Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
wired.com
wired.com
Story time: Back in 2005/2006 when I worked for Siemens Automotive on Immobilizer feature (was involved in Mazda and Ford projects) I got my hands on the highly secret crypto source...and much to my surprise I've seen they implemented a Vigenere style of cipher. I was astounded by this. Having some crypto background as pet projects on previous years I knew this class of ciphers are at least 1.5 centuries obsolete and they are thought only from historical perspective. Therefore I prepared and called a panel of higher-ups (managers, group leaders and even including the hardware department chief) showing to them that the source code implementation is very dangerous and that for a criminal group to mass steal cars would be very easy. Including telling them exactly what the article is talking about - put an RF recorder under the handle door (how many car owners will check there?), record sessions of radio communications between key fob and the car, analyze that, extract the crypto key and steal the car with a duplicate no more then maximum a week after. Their reply? : "standard in industry call that we also allow mechanical keys to open doors/start the car, so a criminal group can do them as well much easier", and that was the end of that meeting.
DST40 https://en.wikipedia.org/wiki/Digital_signature_transponder used in Fords of that period is a Feistel cipher not a Vigenere cipher. Now, I wouldn't choose a Feistel cipher for this problem today but it certainly is not 1.5 centuries obsolete, this type of encryption wasn't even invented until the mid 20th century and a very famous example would be DES.
Here is an analogy - Microsoft is Siemens and Ford is IBM. Microsoft sold DOS to IBM to equip their PC's. As for what IBM implemented/used for BIOS, was not Microsoft's job, get it?
Also I can tell you on all current and last gen Ford and Mazda’s, the inter-car encryption and authentication has vastly improved.
Wrong! Immobilizer is just a tiny part of the BCM (Body Control Module), to which the normal folks usually interact with and call it on-board computer. The truth is that you have CAN (Controlled Area Network), used by BCM and ECU to communicate through, at the very least. When you press the start button, ECU asks BCM "hey dude, can I start the car?", and BCM responds with "yes" or "no" based on various factors, one of them which is Immobilizer. Even with correct key fob and authenticated, if your door is opened it will not let you drive. Of course, all these varies from car maker to car maker. Some will let you start it but you can't drive for more then 3 meters, others won't even let you idle the engine. You have a crapload of sensors that are part of BCM (tire-guard, wipers, door ajar, belt, etc etc) all of which are taken in consideration to yield that "yes"/"no" response.
And that's just a small part of what BCM does. Also poor ECU, an entire computer on its own right, reducing him to running the fuel pump is like saying a house is to shelter you from bad weather.
Saying immobilizer simply keeps the ECU from running the fuel pump is like saying that all you need to create Witcher 3 game is Visual Studio.
<Also I can tell you on all current and last gen Ford and Mazda’s, the inter-car encryption and authentication has vastly improved. >
As per article, you can see for yourself this is not really true. My code that I've worked in those years (2005/2006) were to be deployed in 2007 Mazda RX-2 and 2008 Ford, so in regards to last gen (cca. 2010) I bet you're simply wrong again. I do hope latest gen has better encryption but I doubt, wanna know why? Because economics. Lemme tell you first hand experience. Managers care about economics and that means cheaper parts. Cheaper parts means less memory, less speed. The goal was always to have the BCM's CPU load between 70% and 90%. Did a smart code and you reduced the load bellow 70%? The higher-ups were jumping happily in the air because it meant a big fat bonus for them due to allowing them to stick a crappier chip on that PCB. That's what they care about, not strong encryption and elimination of theft. Also read about Ford/GM practices in 60's when they preferred to allocate about 200 millions USD/year for paying victims of accidents than have belts. Until they got regulated by law, they could not care less about lives.
