Car thieves using tech disguised inside old Nokia phones and Bluetooth speakers
vice.com
vice.com
But the acutal post with technical analysis is https://kentindell.github.io/2023/04/03/can-injection/
Discussed 16 days ago https://news.ycombinator.com/item?id=35452963
In a way its a problem CPU's suffer as well, when thinking of code that pretends its a USB mouse and keyboard and then destroys stuff off the computer whilst masquerading as the user. Until such devices have self preservation built into them as standard, the ability to hack devices remains easy.
How you can prevent a car theft?
Hardware:
- Kill switch - hide a switch somewhere to the battery/ignition
- Steering wheel or pedal lock - annoying for the daily use. Not much of a deterrent if someone has a pick or liquid nitrogen.
- Chain and a lock in your garage - the need to cut something would be too risky. Doesn't help in a public place.
- Replace ODB with a fake - stops the hacking
PsyOp:
Have a message displayed or an extra devices that would communicate (this is car is being track, please leave the vehicle, police unit is dispatched etc.)
Tracking:
Thieves know how to disable car alarms with GSP, but Airtags maybe hard to find.
A hidden kill switch is probably the best idea since you actually need to find it which costs time.
fun fact, when I told the cops there was an air tag in there their first reaction was "what's that", and their second was "our investigators tell us it's not accurate enough to be actionable information." I recovered it myself and in some sense they were right, the airtag was kind of useless in finally recovering the vehicle.
https://www.autoblog.com/2022/04/06/man-rigs-flash-bang-to-s...
I want this, but on my electric car. Fuses aren't usually so accessible. I made a switch like this on my next (gas) car, but I could get the manuals and find the spot in the wiring diagram. I have no idea how to do this for a tesla. I don't think the fuses are so accessible in evs.
The stereo in the trunk is a big red herring because if you yank it out the car isn't going to crank pal.
I've seen someone protect a Ferrari F40 in his garage by having a gigantic door security "trunk" on his garage door. Literally the size of a tree trunk.
Stealing the car required getting inside the garage, which was only accessible through a regular but armored door.
The owner's idea was that you couldn't use another car to destroy the garage's door as there was this huge metal "trunk" taking all the width of the garage, going through huge holes in concrete.
So you'd first need to open the armored door, then slide that gigantic metallic trunk. That trunk was so heavy is was on little wheels.
I think the light can also report a failed lightbulb to the dashboard.
Any message sent to a security critical part of the car (eg. the door locks) would be signed by the ECU. The signature would use the current date/time as a nonce to prevent replay attacks. The signing certificate would be pre-programmed in at the factory.
Now anyone can say malicious things over the bus, yet still can never unlock the car.
ECUs are already tightly paired with immobilizers and dashboards, so they already need to be swapped together. Let's not do this with other parts which frequently break such as lights, locks and windows, please.
Once you replace the key fob, you must reprogram your engine ignition.
What prevents a thief from reprogramming the engine ignition for some other key? The same thing that prevents the thief from starting ignition manually: it's buried in the car. Notice that in this case, thieves rely on CAN buses running in easily accessible places.
If the thief can access your car's ignition directly, you can't stop them anyway.
Reprogramming of 2nd hand components to a different vehicle might also be possible, but using some procedure which is hard to do from outside the car. For example, short two pins on the back of the lock.
So basically I need to pretend to be a new part to steal a car. Some common key as an attack vector.
I guess the attack vector would rather be some unscrupulous mechanic replacing the part with a bogus one that would accept every unlock command, and the thief, in cahoots with said mechanic, would show up and unlock the car once the owner got it back from the shop.
- Open a hood
- Connect new, unprogrammed ECU (no immobilizer loaded)
- You can now start the car without chip in your key
As I see, people are reinventing wheel here, and are creating same problems as OEMs did 10-15 years ago.
My dad used to have a Citroën that would require taking out the whole front bumper assembly to change a freaking light, so it would be beyond stupid to have the ECU easily accessible...
ECU is on the right side in plastic cage next to a battery.
To get into the car thief will use a relay attack on your key, so no damage to the car will actually occur.
That ECU swap happens only if you have car with keys. If you have keyless car (start/stop button) then you can relay your way into starting engine.
Of course, they seem harder and harder to come by for some reason...
However even mechanical token can be generalized as this video shows: https://www.youtube.com/watch?v=9NtDH-8z95M
So I think that in the end it probably does not matter. When somebody wants to steal your car, you have probably no chance to prevent it.
1. They're already in the car. So how you authenticate the ECU and door modules to each other is really irrelevant. They bypassed that already.
2. They can just go ahead and replace the ECU and all the door modules with their own. So, again, how auth works doesn't matter.
3. At some point, you have to ask: Am I replacing the electronics in the car, or am I replacing swapping all the non-electrical parts from one car to another?
