Tesla Plans to Open Car Doors to All Hackers This Summer
forbes.com
forbes.com
Essentially it boosts the search range for vehicles from a few feet to something more like 100 meters, when searching for wireless key devices. Then the car will unlock as if the device were very close.
The devices are very inexpensive and starting to see increased use.
[1] http://www.networkworld.com/article/2909589/microsoft-subnet...
This is done for obvious safety reasons. Imagine for example if a car just suddenly turned off while you were going over a major highway bridge with no shoulders, etc.
I once watched a friend's girlfriend throw his cell phone out of the car while on the freeway. Had this been his car keys I would hope that the car would not immediately power off (especially since I was in the car).
http://physics.stackexchange.com/questions/101913/why-does-a...
https://www.youtube.com/watch?v=0Uqf71muwWc
EDIT: i_cannot_hack got the link in before me. Kudos ;)
That said, signals in twisted pairs propagate at about .6c whereas signals in air propagate at speeds very close to c, so this use case is a little more challenging.
The escalation just after that, of course, is GPS spoofing.
When I was a teenager, my family had a Fiat 500. Something had broken in the part of the ignition switch that you insert the key into, and so my Dad took it off until we could get it fixed, and we kept a screwdriver in the glove box to use to start the car.
There was virtually no car theft in our town (at least in the places we went), and people often left their car doors unlocked. Soon we got out of the habit of bringing our car keys with us. We weren't locking the doors, and we used the screwdriver to start the car, so why bother?
Well, I found out why we should have bothered a few weeks later when I was driving home. We lived a few miles outside of town, out in the sticks. I was a couple miles from home, taking a back road that had almost no traffic, and a tire blew out.
The spare was in the trunk.
The locked trunk.
Back in the later 80s my parents had a Toyota van. One day my mom accidentally started it with her house key. We then realized that pretty much anything that fit partway into the ignition started it. Many years later the key got lost and we kept a screw driver in the cup holder to start it. It was a little odd driving around without a key in the ignition.... always thought cops would get suspicious.
I accidentally stole a bike in college, because it was the same brand as mine, and had the same brand of lock. Got all the way back to my dorm before I realized that the reason the seat felt weird was that it wasn't mine. But my key worked!
I also used my apartment deadbolt key to let my girlfriend into her house when she accidentally got locked out. She was both horrified and grateful that it worked. (I expected that one to fail, but I figured why not try?)
I'm not sure what the trick is to finding locks that aren't vulnerable to this trick. I suspect it's "buy locks at least 50% more expensive than the cheapest option", but that's just a guess.
The one thing that I could see working in theory would be detecting the roundtrip transmission time with a strict ceiling on it. No matter how good your relay is, it can't relay data faster than the speed of light, so you can enforce the fob being close by only listening to it if it responds fast enough.
The problem with this is that light moves pretty fast, and internal delays within the fob will dominate. If you want to put the range limit at, say, 30ft, that means your response time ceiling is a mere 60ns. Can you build a fob that responds anywhere close to that fast?
Edit: one other possibility is if the fob knows where it is. A GPS receiver on the fob, for example, would allow the fob and the car to securely confirm proximity (absent GPS spoofing). Getting a GPS receiver to run on a wireless fob's battery is left as an exercise for the reader.
Why not just make the keys responsible for starting the car again?
We've traded too much security for convenience and it's time to take a step back.
You can still start the car with the push of a button.. only now that button is on the key.
Problem solved.
Yes, the problem becomes substantially easier if you require a direct physical connection, but that's not such an interesting problem.
Also, given that modern cars are vastly more difficult to steal, I object to your characterization of "traded too much security for convenience." If the current state is too insecure, then you must think that cars from 20+ years ago are absolutely appalling.
Although from what I was seeing in the rest of the thread it seemed that preventing relaying may be more difficult than expected (as most methods relied on timing the signal response). I don't expect it to be impossible though.
The trouble is that the wires must be fairly exposed to the occupants of the car, since the switch has to be accessible. That means you can just bypass the switch entirely by removing the appropriate covers and attacking the wires directly. This is "hotwiring."