The encryption has been broken already but it’s basically trailing bmw and Mercedes etc by about 13 years, so definitely money related but likely they don’t want to or are unable to negotiate patent rights in their technology
It looks like Wikipedia agrees with me and in addition, the Engine Control Unit article state that they are usually called the Engine Control Module (ECM) to lower confusion. https://en.wikipedia.org/wiki/Electronic_control_unit https://en.wikipedia.org/wiki/Engine_control_unit
Different OEMs vary in architecture and naming. Making it a bit of a hassle working in a teir-1 with multiple customers.
Instead of paying $100’s to rekey the car, I stuck the broken key into a machine at Home Depot. It cracked the encryption in a few minutes and produced a duplicate key. The brand on the replacement is “Ilco”. It’s bulkier than the OEM key, but it works great.
Anyway, I’m not at all surprised to hear the car uses an obsolete encryption protocol.
"[1052] Defeating a RFID System With The ESPKey" => https://youtu.be/0SEHUqkbIjU
"[1056] This Black Box Reads RFID Cards in Your Pocket" => https://youtu.be/dTObKtHzroM
The lesson in 1052 sort of misses the point. LPL (his videos are a lot of fun by the way and I recommend them to anyone who is curious about lock picking) says:
> So, if you are installing an access control system like this it is really important to use one that only transmits encrypted data
This would defeat the ESPKey demonstrated, but of course that product exists precisely because it's all you need for common systems today. If "encrypted data" was common the ESPKey's successor would probably be a product that sits next to the reader and gets its own copy of the raw RFID signal. Not as convenient, and less fun for doing cool demos, but still plenty effective enough for crooks.
What you actually need to do to defeat this is a bit more expensive. You need the token (keyfob, card, etcetera) to be smart enough to use the tiny surge of power to do local computation, and then produce one-time-only access codes. That would actually fix the problem, because to get the current code a bad guy needs to steal the token and that's an ordinary physical security consideration that humans are used to dealing with. This way an ESPKey gets the one-time code you just used, but neither replaying it nor copying it to a card to try later will do anything useful.
Unfortunately this smarter token would be significantly more expensive. We saw with EMV cards (payment cards) that the smart and secure option (DDA with changing cryptograms) is expensive enough that providers would often rather take a risk and give you an insecure cheaper alternative which looks identical, especially if they believe regulators, courts etc. won't realise they took the cheap option and so the risk actually lands on their customers not on them.
Why do you need the keyfob to rely on a "surge of power"? Can't you put a battery in it and charge that battery when driving? If the battery runs down, you needed a backup anyway (physical key or phone app) in every implementation I've seen.
There are literally hundreds of other protocols and systems that are much better: the DesFire EV2, etc [2] for similar costs (ie 80c vs 70c) [3][4]
Just wanted to point out that the systems that you hypothesize exist already, and are not orders "Significantly" more expensive.
[1] https://en.m.wikipedia.org/wiki/Wiegand_interface
[2] https://en.m.wikipedia.org/wiki/MIFARE#MIFARE_DESFire_EV2
[3] https://www.idcardsdirect.co.uk/nxp-mifare-desfire-ev2-4k-bl...
[4] https://www.amazon.com/100pcs-Proximity-ISOProx-26-Bit-H1030...
There have been vulnerabilities found in older versions, but as far as I know, later versions are still considered secure.
MIFARE is not a card type, it's more a family of cards in the 13.56MHz space, produced by NXP.
There are multiple cards under the banner of Mifare, including:
- Mifare Classic 1/4k - UID + Storage space, with individual keys and crypto. Suffers/ed from multiple vulnerabilities. Used mainly in cheaper hotel access systems, gym cards, etc etc. Can be secure, if your security layer relies on strong crypto on card contents, as opposed to the crypto of the card itself. There are no counters in Mifare Classic.
- Ultralight / Ultralight-C / Ultralight EV1 These cards are low cost, reduced storage space, and are / were conceived specifically for the transport industry. They have 'one way' counters that can be used to deduct 'credits' - but these can't be re-written - so they fulfill the task of discardable tickets.
