A surprisingly simple way to foil car thieves
news.umich.edu
news.umich.edu
I drove in it once to get lunch and near the beginning the car begins sputtering and he's like, "oh right, you're thirsty" and reached under and flicked the switch. So understated, I still laugh at the memory.
My previous vehicle was a '97 Jeep Wrangler. There were two kill switches installed when I bought it: one down by the driver's seatbelt latch for the fuel pump, and one reachable by inserting your finger into the opening for the 4wd shifter the disabled the starter. Neither was easily visible.
In my case it was motivated more by maintenance headache - the mechanical linkage that went from the ignition switch to the ignition control device at the base of the steering column was busted and I was too cheap to buy another one and it was a pain to replace.
Project trucks that nobody can drive but you are the best trucks, IMO.
It would work great on many Hyundais built as recently as last year!
No snow means no salt which means no rust.
Not unusual around here to see farm trucks from the 80s or earlier (sometimes MUCH earlier) still kicking around.
If you got in the car, and did not specifically turn the AC to the correct setting, the car would overheat about a mile down the road.
Luckily for me, I never had a chance to put this into practice, because nobody stole my car. Unluckily for me, there were several times where I forgot that I had to do this, and my car overheated about a mile down the road.
All that trouble, rather than run to NAPA to spend $12 on the thermo-switch that would be easier to install than hacking into the A/C controller. Yeah, I've known some dads like that.
And then the stupid solution is already working, so...
Couple years later it went bad again (I probably put in a crappy one from a generic country) so instead of going through that again I just stuck a bent paper clip into the socket of the wire that plugs into the thermoswich. Now it always has the fan on when the car is on.
Could have gotten the same effect by tampering with the relay (this short that I added actually just activates the relay for the fan) but I went with the easiest option.
And even I wouldn't do something that stupid.
Another story is once my friend called me for help because his car would't start. I looked it over; tested his battery etc, but it wouldn't turn over. I asked him if he had an interlock of any sort and he said no. I didnt do any more investigating since the car was still new, so I showed him how to push start it and drove it over to the dealer. Come Monday morning the dealer called him to ask where he had put the interlock loop that he had pulled out from under the dash. "Oh that thing? Yeah I thought that was weird." SMH
but i'd totally download a car
Damn, I thought I lived in a bad part of town.
To make it so that she could drive without bumping Delilah, I wired them to the defrost switch.
It wasn’t long into winter until I was forced to take them out.
The slushbox would shift into high gear and lug the engine unless you drove it like you stole it. The ignition didn't really need the keys unless you purposefully locked the steering column The exhaust split down the middle, giving the car a great sporting growl, and last but my favorite, the radio would often lock itself to the particular station and volume you were last playing. Sorry mom, hope you like metal at 11!
Many had a "cop switch". Cops suspecting you messed with the engine would put the scooter on a test belt to measure its maximum speed. The cop switch would instantly cap it to the allowed speed. Mine was hidden in the left mirror, a minor adjustment would activate it.
Of course, my system was just a bit flaky, and time and again I'd be on the highway, desperately pumping the lighter trying to keep the car going. I ended up yanking the whole shebang.
Same car had an alarm system, which over the years got triggered several dozen times by yours truly. The one time someone else triggered it by bumping my car, I came outside and thanked them.
What's the point of this? Modern cars already have engines that are cryptographically tied to keys[1]. They're not perfect, but is adding a whole new rube goldberg machine into your car really better than fixing the existing system?
> With a new $1.2 million dollar grant from the National Science Foundation...
What I find hilarious about our industry is that this could be completely made up ... or not.
https://www.restaurantdive.com/news/Stellar-pizza-robot-truc...
>Stellar, which was founded by former SpaceX employees in 2019, uses a robot to cook mobile ordered pizzas which are then delivered by the truck driver.
https://www.crunchbase.com/organization/steller-pizza
edit: looks I'm looking at the wrong company, see replies for details
https://www.axios.com/2023/06/12/softbank-pizza-robot-shuts-...
Discussed last month: https://news.ycombinator.com/item?id=36293636
The last 15 yrs in Biotech (esp genetics) and ML were more exciting than the previous 50.
The technology was immature but the fundamentals were there, and they'd save a not-insignificant amount of gas.
I wonder the efficiencies of cooking in a vehicle as opposed to a fixed pizza oven.
Back-of-the-napkin says no.
Automated driving is orthogonal to the bake-as-you-drive model. Dominos will also switch to self-driving when they can.
The cost of owning 10 oven-vans vs 1 store + 10 regular cars will be the tough part and will require scale, but pizza is big business.
But of course, you could offer the same latency by having a non-customizable menu and having pizzas ready to go when they're ordered. If it's 6:30PM on a Friday night, odds are someone wants the Pepperoni pizza that just came out of the oven. No fancy hardware required. The pizza is technically less fresh, but are minutes of freshness worth millions in VC? I don't know.
Taxpayers cannot pull their money out of the NSF and reallocate it to a different government agency.
So I’m ok if we spend $1.2M on research. That’s like 5 developers for one year who would otherwise be allocated by the invisible hand into effectively useless endeavors like high frequency trading or ad tech.
Cut to the alternative universe where they’re working at Blackrock and a car thief is driving their car away.
I'm not. Where do I opt out of funding government grants?
At least I can decide not invest in something if I don't want to risk losing money.
(remember that government spending basically created transistorized logic, microchips, and computer networking as we know them today. would you have opted out of those too?)
If you're on HN in the first place, there is an approximately zero percent chance that the few dollars of your tax money spent on this kind of research hold a candle to the benefits you've gained from it.
It's possible that some other manufacturer may try it again in the future, but the hit to Hyundai/Kia's reputation has been substantial.
The switches themselves aren't bypassed. Their design for the lock cylinder is so crappy that it can be snapped off, exposing the peg that actuates the switch.
Modern cars also have new vulnerabilities: https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
There are aftermarket immobilizers systems as well, that also use cryptographically bound keys.
> Modern cars also have new vulnerabilities: https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
If car manufacturers can fuck up implementing today's immobilizer systems, what makes you think they won't fuck up implementing the rube goldberg contraption? Why do we have to switch to it just to get a non-broken cryptographic implementation?
Modern cars have engines that are cryptographically ties to keys
But the Pentagon couldn’t put biometric locks on their humvees?
https://www.ibtimes.co.in/isis-takes-dozens-captured-us-humv...
They can’t account for trillions of dollars… but we vote them more money they didn’t even ask for
https://www.nytimes.com/2019/03/11/us/politics/trump-budget....
”Mr. Trump’s budget, the largest in federal history, includes a nearly 5 percent increase in military spending — which is more than the Pentagon had asked for“
We need oversight but politicians are not very interested in doing oversight because corporations use their money as free speech helping their favorite politicians get re-elected, because of the Supreme Court decision that allows that to happen.
So we need a more informed population to stop corruption from happening, but some politicians don't like the idea that people should be able to read whatever books they want.
There is almost zero reason to include robust locks or immobilizers on military vehicles. They're either occupied by soldiers with guns. Or in a locked facility, guarded by soldiers with guns. Or abandoned on the battlefield (in which case, they should be scuttled, but shit happens and sometimes you need to GTFO ASAP).
You might be familiar with locks on vehicles due to your own experiences, but deterrence to unoccupied theft is a requirement that is somewhat unique to civilian passenger vehicles. It is completely normal for many other types of vehicles to have very minimal or zero theft mitigations due to operating in different conditions with different requirements. For example, multi-million dollar jets have no anti-theft systems at all.
It's a fine solution to the very pressing "VCs aren't giving me money" problem. You can't have a blockchain or AI startup, say, without throwing technology at random things!
All you have to do is have every soldier who is authorized to use your equipment unlock the vehicle through an affirmative phrase — and the vehicle can check their voice for instance, or other biometrics like their fingerprint. Or each of them can wear a beacon or smartphone which does that.
Cars today open with you just getting into the car. This is easy stuff man
Yes, it would be possible to do what you are saying. However, militaries find this undesirable because they find the drawbacks outweigh the benefits.
There is no realistic scenario in which a military has lost physical control of the vehicle, and the situation is mitigated by locks on the vehicle. It is always already too late at that point.
