Rolling-PWN vulnerability affects all Honda vehicles
rollingpwn.github.io
rollingpwn.github.io
You can buy (on the usual dodgy places) a briefcase with a multi-car unlocker which will unlock lots of different cars if turned on in a car park, allowing you to then empty out the contents of any car that does then unlock.
And since there is no smashed window, insurance won't pay out either.
In a simple form it seems like this: The attack is you have a briefcase that contains specific RF transceiving components in it. You turn the brief case on in a hidden place, leave it, it records data, you come back to it later, and then press a button(s) that replays those RF signals.
Perhaps, there's some very weak cars that don't even need a replay, but are vulnerable to a master key, or bruteforce, or something else.
He was worried that insurance wouldn't replace the hood but would just pay someone to try to knock them back into shape, which was unacceptable to him. So he went and bashed up the hood himself with a bat. The insurance claims guy came out to inspect it and said: we'll replace the window and we'll have a shop hammer out out the damage in the hood.
Served him right.
Modern systems have some form of protection against brute force and replay attacks but personally I don't trust them.
I think the main drawback of wireless unlocking is that hacking it is less conspicuous. If you have a device that can unlock a car in 10 times the time it takes with the legitimate key that looks suspicious if you spend that time holding an object to a keyhole, it's completely unnoticeable if you stand a couple meters away on a parking lot doing it wirelessly. Even worse with a method that works on 10% of cars: with a physical keyhole you go from car to car, looking very suspicious, with a wireless device you just stand there and go to the first car that unlocks.
I agree with the inconspicuousness of wireless hacking, but I wouldn't even call it the main drawback: the main drawback is that many insurance companies won't pay a dime if there are no signs of entry at all. Break a window, steal an entertainment system, and the original owner probably gets some money for window repair and a new part. Do the same thing digitally and the insurance company will probably tell you to pound sand.
If you have comprehensive insurance (which is what would cover a stolen car), they'll pay whether or not it was broken into, you left the keys in it, or even if you left the engine running while unattended.
https://www.progressive.com/answers/car-theft-with-keys-in-c...
As long as you have comprehensive coverage, you can file a claim if your car is stolen while left running. Comprehensive can still pay to replace your vehicle if it's stolen while your keys are inside it or if you left it running.
Car insurance won't pay for any personal effects stolen from the car, that would be covered by homeowners insurance, but as long as you have a police report, they'll cover it. I had a bicycle stolen from my (unlocked) car while parked in a garage -- homeowners insurance just asked for the police report, then sent me a check for the bike. They d
There are a ton of other options though. Atomic clock signals are broadcast nationwide in the US. GPS, Glonass, etc. signals broadcast the time. Cellular networks broadcast the time.
Also Honda does offer bidirectional fobs, that make this attacks a lot harder (still not impossible if the same resync strategy is used)
What is a bidirectional fob doing resyncing at all? There is absolutely no need for any sort of state in a bidirectional if any reasonable protocol is used. The fob should not even need writable nonvolatile memory.
2) Price - just the MCU is more than 10+ USD. Those MCUs are basically ASICs with a lot of stuff integrated (plus - automotive rating). Precise and stable OCX doesn't come cheap either...
3)There is no single chip solution in the automotive market that would integrate all functions (LF Rx, RF Tx+RX, transponder Rx+Tx). Additionally, RF bi-dir + passive LF is power hungry, and getting a year out of your standard CR2032 forget about it - so a more expensive power source needs to be used...
4)NFC is basically just only one of the aforementioned functions - similar to transponder Rx+Tx.
5) Oh it needs writable nonvolatile memory for a lot of reasons... - configuration to cover different vehicle/market/protocol variants, DTC, Secret Keys for pairing, unless you want your fob replacement price to skyrocket...
Regarding fob price - keep in mind it's not just the electronics, although automotive MCUs have harder requirements to satisfy (op. range of temperature, voltage, very low quiescent current, very low ppm failures). Mechanics are expensive, although deceiving when you look at them. Keep in mind they go through some pretty nasty tests - including (and I kid you not) a washing machine test - basically testing if it will survive a washing machine.
"I am fob", "Checks out, I am car", "Checks out, please open", "Ok".
Add some details such as nonces but not nothing out of the ordinary compared to things like mTLS or mobile phones that we use every day. What am I not seeing?
(Press button) “hey, I’m the fob!”
(Press button) “hey, I’m the fob!”
There’s no communication back from the car because these systems are physically incapable of it.
