Meanwhile, my Honda has a physical key without a transmitter and the car has no receiver. There's nothing to intercept and I can go swimming with the key with no ill effect. No batteries to replace and if I need a new key it's $5, not $400. It's a brilliantly simple solution!
Attacks which can be performed by sitting a safe distance away while pretending to do something else can be more widespread as there's so little risk to the attacker.
Also Honda does offer bidirectional fobs, that make this attacks a lot harder (still not impossible if the same resync strategy is used)
What is a bidirectional fob doing resyncing at all? There is absolutely no need for any sort of state in a bidirectional if any reasonable protocol is used. The fob should not even need writable nonvolatile memory.
2) Price - just the MCU is more than 10+ USD. Those MCUs are basically ASICs with a lot of stuff integrated (plus - automotive rating). Precise and stable OCX doesn't come cheap either...
3)There is no single chip solution in the automotive market that would integrate all functions (LF Rx, RF Tx+RX, transponder Rx+Tx). Additionally, RF bi-dir + passive LF is power hungry, and getting a year out of your standard CR2032 forget about it - so a more expensive power source needs to be used...
4)NFC is basically just only one of the aforementioned functions - similar to transponder Rx+Tx.
5) Oh it needs writable nonvolatile memory for a lot of reasons... - configuration to cover different vehicle/market/protocol variants, DTC, Secret Keys for pairing, unless you want your fob replacement price to skyrocket...
Regarding fob price - keep in mind it's not just the electronics, although automotive MCUs have harder requirements to satisfy (op. range of temperature, voltage, very low quiescent current, very low ppm failures). Mechanics are expensive, although deceiving when you look at them. Keep in mind they go through some pretty nasty tests - including (and I kid you not) a washing machine test - basically testing if it will survive a washing machine.
"I am fob", "Checks out, I am car", "Checks out, please open", "Ok".
Add some details such as nonces but not nothing out of the ordinary compared to things like mTLS or mobile phones that we use every day. What am I not seeing?
(Press button) “hey, I’m the fob!”
(Press button) “hey, I’m the fob!”
There’s no communication back from the car because these systems are physically incapable of it.
Also, without some elaboration, your example is vulnerable to a replay attack too, but it’s not conceptually hard to fix. A simple arrangement that probably works (but would want a proof!) is:
“Hey, I’m fob #123” “Hey fob #123, I’m the car. The challenge is abc. Answer after 5ms.” “Hey car, HMAC(‘abc’, our secret) = ‘xyz’)”
And the car answers and also checks that the answer was received no more than 5.0000001 ms later. There are more clever variants of this sort of thing in the literature, and I don’t think cars use them because the manufacturers don’t seem to care. (The main problem with the scheme above that I’m immediately aware of is that it requires very good timing. If the microcontroller in the fob takes nearly 5ms to calculate the MAC and the goal is 100ns of allowable latency (100 ms is about 100 light-feet), then the timing precision needed is 20 ppm. Getting precision that good on a cheap key fob may be challenging. For that matter, getting that level of precision in the car, which may be rather hot, may cost more than the manufacturer wants to pay. More clever schemes don’t need this kind of precision. Also, my silly scheme has the fob broadcasting its identity every time a button is pressed, which isn’t great.)
I am surprised these things contains no receiver. Receiving is the easy part in a transducer, and there commercial off-the-shelf solutions to this for about a dollar. But that would explain it.
There are a ton of other options though. Atomic clock signals are broadcast nationwide in the US. GPS, Glonass, etc. signals broadcast the time. Cellular networks broadcast the time.