What's the point of this? Modern cars already have engines that are cryptographically tied to keys[1]. They're not perfect, but is adding a whole new rube goldberg machine into your car really better than fixing the existing system?
What's the point of this? Modern cars already have engines that are cryptographically tied to keys[1]. They're not perfect, but is adding a whole new rube goldberg machine into your car really better than fixing the existing system?
The problem is relay theft, where thief's relay the signal of your fob key inside the house to the car via a simple antenna and amplifier system. Cryptographically signing won't help.
However, this can be fixed by adding a motion sensor that makes key fobs go into a sleep mode when they have been inactive for a minute. Upmarket car manufacturers like Mercedes have started to add this. The only reason this is not yet widespread as increased car theft is good for car manufacturers.
Keyless cars top the list for most stolen cars across the UK, with around 93% of all stolen vehicles in 2020 being taken without vehicle keys. Addressing this stupidity would be the first step. It is like projecting your bank account details and security details on the facade of your building, and then being surprised your bank account is drained.
can be picked
>The problem is relay theft, where thief's relay the signal of your fob key inside the house to the car via a simple antenna and amplifier system. Cryptographical signing won't help.
AFAIK the attack you describe only applies to keyless entry systems (ie. you can open and start a car without having to pull your key out), which is related but not the same as an immobilizer. Transponder keys without keyless entry systems still exist on today's models, and is the default on most cars unless you opt for an upgrade.
>However, this can be fixed by adding a motion sensor that makes key fobs go into a sleep mode when they have been inactive for a minute.
That helps against someone cloning your key while you're at your desk, but it seems way easier to clone the key while the driver is walking away from the car? That way you know which car to steal and don't have to follow the victim into the building, which might be secured (eg. office building with badge system). Measuring RTT time and/or trilateration (multiple antennas inside car) should be much more reliable.
They don't clone the key, they use an antenna to amplify the signal from your key fob and then drive off. In principle you can do this by following someone, but much safer to do this at 2am at night. Similar to a one time password, the signal is only valid for a short period of time.
My understanding that your average ignition is a little more complicated (or at least different .. wafer locks) circa 70s-90s and then they started adding radios and other things into the mix. I dunno, I've never tried to pick one of these.
Destructively bypassing your average old-school ignition is still something you can do blindly with a bent flathead screwdriver and some elbow grease in about 15 seconds flat. As is destructively bypassing any given door lock.. well not bypassing the lockper se, but instead the bolt/doorframe generally.
Standard house locks don't require picking at all - you can bump them in a few seconds in any light conditions.
I have no idea how hard it is to do with that tool. I myself have as close to zero lockpicking skills as it's possible to have while still having picked a lock (I messed with a friends clear practice lock one time). But just seeing the LPL do it gives almost no indication of how hard it is to replicate what he is doing.
This is often used by thiefs who bring the relay close to the front door, hoping for the keys to be in a bowl or a hook near the door. Then they can open and start the car using the relay. The car then won't turn off when it loses connection to the key (because that is dangerous) which allows stealing of the car.
There are cases where this was done over much larger distance, but those attacks are more easily defeated by having tighter tollerances on the latency of the reply. The latency tollerance does not do much for the 'keys near the front-door' attack, which is what the 'stationary keys do not reply' solution is aimed at.
I've always wondered why the car doesn't warn the driver that there's 100 yards left before it will cut the engine (or limit it to idle), keep the power steering, turn on the hazards, and warn the driver that the vehicle won't continue to function because the key is not in range. Doesn't seem dangerous at all...
I think at most you could do something like have the car go into 'limp home' mode if it senses the key was never present in the car for some amount of time after the car is started.
I've had cars with chips, with contacts, in the mechanical keys [1].
Seems like one solution is to go back to the good old days of physical intent.
[1] One implementation: https://www.uhs-hardware.com/cdn/shop/products/df4ddf21436c4...
The persistent rumor, of course, is that this has been cracked for specific models from specific manufacturers, with the help of someone at the dealership, maybe someone who owes large amounts of drug or gambling money to local criminal syndicate types. "All" you'd need to do then is use a valid challenge response pairs off as a cryptographic oracle to brute force the challenge-response algorithm and recover the seed value computation algorithm for the key and the car. Then "all" you need to do is record a challenge-response pair from the real key talking to the vehicle, and maybe the VIN, in order to duplicate the key, in order to steal the vehicle.
If this has been been done, the algorithm and seed-value recovery technique have not been publicly shared over the Internet, so it's only a rumor that it's been done, but given how high-tech thieves are these days, I don't consider it outside the realm of possibility.
What isn't outside the realm of possibility is the Rolling-PWN attack, which can be done with a $32 device and has been demonstrated against 10 years of Honda vehicles, up to 2022.
The full fix is time of flight measurement but as I understand it that's still beyond cheap electronics.
Or just.. you know press a button when you want to unlock your car.
For reference 20 meters is about 66 nano-seconds.
