Vulnerability in Honda's Remote Keyless System
github.com
github.com
Perhaps there is more to the setup of this CVE than they're talking about. Is it possible they're doing a rolljam attack + replay?
The CVE is really scant on details, so while I believe they did manage to get this to work, they don't really say how.
If rolling codes are implemented, it should be pretty simple with the right gear to prove it.
Honda told us, multiple automakers use legacy technology for implementing remote lock-unlock functionality, and as such may be vulnerable to "determined and very technologically sophisticated thieves."
"At this time, it appears that the devices only appear to work within close proximity or while physically attached to the target vehicle, requiring local reception of radio signals from the vehicle owner's key fob when the vehicle is opened and started nearby," a Honda spokesperson told BleepingComputer.
Note, in their statement to us, Honda explicitly mentions it has not verified the information reported by the researchers and cannot confirm if Honda's vehicles are actually vulnerable to this type of attack.
But should the vehicles be vulnerable, "Honda has no plan to update older vehicles at this time," the company tells BleepingComputer..."
https://www.bleepingcomputer.com/news/security/honda-bug-let...
https://github.com/HackingIntoYourHeart/Unoriginal-Rice-Patt...
I understand that, in general, door locks aren't considered to be very high-security in vehicles: doors can be opened in other ways. But remote start is a very big deal. Article doesn't mention whether the car prevents people from driving away after it's been started. I would have loved to see a portion of the video where they tried to shift into D and move the car.
Back in the day it was pretty easy to get the door open like this
Might be able to short the right data pins from behind to ground and rip that out as needed. Or a hidden switch that does that.
I understand a lock, but just have a hard time seeing how it would actually lock (well), especially as a universal device.
A better way is to use a different kind of connector but you'll have to build yourself an adapter and to keep in your place or something.
But instead of spending days and weeks chasing it down, I spent maybe $30 on a battery cover with a little hidden flip switch. It was originally designed for turning on (illegal in my state)under lights, but I modified it slightly and had the switch connected to the ground terminal instead, so whenever I got off the bike I'd flip the switch and boom, problem solved, no more dead bike.
You can also put a lock on the hood, which is a good idea since that way nobody can disable the security system lol.
Edit: Also of note, the JL wrangler uses an RFID chip for the ignition startup itself. It's separate from the rest of the keyless go system.
I don't think it was limited to Chevies.
https://www.cbc.ca/news/canada/marketplace-car-thefts-1.6396...
the 90s era hondas up to about 2001 use various key-turn-rituals to enroll/program keys into the immobilizer, the later ones use the Honda HDS system which is just a specialty Toshiba/Panasonic ToughBook with an obd dongle and special software.[0]
I've enrolled keys myself for my 04 BMW with bootleg 'BMW MODIC' and 'BMW Rheingold' software packs pirated from The Pirate Bay.
You don't need existing keys for either system.
The trick (used to be) at the time that BMW keys were difficult to cut, and the key cutters were well controlled. This isn't the case any more, and in reality if a key was the deterrent you could always just program an immobilizer chip from another key, tape the key/chip to the column, and then use a pry bar and screwdriver to break the key tumbler and turn the switch without a key. This is neither rare nor hard to do -- and it used to be the defacto way to steal pre-immobilizer Hondas (breaking the column/tumbler, that is).
It was common enough that an in-joke at the Honda dealership I worked at was that a flathead screwdriver could be referred to as a 'lazy CRX key', a majority of those era cars encountered were so worn that a flat head would turn most of their tumblers by the time I got to work on them.
[0] : I was a Honda tech from 07ish to 09ish
So now I have an 80 and an 81 Accord... and I have also interchanged keys between them. The 80 doesn't open as easily, as I think it's less worn out. But there's practically no security on these old Hondas.
Right to repair has two sides of the coin.
All cars sold in the US since 2008 use ISO 15765-4 OBD over CAN for emissions diagnosis, and almost all use ISO 14229 UDS for manufacturer/dealership diagnosis.
The intent of OBD-III is to use some kind of wireless mechanism to notify the state that your check engine light is on. In California, for instance, you have to pass a smog check every six months, so people driving four months with a failed emission control system are contributing a lot of emissions.
It's been hung up forever because of privacy concerns, fears about rent seeking (being forced to buy a cell phone plan for your car), etc.
These sort of applications
https://www.nhtsa.gov/technology-innovation/vehicle-vehicle-...
are also hung up indefinitely because the cell phone industry is pushing "secure" solutions that involve cellular infrastructure but not promising to invest enough in their network to cover all the places you might want them. That and the rent seeking, privacy, etc.