- Mifare DESFire 3DES / EV1 / EV2 The EV2 is the latest generation - ID + Storage + "Applications", with AES encryption. The 3DES was cracked with side-channel power analysis (like the items in this article) - but the EV2 has no practical attacks to this day.
Information aside, most transport systems do not store value on the cards, but allow for offline use by forcing sync the next time the card passes by an online system - IE, limited trust.
The best solution is to assume that a card's encryption is or will be broken, and build a system around it.
That is to say, store encrypted or signed data on the MIFARE card.
VIGIK is a French system that uses RSA signed data in MIFARE cards which has not been cracked to date.
When you topped up online (I haven't lived in London for a few years, so don't know if it still works like that) you had to select which station your top up would be applied to, then overnight that station would download a list of topups, and apply it to your card when you touched in or out next. So at the time there was no real time connection to a centralised database.
Most popular card/fobs (95%+ of all I've seen) don't use challenge-response, but always transmit the same 26 bytes. I don't have to explain how "secure" is that.
I'm less concerned about someone stealing my car. The local police department takes it seriously, no less because stolen cars are used to commit other crimes.
I like how some Chrysler products handle this. You can buy a $50 fob online and program it to your car yourself. The catch is, you need two key fobs to do it. This is so the valet attendant (who only has 1 of your key fobs) can't make his own copy. So, you just have to plan ahead and do it asap when you get a vehicle and always keep 2 in storage in case you want to make another.
https://www.theguardian.com/technology/2013/jul/26/scientist...
Well done David, and thank you :)
"Hackers Can Clone Toyota, Hyundai, and Kia Keys" gets the same point across without the sensationalism.
I'm bringing it up because I've seen many of these "millions of [thing that exists in the millions]" headlines recently, and I think it's more than just Baader-Meinhoff at work.
It's not a terrible headline, but it could also be improved.
He made the point in one amazing talk (that included references to centaurs and American exceptionalism and possibly ancient sumerian) that we've long used locks not for security, but as a social symbol of security.
Anyone can just put a cinder block through your window and steal your car. The barrier isn't technological, it's social. Locks are a great defense against the kid or confused person who is wandering around and forgets that we have social mores against making off with thousands of dollars of other people's property on a whim. They are not designed to defend against dedicated thieves.
We defend against dedicated theives by hiring detectives and prosecutors and making it in general more hazardous as a profession than other professions that one might take up. We defend against theft by just generally making it more lucrative to apply the same amount of ingenuity and dedication to other endeavors, like giving amazing talks about perfect security and American centaurs.
I'm probably butchering or overextending his point though, would love for the man himself to weigh in.
Whether or not these locks are made to be appropriately 'secure' is the difference between the owner and the manufacturer being liable for the result of criminal action.
There are plenty of offline hardware based solutions already on the market especially for unlocking computers with MFA. It needs to be offline generation for computers for NIST DFARS 800-171 compliance.
Not necessarily. Relay attacks are very hard to defeat, regardless of your crypto scheme:
https://www.wired.com/2017/04/just-pair-11-radio-gadgets-can...
Signals from an RFID device don't travel very far. So, (here's the error) if the keys can receive and respond to a signal from the car they must be very close to the car.
But signals can be relayed. Crook A stands next to your car. Crook B walks up to your front door.
Crook B is relying on the fact that most people leave their car keys on a key hook, or in a bowl, or maybe even in their outside jacket, which they leave by the door because that's convenient. You have done this.
The car is sending radio pulses. "Hey, are you my key?". Crook A has a relay transceiver, it doesn't need to understand this pulse, just relay it to Crook B. Crook B has another transceiver, and when it says "Hey, are you my key?" the key, on the far side of a locked front door, says "Yes! I'm the right key, see! 023483109" and Crook B's transceiver sends that right back to Crook A. "Yes! I'm the right key, see! 023483109" the one-time code from the key matches, the car unlocks. Crook A gets into the car and starts it. Crook B walks over and gets into the passenger seat.
