Researchers demo Bluetooth relay attack against Tesla
duo.com
duo.com
> “The tool that researchers at NCC Group developed adds just 8 milliseconds of latency in the response time”
Radio waves propagate at the speed of light so a signal can travel about 2400 km in 8ms. I think there are some key aspects of the Bluetooth le proximity auth protocol that the article is missing which makes the whole thing sound like nonsense.
I think the real reason that Bluetooth le proximity authentication is broken is that it is a passive communication protocol. They do hint at this in the article. Imagine how broken TLS would be if there was no two way communication to negotiate proofs.
I'm wondering what the point of this attack is. Any thief who wants in my car will just bust the windows. If they do the relay attack they can steal the car but the car has GPS and can be locked down remotely so it seems like a high risk low reward crime?
https://www.tesla.com/ownersmanual/modely/en_us/GUID-94B0E05...
Isn't this what the research team is abusing? If so, make sure that's turned off too!
On the other hand if you are a high value target and some person/organization/government has the incentive to target you in this way, you better have adequate protection.
There are quite a few security camera videos on youtube of people stealing cars parked in driveways by what appears to be a relay attack.
On those video it looked extremely "easy" to me
Car thief != pick pocket thief
Having owned some fancy cars, the advice you usally hear from other owners is this - the best protection you can have is a good insurance policy. Putting any kind of lock out/pin/hidden switch system on it, hiding your keys in radio-proof bags etc, is the best recipe to get hurt. Exactly because if you drive such a fancy car, the people coming to steal it are not opportunistic thieves - they are coming to get your car, and they will hurt you to get it. That's why you don't install any extra fancy "trap" systems in the car and you hang your keys right next to the front door, in plain view. If they want to take the car, don't give them a reason to come in and threaten you or your family for the keys or a lock out pin because you thought you were clever with a fancy alarm system. A Lamborghini is replacable. Your life(or the life of your children) is not.
I still remember a video from a break in our country where the thieves where pounding the door with an axe for minutes to enter, then threatened the homeowner to open the safe they knew was in the house. His wife and kids where “safe” in the attic. If they know what they want they will get it one way or another.
1) luxury cars that are stolen "on order" are usually placed on a trailer/container straight away and not driven around.
2) you assume you can still talk to the car after it's taken - sadly, GSM/GPS jammers are very cheap and common amongst car thieves.
3) even if you have L5 autonomy, I would be really surprised if you could override what the car is doing while it's being driven. Sounds like a recipe for disaster. I'm not sure anyone should even have the ability to do something as simple as shut it down remotely - there's far too much risk of abuse.
Someone elsewhere suggested putting the car in a cargo container, but I don't think that works either. I was on a large ferry recently, my phone worked below deck several inclusive distance units away from the coast.
Maybe things changed in the last few years
But considering that Teslas are infamous for authenticating every start/stop of individual cars between the key and the infotainment computer and a datacenter in California...
The upvotes on social media alone will be worth it to many nowadays.
It’s likely not completely bullet proof but if you are up against such sophisticated attacks then it’s reasonable to say just don’t use these features.
1. Disable the ability to unlock the car if the phone has been stationary for a while. No more siphoning authentication from a phone in the night stand.
2a. Setup phone presence inside the car as a second authentication factor for starting the car. BMWs can detect if the key is inside or outside the car; I imagine the same positioning can be detected out of a bluetooth+wifi+nfc radio source.
2b. If phone positioning would require extra hardware, an alternative is using phone NFC as authentication (I think the keycard is NFC, so the hardware should be present)
https://insideevs.com/news/339271/tesla-adds-new-pin-to-driv...
Sometimes he's right. Often he is not.
Several dramatic "defects" of Tesla's could have been prevented - but why should Tesla care? "Bring it in for a fix!" they say. "It is not our money! Haha!" they say. And investors and buyers keep coming.
Why do you single out Tesla?
The title is wrong, this is a generic attack against BLE.
The lesson should have been to 1) pick or come up with an adequate protocol that includes tight time-of-flight checks or 2) not use proximity auth at all, if it is impossible to mitigate against relay attacks, in terms of physics and maths.
I'm saying Tesla's engineers should have known better, by 1) paying attention to news in the industry; and 2) properly understanding BLE before choosing it as the auth protocol.
They say they got the added delay somewhere below 8ms to defeat the system. In 8ms, light/radio travels around 2500km.
[1] https://networkingnerd.net/2016/09/21/apple-watch-unlock-802...
> a more trivial radio scheme
Which would require hardware not available in typical - or low-end - consumer smartphones.I imagine you would use UWB for the location, and BLE for authentication/data transfer though.
BLE has some other mechanisms for determining the proximity of a device, such as Time of Flight (ToF) and Angle of arrival (AoA). I'm unsure if Tesla uses these, or if the reachers were able to circumvent them.
Time-of-flight: https://software-dl.ti.com/simplelink/esd/simplelink_cc2640r...
Angle of arrival: https://dev.ti.com/tirex/explore/node?node=AOSUfCXMkNaUAy6wn...
- Unlock the car via BLE. Not able to drive away.
- Enter a PIN-to-drive on car screen, to turn on the virtual ignition. Able to drive away.
Unfortunately, the PIN to drive is not enabled by default.
Pin-to-drive can be bypassed through the Tesla mobile app, and this bypass is not relayed to the car via BLE but rather via the link between car and Tesla servers.
Therefore, someone with proximity to a locked phone can unlock the car, and someone with access to an unlocked phone can unlock the car and drive away.
They literally just walked up with an antenna close to a house and the car parked in front of it opened.
It's _very_ different from spying on someone to steal their PIN.
However, it will impact all electric locks that support this very same functionality as its a fundamental limitation of how BLE is implemented on cell phones. Trying to be more prescriptive on the latency or other parameters under the locks control will make the user experience significantly more frustrating and unreliable, crippling the feature.
It takes effort to make a site slow, not the other way around.