You do realize that in a war zone, that list of authorized users can change rapidly (as people are injured, die, or rotated out of combat)?
Let’s assume for the sake of argument that electronics are perfect, and never fail for any reason (including but not limited to battery drain, battery overcharging, battery age, heat, cold, sudden change between heat and cold, vibration, shock, moisture, dryness, flooding, corrosion, UV degradation, rodent infiltration, wind, wind containing abrasives such as sand and dirt, chemical exposure, fire smoke exposure, fire heat exposure, sabotage due to local exploits, sabotage due to remote exploits, etc.).
Ignoring all those possibilities, you are only left with the problem of key management. You can find an overview of those challenges at https://en.m.wikipedia.org/wiki/Key_management
Managing secrets at a scale beyond people you know personally is extremely difficult to do correctly.
Not a big deal when physical security is provided at the broader level. For example, for any failed access attempt just fall back to TOFU.
(Sorry, I'm just 85% sure the top-level ancestor is trolling and I wanted to help by taking it one level deeper. :)
You don't know who is going to need to be able to drive something at the drop of a hat. And the more fiddly and complicated something gets, the more likely it is to fail because of either technological or UX/human reasons in stressful situations. This would cost lives.
Slow down there with the sarcasm and think about the actual requirements or use-cases first. Your average operable military vehicle is in one of three situations:
1. Actively occupied or guarded from theft by current owners/operators with guns who will not tolerate strangers getting close.
2. Parked somewhere in the middle of a whole bunch of people who are generally guarding the whole area, and those people may need to be able to operate it very quickly.
3. In some long-term storage which is well-fenced, under surveillance, guarded by people with guns, and typically very far from both overt enemies and opportunistic thieves.
So there's already an access control system tuned to a particular set of needs... and one of those needs includes "using it to escape from something dangerous even if the prior-driver and everything in their pockets got vaporized."
https://www.newsweek.com/how-russian-tanks-captured-ukraine-...
Also for other things too:
https://nypost.com/2023/05/11/ukrainians-strike-russians-wit...
Every TV show has a self destruct mechanism to prevent a ship from falling into enemy hands and blabla etc
Scuttling has been a common military practice, for literally millennia. This practice is unrelated to the presence of any locks on the vehicle. Militaries are equipped with explosives and weapons and can perform these actions without them being built into the vehicle. The reason this did not happen is not due to the construction of their vehicles, it is because they did not take action to do so. https://en.wikipedia.org/wiki/Scuttling
The automated self-destruct countdowns you have seen in movies and TV shows are used for dramatic effect. In reality, it is cheaper, more reliable, and safer to scuttle a manned vehicle manually.
Just a question, have you ever worked with soldiers before?
If anything, it suggests other things like:
1. Russia shouldn't have tried a desperate blitzkreig through muddy terrain.
2. The Russian military should have had better policies/equipment to destroy or scuttle the ofabandoned tanks.
3. Russian tank-drivers should have had better training so that they didn't get their vehicles stuck in embarrassing ways.
Plus it's not like the opposing force will be a bunch of joyriding delinquents: Even if you completely remove your abandoned truck's steering-wheel and pedals, your way out, they've got mechanics and tools and factories, they can just fit their own. Truly denying them any valuable salvage is actually a lot of work/damage.
You don't want either of those things in a widely used military vehicle. Soldiers do not need to die because they're fumbling and dropping keys under fire. They also don't need their truck dying in the middle of a maneuver because the kill switch accidentally went off.
Also, in war, trucks will be getting destroyed left and right. It'll literally be a rounding error.
And on the other hand, if you are ambushed, you don't want you and your unit to die because the soldier who had the keys just got fragged by the enemy and now you can't escape.
Also those were Humvees taken from Iraqi personnel.
This one is nothing more than a relay on the battery line. Simply find the relay and bridge it. Problem solved. Might take you a few hours to dig under the dash to find the damn thing, but once you do 'problem fucking solved'.
The tanks that were stolen belonged to the Iraqi armed forces, not the US Army.
The problem is relay theft, where thief's relay the signal of your fob key inside the house to the car via a simple antenna and amplifier system. Cryptographically signing won't help.
However, this can be fixed by adding a motion sensor that makes key fobs go into a sleep mode when they have been inactive for a minute. Upmarket car manufacturers like Mercedes have started to add this. The only reason this is not yet widespread as increased car theft is good for car manufacturers.
Keyless cars top the list for most stolen cars across the UK, with around 93% of all stolen vehicles in 2020 being taken without vehicle keys. Addressing this stupidity would be the first step. It is like projecting your bank account details and security details on the facade of your building, and then being surprised your bank account is drained.
can be picked
>The problem is relay theft, where thief's relay the signal of your fob key inside the house to the car via a simple antenna and amplifier system. Cryptographical signing won't help.
AFAIK the attack you describe only applies to keyless entry systems (ie. you can open and start a car without having to pull your key out), which is related but not the same as an immobilizer. Transponder keys without keyless entry systems still exist on today's models, and is the default on most cars unless you opt for an upgrade.
>However, this can be fixed by adding a motion sensor that makes key fobs go into a sleep mode when they have been inactive for a minute.
That helps against someone cloning your key while you're at your desk, but it seems way easier to clone the key while the driver is walking away from the car? That way you know which car to steal and don't have to follow the victim into the building, which might be secured (eg. office building with badge system). Measuring RTT time and/or trilateration (multiple antennas inside car) should be much more reliable.
They don't clone the key, they use an antenna to amplify the signal from your key fob and then drive off. In principle you can do this by following someone, but much safer to do this at 2am at night. Similar to a one time password, the signal is only valid for a short period of time.
My understanding that your average ignition is a little more complicated (or at least different .. wafer locks) circa 70s-90s and then they started adding radios and other things into the mix. I dunno, I've never tried to pick one of these.
Destructively bypassing your average old-school ignition is still something you can do blindly with a bent flathead screwdriver and some elbow grease in about 15 seconds flat. As is destructively bypassing any given door lock.. well not bypassing the lockper se, but instead the bolt/doorframe generally.
Standard house locks don't require picking at all - you can bump them in a few seconds in any light conditions.
I have no idea how hard it is to do with that tool. I myself have as close to zero lockpicking skills as it's possible to have while still having picked a lock (I messed with a friends clear practice lock one time). But just seeing the LPL do it gives almost no indication of how hard it is to replicate what he is doing.
This is often used by thiefs who bring the relay close to the front door, hoping for the keys to be in a bowl or a hook near the door. Then they can open and start the car using the relay. The car then won't turn off when it loses connection to the key (because that is dangerous) which allows stealing of the car.
There are cases where this was done over much larger distance, but those attacks are more easily defeated by having tighter tollerances on the latency of the reply. The latency tollerance does not do much for the 'keys near the front-door' attack, which is what the 'stationary keys do not reply' solution is aimed at.
I've always wondered why the car doesn't warn the driver that there's 100 yards left before it will cut the engine (or limit it to idle), keep the power steering, turn on the hazards, and warn the driver that the vehicle won't continue to function because the key is not in range. Doesn't seem dangerous at all...
I think at most you could do something like have the car go into 'limp home' mode if it senses the key was never present in the car for some amount of time after the car is started.
I've had cars with chips, with contacts, in the mechanical keys [1].
Seems like one solution is to go back to the good old days of physical intent.
[1] One implementation: https://www.uhs-hardware.com/cdn/shop/products/df4ddf21436c4...
The persistent rumor, of course, is that this has been cracked for specific models from specific manufacturers, with the help of someone at the dealership, maybe someone who owes large amounts of drug or gambling money to local criminal syndicate types. "All" you'd need to do then is use a valid challenge response pairs off as a cryptographic oracle to brute force the challenge-response algorithm and recover the seed value computation algorithm for the key and the car. Then "all" you need to do is record a challenge-response pair from the real key talking to the vehicle, and maybe the VIN, in order to duplicate the key, in order to steal the vehicle.
If this has been been done, the algorithm and seed-value recovery technique have not been publicly shared over the Internet, so it's only a rumor that it's been done, but given how high-tech thieves are these days, I don't consider it outside the realm of possibility.
What isn't outside the realm of possibility is the Rolling-PWN attack, which can be done with a $32 device and has been demonstrated against 10 years of Honda vehicles, up to 2022.
