Replay-based attack on Honda and Acura vehicles
github.com
github.com
German cars do have a rolling code, especially BMW with EWS2 around 1996'and it's a nicely documented system to break.
With that said, it would be fun to dump older car firmware to see how simple the security was, previous to 1996, most cars ECU firmware were litereally on eproms.
There are also communities and such dedicated to bypassing this, not for theft but for engine swapping and car modification - having an annoying security system that can disable the starter or fuel pump sucks when you engine swapped your car.
It would make sense to do that if it detected the fob inside the car. But it does it no matter what.
That's not a feature.
> To lock all doors, with the driver door closed, press and hold 7•8 and 9•0 at the same time. You do not need to enter the keypad code first.
https://www.ford.com/support/how-tos/keys-and-locks/securico...
I've got an early 80s SAAB that handled this in a more straightforward way. The driver's door lock plunger will not go down while the door is open, forcing you to lock it with the key (or reach around from another door, and then lock that.)
It's not particularly obvious why insurers don't seem to care, though there have been some rulings where they didn't need to pay because stealing a car like this wasn't technically stealing under the insurance policy.
Link? This seems so wild.
Fun fact: they usually go to sleep (i.e., way more battery life) based on an accelerometer detecting no motion, because legitimate use would always be hand-held. To take advantage, put it on a table or hook (but not too close to your front door, perhaps) instead of keeping it in your pocket while home.
I guess sleep mode is really more about preventing relay attacks, with improved battery life being a side effect.
Or better yet, an S&G digital safe lock. If it is good enough for missile launch codes it is good enough for my civic. Replacing an S&G lock body is far cheaper than any car immobilizer.
1: https://arstechnica.com/tech-policy/2013/12/launch-code-for-...
[0] https://everything2.com/index.pl?node_id=1520430&displaytype...
My car has an optional subscription that would let me unlock it with my phone -- I didn't sign up for that subscription, but I bet that it's active on the car's side and if there's a remote vulnerability, it's exploitable whether I've signed up for it or not.
That convenience shouldn't have to be traded for the huge vulnerability of allowing replay attacks.
Door keys suck. Ignition keys suck more. The worst is the middle years of both immobilizers and physical keys.
Source: I can use 4 different keys to open 1 car right now. In fact, I only realized this after I locked my keys in the car and tried a few spares at the shop. A little jiggle and they all work
This should be "paddy" rather than "patty". Note that Honda is a family name (after founder Soichiro Honda).
And while "original rice paddy" is a correct if painfully literal translation, something like "Mainfield" probably captures the essence better. In Japanese, a field defaults to rice and there's a separate word (畑 hatake) for non-rice fields, with a little fire radical 火 added to the rice field 田 to show that this is a burned (dry) field instead of a wet one.
Remote unlock is a safety issue for assaults.
Thankfully according to https://owners.honda.com/Linked-Content/PDF/RemoteEnginestar... the remote engine stop doesn't work if the engine was started with the ignition key rather than the remote.
It’s like home invasions. Perhaps someone might pick your weak lock or hack your smart lock, but in practice they usually just break a window or kick the door in.
It should still be fixed, but this strikes me as something that’s more likely to be used by a state or quasi-state level actor to take out a high value target more than something that’ll be used to randomly assault people at the mall.
Remote unlock actually doesn't work on [most?] Honda vehicles if the engine is running.
Carbon monoxide being present is an assumption in the perspective of the building codes. This is why attached garages must have ventilation to outside, doors with gaskets, etc. There’s some danger, but the codes were made for the case where people forget and leave their car running, which isn’t all that uncommon.
[0]: https://gist.github.com/ryjones/73739f6a7e662b9ed9ba64d9141f...
The thief just hangs around the target, waits for the fob to be used, clones the signal and can steal the car within 3 minutes.
The problem is so pervasive that Land Rover offers discounts to previous customers who are victims of theft:
https://www.landrover.ca/en/ownership/protection-program/veh...
You could effectively leave it in the bushes at a work parking lot, come back the next day, and unlock + start all of the cars with keyfobs that were present the day before.
I guess that falls in line with their reliabity standards and replace every 2 year business model.
I guess there must be a mechanism for the car to resync somehow?
How is Volvo's system functioning properly considered a downside? You're saying that having a security system that downright does not work is comparable to a security system that actually works and prevents unauthorized entry to the vehicle because the former is more convenient to circumvent than the latter?
(Though it's funny that you decided the security was the part I felt was a downside.)
Obviously not a replay attack, but still seems to be a huge vulnerability.
Relay attacks on keyfobs seem to be much more common in the UK than in the US. Some manufacturers now include accelerometers in their keyfobs to mitigate the risk, as one of the most common attacks is stealing a vehicle out of a driveway when somebody has left their keys on a hook inside the house. With an accelerometer in the keyfob, it will refuse to authorize starting if it hasn’t been jostled recently.
No, it isn't fake. I'd love to show you more videos! This attack does require the target to use their FOB, the range that is required is quite long! This can be performed from great distances away. Though recreation of this part of the attack, we know it's possible to convert a "lock" command (or any command at all) into any other command, and unlike the rolljam attack, these codes will work forever (until the key gets reset by a dealer).
Rolling Code does not help here since the vehicle never received the original signal from the key. Thus it is for the first time played to the vehicle, and no rolling code increment is expected compared to the key's initial rolling code value.
The point of rolling code is that same signal cannot be used twice to open the vehicle.
That's why I never use the remote and always use key-in-hole.
Once you know that it's, say, 9600 baud FSK at 433MHz, you can buy a transceiver IC for a few dollars that can send and receive that frequency and modulation, and drive it with a microcontroller.
I wouldn't be surprised if we start seeing such devices on AliExpress for $10 within a year or so.
Looks like maybe a custom case, but 99% sure it's this hardware that has been customized.
edit: Actually you can find the exact model they are using on eBay...just google the first line of text in this comment.
edit: ok, direct link https://www.ebay.com/itm/224339096828?chn=ps&mkevt=1&mkcid=2...
Is a keyfob / "remote start" / "added security" really worth the trouble? How many people buy these things when its an option they have to wait for vs something already there to bulk up the price?
1st - message is recorded while key is outside of the vehicle range. Rolling Code does not help here since the vehicle never received the original signal from the key. The point of rolling code is that same signal cannot be used twice to open the vehicle. There is no protection against this with unidirectional RF keys, but requires physical access to the key and your recorded message needs to be first one sent to the vehicle.
2nd - it's fake. This I say because the key gets out of the frame in the video when the signal is replayed...
Dude uC used for keys come withe special sections of rolling code to have extended lifetime compared to conventional EEPROM. Same way they come with Transponder built in.
P.S. And the second key in the frame as well...