Also, without some elaboration, your example is vulnerable to a replay attack too, but it’s not conceptually hard to fix. A simple arrangement that probably works (but would want a proof!) is:
“Hey, I’m fob #123” “Hey fob #123, I’m the car. The challenge is abc. Answer after 5ms.” “Hey car, HMAC(‘abc’, our secret) = ‘xyz’)”
And the car answers and also checks that the answer was received no more than 5.0000001 ms later. There are more clever variants of this sort of thing in the literature, and I don’t think cars use them because the manufacturers don’t seem to care. (The main problem with the scheme above that I’m immediately aware of is that it requires very good timing. If the microcontroller in the fob takes nearly 5ms to calculate the MAC and the goal is 100ns of allowable latency (100 ms is about 100 light-feet), then the timing precision needed is 20 ppm. Getting precision that good on a cheap key fob may be challenging. For that matter, getting that level of precision in the car, which may be rather hot, may cost more than the manufacturer wants to pay. More clever schemes don’t need this kind of precision. Also, my silly scheme has the fob broadcasting its identity every time a button is pressed, which isn’t great.)
I am surprised these things contains no receiver. Receiving is the easy part in a transducer, and there commercial off-the-shelf solutions to this for about a dollar. But that would explain it.
Meanwhile, my Honda has a physical key without a transmitter and the car has no receiver. There's nothing to intercept and I can go swimming with the key with no ill effect. No batteries to replace and if I need a new key it's $5, not $400. It's a brilliantly simple solution!
Attacks which can be performed by sitting a safe distance away while pretending to do something else can be more widespread as there's so little risk to the attacker.
> What does Honda think about this Rolling-PWN Bug?
> We have searched through the Honda official website, but we can not find any contact info for report Vulnerability. Seems Honda motor DOES NOT have a department to deal with security related issue for their products. And a person who works at HONDA has told us "The best way to report the Honda vulnerability is to contact customer service". Therefore, we filed a report to Honda Customer service, but we have not get any reply yet.
> In addition, we found an article from Bleeping-Computer (https://www.bleepingcomputer.com/news/security/honda-bug-let...), which Seems that Honda does not care about security issues anyway :(
Hope the authors are either anonymous enough or in a jurisdiction they can't be sued for making this public.
If corporations deprioritize security, that doesn’t mean we should shift responsibility onto individuals.
I'm was simply writing my comment out of worry for their safety, nothing else.
Responsible disclosure for issues like these is more of a curtousy to show good intent and to protect people by allowing the manufacturer to roll out patches. Honda doesn't seem interested in protecting their customers and they seem unwilling to get into contact with these people, so if it's true that they tried to contact Honda, that's enough of a curtousy for me, at least.
I don't know exactly what country they're located in, but I'm assuming that filming yourself unlocking random peoples car in the wild can be classified as breaking into something, especially if a corporation would like to hide a story and have government contacts they can engage in the silencing.
I don't see anything wrong with what they did, they went above and beyond to test Honda's systems for Honda, in exchange for nothing. But I do worry about courts not being as technically adept as me, and not seeing it like this.
They go out of their way not to make the details public to prevent car theft so I think any decent court should see that they're operating in good faith. A bad court may sentence them regardless, but I don't think responsible disclosure would've helped them in that situation either.
Yes, we do, since one of their videos are labeled "field test" which I presume means "testing random vehicles found in the wild".
> We have successfully tested the latest models of Honda vehicles. And we strongly believe the vulnerability affects all Honda vehicles currently existing on the market. Please see the field test video down below.
https://rollingpwn.github.io/rolling-pwn/video/Demo-Video-Fi...
> so I think any decent court should see that they're operating in good faith [...] A bad court may sentence them regardless
I hope so too, for the sake of the authors. Overall, they did the only thing they could do in this situation, since Honda doesn't seem to be receptive to security disclosures at all.
Laws are lacking for these cases in China, OTOH you don't face fair judgement if someone decided to f-u :( see WooYun[1] for an example. tl;dr China had their own HackerOne/BugCrowd and it's even founded earlier than both, only to have it killed in 2016 because it annoyed the wrong guy.
Consider their refusal to fix their head units - https://didhondafixtheclocks.com/
https://www.edn.com/toyotas-killer-firmware-bad-design-and-i...
Some of them are learning -- I think VW management now understands the issue, although there are as yet no VW products demonstrating it.
Not a new threat https://s34s0n.github.io/2019/07/18/Jam-and-Replay-Attacks-o...
This is such an infuriating trend in modern cars, especially hybrids. I can never tell when the damn thing is done starting up so at least ten percent of the time I take my foot off too early and it just goes "Try again, bitch."
Could this be legal? What would happen if your car is stolen because of that? Under french law, I think that it would be a "hidden defect" that the manufacturer has to cover for.
Could the counter and clock resynchronization schemes in RFC 6238 "TOTP: Time-Based One-Time Password Algorithm" and RFC 4226 "HOTP: An HMAC-Based One-Time Password Algorithm" have similar bugs? In implementation if not in principle?