The full fix is time of flight measurement but as I understand it that's still beyond cheap electronics.
Or just.. you know press a button when you want to unlock your car.
For reference 20 meters is about 66 nano-seconds.
Consider how annoying the modern cigarette lighter is for a non-smoker.
Now I'm wondering how hard it would be for the thieves to shake the ground outside the house enough to fool the motion sensor...
I don't get why it's not a keypad and relay though. Sounds like a complex solution to a fairly simple problem. I might be missing something though.
Edit - ah it's intended to work with many other options like controlling indicators or wipers or something - so you choose some pattern that is your password.
I think you're asking exactly the right question though - how is all this not just a more complex, less secure, shittier version of a keypad that you enter a 4-6 digit code on?
This coupled with a CANBUS integration with the ECU to prevent it from starting would be pretty good though, since no one can wirelessly collect the signals to spoof the code.
Not if your brand is one of the ones known to be easy to steal. I doubt I’d buy a Hyundai in the future given my understanding of their reputation as easy targets.
Maybe it's different for very high-end vehicle thieves, though.
It seems relay theft could be 100% prevented by measuring the response time, and capping it to whatever is the equivalent of say 100 meters + processing time in key fob.
I just use a steering wheel lock, one of those bright yellow chunks of steel that bolts onto the steering wheel: https://www.milenco.com/products/automotive-security/automot...
This is visible to the theif and just raised the theft effort from "jump these cables just behind the headlight" to "jump these cables behind the headlight and then use a loud angle grinder in a very enclosed space". I'm in a residential area, this is a strong deterrent and avoids the initial damage being done to the car.
PS: Some sports cars kill their CAN when the car is turned off... but we do insist on keyless entry and this is what we get for it.
> What we knew was that the Club is a hardened steel device that attaches to the steering wheel and the brake pedal to prevent steering and/or braking. What we found out was that a pro thief would carry a short piece of a hacksaw blade to cut through the plastic steering wheel in a couple seconds. They were then able to release The Club and use it to apply a huge amount of torque to the steering wheel and break the lock on the steering column (which most cars were already equipped with). The pro thieves actually sought out cars with The Club on them because they didn’t want to carry a long pry bar that was too hard to conceal.
https://freakonomics.com/2010/06/what-car-thieves-think-of-t...
I'm having trouble visualizing that part, unless it refers to steering-wheels of the past with a lot less material. Wouldn't a piece of hacksaw blade also be much less effective, without the rest of the hacksaw to provide tension?
Source: Not a car thief, but have misplaced my hacksaw, for small tasks, far too many times.
IIRC the first iteration he made used a keypad to enter the code, and the second used the blinkers.
https://web.archive.org/web/20010206124335/http://www.kapinn...
A whole lot of people have these on their own cars, any DIYer can do it in an hour or two. I may or may not have one on mine. But the "security" comes from there being no standard location for any of the components.
The video says "alarms sound the when authenticator is removed", but that's a gimmick. They should be entirely disconnecting the whole negative terminal (duh), not just the wire to the device, leaving the whole car without power until the positive terminal is freed.
And if anyone bothers to ask what the thief is doing, they have a 100% plausible reply "got a parasitic drain, so I've put a cheap relay and now this crap is failing on me".
Although I don't own a car, I'm happy when I hear throughout the day and night that my neighbor's cars are well protected.
For the device in TFA, I don't see what prevents a thief from just bypassing the thing with a jumper from the battery + terminal.
I still think car alarms are a net negative to society. Thousands of hours of disrupted sleep and it prevents approximately no thefts.
All a thief has to do is trigger enough false alarms (directly or indirectly) to annoy you and the neighborhood that you either disable it or learn to ignore it as false alarm.
In addition, if the driver should be able to manually recreate the voltage pattern by actually flicking the lights/wipers, there will be a relatively small number of voltage combinations which could be iterated through an automated device connected directly to the wires very quickly.
More energy required to start engine --> Minimum battery health required to start engine increases --> battery lifecycle decreases.
Yes, if you flashed your lights everytime 500+ times and got your battery to a meaningful low voltage where it barely started every time, sure. But not in the use case presented here.
It can be nice if you’re in a hurry or worried about walking alone in a parking garage at night.
But yes, it can be annoying, especially because you’re expected to tip them in the US too.
And to answer your question: No, valet parking is usually useful because the parking place is far from where you're going (usually a hotel or restaurant). Having the valet saves you the walk from the lot to the place where you're going. It is even more useful when it's raining and you're having a formal dinner.
The wait for getting the car back is also pretty short because someone radios a driver already in the parking lot to bring your car in most circumstances.
It was quite nice and let me focus on work instead of worrying about charging and only initial paperwork (we had QR stickers on the car and keychain QR).
That's about the only time I've used a valet regularly.
1. at parking garages so that cars can be double- or triple-parked. This is by far the most common use case for valets today. At these lots, you actually do have to pay more (or arrive early) for a spot that doesn't require valet parking.
2. at high-end restaurants or other similar venues where there is no immediately nearby parking and limited or no street parking. The valet drives the car to a lot or garage a few blocks away and returns it to you when they are done. You can almost always opt out of these, although you may or may not save money by doing so and at some places it can be worth it to just pay up and deal with the inconvienance because the nearest parking is a bit far.
I've also seen it as a weird status symbol thing in cases where it's entirely unnecessary, primarily used by people who have never had to put up with #1 or #2. Think up-scale hotels but located where parking is extremely ample. I think that only exists because there's a general impression outside of super-dense cities that valets are a "fancy" thing because they are only really common in "fancy big cities". (Which, to be fair, owning a car in midtown definitely makes a person fancy in some sense even if I'd never ency that person :p)
But actually, for the most part, valets are not a fancy optional service. They are mostly a non-optional service that you have to pay more or go to significant inconvenience to not use.
Surprisingly many of them use a text system so you text them to the number they confirmed with like 10 minutes before you need your car and they have it waiting — very convenient.
Also use it at big events like operas or plays or whatever where parking is awful but valet, despite being a little expensive, puts you right up at the front door when walking in and then they get it when you leave.
Prior to that I had lived in LA from 1966 on and got around on foot and on my bicycle and city buses.
I drove that giant Buick — I mean it was HUGE, both in terms of length and width as well as weight — for about five years, the final 2-3 of which featured a caved-in non-functional driver's side door resulting from having been T-boned by a little old lady who ran a stop sign.
No worries: I'd just hop over the side or use the passenger side door.
After the crash I never worried about theft.
Also, amusingly, when I was on freeways, cars in adjacent lanes would quickly move away.
First, what happens if the electrical characteristics of your vehicle change in some way? New vs old battery? Busted headlight? Phone plugged into an outlet? Diesel air intake heater grid kicking in on a cold day? What if you need to jumpstart your vehicle? It just seems so finicky in the real world.
Second, what's the point of using this analog signaling system to begin with? I don't see the supposed simplicity of it. Both the transmitter and the receiver are more complex than would be needed for digital. The other argument is that it is somehow more "hacker-proof", but using analog signals doesn't make it so. You can have a similar scheme operating on the CAN bus with no added risk. In fact, I bet there are devices on the CAN bus that can both measure and modulate battery drain, so the isolation may be illusory.
Ultimately, it's not about not having the technology. It's just that your average customer favors convenience features over having a fortress on wheels. Plus, the returns on sophisticated defenses are diminishing, given that a car can always be loaded onto a tow truck, the hood can be popped open, or the whole thing can be stripped for parts with a Sawzall (as catalytic converter thieves tend to do).
I think the whole "flip on wipers, flash high-beams twice, turn on map light" thing is a fallback for when you don't have the keypad or don't want it to always be plugged in. If the voltage variances for those actions changes, I suppose you can retrain it with the keypad plugged in.
And the point of that analog signalling is to make installation easy. You just plug the keypad into the lighter port. It handles the rest.
Beyond that, I don't see the "simplicity" argument for analog. You're already messing with the vehicle's wiring. CAN bus is easily accessible from the passenger compartment. Or, running an extra data wire takes 10 minutes. Short-range RF can be easily secured in this application too.
Plus, on many newer cars, USB charging ports are displacing 12 V outlets, so it's not even all that future-proof.
It's not that I'm desperate to dislike this design, but I'm struggling to see the qualitative improvement over a billion aftermarket designs that most people just kinda don't use...