Consider how annoying the modern cigarette lighter is for a non-smoker.
Now I'm wondering how hard it would be for the thieves to shake the ground outside the house enough to fool the motion sensor...
I don't get why it's not a keypad and relay though. Sounds like a complex solution to a fairly simple problem. I might be missing something though.
Edit - ah it's intended to work with many other options like controlling indicators or wipers or something - so you choose some pattern that is your password.
I think you're asking exactly the right question though - how is all this not just a more complex, less secure, shittier version of a keypad that you enter a 4-6 digit code on?
This coupled with a CANBUS integration with the ECU to prevent it from starting would be pretty good though, since no one can wirelessly collect the signals to spoof the code.
Not if your brand is one of the ones known to be easy to steal. I doubt I’d buy a Hyundai in the future given my understanding of their reputation as easy targets.
Maybe it's different for very high-end vehicle thieves, though.
It seems relay theft could be 100% prevented by measuring the response time, and capping it to whatever is the equivalent of say 100 meters + processing time in key fob.
> With a new $1.2 million dollar grant from the National Science Foundation...
What I find hilarious about our industry is that this could be completely made up ... or not.
https://www.restaurantdive.com/news/Stellar-pizza-robot-truc...
>Stellar, which was founded by former SpaceX employees in 2019, uses a robot to cook mobile ordered pizzas which are then delivered by the truck driver.
https://www.crunchbase.com/organization/steller-pizza
edit: looks I'm looking at the wrong company, see replies for details
https://www.axios.com/2023/06/12/softbank-pizza-robot-shuts-...
Discussed last month: https://news.ycombinator.com/item?id=36293636
The last 15 yrs in Biotech (esp genetics) and ML were more exciting than the previous 50.
The technology was immature but the fundamentals were there, and they'd save a not-insignificant amount of gas.
I wonder the efficiencies of cooking in a vehicle as opposed to a fixed pizza oven.
Back-of-the-napkin says no.
Automated driving is orthogonal to the bake-as-you-drive model. Dominos will also switch to self-driving when they can.
The cost of owning 10 oven-vans vs 1 store + 10 regular cars will be the tough part and will require scale, but pizza is big business.
But of course, you could offer the same latency by having a non-customizable menu and having pizzas ready to go when they're ordered. If it's 6:30PM on a Friday night, odds are someone wants the Pepperoni pizza that just came out of the oven. No fancy hardware required. The pizza is technically less fresh, but are minutes of freshness worth millions in VC? I don't know.
Taxpayers cannot pull their money out of the NSF and reallocate it to a different government agency.
So I’m ok if we spend $1.2M on research. That’s like 5 developers for one year who would otherwise be allocated by the invisible hand into effectively useless endeavors like high frequency trading or ad tech.
Cut to the alternative universe where they’re working at Blackrock and a car thief is driving their car away.
I'm not. Where do I opt out of funding government grants?
At least I can decide not invest in something if I don't want to risk losing money.
(remember that government spending basically created transistorized logic, microchips, and computer networking as we know them today. would you have opted out of those too?)
If you're on HN in the first place, there is an approximately zero percent chance that the few dollars of your tax money spent on this kind of research hold a candle to the benefits you've gained from it.
Modern cars also have new vulnerabilities: https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
There are aftermarket immobilizers systems as well, that also use cryptographically bound keys.
> Modern cars also have new vulnerabilities: https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
If car manufacturers can fuck up implementing today's immobilizer systems, what makes you think they won't fuck up implementing the rube goldberg contraption? Why do we have to switch to it just to get a non-broken cryptographic implementation?
It's possible that some other manufacturer may try it again in the future, but the hit to Hyundai/Kia's reputation has been substantial.
The switches themselves aren't bypassed. Their design for the lock cylinder is so crappy that it can be snapped off, exposing the peg that actuates the switch.
Modern cars have engines that are cryptographically ties to keys
But the Pentagon couldn’t put biometric locks on their humvees?
https://www.ibtimes.co.in/isis-takes-dozens-captured-us-humv...
They can’t account for trillions of dollars… but we vote them more money they didn’t even ask for
https://www.nytimes.com/2019/03/11/us/politics/trump-budget....
”Mr. Trump’s budget, the largest in federal history, includes a nearly 5 percent increase in military spending — which is more than the Pentagon had asked for“
We need oversight but politicians are not very interested in doing oversight because corporations use their money as free speech helping their favorite politicians get re-elected, because of the Supreme Court decision that allows that to happen.
So we need a more informed population to stop corruption from happening, but some politicians don't like the idea that people should be able to read whatever books they want.
There is almost zero reason to include robust locks or immobilizers on military vehicles. They're either occupied by soldiers with guns. Or in a locked facility, guarded by soldiers with guns. Or abandoned on the battlefield (in which case, they should be scuttled, but shit happens and sometimes you need to GTFO ASAP).