I've heard of people using amplification attacks where they simply amplify the key fob from a distance (https://cbsaustin.com/news/local/car-thieves-are-hacking-key...), but using a replay exploit like this seems like it's a lot less common. Lately the big thing locally (south central Texas) has been catalytic converter thefts more than stealing anything inside the car though.
While I am 99% sure the politicians will write crappy legislation, over time it should become better and ensure that the purveyor of compromised SW is responsible for their sloppy work. It took decades but seatbelts, crash tests etc etc made us all massively safer when driving and we probably need the same minimum across some digital services.
The system can auto correct.
For example, one person claims that such a vulnerability means that the insurance company won't pay, for it leaves no smashed windows if you are robbed.
However, all it takes is one person going to court, publicizing it enough, and winning against the insurance company.
What happens? The insurance company, naturally, starts to increase rates for owners of that brand of car.
It has to pay out more often, for that car has a weakness, and this is the result.
This has happened before, with cars that didn't have physical steering wheel ignition locks, back in the 80s.
The result? Sales dropped for those cars, no one wants to pay 50% more for insurance, and manufacturers quickly worked to fix the issue.
It's a sad thing though, to see a relentless stare at the daily, short term bottom line, without thought to other factors, and long term profit.
Way to drive away customers, and crash a reputation! Brands to steer clear of, to be sure!
I wonder, would this also be a physical retrofit? There could be hardware limitations to change here.
In all cases the margins were razor thin. Poorly equipped cars were stolen marginally more and likewise cost a trivial amount more to insure.
But personal new car buying is 500% driven by consumers using emotion driven logic to magnify tiny differences so sales dropped, somewhat, maybe. It's hard to separate this from the variable of older products and cheaper products generally selling less well than the new hotness. Column locks went on to become standard as OEMs refreshed product lines and did mid-life facelifts.
And just waving it all away with "No, people just buy shiny" is counter to volvo even existing as it did. Many people do not buy just shiny.
Also, where do you live that businesses selling goods to you are not liable if they don’t work as expected? This is not a software problem, the problem here is that a key doesn’t work as expected. The fact that it may “have software” somewhere doesn’t make the problem go away.
From the description it almost sounds like validation for counter synchronization is separate from validation for command execution and it doesn't take into account requirement of counter in the message being bigger than counter in last valid message. Thus allowing to rollback the counter and making previously recorder messages valid again.
> You can follow the author on Twitter [@kevin2600] (https://twitter.com/kevin2600). However, we will not be releasing any tools required to go out and steal the affected vehicles. At a later stage, we will release technical information in order to encourage more researchers to get involved in the car security research.
It's been possible forever to unlock most cars by replay. I care a lot more about the crim driving it away. This news implies only that an enabled remote start can be compromised, not that every so-equipped Honda less than 10 years old is at risk. Just de-config your remote start.
Which car manufacturers have good security when it comes to those wireless keys? Are there any?
I feel like most of those things are either designed by regular developers who lack the hacker mindset; or maybe they do have it, but product management cuts corners to have better 'ease of use' etc.
I'll have you know I drive a Honda and it's not vulnerable to this attack.
2000 Honda civic
Source: Aforementioned 2000 CRV stolen once (Chicago =D) AND RECOVERED. Totally still working just dinged up a bit. They left it parked in front of a hydrant with the doors and windows open! Insurance totaled it, but said I could keep it.
That's the story of why I still have and drive a 22 year old, 5-speed, 2000 CRV. Hard to sell with the 'rebuilt' title, still runs great though. Dented up like a truck, but only has 135k miles. It's a keeper. My 'city' car.
I wish theives would use sophisticated methods like this.
Instead I have to pay the decutable for broken car windows or replace it out of pocket.
If a thief is caught stealing (unlikely) the consequences are minimal. So little insensitive to use sophisticated methods.
Of course there are those that want undetected access to a vehicle for reasons other than stealing. But I'm not worried about that personally because I'm not important enough to be targeted.
Keep shedding light on these issues.
More specifically: rolling codes are used to prevent replay attack while allowing the remote fob to be only a transmitter, not a receiver, which saves on costs.
If there was bi-directional communication there are obviously better ways to secure the fob/car (like regular challenge/response).
I do not want any wireless connections to my car, unless I add them
Your chance of getting a new car any time in the last decade that has no remote central locking and no potential replay attack surface is very, very low - this attack vector has been proven in many car key fobs for a long time.
So they can get in, but not drive it off I suppose.
Thankfully I've been doing a lot of research lately on buying a new car and whichever EV I want is only a 6-24 month waiting list.
(But truthfully, my car sits barely used in a secure underground garage 99% of the time- I'm not very worried)