2. It adds tons of uselees innovation to a kill switch.
3. If your car is antique/valuable/interesting, the people stealing it know the starting diagram/circuit and can easily rip it out/bypass it.
4. IF your car is antique/valuable/interesting you wouldn't add this as it can depreciate the car value/make it more ugly. You're not installing this in a brand new BMW M6, or a new Honda Civic, or a E24/1980's BMW M6 or a 1990's Honda EK Civic.
Solutionism at it's worse. Ignores the whole idea of what a car is. Ignores the innovation in Transponder tech that has been the standard for a while - only Kita/Hyundai in the USA has been avoiding it because if added BOM.
Outside the USA car thefts are not as common and in Domestic Japan/India/Asia a transponder is still pretty rare.
But back to the article - seeing this was sponsored by "University of Michigan- " - WTH is going on there? That is Ford/GM.
Ford has had PATS technology for the longest time - https://en.wikipedia.org/wiki/SecuriLock
GM has PK, same idea.
"Battery Sleuth bypasses both the wireless communication that key fobs depend on and the standardized onboard communication network that’s used in today’s vehicles. Instead, it authenticates drivers by measuring voltage fluctuations in a vehicle’s electrical system. "
Worthless, so it knows the cars resting voltage usage (easy enough) and if theres a drain, it means something is connected and that it can lock it up, but the same as a killswitch, it can be removed or bypassed.
"Battery Sleuth also has defenses to guard against hacking or physical attacks on the device itself, including a siren that sounds if illegitimate activity is detected and a resistor that shuts down the vehicle’s electrical system if an unauthorized power source is connected to the vehicle. "
Very easy to pop hood, pull siren out/disconnect. and lol "resistor" means anything/nothing.
Most unique rides are typically stolen due to owner laziness(leaving keys on top of a tire, keys in the visor, left running, etc.).
Stripping an security system is also doable, via the can-bus attacks we see of late, but more personalized can just be to replace the ECU. In many cars this can be done in less than 15 minutes.
Car shopping as presented in gone in 60 seconds is somewht common - ask people on any enthusiast forum and you'll see.
Miatas in Bay area, stolen for the hard top/car itself. Skylines Honda Civics - just spare parts basically, though if it's a mint enough model I can see people vin swap because 2000's Honda S2000 - mint models reach 30K now, so it's own market.
And that's just from what I've kept up* in.
Now would someone pull up to someones garage, open that, and drive out? Probably not - but alot of people do drive cars to a parking space for work, or if they live in a condo - have shared/communal parking, and such.
And to add an extra layer of paraonia, it is very inexpensive to attach a GPS/Air tag to a car and track it - within a week or two you can see a pattern of where it goes, for how long and what amount of time its standby.
The VIN number is also viewable from the windshield, meaning if the thief has any sort of connection - they could even just order a replacement key thats preprogrammed with a base code and potentially just turn up to the car and drive away.
But for opportunistic theft, yes - keys left within car/visible and then stolen but there are many different type of thieves for different markets. For unique/"antique" cars or any cars that were in the first three gran turismo - being targeted is a very big thing now in the community.
I was living in Miami during that time, a friend had his EK hatch stolen, beautiful example too, spent a fortune on that car and it showed. Of course the aftermath was the same ole story of it being stripped, and cut to a near nonexistent state.
Now thinking on this "solution" the amount of social engineering that happens today will defeat this pretty quickly. Most of the thefts for cars like my friends were done by people who knew the owners.
Running cars are worth $5000, coupled with a hard top its worth around $7000 easily - mint/very nice ones exceed $10,000. For a 20-30yr old car, it's appreciating to exceed new cost (msrp for a 1990 miata was not even $14,000!)
Over in honda land, same thing, you used to be able to pick up a basic ek no/manual/only option is AC for less than $3,000 now those are the ones in most demand and exceed $15,000-20,000!
My priors are that car theft inside the USA is fairly rare now, but exceedingly common in Europe. I'm constantly hearing about all kinds of sophisticated electronic attacks on vehicles particularly in the UK, that are simply not an issue in the US.
Would anyone be able & kind enough to explain what sort of testing could go from a sample of eight vehicles to a result of "more than 99.9%"?
Does that mean they tested 1000 ways of hacking (or 125 ways on each of 8 cars) and found 0 of them were successful? Or...
http://www.kingoftheroad.net/charge_across_america/graphics_...
Slap your PIN in and hit the RUN button and it'd fire right up.
Would this deter thieves? Possibly! Would thieves eventually be able to work around it? Also probably! Would it increase the friction of getting in and driving? Definitely!
Today, your house keys are basically useless for security -- getting into your house is trivially easy both destructively and not. But we all use house keys because they feel safer. Ask people to provide biometrics or long passkeys or keycards and eliminate the existing locks? It's a hassle most folks won't tolerate.
Likewise, people are comfortable with the walk up, push button, leave nature of fobs. Replacing that with "walk up, scan fingerprint" or "walk up, type in password" is going to tick off a lot of people.
[1] Yes, I'm aware of european cities where cars aren't necessary or are actually slower than public transit. That's not applicable to most of the US though.
The only reason I have a car is because there are some specialized transportation needs (towing) that I cannot get from my bike. I use my bike for everything from hardware to Costco to groceries to child care to ... lots of stuff.
Not that much. One site[1] lists the TCO of a compact car at around $33k/year if you drive it for 15k mi/year for 5 years. That works out to $550/month. Of course, if you're comparing this to getting ubers, there's no way that you'll be driving anywhere near 15k mi/year, so the TCO of a comparable car is probably $450/month. That's a lot of money to spend on uber/instacart, but keep in mind that if you have a modest commute of $20 each way, that only works out to 11 round-trips a month, or half the working days. So if your lifestyle is such that you don't need to drive to work most days, and you don't any other similar uses for cars (eg. picking up kids from school and/or driving them to extracurriculars), then by all means uber everywhere rather than owning a car.
But I was refuting the specific idea that house locks are a tamper evident seal. They are trivially easy to bypass in a tamper evident manner.
If it's just a code, tons of legal ambiguity comes up. Can a gf shoot her exbf that she gave the keycode to last month?
How is this different from a physical key?
True, the solution very obviously to reduce poverty. It's a social problem, not an engineering nor a policing problem.
Land value taxes are only taxes on the value of the land.
A land value tax would tax a giant residential building and the parking lot adjacent to it the same, which encourages maximizing the value of the lot rather than leaving it for parking.
They are not useless. Only some people have the skills and tools to open them - so they are useful at keeping most people out, even though they don't provide perfect protection.
Most thieves are not professionals, but for example junkies who look for something easy. A simple automatic light, is already doing wonders to keep them away.
But also, bricks through windows are equally not difficult and not expensive, though they do leave a bit more evidence. When my neighbors have been burgled, this is the preferred method of entry I've seen.
But that would be loud. You don't want attention when breaking in. (Unless you are a fucked up junkie not caring about anything anymore)
But yes, my parents for example are paranoid about always locking the front door 2 times(and get angry if I don't do it when I visit), but have a glass door in the back. There are also glass cutters.
"Raking house locks is a) not difficult and b) not expensive. You don't need to be a professional to do that"
But you do have to make some investment. They are illegal to purchase (in most places), I would not know, where to start looking. And then you have to learn to use them. And I know someone who did play with those a bit - yet he still could not enter my door at all. So it is a barrier.
amazon. Not much of an investment needed https://www.amazon.com/Stainless-Steel-20-School-Toolbox/dp/...
(It is indeed cheap)
Lockpicks are legal almost everywhere in the US.[0] Even in places where they aren't legal, they're not exactly difficult to obtain, given that a perfectly adequate rake can be made from any key that fits the target lock, and there are only ~3 keyways in common residential use.
That said, just because people have low-security locks on their house doesn't mean that better options aren't available. I have Medeco locks. They are harder to pick than what you get at the hardware store. So far, no break-ins from lockpickers! Also, I'll sell you a rock that keeps tigers away.
Pre-Covid, it didn't matter if you were loud. You and your neighbors were all off at work all day. So long as a thief felt confident there was no alarm to trigger, they could make all the racket they wanted and no one would hear.