In a few seconds the car will discover that the key, which was apparently right there, has somehow vanished. But for safety reasons it is unsafe to suddenly lock everything and shut off. The thieves will ensure that by the time it decides it would be safe to lock itself, it's inside a chop shop and that's too late.
So no, the attacker doesn't "have" the key, they just need to be able to stand relatively close to it.
Otherwise the attack seems arbitrary. If my key keeping bowl at home physical security is compromised I have someone in my house.
I generally dont leave my keys out anyway, but a nefarious plumber/home contractor could potentially gain access.
Is there any reason a challenge/response protocol with proper timing filtering isn't safe against relay attacks?
Yes, you can do this. I have done this (restricted the negotiation to about 12 meters)--you're essentially racing the speed of light, see DE102012104955A1. Most of the reasonable approaches are patented by NXP.
- superglue and baking soda in the lock tumblers
- 10 lbs / 4.5 kg of sugar in the gas tank
- pulling the fuel pump relays and spark plug wires
- unhooking the starter positive solenoid wire
- slashing the tires' sidewalls so they can't be repaired.
DoS complete. :) Maybe a swift kick in the bumper to set off the alarm at that point. ;)
First: Auto manufacturers ought to get together and agree on one common key + entry system standard. It can be a combination of physical key and remote key if necessary.
The problem: If you have multiple vehicles (and many families do) you end-up with a keychain full of horrendously large and unnecessarily inconvenient keys, key-fobs, whatever. Some manufacturers seem intent on making the larges and most inconvenient boxes they can possibly imagine. This is entirely unnecessary. In this day and age one ought to be able to have a universal programmable entry system that gets programmed for your vehicles and that's that. One device to rule them all.
Second: Auto manufacturers ought to get together and agree on placing the fuel tank port on the same side.
The problem: Today you have cars and trucks with fuel tank refill ports on the left and the right. It can be an absolute nightmare to go to a gas station where most of the cars have ports on the left and you show-up with one on the right. This is one of the reasons for which I hated driving our BMW. Going to the gas station was always a game of chicken with cars entering in the other direction.
I want to believe this is to be able to spread the use around both sides of the pump without pulling the pump hose over/around the car. In some gas stations there's no easy way to turn the car around the pump.
Uh, other direction? Almost always there are hoses from both side of pillar. Is it some regional thing?
In these stations.
From my experience most vehicles have it on the left side, in the US that would be the driver side.
If you show-up at a busy gas station with a BMW --which has the port on the right-- well, good luck, it can get ugly. Rather than lining-up behind the car currently fueling-up, you have to line-up in front of them. Which means that someone entering the station with a left fuel vehicle often ends-up behind them --even with you waiting patiently in front way before the third car showed-up. That's where the problems begin. This has happened to me many times.
Because the car that finished fueling drives forward to exit, the car behind it has a natural advantage and the one in front a disadvantage (at the very least you have to allow plenty of room for them to drive out). The car behind them, if they want to deny your rightful turn, just crawls forward as the first car exits. Before you can do anything at all they are in front of you, took control of the pump and you have to choose between waiting, moving or getting into an argument with someone you know isn't likely to be a nice person.
If all fueling ports are on the same side there are no problems.
The alternative is to require that hoses be longer. The problem with this is that it doesn't work at all for trucks.
I would say that in EU (German, French, Italian) cars have it on the right (like the BMW), i.e. opposite the driver side, I have now an Opel and it is on the right, and my my previous car was also on the right.
I believe it being on the right is a traditional safety provision, though they are becoming very rare nowadays (and since several years) a number of fueling stations (at least in the cities) were not, like it is common nowadays, in a (large) court, the pumps were simply along the road, at the most in a 3-4 meters enlargement of the road itself.
So it made sense to have it on the right, the only moment where the driver is exposed to the trafic is when he/she gets out of the car, during the refueling he/she can stand on the right of the car, i.e. between the car and the sidewalk (and the same applies to - as it was once most common - to the gas station service personnel).