You might be familiar with locks on vehicles due to your own experiences, but deterrence to unoccupied theft is a requirement that is somewhat unique to civilian passenger vehicles. It is completely normal for many other types of vehicles to have very minimal or zero theft mitigations due to operating in different conditions with different requirements. For example, multi-million dollar jets have no anti-theft systems at all.
It's a fine solution to the very pressing "VCs aren't giving me money" problem. You can't have a blockchain or AI startup, say, without throwing technology at random things!
All you have to do is have every soldier who is authorized to use your equipment unlock the vehicle through an affirmative phrase — and the vehicle can check their voice for instance, or other biometrics like their fingerprint. Or each of them can wear a beacon or smartphone which does that.
Cars today open with you just getting into the car. This is easy stuff man
Yes, it would be possible to do what you are saying. However, militaries find this undesirable because they find the drawbacks outweigh the benefits.
There is no realistic scenario in which a military has lost physical control of the vehicle, and the situation is mitigated by locks on the vehicle. It is always already too late at that point.
You do realize that in a war zone, that list of authorized users can change rapidly (as people are injured, die, or rotated out of combat)?
Let’s assume for the sake of argument that electronics are perfect, and never fail for any reason (including but not limited to battery drain, battery overcharging, battery age, heat, cold, sudden change between heat and cold, vibration, shock, moisture, dryness, flooding, corrosion, UV degradation, rodent infiltration, wind, wind containing abrasives such as sand and dirt, chemical exposure, fire smoke exposure, fire heat exposure, sabotage due to local exploits, sabotage due to remote exploits, etc.).
Ignoring all those possibilities, you are only left with the problem of key management. You can find an overview of those challenges at https://en.m.wikipedia.org/wiki/Key_management
Managing secrets at a scale beyond people you know personally is extremely difficult to do correctly.
Not a big deal when physical security is provided at the broader level. For example, for any failed access attempt just fall back to TOFU.
(Sorry, I'm just 85% sure the top-level ancestor is trolling and I wanted to help by taking it one level deeper. :)
You don't know who is going to need to be able to drive something at the drop of a hat. And the more fiddly and complicated something gets, the more likely it is to fail because of either technological or UX/human reasons in stressful situations. This would cost lives.
Slow down there with the sarcasm and think about the actual requirements or use-cases first. Your average operable military vehicle is in one of three situations:
1. Actively occupied or guarded from theft by current owners/operators with guns who will not tolerate strangers getting close.
2. Parked somewhere in the middle of a whole bunch of people who are generally guarding the whole area, and those people may need to be able to operate it very quickly.
3. In some long-term storage which is well-fenced, under surveillance, guarded by people with guns, and typically very far from both overt enemies and opportunistic thieves.
So there's already an access control system tuned to a particular set of needs... and one of those needs includes "using it to escape from something dangerous even if the prior-driver and everything in their pockets got vaporized."
https://www.newsweek.com/how-russian-tanks-captured-ukraine-...
Also for other things too:
https://nypost.com/2023/05/11/ukrainians-strike-russians-wit...
Every TV show has a self destruct mechanism to prevent a ship from falling into enemy hands and blabla etc
Scuttling has been a common military practice, for literally millennia. This practice is unrelated to the presence of any locks on the vehicle. Militaries are equipped with explosives and weapons and can perform these actions without them being built into the vehicle. The reason this did not happen is not due to the construction of their vehicles, it is because they did not take action to do so. https://en.wikipedia.org/wiki/Scuttling
The automated self-destruct countdowns you have seen in movies and TV shows are used for dramatic effect. In reality, it is cheaper, more reliable, and safer to scuttle a manned vehicle manually.
Just a question, have you ever worked with soldiers before?
If anything, it suggests other things like:
1. Russia shouldn't have tried a desperate blitzkreig through muddy terrain.
2. The Russian military should have had better policies/equipment to destroy or scuttle the ofabandoned tanks.
3. Russian tank-drivers should have had better training so that they didn't get their vehicles stuck in embarrassing ways.
Plus it's not like the opposing force will be a bunch of joyriding delinquents: Even if you completely remove your abandoned truck's steering-wheel and pedals, your way out, they've got mechanics and tools and factories, they can just fit their own. Truly denying them any valuable salvage is actually a lot of work/damage.
You don't want either of those things in a widely used military vehicle. Soldiers do not need to die because they're fumbling and dropping keys under fire. They also don't need their truck dying in the middle of a maneuver because the kill switch accidentally went off.
Also, in war, trucks will be getting destroyed left and right. It'll literally be a rounding error.
And on the other hand, if you are ambushed, you don't want you and your unit to die because the soldier who had the keys just got fragged by the enemy and now you can't escape.
Also those were Humvees taken from Iraqi personnel.
This one is nothing more than a relay on the battery line. Simply find the relay and bridge it. Problem solved. Might take you a few hours to dig under the dash to find the damn thing, but once you do 'problem fucking solved'.
The tanks that were stolen belonged to the Iraqi armed forces, not the US Army.