Today, it's a little more risky but of the half dozen houses on my street I'd probably only hear one getting broken into and that's only if I were downstairs. Our homes aren't on especially large lots either (7-10k sq ft).
Dog owner gets up, yells at dog to shut up... because rain!
They've tried various blanks, and I've never gotten a satisfactory explanation from any of them. It's possible all my local locksmiths are inexpert.
The pins in new locks have pretty tight tolerances for the first couple years until they wear a bit. Its likely they are just using older equipment which isn't sufficiently precise to cut them. Get a key that is exactly right, and works with a bit of wiggling, use it as your primary key for a couple months and it will work just as well as the originals. The slight variations in the key ways/etc will knock the edges off the pins with enough use. Assuming the key is cut correctly from the right blank, you might just need a bit of lube/oil on the key. If you can see variations by eye in the ramps/etc its likely the key is just wrong.
No, not really. A large part of the security of locks comes from most people not knowing that they have the tools and skills to open them. It's like if everyone taped their door shut, and we depended on most people not knowing that tape is easily removed.
My kid accidentally locked us out of the house the other day by twisting the knob lock on our garage door. Turns out we never got a key for that lock when we bought the house - oops! And we didn't have keys for the back door, for complicated reasons. No worries, I took my wife's key ring and used the key to her parents' house to open our back door. In my experience, most keys work in most locks, if you just apply a light turning force and then rake the key in and out a bunch of times, ending with the key sticking all the way out except for a millimeter or two.
Which is always hilarious to me considering insurance has no problem with glass windows or fenced in backyards.
My front door is a pricey digital lock with a key for backup, and I don't think I could pick it with this method. That's why my first instinct was to try on our cheapest door.
In my suburban area, the biggest problem is unlocked doors on houses and cars. Despite this problem existing for many years, doors are still regularly left open. The criminals don't attempt to exploit the same neighborhood repeatedly. They pass through in waves and then go elsewhere before returning when everyone has let their guard down. When they attempt forced entry, or anything more than casual theft, they get a lot of attention and caught.
They could improve their takings by developing some lock picking skill, but it's also higher risk since they have to spend some more time on each target which increases the risk that an observer will actually notice them. I could easily imagine a dog walker ignoring someone entering a home through an unlocked door, or making it look like they are checking a door is locked when entry fails.
Good locks are expensive, but they also last a long time. And nearly unpickable is good enough. There is wall of window next anyway that then becomes much easier.
You can't shoot someone that walks into your home through an open door.
You can shoot someone that rams your door to open it.
The number one, by far most effective thing you do comes well ahead of those armed, home entry thieves, and that is you make your home scream "GO AWAY!"
Get a dog
Employ great lighting
Put the home alarm stickers on, actual alarm optional, [3]
Clean up.
Etc...
The criminals work on risk reward. You can bias that equation away from favorable meaning the baddies pick another home, not yours.
From there, should you really feel this scenario could happen, maybe consider a gun. But if you do, please get gun education. One bad scenario is to have a gun, and face experienced users. Your chance of getting you, and or family, hurt go way up!
I do mostly identify with the left, but am gun friendly having grown up rural and well educated about guns.
[3] - no joke! Neighbors had done the sticker thing for roughly a decade. That, plus the other suggestions work well.
If that's your definition of "hard", I'd say you're setting that bar far too low.
Is that assertion based on study or "common sense?" It may well be that they don't feel the need to bring a gun because they know their victims are definitely not going to be armed anyways.
The real question would, do the criminals not use a weapon at all, or do they use weapons that just don't happen to be guns?
> broad social safety net that reduces poverty
People aren't being shot in the US because of poverty. The _majority_ of "gun violence" in the US is actually suicides. It's nearly 2/3 of that terrible statistical category. The remainder of murders typically involve alcohol and arguments.
The majority of murder victims in the US know their murderer by name and have been acquainted with them for years. Means. Motive. Opportunity. These things don't change.
If the legal rule is "you can't shoot anybody", which is what the post I responded to said, wouldn't that make it impossible to legally obtain weapons? Why just "hard"?
If, OTOH, you mean make it hard to illegally obtain weapons, where has this actually been done successfully? My reading of human history is that criminals who want weapons have always been able to get them somehow.
> The US thinking to me seams to go along the lines of handing out nuclear weapons to everybody so forces are balanced...
I don't know where you are getting that from. The US thinking is very simple: since it is impossible for governments to prevent all violent crimes or to ensure that police show up in time to protect citizens from being harmed by violent crime, citizens must be allowed to have the means of self defense. The best way to minimize the number of citizens that feel the need to have weapons for self-defense is to extirpate crime--but unfortunately the US in recent decades has been moving in the opposite direction.
But Americans know that this (a pre-shooting checklist) isn't a reason for door locks for every American. And I'd guess it only is for a small minority of Americans.
>You can shoot someone that rams your door to open it.
So somebody destroys a door and that entitles you to take their life?
I think in both situations you should just refrain from shooting at all. Seems to work in most of the rest of the world..
If the door is locked, and they break in, you are not shooting them because they broke a lock. You are shooting them because theyve shown criminal intent by forcibly making their way through a locked door.
https://en.wikipedia.org/wiki/Castle_doctrine
But the basic idea is that the natural right of self-defense extends to certain areas, including one's home. (That is, you do not have to wait until the intruder has his hands around your neck in order to defend yourself.) If you would prefer to not be allowed to defend yourself, that's you. In many countries (not just the US) invading people's homes makes for a dangerous and short career, as it should.
Absolutely not the case. With toughened glass and modern reinforced doors it is very far from trivial. At least in the UK. I understand security standards can be much lower depending on the country.
Imagine if the folks who built FaceID, TouchID, and Secure Enclave were tasked with building car security. Cars are a lot more expensive than phones and laptops, it would be worth the $50 or $100 in extra hardware to secure them.
And as an added bonus, you wouldn't even need a key anymore because you could start your car with your face. :)
Put the keypad in 3 times incorrectly in a row, system blinks rad, you sat for an hour unless you called the rental place for an override key.
Voltage fluctuation aside, it seems like the same system.
The pin pads Ford often fit to doors are not the same thing - those are to provide cabin access without a key at places such as worksites or camping trips etc.
It's so simple, it can be done "With a new $1.2 million dollar grant from the National Science Foundation"...
I guess simple doesn't mean what it used to mean...
"You should see our new, redesigned, UI/UX" /s
Running a relay into the car to a switch thats protected just moves a analog electrical problem somewhere else, it' still just two wires to jump at the end of the day
What you want is what smarter cars have, integration to the ECU. So you put in the wrong key, it does a crypto exchange with the ecu, and the ECU won't crank. Even if you crank it by jumping the solenoid, it won't power the fuel pump, the computer will still say 'I am off' sorry no fuel no timing, nothing.
Maybe they want that thing to talk to the ECU? Otherwise, how is it locking the car?
but you need to tuck that shit up under neath in the dash or wherever the ECU is, and that doesn't solve any issues because it's still just one wire to short out. You need something tucked up underneath you can use wireless transponder so theres nothing obvious preventing it from cranking.
What you want is to be original. You just need to think like a thief.
What thieves don't like? Surprises.
Just do something surprising that will make the thieve think it is just too risky to try and they will go for an easier alternative.
Car manufacturers are directly to blame for the increased theft of cars. It is a win win for them, as it results in higher car sales. If a dood manufacturer would sell doors that can be easily opened, everyone would complain. Far less so with cars.
Keyless cars top the list for most stolen cars across the UK, with around 93% of all stolen vehicles in 2020 being taken without vehicle keys.
Here are stats for UK. Total cars stolen in UK dropped from ~300K to ~100K in the last 20 years. [1] Even though number of cars keep growing [2]
[1] https://www.statista.com/statistics/303551/motor-vehicle-the...
[2] https://www.statista.com/statistics/299972/average-age-of-ca...
I don’t know much about it but it seems like a key is supposed to be the password for the car, so seemingly the key is where improvements could be made. Like add unique and random differences in the metal on each key and have the key slot read those and only turn on the car if it matches (since I guess the metal bumps are easily bypassed by thieves?)
Or couldn’t the bumps on keys just be replaced by.. pretty much anything that is physically secure and not multiple hundreds of years old technology? Credit card chips, magnet strips, 2fa fobs, fingerprint sensors, etc?