I live in California and you only have to do it every other year [0]. My car is almost 30 years old, not super well maintained, and it's never failed.
There is usually a window between when the car will report there is not enough data to pass the emissions test, and when the car reports a failure of the emissions test. Maybe try unplugging the battery every night for a week and you can get a good idea of when you can get it inspected and passed.
Wife's 2005 CR-V will around once per year set P0325 (knock sensor, bank 1). I've replaced the knock sensor [twice], rang out the wiring, and checked/cleaned all the connectors. It's a 17.5 year old car with ~225K miles on it that sets a code once a year. It's not going to get any more fixed than it already is.
Alternative option is to sell the car to someone in a state that does not require emissions testing.
Also, if someone steals your catalytic converter, and there is not much damage, it is possible to “straight pipe” it for cheap and just not put in a catalytic converter. Although, I would assume inspection stations have cameras or mirrors where they can see the bottom of the car, so this might only be worth it in states that do not do inspections.
And indeed, many cars in the early 2000s supported key enrollment without cryptographic material using diagnostic tools, so it was only a matter of sniffing a dealership tool.
More modern cars from most manufacturers require cryptographic material from a central server to enroll keys. These systems are still often broken (look up XHorse for a popular product in this space) but generally require more in-depth physical access or complex software exploits to bypass the signing process or extract private key material from hardware.
It has an entirely separate and different physical connector for a CAN bus, one in the engine bay and another under the driver seat IIRC. This one has all the goodies--locks, entertainment system, full engine diagnostics and sensors, etc. I actually have the full factory service manual for the car and key programming is only possible with GM's tech 2 computer system connected to the CAN bus, not OBD-2.
For example, on modern VW AG cars, key programming is performed over the OBD connector, using specific UDS readLocalIdentifier and writeLocalIdentifier requests, but the data involved in the Immobilizer is both signed and encrypted using secret keys on a VW server (called FAZIT) over a subscription system called GeKo. The dealer diagnostic tool essentially sets up a tunnel over UDS between the Immobilizer software module in a control unit and the FAZIT server.
As an analogy: One can access a computers PCI bus over the Thunderbolt / USB-C connector, given the correct situation.
Post-2018-ish, they tend to have a gateway module, and accessing anything interesting requires you to get into the wiring "behind" the gateway where all the internal buses are. But that's also trivial, in most cars it takes about 20 seconds once your wrist knows the way.
> requires the $20k dealer computer system
Or knowing the messages it sends. It's only $20k because it can be.
> or some serious reverse engineering chops and weeks of time to figure it out.
Which someone then packages into a $500 car-stealer they sell on aliexpress and then all the criminals have to do is buy that thing and push a button.
If you want to see what's possible with modern cars, keywords like "VVDI" or "Abrites" and "All Keys Lost" will show you what aftermarket tools are capable of. Generally speaking, the capabilities in these tools are roughly equivalent to those the most sophisticated criminals have, as they're usually just stealing the techniques from one another in a big circle.
The level of security varies heavily from manufacturer to manufacturer.
For example, most modern VW cars require using an ECU exploit (which depending on the specific ECU, almost always requires physically removing the control unit and sometimes requires opening it) to extract encryption key data (CS/MAC) or physical extraction of the instrument cluster EEPROM.
However other manufacturers like Toyota seem to be more vulnerable to other exploits (I only research VW for the most part, so I frankly have no idea what's going on here), including a bizarre process which seems to require disassembling the steering column and unplugging a connector.
Automobile companies won't do that however, they'll serve you subscription spyware/adware laden services and you'll have no choice.
For example, here they market it as a way to find where you parked: https://www.ford.com/support/how-tos/fordpass/getting-starte...
I'm not sure what the effect of that observation is, though - key and immobilizer security is extremely important still, because cars which are stolen by any mechanism (tow, stolen key, transponder relay, etc) then need to be resold or broken down for parts. Especially in Europe where control module security is generally both more robust and more insurance regulated, many parts on a stolen vehicle are increasingly not valuable unless the immobilizer / key enrollment system can be bypassed.
"Among the nation's largest cities, Chicago stands out for both its high murder rate and for the number of its murders that go unsolved. In recent years the police have been solving about 4 of every 10 murders in the city, but police data show the rate is even worse when the victim is African American."
See https://www.npr.org/local/309/2019/10/09/768552458/chicago-s...
