BMW fixes lock security flaw
bbc.com
bbc.com
On the one hand, I trust old fashioned locks more. On the other hand, breaking into a car is easy anyhow (just smash a window). At least, there's no physical damage done to the car in this way (which often exceeds the costs of the lost goods). So perhaps it's not so bad. Just never leave valuables in your car.
Even if I had a printer I'd need some fancy scanning equipment to figure out how to make the key.
With that in mind, seems like it should be possible for someone to scan a key, save the pattern, and be able to use it later on to cut new keys on-demand. Does a service like this exist?
Maybe the downmarket carmakers have gotten smarter, but for a long time BMW stood out as the one that did not permit simple duplication of the data in the RFID transponders (each transponder has its data changed every time it is used.)
As far as mechanical key bittings go, any locksmith should be able to clone a key with a photograph of it.
We have 2FA devices like the Yubikey (https://www.yubico.com/prodcts/yubikey-hardware/)
that are so incredibly small. Why is this not something you'd implement via RFID challenge/response to stop any attack?
As far as I know all the technology able to fit in a 7816 card has been put into contactless cards too.
I think that carmakers are lazy, they go to a vendor who designs a system with off the shelf parts and implements it poorly, and we end up with our $30,000 car secured by a PCF7930 or something weaker and if it has security features they are not fully utilized.
I think they also have to design these things within the constraints of being able to service them in the field and not upsetting the customer. Vendor doesn't want to be responsible for a bunch of cars not working if reliability is low, and carmakers wouldn't want the bad press. On the other hand, when criminal activity is involved, it's real easy to blame the criminal.
Although it doesn't really matter if you are talking about common household locks - they are trivial to open with a bump key or lockpick anyway.
Each key manufacturer has a fixed set of depths to cut each position on the key at, which you can represent as a single digit. Combined for the whole key and you can talk about the data encoded into the piece of metal as a string of digits.
Telling you my apartment key is a kwikset KW1 with bitting 64265 is enough to cut a new key.
Keys have been reproduced from a single photo before. It seems to always involve someone who has experience making keys using the photo to reproduce the key, but in theory software could be able to automate this for the easier cases.
The device the software runs on most likely sits on the CAN bus with everything else and could be used to feed false data in that could at least confuse other systems on the car. Similar attacks have been done before in experiments. Local (USB drive) system updates look to be cryptographically signed, but who knows about the OTA ones, and even then the key might be extractable.
http://www.theguardian.com/money/2014/oct/27/thieves-range-r...
[1] https://nakedsecurity.sophos.com/2012/09/18/bmw-stolen-hacki...
However, in the cars with real ignition locks, the immobilizer is not as easy to defeat as the "nakedsecurity" piece implies.
Since 1994 or so (with the introduction of the EWS2 system) the ignition key contains an RFID tag with a permanent shared secret and a password which is updated every time the key is used. It has always been possible to get close to such a key and read it, then write the information into a new key. Since the password is updated when the key is turned to the 'run' position, as soon as either of the "identical" keys are used, the other will stop working.
To authorize a new key on the EWS2 or EWS3 systems using the diagnosis connector, the new key must contain a shared secret already known by the EWS brain. The factory programmed ten such secrets into each EWS brain during manufacture, and four keys were delivered with the new car when it was sold. When a new key is requested through the parts department, that key is delivered with one of the known shared secrets. Then it can be authorized with a diagnosis request.
To change the shared secret information in the EWS brain to arbitrary information, or to discover the shared secrets known by the EWS brain, it must be removed from the car, physically opened and bootloaded. (It's one of the 68hc11 processors, and there are test points on the board for the mode select pins, manipulating these can place the hc11 in a mode to run a bootloader delivered over the serial line.)
(One difference between the EWS2 and EWS3 systems is that the EWS2 brain sent another, static shared secret to the engine control to signal permission to start - a simple 32 bit word. In EWS3, this communication involves some cryptography.)
It is possible that the database of shared secrets became available when the "Heartbleed" flaw became known. I have heard that their VPN was attacked. If this material were stolen, probably the bitting information required to cut a mechanical key were stolen along with it.
The keyless entry remote of these BMWs is more like the ones used in every car, even though it is part of the same ignition key with RFID tag for immobilizer: the key has a seed and does some transformation every time a remote button is pressed.
I am still convinced to this day that it was my cat that pushed the button.