Each device that needs to sign messages (which probably should be only the ECU) is provisioned with a certificate signed by the carmaker. The device is also provisioned with a public-key pair, which is signed by the certificate (so you have chain of trust back to the manufacturer). The public key pair could be either programmed when the firmware is first flashed or generated at first boot.
A new door BCM accepts the first broadcasted public key from the ECU which is correctly signed. This would happen inside the factory for a new car, or when a new BCM is installed to replace a faulty one.
A used door BCM from a junk yard car could be programmed to accept a different (signed) public key by:
1. Being in the unlocked (and perhaps window-down) state; and 2. Pressing some combination of door buttons; and 3. Sending an appropriate command over the CANbus
It, of course, then verifies that the new key is correctly signed and reprograms itself to the new key.
The signing key would of course be unique per ECU/keyfob that needs to sign stuff so dumping another ECU doesn't help you crack it.
Loading a new private key from the server? Well, thief's device can probably pretend to be a server and load a new private key into the control unit behaving as a master of immobilizer. Then the thief will get car and instantly new set of keys.
Erm... using the LSB of a network RX timer is common way to add entropy (and perfectly feasible here). You could also use the LSB of the +voltage rail sense or the thermometer that probably exists on your MCU.
Just use a simple rolling code, like a garage door opener, HOTP, or the key fob itself, and enforce a rate limit for bad codes. 3 bytes can hold 6 packed digits, which is plenty.
The threat model here is that the thief walks up to your car and tries to broadcast messages to the door controller. If they can't observe prior messages to the controller, the chance that they will correctly guess the next code is, literally, 1 in a million.
Let the door controller start rate limiting (ignoring messages) after 10 bad attempts, and then only listen to one code per second. The thief will have to stand here for a week for a 50% chance of correctly guessing a 6 digit code.
Congratulations. Everyone is now potentially DDoS'ing everyone else's car, and all it takes is one a-hole with a gibberish screamer to lock everyone out of their cars within range.
You have solved nothing, and in fact, made plain old keys the more attractive alternative. I swear, people want to throw cryptography, radios, and security buzzwords at everything, but completely forget that the easiest way into the car will be taken. The tumbler lock. Once in there, hoods can be popped. Replace brain box. Move right along.
Btw it's "fun fact" and it typically means there is something factual, not just guesswork.
I would imagine my Passat which has a CAN interface on the headlight cluster would be vulnerable to this attack as well. Maybe even the bonnet sensor could be vulnerable.
Car manufacturers could remove CAN interfaces from peripheral systems (lights, wing mirrors) but they probably won't because it would make maintenance a little harder and less cost effective.
The idea of a software update by the security researchers sounds sensible but updating ECUs (engine control units), CCU (climate comfort units), infotainment systems of legacy cars will not happen.
Say goodbye to the old car thieves with their manual tools, hello techy thieves.
There are rumors that the algorithm and secret key for various manufacturers has been broken, and that any car with a remote can be stolen after recording the unlock and start sequence from nearby. But if you had the code that would do that, it's not like you'd upload it to GitHub, so that rumor remains just that, a rumor.
There are over 100 issues (aka bugs) in the spec though. Uncovered by these guys: https://youtu.be/zi0rHwfiX1Q?t=1150 (starting at 19:10, includes examples)
I think the proposal is to, uh, not do that.
Deniability if searched by police.
If a policeman suspects you of being a car thief and catches you with a Raspberry Pi, that looks pretty suspicious.
The same policeman wouldn't think anything suspicious about (what appears to be) a Nokia cell phone.
Indeed, who did he have to kill to get one?!
I'll have to relay that to my dad who drives around with a small cluster of SBCs mounted into his vehicle
Apparently quite common with Teslas as well, there is no way you can sell a whole functional car to anyone(well, not in any developed country anyway), but stripping them to pieces and selling them elsewhere is relatively common.
Volvo took really aggressive steps basically making sure that every component in the car that has any kind of electronic chip inside it has to authenticate with the car's VIN or it won't work at all - really annoying for the 2nd hand parts market but hopefully also annoying for thieves.
Modern cars can contain over a mile of wire and some of the important wires are all laid out during early stages of manufacturing, making it difficult to get at them for maintenance. Some cars have better access than others, but if they were carelessly tearing the car down, there's a good chance you need to take off, rewire, and test every ECU in the car.
As far as I can find online, most repair shops ask for about $1700-$2500 just to replace the main wiring harness, including the cost of parts and labour. A luxury Mercedes will have more wires and more automated systems, so you'll easily end up in the higher end of that range.
With a car in such bad shape, I wouldn't want my company to try to repair that car either, not without a "this is a bad idea" surcharge anyway. You just know it'll never run as well as it used to and if you make it a standard practice, you know at least a portion of your customers will blame you for it because you put the "repaired" sticker on that car.
The profitability of the second hand used components market is a real problem. I don't want a future where you can't reuse the parts in a broken down car because of some hard-coded encryption key, but the theft situation is seriously out of hand. Sadly, I think the Volvo approach will be the norm in the future.