Physical locks are also not all that difficult to defeat directly. You can pick an ignition switch much like you might pick any other lock.
Starting around the late 90s or so, car manufacturers started adding more robust security measures. These include things simple like locking the steering column when the ignition switch is off (thus preventing you from driving the car after hotwiring it), all the way up to authenticating the key with a relatively sophisticated protocol, and having the engine computer refuse to run the car unless it can sense a real key.
As a result of these changes, the list of most stolen car models is still topped by cars manufactured in the late 90s. Low-end Hondas from around 1998 are right at the top of the list, because they occupy a sweet spot of being relatively valuable and still fairly easy to steal. Modern cars are stolen literally orders of magnitude less frequently; about 100,000 older Hondas stolen per year in the US, whereas new cars are stolen at a rate of hundreds per model per year at worst. Also as a natural result of these changes, car theft is way down in the US. About 700,000 cars were stolen in the US in 2013, compared to almost 1.7 million in 1991. Pretty much the only way to steal a newer car is to either tow it away or steal the owner's keys. (A common scenario for car thefts is a burglary turned into auto theft when the burglars find car keys in the house.)
It's easy to get into many older cars. Slim jim past the window is the classic example (and I opened my 80s Toyota with a coathanger multiple times when I locked myself out), but many times the locks could be opened by keys to other cards from the same manufacturer as well, they just didn't seem to be that precise. And of course, smash the window as a last resort, that wouldn't set off an alarm in the past. Nowdays cars have recessed lock things in the door panels (or button-controlled-locks that can't be as easily manipulated with a coathanger, or even that don't work at all if the car was locked from outside) to help prevent this, and the interior of the doors has more protection built around the lock mechanism so you can't easily fish through there and hook onto the right lever.
Once inside an old car, starting it is usually just a matter of shorting the right pair of wires. Or using brute strength to turn the ignition cylinder even if they key isn't an exact match (or maybe with a screwdriver, as another poster mentioned doing in the past in this thread). Modern cars have chips in the keys so that it's not just a matter of closing a circuit, the key has to be coded to the car.
Or just tow the car somewhere and work on picking the lock later at your leisure. Overkill for a common car, but for something really nice it could be practical. Nowdays your more expensive cars have tilt and motion sensors that'll set off the alarm if you locked it, left it, and someone else comes up and tries to tow it. Possibly GPS tracking or similar as well, IIRC, on some fancy stuff.
The fob-in-pocket entry/pushbutton start stuff gives up some of those improvements given an exploit like this, but overall I'd say is still much more secure. You need specialized hardware (that's only useful for breaking into someone else's car) and it wouldn't work to, say, steal cars from an airport parking lot or somewhere else where they were left and the owner wasn't in range. Keeping your car in a garage at home seems to mitigate a lot of the easiest vectors for this attack.
Your opinion is an unpopular one, albeit one I share.
There are far too many cases where security is getting removed in the name of convenience, and this is no exception.
Further, a Tesla has a GPS, sophisticated processor, and a 4G WAN. It would be easy enough to have the car report back to the owner if it's being driven without sensing the key, and give the owner the option to route a theft report and live location of the vehicle to police with one click. That's something I wished for in my revenge fantasies when my car was stolen a decade ago.
We could do more, sure -- but it's hard to argue that we are making cars less secure, or even that car security should be a major care-about for the buyer.
The Tesla app does show the car location on a map; they don't have a "report to police" option, but they aren't that far away from it.
BTW the Tesla modem is 3G.
https://news.ycombinator.com/item?id=9383462
https://en.wikipedia.org/wiki/Distance-bounding_protocol
(I don't pretend to have a clue whether it can be effective or not)
1. Use a modified form of triangulation. Have multiple transceivers in the car (At the front and back) and make the remote directional aware. Then have the remote and transceivers ask each other if the angles they are seeing are the same. The only way for the thieve to bypass this would be two remote amps set at almost 180 from each other.