The key fob is still available if you want it. Tesla even allows adding and removing keys at home. It's an underrated part of the Model 3. Phone key could have been a disaster but they nailed it.
So there will be two standards, Apple and Google and all cars will support both. Kind of like with CarPlay and Android Auto.
As a side note, I stopped buying phone controlled devices a while ago. All of these things are going to end-up on a big pile of trash as technology evolves. I don’t need a phone controlled toaster oven or power drill.
I have this smart key thingy too and I keep it in one of those RFID pouches. Since I don't have to use the key to start the engine, I feel the whole thing became more of a problem than it was before. You at least always knew where the key is and where to put it. Now it sometimes slids down the seat, or is in my jacket that I wanted to leave in the car or the engine/electric is not on/off because pushing the button does several things. It became an inconvenience and the few times I really used the automatic open feature after deliberately taking out the key out of the pouch to profit from it are negligible.
Damnit, speaking of unwanted features...
I have 3 kids around the same ages. I wouldn't say they're the hardest thing in life but they're often a very difficult variable to manage along with life's other challenges. They have this compounding effect...
Maybe there are no carts at this store for some awful reason. Maybe the story was so focused on how this type of key solved their problem that they didn't give a fair shake to other possible solutions. More information is needed.
There are multiple ways I can/do give benefit of the doubt, but doing so doesn't make the situation any clearer.
I have a hard time imagining snow such that you can walk to a car with four kids while carrying bags, but can't push a cart.
> even with a cart you still have four kids to keep an eye on.
I would posit that kids + cart + grabbing keys is basically always preferable to kids + both arms full of bags + not grabbing keys.
I no longer have to pry the key out of my jeans, or go looking for it in all my bags when I’m travelling.
Hence the article says thieves would be able to "hot wire" a car after using this attack. You can't (if manufacturer's did their job properly) "hot wire" modern cars like you see in a movies, the computer overseeing things doesn't let it be driven anywhere just because somebody jammed a screwdriver in a hole and taped some wires together.
Keyless entry and keyless ignition are entirely different technologies that have a different problem (relay attacks) which has been covered a long time ago and has numerous quite different solutions from this.
This article is about the all-to-common situation where somebody cut too many corners and left themselves open to a pretty easy cryptographic vulnerability. (Some) Car manufacturers did a crap job of making the "smart" key that disables the immobilizer actually secure, and bad guys can use that to clone such a key and drive off in your car. If they didn't also copy the mechanical shape of the key (which would be more effort) they can smash the lock just as they would have in the 1980s to steal a car. Some of them might even remember stealing cars in the 1980s and not need to learn a new technique.
Apart from inevitable consequences like from this article, are benefits outweighing other intended, unintended, and inevitable consequences like these for most people?
- Forgetting car keys more often per new learned behaviors
- Fob batteries dying
- Replacing lost / broken fobs is more costly in time, money, and hassle
- Leaving fobs in the car more often
(1) Understood keyless entry / alarm / remote starting are clear benefitsOTOH, it's much harder to leave a key in the car when you never have to take it out of your pocket in the first place.
If you have, I’d ask you to name it explicitly because I have yet to drive one (out of 10+ be driven) that does not visually and audibly scream at you that the key is not in the vehicle. That’s if it will even let you shift out of park (in a non-manual).
https://bgr.com/2018/09/18/iphone-xs-vs-iphone-xr-nfc-chip-w...
When my current car fob starts displaying a low battery warning I have at minimum weeks to replace the battery. (Not to mention my current car fob is resistant to being dropped, stepped on, etc.)
Now Ford lets you in your car with a pin code on some and there are suggestions you may be able to start their Mach E EV with just a pin as well.
If only this was deemed as a road safety problem forcing a recall.
Is it possible to remove the antenna or disable the radio receiver in the car to force physical key use?
If she loses her keys just once it pays for itself many times over.
Which is straightforward when you want to steal a particular vehicle because you know where it is and can easily follow its patterns.