On classic cars you can do this sort of thing easily enough, there the chassis was made first and then the wiring loom was put in place but on these modern vehicles you're sore out of luck. And EVs will likely be worse still, what with all the HV DC cabling to motors, batteries and charge ports.
>Ian’s sleuthing found that mostly these cars are destined for export, sent via shipping container to places in Africa
"These cars" might specifically mean things like the RAV4 and that other cars more reliant on good roads have less of a market in "places in Africa".
There must be a noticible flow of parts (eg headlights) to patch up damage caused by the theft. Likely the car manufacturers know, but it's not in their interests to talk about it.
Or chopped up for parts.
Or shipped overseas complete in a container.
Then they end up in a container ship bound for West Africa.
https://toronto.ctvnews.ca/car-stolen-from-an-ontario-street...
The cost of these devices is out of the 'simple criminal' pricerange, but is a minimal expense to a crime ring that can export a boatload of stolen cars at a significant profit as these cars go for significant price premiums overseas.
There's probably people on this forum that have never seen one in the wild.
I’m pretty sure it was last century, when I had that exact model (which was great, BTW).
It's from after the reboot so that technically not a 'real' Nokia (N-800).
I really liked those old 2G phones.
I remember, in the 1990s, in Japan, the phones kept getting smaller and smaller. It was pretty cool. One reason they could be so small, was they had antennas everywhere, and it was a fairly low-power system.
I brought the last iPhone 13Mini. I will miss the smallness.
Sad because it's stupidly reliable and in great mechanical condition, I expect it to run another 15 without batting much of an eye if properly maintained.
Ironically if it were older (like, > 30 years old) I'd be able to keep using it, as it would be considered a collector car (... provided it's vetted on a case by case basis by local authorities).
But then other regulations would take effect like max mileage per year and limited allowed range (e.g leaving local administrative area), which you can only exceed with more vetting from local authorities and under specific circumstances (e.g participating in a collector car showcase)
Better to live in an area where this is not a problem or carry insurance.
My fear is spending a lot of money on a sweet car and then having it stolen right away and, yes, I should carry insurance but making insurance claims is time consuming and inconvenient. Not to mention the fact that it sucks to have to pay deductible for being a victim of car theft.
I have to ask - does the automobile industry hire from a different pool of systems engineers than the usual pool I’m used to interacting with? It seems like everyone I know would say “obviously you should verify that the security mechanism first”.
Or is this a result of how the automobile industry is structured and what is outsourced to vendors/suppliers and what is done in house?
I’m not going to be buy that this isn’t solvable for a technical reason at this point. We have had a lot of experience dealing with PKI infrastructures and zero trust architectures in other parts of the industry.
It’s possible the ECUs in question have been so cost optimized there’s not a lot of power left to do asymmetric (or possibly even symmetric, idk) crypto.
Bus capacity is also a concern.
That security is slowly trickling down to other areas of the software industry. Even when you have individual engineers or teams who understand that it needs to be more secure, their procedures don't have that built in. And securing the car needs to be done at a system level, which means coordinating across suppliers & subcontractors, which requires management buy-in.
Similar problem in the medical device industry, but at least we have FDA cybersecurity requirements to adhere to.
In fairness the headlights were probably a $500 LED board anyways.
Ever want to run away from your loveless marriage with the secretary at work? Your car knows (what you did last summer, lol). So does Elon.
Would he impulsively cut you out of your own Tesla, because you insulted his minisub on twitter? What if you stole his favourite secretary?
Remotely disabling someone's car is a crime against freedom. Cars are required to keep people alive and working in the US. It's weird watching potential Internet-Feudalism™ roll down into mechanical automobiles.
``` the attack, called CAN (controller area network) injection, works by sending fake messages that look as if they come from the car’s smart key receiver, the research continues. The underlying issue is that vehicles trust these messages without verifying them. Once the thieves have accessed the necessary cables by removing the headlights, they can use their device to send these messages, it adds. ```
I mean car manufacturers don't pay if a car is stolen, they benefit because someone needs a new car.
Bonus, even if the car could report itself stolen in real-time and ubiquitous license plate readers were online so it became a significant problem for thieves, how would it defeat the simple measure of slapping on a valid plate with a magnet for the trip to the shop?
Wasnt the mindset of computer security that "if they can access the hardware then it is over"?
Automotive ethernet is faster and might be back to a single bus...
https://www.theverge.com/2022/9/12/23348765/tesla-model-y-un...
and i'm kinda expecting software first companies to already have this stuff in place? also stolen car media seems to focus on legacy autos being stolen not so much the newer ones, hence the question but maybe the theives target better build quality, who knows.
Of course some sort of override is needed to reset the pairing in case one or the other side is replaced in a repair. But this can be made cumbersome enough for a thief not to bother.
I'm sure this is well in scope for a field firmware upgrade, so hopefully this attack vector doesn't last long.
Ken has everything greatly documented. Ken is a long time fellow in the area. Btw, he has also solutions.