So turn a $100 ignition switch assembly into a $3,000 1-of-1 monstrosity? Would you need to replace the entire ignition assembly if you lose your keys, or would you be able to generate a key from the ignition assembly (or VIN or other unique identifier)? Thieves would probably just do that for high end vehicles anyway.
> Or couldn’t the bumps on keys just be replaced by.. pretty much anything that is physically secure and not multiple hundreds of years old technology?
Isn't this exactly what push-to-start tech is? I'm not sure the percentage of vehicles that have push-to-start at this point but I'd imagine it's well into the majority, and increasing.
For car keys manufacturers try to get away from physical keys for years, and for a remote keyfob it's just a cost question. Bidirectional communication allows for good cryptography with challenge-response protocol, but costs more than unidirectional. But then people want to be able to open their car when the battery of their fob is dead ...
Ford had their dial pad on their vehicles for the longest time to prevent entry if you were using a non factory key to enter. I always thought that was a neat feature, but heavily under utilized.
Edit: the original idea was that there would be some kind of reader unit that converts the ISO 7816-ish protocol to RS485 and the actual cryptographic challenge-response verification will happen in a unit buried deep inside the engine bay. Well, as long as it is one-off obscure hack, you don't really need any of that.
Give me a way to protect the inside of the car.
Plus the fact that neither SFPD nor Oakland deploy decoy cars to actually go after the thieves - what a total failure of basic policing this area is. Can I get a 10mil grant to propose that!?
A sufficiently motivated actor will steal your car if then want to. The immobilizer is kind of a joke when you can, with an Arduino and access to the CAN bus, just dump the memory of your immo controller or instrument cluster and find your pin, then use that to pair a new key you had cut to a vin.
(Maybe instead of skunk spray, you could turn the radio up full blast, playing some CIA-approved heavy metal music?)
Use a manual transmission. I had a car that in the previous century (Saab 900Turbo 5spd) was visiting in NYC and found it broken into, scratches around the ignition (also in a weird place in the center floor), but not stolen; clearly they had no clue about operating the gears.
These days I read multiple articles about would-be thieves foiled by manual trans.
It is merely security by obscurity, but it is nevertheless effective.
Nobody that doesn't already know how to drive a manual thans is going to figure it out in the 60 second window, and very few people already know.
Anyways, I installed a switch up under his dash the disconnects the fuel pump +12v wire. It takes just a moment to flick the switch if you know where it is, and afterwards, the engine will crank and crank and crank and sort of sound like it wants to start at first, but never do anything. It would probably take several minutes to find it if you had to look for the switch, especially if it were at night and you were trying to steal the car. Seems like a good lower tech deterrent to me! The car has not been stolen since.
I have a buddy who had an old Ford in San Francisco. Once in a while he'd get in the car in the morning and notice that it felt .... strange. He couldn't put a finger on it. Then one day he had to get to work a little early and showed up at his car much earlier than normal. He found a guy sleeping in his drivers seat. Needless to say, both were startled and the homeless dude ran off, leaving a big bunch of keys behind in a keychain. Those were "master" keys to get into a whole slew of older vehicles.
I'm just imagining having this technology become ubiquitous, then using it without knowledge of how it works. We end up with magic incantations that a general population does without reason. People already do so many things on their computers etc because that's how they learned it the first time--whether or not the specifics of their actions are relevant.
How is this any better than a hidden killswitch under the glove box or behind the gas pedal?
Once the attacker knows they can just short the circuit.
[1] https://www.statista.com/statistics/191216/reported-motor-ve...
Since you have to open the car to 'pop' the hood, the only way to steal it is to get inside somehow (slim jim, smash the window, etc), pop the hood, pop the hood safety, know which black plastic box has the knife switch, open that, close the switch, close the hood, hotwire the ignition, and, finally... drive away.
Too much trouble. some other victim car will be chosen by the typical car thief.
Source: nobody has ever stolen any of the cars I've owned while I've been troubleshooting the ongoing electrical problems.
From a user perspective, this is "you need to physically be in the car and scan your thumbprint or type on a keypad to start it"; it seems like there are lots of simpler ways that such functionality be built into a car by the manufacturer that are just as secure, it's just that there's no demand for it.
Adequately punish the ones police happen to catch.
It’ll create a reinforcing cycle. Police are more interested in pursuing these cases because it’s worth it for their time, and thieves will be dissuaded from car theft because there might actually be consequences if caught compared to the current slap on the wrist.
I wonder if there's a mechanics forum somewhere in which posters are confidently proposing Caesar ciphers and so on.
[1] https://batlabels.tumblr.com/post/158029360040/anti-theft-ac...
It's ridiculous this sort of thing is needed, but it's sort of...fun?
Whats not clear to me is if this blocks the starter (high current) or is a bit smarter by blocking a lower current component (like injector pump, or the ignition).
Deal with those issues first. Or someone will smash a window to steal something valuable no matter what you try.
We already do stuff to prevent crimes. The cars have locks, alarms, cryptographic key fobs, tracking, cameras etc. etc.
None of that works.
Adding a new layer of security is surely not going to help. That's my point. The resources are better put elsewhere.
And you know property crime is only a recent phenom of the last couple years. Never existed before the 1980s or you know tomb robbers etc.
Uber: just hail a taxi
Amazon: just visit your local bookshops
netflix: Renting DVDs is perfectly fine.
Spotify: all the music you need is on AM/FM.
Instagram: just meet up with friends in person
Zoom: Conduct face-to-face meetings
Zillow: Work with a real estate agent
Yelp: Ask locals for restaurant or service recommendations
Doordash: Call the restaurant directly for takeout or delivery, or cook at home.
This, however, is not a good solution. A starter relay kill switch, hidden somewhere non-obvious, is far better. Not a suitable solution for mass-market of course, but, for a hacky intermediate solution, it'll work just fine, which is all the power sensing keypad is good for but with way more steps.
The actual solution is to have real cryptographic security that isn't subject to replay attacks. Not difficult to do, or expensive, and already exists.
Yeah, that kinda sounds like my Caterham 7 back in the 1990s during wet weather.
But also, what seems very goofy to me is the removal of the requirement of sticking your key in the ignition.
It really feels like this older thing, plus the wireless crypto/radio bit they also have, really ought to be sufficient for all of this?
Car thieves learn how to break into various makes and models of cars and hotwire them. They have also figured out this thing called a "clutch".
You're obviously wrong about the car thieves, because this happened to my car. Two of the thieves were central american gangsters. They left reggaeton and stolen audio systems in the car. Another guy was an old meth-head, who stole and lived in it for a week by the bay. I found all his drug crap in it afterward.
Mine sits straight near the car CPU and is protected by a metal box.
Now I’ve seen grift, but come on. I want to hire their grant writer.
Literally a relay in the starter lead. This looks like one of my afternoon projects, and I’m not even joking. I have a 1990s montero diesel and it leaks power, and I often forget to disconnect the terminal.
So I bought a relay from AliExpress (same one shown in this photo but one size up) and hooked it up with an esp32 and some discrete components.
It senses my phones Bluetooth radio and energises the relay if I turn the key on when I’m within a few feet, as well as any other Bluetooth radios I authenticate.
I can also just turn on the wipers momentarily and it will latch the relay. If the vehicle is not running, the relay unlatches in 15 minutes.
That way I can basically forget that it exists, problem solved. It has been working flawlessly for two years now. The whole thing took me about 3 hours to put on strip board and program, another half hour to enclose and mount it.
Give me an hour more in micropython and I could make it require a passcode entered on your phone with a secret wiper switch sequence as a backup. If I threw a five dollar Hall effect current sensor (as shown in their project) it could require a whole dog and pony show of switch activations to unlock it. Adjusting it to different vehicles would be a one- time calibration sequence like I use for my water flow meters.
I guess I should have applied for a grant.
(Also, their device is supposed to be tamper proof. That sounds more difficult)
At any rate, good for them. It will be a great learning experience at least.
But they might be funding for marketing costs and other soft expenses. Nice project and a great jaunt for a year or two. I’m sure they will learn a lot. Good for them.
The real screwy thing here is it’s like they did no market research or customer testing here. There are already a multitude of cheap, sophisticated, highly effective solutions in this segment that are much less user hostile than this gadget seems to be .