2. stick an ultrasonic speaker in the key fob and have the car send it a random sequence to play back. For those worried about battery life use a wireless charging system.
Both of these assume that the transmission is encrypted and the thieves are just boosting the signal.
the attacker has two devices communicating by radio. Device A is near the keyfob, and device B is near the car. Each is a repeater for the other: Whatever the car sends is picked up by device B and repeated by device A. Then the keyfob's response is picked up by device A and repeated by device B.
This type of setup will defeat both of your proposals. Triangulation won't detect anything out of the ordinary, because device B can be right next to the car. And the ultrasonic challenge/response can be defeated just like a radio challenge/response, using microphones and speakers on the repeaters.
I don't see how ultrasound helps matters at all. You just change the nature of what the attacker has to relay.
Rather than put an ultrasonic speaker in the fob, I'd put a microphone. The car would send an ultrasonic signal, and the fob would send a radio response indicating it heard it. The car could then calculate how far away the fob is.
The speed of sound in air is about 1ms/foot, so if you're trying to measure proximity within 30ft, you're looking for a 60ms roundtrip delay, or 30ms for one-way. If the attacker has ultrasonic microphones and speakers connected with radio waves, that means he can spoof your fob from up to 9,000km away for roundtrip ultrasound, and 4,500km away for one-way, under ideal conditions.
The speed of light imposes difficult constraints in terms of how fast you have to respond, but at least the attacker can't outrun it (as far as anyone knows).
If the car then did an ultrasonic distance check by emitting a coded ultrasonic signal that the fob had to receive, and then relay the code back to open the door, I don't see how the attacker would spoof that. Even if he has an ultrasonic microphone near the car, and an ultrasonic transmitter somewhere else, with a radio link to tell the transmitter what the send...how does he place the transmitter so that your fob will hear it?
If the attack is targeted against a specific individual, where the attacker knows both where the car is parked and where the individual is when away from the car, and the attacker can place equipment at both locations, then yes, I see that the attacker can get around ultrasonic distance measurement.
But for the most common case, where the attacker is at the car and has no idea where the owner is, it seems workable to me.
So, in theory, if you wanted to steal a REALLY expensive keyless car you could have two devices connected over a mobile data connection that just relays communication with the keyfob. You put one device near the owner of the fob, so in his office, and you keep the other. Then you can just walk off with the car.
Yikes.
Although sometimes you can even skip the second device and just have the one near the keyfob.
The timer idea is a good one, although a ns-accurate timer is starting to get a bit much for something to put into a key fob. Especially give it's run off of a watch battery (power requirements) and often exposed to heat / cold (thermal drift).
Dylan's comment requires a timer in both the key fob and in the car. The key fob to delay transmission of the challenge response, the car to check if there isn't too much delay in the challenge / response pair.
You really need a timer in the key fob, as the processor in the key fob is often so slow (for battery / cost reasons) that an extra couple clock cycles somewhere would throw off the timing enough to make it fail.
Cool trick in that one, the Prover(i.e. the key fob) does the distance measuring part of the challenge response protocol using analog only components. This means its response time is <1 nano second.
So you can do it with only the car having a good timer.
https://en.wikipedia.org/wiki/Quantum_key_distribution
Edit: Nope, I am wrong, as the comments below point out.
1. You place device A near car and device B near fob. 2. Device A relays all Rf transmissions in the target frequency range(s) to device B, which rebroadcasts, and vice versa.
Public-key encryption / authentication only ensures that no-one in the middle is reading or editing your connection. It does not prevent someone from relaying your communication. (And a good thing too, else the entire encrypted web wouldn't work.)
When the driver presses lock/unlock on the fob, the car first sends a signed message with a session secret. The fob checks the signature, takes the secret and creates a _single use_ auth token and signs it with the private key stored on the fob. That signed auth token is then sent from the fob to the car to lock/unlock the car.