I could get in the car, but it was not possible with the security system enabled without a currently working chipped key to program a new one without the dealership to do some I think cryptographic pairing of a new key to the car.
I could start the car and it would after one second shut itself off after buying a replacement key and tried many things with many scan tools before giving up and getting towed to the dealer.
There might be some sort of cracked tools out there but I was not able to find them, or get a straight answer if the very expensive software packages out there could actually solve the situation.
Would you rather a car where you could reprogram the keys yourself with a small chance it might be stolen? Or a car where if the keys get damaged you have to spend several thousand replacing all of the computers?
CVE-2019-20626: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2062...
CVE-2022-27254: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2725...
I own a Honda model just prior to this date range — but I assume it's not necessarily the case that pre-2016 Honda vehicles used a more secure system? It may just be that they aren't specifically vulnerable to the exact same RF signal type as 2016-2020 vehicles?
At least I always naturally follow the advice in the article: I use the passive entry system and I can't recall ever pressing the buttons on the fob.
(Honda does not mean "Original Rice Patty." It literally means "Original (as in older) Rice Paddy", but you wouldn't translate Henry Ford's surname as "Shallow River Crossing.")
Honda enthusiasts commonly store their cars in private garages, install hidden killswitches and avoid keeping items in their cars.
I did my own research (albeit not as far as this person) a couple years back and the 2018 CR-V is also vulnerable.
[0] https://github.com/merbanan/rtl_433
[1] https://github.com/merbanan/rtl_433/blob/master/src/devices/...
"Have a car with a push-to-start ignition? Here's how it could end up stolen and overseas"
https://www.cbc.ca/news/canada/marketplace-car-thefts-1.6396...
The problem is that manufacturers are using strength of signal to detect keyfob proximity, which is, of course, defeatable with a (somewhat expensive) amplifier.
I wonder how hard could it be to measure response latency instead? That should solve the problem.
I thought about selling those for a while (and got a few requests), but realized I can't easily design them for the many kinds of key fobs out there. I suppose the manufacturers are not adding them themselves because that would hurt the image of "security" of these key fobs.
I think those guys shall make some research before. Starting the engine requires either an immobiliser or a Passive entry functionality.
Rolling codes are implemented from a long time. (from some time the RF communication is also encripted usually with AES-256) Will be nice to tell us if those are original dealer vehicles or modified. Basically all the keyfobs produced in the last 15 years have rolling codes, relay attack protection and most of them also encription. At the level at which this article is written i see no need for Honda to make any comment. Source: worked on keyfobs in automotive. Honda is a customer with strict requirements.
Remote start is troubling though.
When I did this at my office car park, well-meaning people would call security and ask them to help the person with open windows by earning them they were open. Or if they knew it was my car they’d seek me out to warn me that my windows were down.
The reason they gave was always that they were worried someone would steal stuff from the car. There was nothing in it to steal.
Eventually I got sick of wasting other people’s time for them and left my windows closed.
So many of them complained that their cars were hot, and/or had them broken into by people looking to steal things.
I think the only real solution would be for me to buy a car that lets me take the roof off. If your car is roofless, no-one comes to warn you.
Or is this a reverse psychology thing where people are supposed to think it’s already been checked by others
For example, "they stole my $20 from my center console, but broke a $200 window to get to it."
I also wonder if potential thieves think a car with open windows is a bait car or something. Probably not often enough in its own right to justify leaving things open?
Sort of violates the idea of a "smash and grab" though. You want to minimize the noise generated and time spent and maximize the potential profit gained. Typically, you just inspect what is in plain view of the vehicle and if there's anything that has value (ie, backpack, clothes, cell phones) then it's a good target. If there's nothing in plain view, then there's no point in attracting attention and increasing the chances of getting caught.
Of course, there are some municipalities that have decriminalized or refuse to prosecute this type of theft so that negative reinforcement no longer applies and you just get people that smash all windows and search entire vehicles.
Anecdotally, just following the idea of "nothing in value being in plain view" has worked wonderfully for me. Works locally in my somewhat big city and when traveling to other big cities.
https://old.reddit.com/r/LosAngeles/comments/dc6s78/came_bac...
I would not choose a future where everyone shares my own moral values - that would be bleak.
In that context, sadly, crime will exist.
https://www.amazon.com/gp/product/B0734QN8KR/
I imagine you could probably ziptie one (or maybe a few, though you'd have to carry a few remotes) onto an inconspicuous location on the car. It would be a good deterrent for car thieves and possibly also towing companies.