The SaTC does have a Transition to Practice (TTP) option. However, this research is CORE (see the text "CORE" in the project title [2]). The objective is to write research papers.
[1] https://www.nsf.gov/pubs/2022/nsf22517/nsf22517.htm [2] https://www.nsf.gov/awardsearch/showAward?AWD_ID=2245223&His...
That’s amazing!
The only way something like this gets traction is “as seen on TV” marketing to naive consumers, and I have no interest in building for that market.
There is value to developing the entire system... to ensuring the keypad mechanism is reasonably robust and tamper proof. There is value to understanding the vehicle as a system and reasoning out this defense strategy. There will be value in preliminary productization of something this for mass production, especially as regards the use of that terrible 12v power port and providing the 'fingerprint' in a safe range of voltage fluctuations to avoid catastrophic and probably non-obvious failure modes. There will likely be D.O.T. paperwork, and UL listing.
$1.2 million is probably a bit meager to truly develop something like this.
Yes, you can hobble some crap together on your Montero. Congratulation. Hardly a solid foundation to speak ill of this team doing something genuinely productive.
But don’t be talking down on my car. That’s just not cool.
That beast is the workhorse of the farm and it gets the job done.
None of the windows roll down though and it’s hot as hell inside, so it discourages unnecessary use, saving the planet.
It rarely sees pavement but it drags what needs to be dragged and it pulls the utility rigs out after they deliver to us.
The point is that your car's modifications and the university's are similar, but different, particularly in scale and broad robustness, which adds difficulty in ways you may not be appreciating.
$1.2 million may sound like a lot to you, but to pay a team of people to work on, and provide materials for them to work with (especially cars, which generally aren't cheap, especially used cars right now!)... Well, it likely doesn't go as far as you think it does.
https://osr.ucsf.edu/news/nih-update-ruth-l-kirschstein-nati....
Also, in my field and in my region, $27k is massive funding. I don't know anybody who makes that much, let alone $44k, and we also don't get tuition or benefits covered. Our TA/RA union is currently striking because it's essentially impossible to live off of funding alone.
[1] https://grants.nih.gov/grants/guide/notice-files/NOT-OD-23-0...
It sounds like his system is more refined than the academic one. It certainly has more features.
As for my “work” it is literally insignificant tinkering by a bored old fucker with nothing better to do than chat on hacker news.. I don’t even respect my work, and anyone who thinks more of it than digging a ditch is just wrong and has obviously never dug a ditch.
But, just calling it like it is, the “signature “ thing they are working on is something that is already solved for decades and if it took anyone more than a week they may not have a clue what they are doing. I have implemented a version of it myself in a technically adjacent application.
In case anyone cares enough - and you probably shouldn’t- feel free to read my incoherent ranting that follows:
In my case I use load vector analysis it to detect and characterise loads on our microgrid. We have several buildings and houses, and we run 100 percent solar on an off grid system.
Using an esp32 and a current transformer coil on each of the three phases, with some good 16 bit ADCs, we monitor and characterise loads. Each of the refrigeration compressors has a somewhat unique starting and load profile. Each water pump in our utility system similarly has a unique startup and load profile. Same with air compressors, fans, and other equipment.
The profiles are programmed into the esp32 by putting it in calibration mode and switching the load off and on 10 times. It’s a pain in the ass because you have make sure no big changes happen in the power system in the meantime, but it works.
The MCU saves the signature as a vector and assigns it a number if it doesn’t sit too close to any existing vector signature.
It is really good actually, even being able to discriminate between identical pumps on the system because of their supply impedance and loading.
I’m not a data scientist or an actual engineer so I adapted some vector code from a DSP project, and the whole thing took me about 2 days using the Arduino IDE (please kill me)
I’m basically an idiot. Anyone who does this for a living should be able to do it in less than half the time.
There are still some rare false negatives because a grid can be quite chaotic, but in general it’s very accurate. In a simple D.C. system like a car in the off condition with predictable loads I would fully expect 4 nines discrimination.
What they did was cool, but it wasn’t hard. Not saying it wasn’t hard for them, and maybe they learned a lot, but I’m pretty sure that 1.2 million to solve the problems described in the article is two orders of magnitude off of reasonable.
From the provided description, If a single engineer with decent tools could not have this from zero to a production ready GERBER file with masks, stencils, and the works to send off for automatic assembly inside of a month they should probably look for another line of work.
Of course, if they work like I do which is to say they don’t, very much, and they mostly drink coffee and fuck off all day, then I’d give them a month and a half knowing full well they did all of the actual work in a week of panicked thrashing, creating months of technical debt in every line of code to build the glass house that somehow works without passing any of the tests but that’s fine you just rewrite the tests.
Of course certification and things like that are a whole different beast, but this was a CORE research grant.
I hate that beast, but it’s my beast to hate.
You can’t just talk shit about it from your comfy chair, or sitting on the toilet with no circulation to your feet, or whatever — that’s something you earn.
You earn it with mild first degree burns on your right leg and tinnitus like the rest of us.
If I seem abrasive and unnecessarily combative, it’s probably just the incessant itching of my leg and the trauma from driving that thing.
https://counciloncj.org/wp-content/uploads/2023/01/CCJ%E2%80...
There's been some other exploits to infotainment systems, but AFAIK, they are all limited to proof of concepts. And the radio-repeater that almost works occasionally on some cars with wireless key access (better implementations have proximity detection which prevents this attack vector).
As it turns out, immobilizers are pretty damn effective.
If I owned an effected Hyundai/KIA, I'd do like we all did with 90s cars and put a killswitch in. It's not professional car thieves hitting the bulk of these cars, but mostly bored people showing of. So if YT can't show them what to do if the car won't start, they will go away.
That’s a cute trick, but if a current day equivalent is integrated into modern day cars (i.e. CANBUS-based), then the security is already defeated.
No one challenged the security of the “cruise control cheat code” of the 1990s simply because there were no devices small enough. The other bit is that criminals weren’t sophisticated enough.
This wasn't to foil thieves, it was to frustrate the repo man.
Yes, my dad was used to removing the rotor from the distributor (small piece, easy to pop off and unless the thief just happens to have the correct model handy, the car can't run) back in the 60s (maybe he did it earlier).
I'm pretty sure some form of this has been popular for just about as long cars have had an electrical system.
(/s)
The concept of a starter interrupter has been around almost as long as the automobile itself. Ways to engage and disengage that interrupter have evolved and advanced over the years. Older folks will remember cars with a keyswitch on the front fender, and then a keypad inside, and then hidden switches like I described in my OP, and then IR and RF remotes, and so forth.
The basic concept in the linked article is not very novel, IMO. The specific implementation is cute, and somewhat current in the sense of evolution of these systems. But the whole thing is as noteworthy as the next arm64 advancement.
^ this is where the value is, which is what the $1.2m is intended to explore.
No Bluetooth, but it does have a dedicated RF remote.
Edit: figured out the keywords I needed for the exact product you want “bluetooth immobilizer”
There are dozens of already existing products that are designed to do exactly this for pretty cheap.
The car is a complicated product. It’s not a website. It’s not an app. My employer has 120k+ employees and factories in every continent except Antarctica. Regulatory bodies interject with anything related to access and security, and those bodies are different in every country/region. The product itself is massive physical good that many countries consider domestic production of which to be a matter of national security. Every single physical change to the product is analyzed by bean counters. Shipping the product requires at least some level of expertise in mechanical engineering, chemical engineering, hardware, software, and manufacturing. You need factories, regulatory approval, supplier networks, programmers, drivetrain engineers, management, people to lobby the government, accountants, and much more. You need it all.
You’d be shocked at how difficult adding a single physical button to any given car can be. Scoffing at $1.2mm for a new ECU that relates to security is naive. “I could do this in one day in my garage” is not how shipping a change to automotive products works.
Maybe I'm reading it wrong, but it sounded like the $1.2mm went to some prototypes and a research paper.
And great if you thing that those voltage fluctuations are gonna be consistent. Eventually some switch will corrode and then the person's wiper switch won't fluctuate the voltage properly. Nobody will want to reset their clocks using this every time they get in the car. Your break-in alarm won't work with the battery disconnectred. Car manufacturers will be pissed that you're disconnecting the battery because they can't get your telemetry and the car can't update while you're not int it. And then when you have problems, this will be the first thing ripped out of the car by your mechanic. This whole concept is flawed, and anybody with basic car or electronics knowledge will stay away from this thing because they can do it themselves.