To check if there was a MITM you would have to pull the door handle to see if your keypress was successful. If it was successful, you don't need to worry if the key was grabbed by a MITM, they can't use it even if they tried. If it was unsuccessful for some reason (e.g. the MITM knew it was single use auth token so they didn't pass the token onto the car in hopes you might not be paying attention and will press the button a second time) then there should be a manual override outside and inside the car that clears the valid auth tokens and allows you to lock/unlock/start the vehicle without sending any RF transmissions. A slot that you insert the key would work.
The entire discussion here is based around not requiring interaction with the key fob.
In that case device B picks up on the unlock command and relays is back to device A which rebroadcasts the unlock command to the car.
No matter what tricky message protocol you come up with, it won't matter. The car and the fob can't detect the difference between being next to each other, and being next to a set of relays rebroadcasting their signals. Not by reading and transmitting radio signals at least.
Edit: just thought of another possibility -- use spread spectrum. An amplifier would have to be tuned to a specific frequency. With spread spectrum, the car and key fob switches frequencies every second based on a cryptographic function, therefore defeating the amplifier.
Look at SDRs. You can "tune" an SDR to tunnel an entire large chunk of spectrum.
If the attack tries to amplify a given range, the honey pot signals will also be amplified, and the car can refuse to be opened.
- If the car was inductively powering the key, that might be harder/more dangerous to amplify.
- The car or house could send a false key signal, which would also be amplified, and refuse to open when receiving it. (New attack: lock rich people out of their car with 17$ of equipment!)
- If your house/public-buildings/phone+gps could track the key, they could tell the car to disable the system.
- Sending the signal with audio or visible light? Something that doesn't pass through walls.
- Use a pedometer to deactive the key when it's at rest.
- Use a really long key (like... 2 metres long) with transmitters at each end, use crypto and frequency hopping, and use multiple receivers on the car to triangulate both ends. If both transmissions are coming from the same spot, it's an amplifier.
Inductive power isn't going to really help, I don't think.
A false key signal, like you mention, won't help. Also, it'd be relatively easy to stop via a directional antenna.
Audio does pass through walls. Visible light would be less convenient than a standard key, I'd think.
Disabling the key while at rest would be really annoying for those who tuck it in their purses.
A really long key... I hope you're joking.
Jamming is better than unlocking. Especially if you can fallback to the normal key.
> A really long key... I hope you're joking.
Obviously you'd have to do something clever with it. Turn it into a walking stick, sew it into clothing, have an anlket+earing combo, or etc.
But, like I said, all the ideas were half-baked.
The fob has no knowledge of it's own location, so the car must figure it out on it's own, allowing the attack to occur. If you gave the key fob some way of calculating it's position relative to the car, you may be able to transmit that to the car over the existing communication channel and have the car verify it.
The question then becomes: how can one give the tiny computer in a key fob independent access to it's location relative to a car? An inertial navigation system[1] would probably be cheapest and most power-efficient. Though they suffer from inertial drift, that could be mitigated by periodic re-calibration while the car is driving and then parks (and the occasional non-keyless entry). The key fob then only transmits a signal when it detects that it's close enough, and the problem is "solved".
Now you just need to replace the batteries on your keys every few weeks...
[1]:https://en.wikipedia.org/wiki/Inertial_navigation_system
(Trivial modification: you have two transceivers. Each transceiver encodes and encrypts everything in the frequency range, and sends it to the other one, which decrypts it and rebroadcasts it.)
Think of the original attack as being the equivalent of placing a megaphone up against the guy whispering, and this attack as being the equivalent of placing a cell phone up against the guy whispering and another cell phone that's connected to the first one up against the guy waiting to hear something.
Not to mention that triangulation has... problems. You really don't want your car to not open because there was a stray reflection off of something nearby.
Relay on a parking lot
One antenna near the elevator
Attacker at the car while car owner waits for the elevator
Also, the radio jamming attack described on page 10 is so simple but isn't something I've considered before. Basically you just jam the right frequency before the victim presses the 'lock' button and you now have access to their car (if they didn't notice).
Great link, thank you.
