Keyless cars 'increasingly targeted by thieves using computers'
bbc.co.uk
bbc.co.uk
That's "solution" is moronic and lazy.
Instead of changing the car's security systems so they're actually secure, you want to make the security obscure by making key-recoders illegal to even own?
Makes me wonder if this is even really about the thefts or the car manufacturers using the thefts as an excuse to push their competitors out of the market using this new proposed law. If authorised dealerships are the only people who can legally re-code cars/keys then they've just assured themselves a huge business boost.
Plus this law will be ineffective. There is already a law against owning tools designed to break into vehicles ("tools of the trade" laws). But they're largely ineffective at stopping vehicle crime.
Instead they should make the technology entirely transparent and hire some damn cryptographers to design their systems. Double public-key cryptography (e.g. one private key in the car and key-fob respectively) make doing this securely absolutely possible.
Set up an industry group who stores the car's private keys and allows any authorised shop to request them and update them. Store an audit log. If a car gets stolen pull the log and see who requested the private key, then send the bobbies around to sort 'em out.
One of the neat ideas that, imho, doesn't receive nearly enough attention in the bitcoin space is smart property -- you can use the blockchain and cryptography to have decentralized property transfer, even offline and in a hostile network environment (ie a thief trying to spoof a property transfer message to the car.
https://en.bitcoin.it/wiki/Smart_Property#Theory lists the gorey crypto-details, but imagine instead of transferring ownership, you just temporarily grant another party (ie your mechanic) to have 'ownership-like' rights to your car while it's in the shop.
> Set up an industry group who stores the car's private keys and allows any authorised shop to request them...
Centralized points of failure always fail. How long before the next Target or Home Depot has a credit card breach? How long before this centralized authority blocks non-dealer shops from being part of the network (or pay exorbitant fees).
We can decentralize all this while still keeping it cryptographically secure.
Why do we focus on keys at all; why can't we just use thumbprints, or heck retina scans to unlock the cars? That technology exists today, we can keep everything local, a crappy thumbprint scanner is $4 on ebay right now.
Combine that with the in-dash electronics we have, and it would be simple to handle 'access management' or authorized thumbprints... much like my rubbish car can handle bluetooth devices.
The problem is that at $429 (CAD) per lost key, my car dealer couldn't care less about this. It's literally not in their interest to give up this revenue stream. Until they have an economic incentive to do it, it won't happen.
As with most ideological debates, the middle ground is probably the most amicable. Bigger crypto-nerds than me will have more fleshed out ideas, I'm sure, but there are ways to have a hybrid centralized/decentralized approach. One algorithm I've heard tossed around, for example, is shamir's secret sharing. Basically you can split a key between different parties... no one party/dealer/mechanic/DMV has access to the family jewels, but you can reconstruct the secret with 3 of the 5 pieces or whatever threshold. http://en.wikipedia.org/wiki/Shamir's_Secret_Sharing
The challenge is, like you say, to make all this magic enough that it becomes consumer friendly. Much more fulfilling a UX gig than designing virtual farms, though.
Perhaps it needs to be an independent third party that tests, breaks, and publicly reviews keyless entry systems. Such a third party could provide "certification" or badges for Cryptographically Secure Keyless Entry systems.
When purchasing a vehicle I'd be willing to pay a small premium for a vehicle with secure locks.
First off there are two generations of keyless entry systems. The older rolling code system, KeeLoq, was developed by a South African company and bought by Microchip in the '90's- a near full break was widely published in 2004/2005 and tools released a few years later[1]. The newer system is called HiTag2/3/Pro. Vulnerabilities also exist in HiTag2.
Additionally there is a vehicle immobility device known as Megamos (which Land Rover is known to use) - a break was published last year but an injunction by the UK High Court prevented release of much of the technical details at the time.[2] If criminals are breaking Megamos than this is news. To paraphrase HN user brians: "given sure confidence that there is a vulnerability, skilled security [criminals] can find it very quickly. " [3]
Most talks and articles that come out focus on Keeloq. It's trivial to capture a packet from the remote when not near the vehicle and replay that packet when near the vehicle to gain access. [4]
Once one has access to the vehicle there is a separate attack on the OBD-II port to start the vehicle. This was a a widely published attack on BMW's involving this.[5]
Also, the equipment required to clone a modern electronic car key is widely available. I personally saw a number for sale in the security malls around Shenzhen. Banning ownership of key-recoders probably won't work as most of this can be done with an SDR. The price for an SDR is about the same as a 3D printer (thousands last year, hundreds this year.) SDR's are already cheaper than most dedicated programmers.[6]
Even though most of the protocols are vulnerable or broken it should be noted they are not ineffective. For instance there was an 88% decrease in theft between the pre-98 and post 98 Honda Civic models which began implementing (broken) anti-theft keys.[7]
[1] https://www.youtube.com/watch?v=l_crMuwBp8I
[2] https://www.usenix.org/conference/usenixsecurity13/dismantli...