And here's the kicker... anybody who doesn't have basic knowledge won't be hooking this thing up to their battery. They are terrified of even touching the battery. Congratulations on your marketing BS, but it's clearly not thought out from a common sense perspective at all.
The target market for this is not "anyone with basic car or electronics knowledge who can do it themselves"... it's, "people who want an extra level of defense against car thieves".
They are claiming that the novel part is using voltage fluctuations to unarm the immobilizer and claiming that it requires less installation since the signaler device can plug directly into the cigarette outlet. A wireless relay requires the same cuttoff relay installation as their “new” idea, but is even more convenient because you don’t have to install a bodged together keypad on the cigarette lighter, and short your electrical system to cause voltage fluctuations.
They have blown through 1.2mm in grant money and their product is a bunch of prototype parts from a $50 arduino starter kit. It isn’t polished, it isn’t ready for consumers, it is a single prototype.
I guess the idea of causing voltage fluctuations is novel, but they sort of reinvented a $30 wheel for 1.2 million.
And it is a fair sight more involved than a simple kill switch, by the look of things. The research aspect comes from exploring the practicality of such an approach. This exploration requires prototypes, test beds and investigators.
Who's really to say what the results of the research will be, at this point? In my opinion, I think smart phones and NFC are probably the way to go... but I'm not going to hop on the internet and make scornful remarks until I know more. I'm not sure why you have done so?
https://a.allegroimg.com/original/03e206/1de3f26447d79428246...
Optional extra on Series 1 Citroën XMs, an immobiliser keypad programmed into the engine ECU. It cost about 100 quid in 1990 money, on a 40 grand luxury car. Most V6es and 2.5 diesels had them, few 4-cyl petrols or 2.1 diesels had them.
There's no need to spend $1.2M developing something that's already existed for a long time. This was actually a development of a similar keypad fitted to most Citroën CX Turbos, from the mid-1980s. The idea is nearly 40 years old.
It's inexpensive proven technology, and it works well.
[LoJack] could also include the incorporation of a scheme whereby an additional step was required to activate the ignition. Prior to starting, it would require the activation of any number of the usual vehicle features such as the radio, headlight switch, or other switched device. Without knowledge of the proper procedure, it would be almost impossible to activate the ignition. Modern transponder key based systems made the original LoJack starting system obsolete
But good for them. They will learn a lot.
Transponder keys aka immobilizer systems.
All those Kias being stolen in the US are being stolen because the US does not mandate any form of immobilizer, and thus Kia on their cheapest models didn't include one.
Canada mandates immobilizer systems. Guess where the whole "Kia boys" phenomenon isn't a problem?
This is one of many examples of how our "democracy" isn't working. The vast majority of the US populace would agree that an immobilizer system which prevents a car from being started with a screwdriver is a good thing.
Every time it's been proposed in congress, the automotive lobby has told congress how very expensive it would be for them (and by very expensive, we're talking probably less than $100 per car.)
The expense to society (the owner losing their likely sole means of transport to work, health care, social activities and suddenly having a massive expense), police response to do something (er, just collect the report, I guess), the lost productivity, emergency services, and medical costs of people injured (victims or perps) from joyriders...all that goes unmentioned, because nobody's spending money to put someone in front of Tommy Tubletone from chucklesville to tell him that it'll cost everyone less to mandate the things.
Consider that ABS was not mandated in the US until 2012, along with traction control.
Compared to a lot of european "socialist" countries, we have much worse alignment between public opinion and legislation, and it's because of how powerful lobbying and corporate election funding is here, and a pervasive, insidious effort to portray anything other than wild-west free-market attitudes as "communism."
Probably half the award is taken up by indirect costs at the university, leaving the remainder for a few PhD students to be funded, money for the devices, and any studies where they are probably paying participants to use the device.
$1.2M doesn't go that far in terms of grants. As far as whether this is a good investment for the government's money, I'm a lot less clear. Given all of the recent car thefts due to TikTok, I assume that influenced NSF and the reviewers.
Or are they slurping funds for other aspects of the uni's operations?
Overhead includes things like administrative & support staff, equipment depreciation, etc.
It’s often calculated as some percentage of the grant. Then you fill out your timesheet to bill hours to specific grants, so it can all be tracked.
There's a valid question of if that number can be smaller, but the general concept makes sense.
I wish I was joking, but a friend who works at a Uni was recently complaining of their budget being affected by (mandatory) things like that.
Open up all federal grants -- especially NSF grants -- to anyone with credentials or experience necessary to PI (so, a PhD or equivalent industry experience). Broaden the reviewer pool so that each panel is at least 51% non-Professor expert citizens.
I can do a LOT of advising and conduct a LOT of research with close to 0% overhead. But most NSF grants are only possible to get if you attach yourself to a university, and at that point it's just not worth the effort. Everyone loses, except for the academic industry, which gets heinously immoral labor laws exceptions so that TT professors and admins can retire-in-place on the taxpayer's dime in their mid 30s.
What possible actual reason does the NSF have for requiring research work to be done at universities?
Spoken like someone whose never done research. I’d love to hear what kind of research you think you can do at 0% overhead. No one can do anything at 0% overhead, are you serious?
A big problem is they don't always get all the money they apply for, and so with the added overhead there's sometimes very little left to do actual science.
I worked at a startup and between the rent for our office and our individual rents, like 80% of the VC money went into landlord pockets.
Also there are plenty of “tax breaks” you can get so that you don’t have to pay so much. Capital expenditures will be taxed at 0%, so you can get your overall rate down significantly.
I believe Stanford is 60%. My university is 54%.
Here is an explanation for the justification of this: https://spo.berkeley.edu/guide/fa.html
It does certainly feel excessive as an academic. I've never seen actual tracking of where the F&A money goes in terms of a quantifiable breakdown, e.g., what fraction goes to university accounting for doing their needed work for supporting a sponsored project, what amount goes toward electricity, etc. Universities always seem to be negotiating with the Federal government to raise the rate. When I was at an institution with a 45% rate, though, it let me stretch my grants a lot further by allowing me to fund more students.
You might need to lay out your whole road map for the first grant, but but that entire grant only covers 6mo or whatever.
Crazy to think you could build at least 4 of these with the same amount of grant money.
This wasn't done. Well, it wasn't done by these researchers, but it has been done countless times before by other people. This research is a joke.
Edit: I've realized the dropbox comment reference is an appropriate reference, but in the exact opposite way you're suggesting. All the ignition interlock switches already on the market are dropbox. This researcher is the one saying "look what I can do with rsync."
It seemed like a simple crib job would cover the entire premise. Let alone all the other strategies out there.
It wasn’t clear to me if the paper in question recognized that people already do that with computers. I tried reading it but it was pretty hard to get through.
100% acceptance of every grant proposal I’ve ever submitted.
Also:
Plugging in a battery booster down stream of the device's imposed amp bottleneck seems like a stupid simple circumvention.
Maybe it isolates the starter circuit, but that starts diminishing it's selling point of being simple and universal, if you need to start dealing with differences in wiring.
But you didn't.
Echoing the sentiment from many of the replies, it's easy to arm-chair quarterback and criticize others' work (and moreover, the existence of the work itself) as intuitively obvious, and therefore lacking value.
Besides the fact that it has value to someone (therefore the grant award), the devil's in the details, and a grant like this isn't just for the idea, but also for development and productionizing.
But, going back to your point... if you think you can do better, than by all means do so. Seems like sour grapes that someone else is capitalizing on something that is intuitively obvious to you.
So, basically a custom rig, with some shit that might or might not work from AliExpress, is out of the question for anybody not knowledgable in electronics ("hooked it up with an esp32 and some discrete components"), and needs even more work to have a functionality that would come in standard in a commercial solution.
Some of the strongest https://news.ycombinator.com/item?id=9224 vibes...
Regarding the article, I get the idea that essentially this is a stripped down version of using something like a Yubikey to access a workstation (in this case, a car). I chuckled at the idea of doing certain actions within the car to get it to operate.
^ ^ v v < > < > B A Start Start