I actually want to work on a modification of this device where it shoots out fart spray in addition to the loud alarm.
* https://carconnectivity.org/digital-key/
Perhaps moving to that will help with security since everyone won't have to re-invent the wheel. (Of course implementation bugs are still possible.)
TLS and SSH are not generally run on disconnected systems that may never get firmware updates, as just one obvious difference.
Sorry to ask a dumb question, but how does this help?
For the MITM attacks on the modern proximity car keys, drop your fob into a metal tin (like the Danish Butter Cookie ones) when you walk in the house to block the signal.
https://www.schneier.com/blog/archives/2017/11/man-in-the-mi...
For example a cellphone will not be able to communicate with the base station if you wrap it aluminium foil and the new car fobs work similar. The fob just needs to be in close distance to the car for someone to open the door or starting the car.
A relay attack puts two radio devices between the car fob and the car, so thieves can open and start a car just by relaying the radio signal to the car fob behind the closed door.
A replay attack will record the radio signals transmitted between fob and car and just replay them.
And both attacks are absolutely possible. You can find videos on youtube for both.
Maybe security in the future starts looking less like obfuscated software solutions, and more like simple analog solutions that ultimately require an operator on location, and are therefore too expensive to carry out to the scale that electronic crime has taken place in the past few decades.
This would mean that the car needed to keep track of the rolling code, but to not lock the user out if he accidentally press the button while away from the car, it will need to accept current rolling code state plus some more (a window of accepted codes). Once the car gets a code within the window, it knows the state counter on the key fob and can synchronize.
Not sure what to do, I kept pressing the key until I saw the car alarm turn off - it must have been hundreds of presses. But the code must in fact be rolling, because everything worked as normal after that.
For a 2005 vehicle this would be understandable. For 2016-2020 model years absolutely not.
To be fair though, my example isn't absolute--as far as infotainment goes, Chevrolet has done free Android Auto/Carplay retrofits in the past if your older model hardware supported it, and Ford SYNC is upgradable by the consumer via USB. I don't know of any Toyota models that offer that same though.
The second day I had it we went to my mother-in-law's new apartment building. Her call button wasn't working to let people into the building, so I asked if I could try to copy her FOB since we needed to get some things from our car and boom, it worked just like that.
Also had some fun mucking around with raw NFC and emulating them. Took a bit of tinkering, but it was pretty cool to see it work.
The #sub-ghz channel on Flipper Zero's discord blew up a little bit today with this news. So far though, the couple us with affected model years according to this CVE have been unable to reproduce. FCC ID matches. The precise frequency was added to a modified firmware, and we are using FSK modulation, but still no luck.
Would storing fobs in RFID restricting material prevent this?
https://honda-tech.com/forums/honda-civic-del-sol-1992-2000-...
https://honda-tech.com/forums/honda-civic-del-sol-1992-2000-...
https://honda-tech.com/forums/honda-civic-del-sol-1992-2000-...
I guess the real answer is that any key/lock that isn't 1-year-new is worn down enough to fit any other honda.
I'm not sure they take security that seriously.
That is hilarious
Turns out it wasn't our car, just the same new VW Golf model in the same color, and her key worked for it for whatever reason. She only noticed because the actual owner had put some stuff on the rear window, which she only noticed when looking back to reverse out of the parking space.
I have no clue if VW had the same keys for all/many cars back then, or if it was a huge coincidence that the key fit well enough.
The story of "how mom almost stole a car" is still treasured family folklore :P
Russians might secretly built 10e10 sq.mi. antenna array field to read tire pressure of all US cars!
I'm also more weary of scam extended warranties than I am of kidnap and ransom, even though one is obviously far more unpleasant than the other.
The way this was written, I thought cars were sending signals to one another somehow.
Furthermore, the "vehicles sending the same signal" refers not to a single signal shared between vehicles. It means vehicle X consistently relies on "the same" (unchanging) signal X, vehicle Y consistently relies on "the same" (unchanging) signal Y etc. As written, it sounds like every single honda of the same year & make uses one, shared signal which is not what is meant, unless I'm mistaken.
It would let someone steal the contents of the vehicle, which may not be insured, and I suspect it would be difficult to collect on without signs of entry to the vehicle.
- the deductible cost
- the risk of the insurance company not paying, or low-balling the payout
- loss of all personal items in the vehicle
- time and monetary cost of temporary transportation
- future insurance premium increases
- having to buy a new car
We must have dealt with different insurance companies if your expectation is that it will be a quick, satisfactory, process.