[3] https://news.ycombinator.com/item?id=8456206
[4] http://www.wired.com/2014/08/wireless-car-hack/
[5] http://www.bmwland.co.uk/forums/viewtopic.php?f=1&t=135599&s...
[6] https://www.avtotools.com/index.php?productID=409
[7] http://www.latimes.com/business/autos/la-fi-hy-honda-accord-...
This never even occurred to me as a way of stealing a car. TV & hollywood car thieves always smash the window or jimmy the lock somehow.
I suppose the comparison with cryptographic keys is also accurate: It's usually far easier to steal someone's private key than it is to break the cryptography.
Of course you didn't have to jimmy the lock. A coat hangar worked just fine.
Cars used to be laughably easy to steal by today's standards.
(The funny thing is, my parking spot is numbered. But they never asked me about that.)
The key difference (no pun intended) is that previous the thieves had access to physical master keys but they still had to go from car to car to find a suitable match. But with keyless systems they can probably find a way to scan a whole parking lot in a few minutes. Makes it far easier. Also, it's easier to copy a digital file without being noticed as opposed to "misplacing" a physical key.
I suppose the issue is that someone could still get you to press the button out of range and copy that value over the air, and then use it on your car. But perhaps there is a scheme to avoid that too. Maybe use a real time clock and use a new key every second.
Really, there should be open source hardware that can do this. Can't these vehicles be unlocked with access to the CAN bus? You could disable the insecure proprietary RF receivers and install an open source system on the CAN bus. They're usually locked down on ignition though...
I'm not educated in this field. But, I believe there are schemes to allow two parties to demonstrate to each other over untrusted channels that they share a secret (here, the codes generated when you physically plug your fob into your car), without leaking the shared secret.
If memory serves, connecting to SSH without a password uses such a scheme.
Sure, you can decouple this to an extent. But, barring complete informational disconnection (read: airgap and no wireless communications) (and potentially not even then), this only reduces the attack surface, not removes it entirely.
What happens, for example, when your driver assist includes GPS data? Oh look... now you're downloading and decoding maps. Whoops! Attack vector.
What happens when your keyfob starts doing encrypted communication with the car (as other people in this thread are suggesting)? Whoops! Attack vector.
What happens when your entertainment console shows options to change the amount of time before the doors automatically lock? Whoops! Attack vector.
Cars are getting more complex - and it only takes one break in the defenses.
It was noted that the Xbox One will accept voice commands from a video the console itself is playing. What happens when someone makes a hyper-targeted Pandora ad that uses your car's voice control function to enter a new destination address? If you are paying attention you will likely notice this, but many people have suggested that at some point you can sleep in your car and wake up at your destination, so even that isn't guaranteed.
No doubt direct control of steering and brakes will be highly locked down, but as you point out that in no way eliminates the possibility for mischief.
Apparently the kinds of thieves who steal mass market cars are mostly younger guys who can't drive stick. Of course all bets are off if you have a classic Bugatti or something along those lines.
Ideally keyless entry would involve being able to buy a generic keyfob which works for any car it's paired with, and the authentication would work with an open protocol much like with WiFi. If people can setup WiFi encryption+authentication, they should be able to setup new keys for their car.
(Personally, I'm not a fan of keyless cars. There's something really satisfying and secure about the feeling of putting a physical key into a lock and unlocking it.)
Right, until the key falls out of the lock and your car turns off.
Or am I misunderstanding what you mean by "keyless"? Something has to authenticate the "keyless" part.
In addition to listed attacks there's even easier one and harder to protect against. You basically need two people, one one carries a device and is close to the car. The other wears an antenna and tries to get close to the car owner. They relay information over radio.
They basically use owner's key to open the car.
I'm wondering if this problem could somehow be solved on cryptographic level. But even then I would love if manufacturers would simply provide a switch on the key, which simply turns off the keyless feature.
I can see copying the key if you have the original fob, but then you have the original fob so why bother? Maybe people are doing the simple credit card swipe bit that nefarious retail people have been doing for a while now? I suppose we should stop handing over fobs to valet parking?
If it is as simple as the key being tied to the VIN then we can all just put electrical tape on our car's VIN. I have plenty to spare if someone wants some, I only used a small bit from a new roll to cover the front-facing camera on my laptop.
I thought many (but presumably not all) cars came with "valet keys", just for that reason. I am not sure how often they are used, though.
They usual "valet keys" I've seen are for keyed ignition cars where the valet key works the ignition but not the glovebox lock.
That sounds remarkably easy to brute-force.
I remember about 2 years ago there was a media frenzy (at least here in The Netherlands) about criminals having a special device that allowed them to detect whether a car contained a laptop or tablet in the trunk, even if the device was fully turned off! In the end it was found that the thieves simple observed the parking lot and looked for people stashing their laptop bag in their car.
Modern keyless access systems are actually pretty good and cars are much, much harder to "crack" then someones front door. Breaking into a house to get the car keys is usually much more easy to do.
Modern keyless access systems are actually pretty good
It sounds like you're well informed about these things - where can I read more about exactly how they secure these things?