust, lack of use + time, or ice, but unused or backup keyholes on vehicles seem to fail far more often than those used for normal entry.
"I'm lucky" is not quite the same as "that's a nonexistent problem".
Source: worked for a valet company
It still leaves a small window of opportunity for abuse, but seems like a decent middle ground.
My personal solution is to not drive often, and when I do it's a 1996 Subaru. ;)
But, he may be saying he's vulnerable for long periods because the idle timer won't kick in for him.
I'd much rather have a solution that precludes relaying; maybe something that involves a precise turnaround time in the radio signal between the car and key, and so the key physically can't work beyond some relatively short range.
As well as taking away much of the convenience advantage that passive fobs have over active-only fobs (most fobs already can be actively used, as well as passively.)
I think the over-the-air updates is one of the big advantages that Tesla has right now. They can respond quickly to critical vulnerabilities like that.
I wonder how fast other car manufacturers are going to catch up? Volvo recently announced that they are working on an Android based system, but it's not going to be rolled out before 2020.
Or maybe where the Tesla auto drives itself to the nearest repo-man?
Yes, reverting from passive-supported to active-only remote entry/start would eliminate the attack by eliminating the feature on which it is based. OTOH, the handsfree nature of passive remote entry is a major selling point.
There is a general trend that car electronics is increasingly acquiring behavioral features that annoy me, that cannot be disabled. This is all across the board; if you don't like it, you have fewer and fewer options: pretty soon, you will have to drive a used old beater if you don't like what new cars are doing.
If they are, just do a stakeout and then replay it later in the day to gain access.
Fly the drone into gated estates, or better yet a country club drive-up near the valet and record many high-value signals.