Car theft by relaying signals from wireless keys
technologyreview.com
technologyreview.com
Sadly but this future already is in Russia for a long time. This google translated article [1] from 2006 is about different code-grabbers. There is different car insurance price depending do you have additional not so easy breakable wireless alarm installed.
Would be nasty. Imagine the car key running out of battery on the motorway.
If you start the car with the key as passive (ie: dead battery - you have to hold it on the ignition button to be detected), it recognizes the difference and doesn't complain.
If your RFID required a battery, and required that it constantly be on, then the battery would need to be replaced often. Couple this with your car potentially shutting off in the middle of the highway and you've got a very unsafe car.
I know for certain that VW keys do not need the battery for the RFID to work. The battery is only used for remote lock/unlock. Perhaps other cars are different, but I'd consider that a design flaw.
edit: forgot to mention that my VW does not even have physical locks except for the glovebox. A dead rfid battery, if it had one, would mean i was stranded. I'm actually not sure what happens if my car battery dies while the car is locked.
My car has no visible physical locks - there's a small notch under the drivers door handle you can pop off a piece of the handle using the fob, and then there is a physical lock you can get into the car with (no way to open the trunk until you turn the car on).
I've had to do this a few times :)
Like I said, you can still use the key to start the car, but if the battery is dead, you have to hold it up to the start button.
I'll stick with "real" keys for a while yet.
Also, once you've driven the car away, you'll have to find another way of starting it in future; relaying still needs some kind of physical access (albeit at 8 metres distance) to the original key.
(I'm aware of broken crypto in some wireless keys, which is purely an implementation issue - you can make these secure. That's not what this article is about. Quote: The attack works no matter what cryptography and protocols the key and car use to communicate with each other.)
Apparently, once the ignition is enabled, you can drive off without needing the key "nearby" (interesting experiment, I'll have to try that next time I get a "keyless entry" rental). Once you can drive off, the car is pwned - you can strip it for parts (chop shop) or fully defeat the key/ignition security away from prying eyes.
If you turn the ignition off and it can't "see" the key, it will give you a warning message on the display cluster and you have something like 20 seconds to re-start the car before you're locked out.
[1] You usually need to press the button a second time to unlock the remaining doors. There's also often a separate button to independently unlock the boot. A typical procedure is therefore: open boot with the relevant button, put shopping inside, close boot, take trolley back to the stand, walk back to the car, unlock only the driver's side, get in, lock door with button from the inside, drive off.
Another way would be to attach the key to something like a smartphone. The car finds it location via GPS and stores it on a server somewhere. If the fob receives a signal from what it thinks is the car, it asks the smartphone to confirm its location is near the car's location. The fall-back in case the smartphone is out of battery or the car did not post its location would be this vulnerable method where the fob simply responds if it has received the message from the car.
If I made cars, I'd make sure I'd solved this problem on my products, then buy some TV adverts showing thieves in carparks bumping other manufacturers locks wirelessly with ease. Perhaps backed by graceful classical music. Try and make it look like the advert was bought by my rivals and aimed at car thieves.
Although that might be asking for it...
No crypto is broken in this scenario.
EDIT: I understand now, having read more carefully, about how this particular MITM attack works. Nasty. The only solution would seem to be to give up some convenience.
The article notes that their system specifically delays the challenge/response by nanoseconds vs. milliseconds by staying in the analog realm because doing a A/D -> Tx -> Rx -> D/A sequence added too much delay.
This implies either the car security system either measures the challenge/response delay or could measure it in which case this MitM attack still will work since attack's nSec delays will be very difficult to detect.
Most relay attacks require the signals to be converted from analog to digital and back, which takes time. The researchers were able to keep the signals in analog format, which reduced their delay from microseconds to nanoseconds and made their attack more difficult to detect.
Untold Billions are probably lost every year by someone in charge ignoring something learned by freshmen undergrads.