There are far too many attacks that get ignored because they don't match the company's threat model, in general, and this is no exception.
Normal keys work great. I don't see the big advantage of techno-keys that outweighs the (almost inevitable) cost of paying so much for a spare.
The other thing -- do the key fobs have an on/off switch? If not, you wouldn't be able to have a spare "hidden" under your car somewhere (yes this is insecure anyway, but it works for most people).
Pop out the battery. You don't need the battery to use the hidden spare if you lose your key: there's a physical key hidden inside the fob to unlock the door, then a slot on the dash to stick the whole fob into to start the car. It's there so you can't be stuck unable to start your car when the fob's battery dies.
Also, the dashboard will always tell you if you are inside the car but key is not detected. So even if it miscalculates where the fob is and let you start the engine, that key-not-present light will be on as you drive off.
I think the trade off makes it not worthwhile. If it's optional, I prefer a normal key.
OTOH, There are lots of other cool gadgets that I'd like to see. A car that remembers everyone's seat position and mirrors, that's progress. Manual transmission, normal key, smart seat. That's my niche.
The simple solution: Just go back to pressing a button to unlock and putting the key in the ignition.
If the manufacturer really wants to keep the feature, then they could switch to those keys that flip out like Fiat has and just turn off the near-unlock functionality on the remote when the key is folded in.
This may not be a problem in California, but it is in some parts of the world. Imagine the shadiest neighborhoods you know. Now, imagine that all of the neighborhoods are like that.
Being able to quickly get in and start the engine is convenient, but also important. The last thing you want to do is to fumble with keys. Or drop them while doing it. It is a plot device in some movies, but also real life.
The problem is that many keyless entry systems - and most wireless 'pushbutton' alarm keys haven't actually picked up gadgety improvements. Instead of a digital system and crypto keys, you have extremely rudimentary, frequency-based systems that are trivial to hack.
I would not have predicted this response for such a trivial thing - what's a few seconds more on top of a 20 minute or 2 hour drive? But it made a big difference to me, and I'm guessing many other people enjoy it as well. The downside of paying for a spare isn't very visible, and when it is, it's just a short acute pain, and is washed away in the daily nicety of "keyless" entry.
How seriously are car manufacturers going to take security though? Is it going to be like the numerous router manufacturers that don't seem bothered? Perhaps some kind of regulatory body will need to intervene to make automotive manufacturers take security seriously.
If you miss your package, it'll get taken to a nearby store where you can collect it with an ID or it'll be given to your neighbour.
Per EETimes [1]: MISRA C is a subset of the C language. In particular, it is based on the ISO/IEC 9899:1990 C standard, which is identical to the ANSI X3.159-1989 standard, often called C ’89. Thus every MISRA C program is a valid C program. The MISRA C subset is defined by 141 rules that constrain the C language. Correspondingly, MISRA C++ is a subset of the ISO/IEC 14882:2003 C++ standard. MISRA C++ is based on 228 rules, many of which are refinements of the MISRA C rules to deal with the additional realities of C++.
I did a quick search for Tesla programming jobs and they do command a familiarity with MISRA C, so somewhere it is being used by Tesla in their firmware. That standard is supposed to ensure security and reliability in firmware programming for critical devices, such as motor vehicles. I wonder if this knowledge expands upon this challenge and other avenues for hacking Tesla, and also I wonder if MISRA C practices extend to outlying modules in the vehicle...
[0] MISRA C: http://www.misra-c.com/ [1] http://www.eetimes.com/document.asp?doc_id=1279810
But on a more serious note this is pretty cool to see not only Tesla but GM and BMW reaching out to these groups. We saw an article or two here on HN not to long about about, IIRC, car makers trying to use DMCA to prevent people from modifying the software in their cars [1] (I know there was another article about tractors as well [2]). I'd be interested to know Tesla/GM/BMW's stance on that issue. They are opening up to hackers to find issues but that doesn't mean they are on board with making it easy for people to modify software in their cars.
[0] http://www.homelandsecureit.com/wp-content/uploads/2012/10/C...
[1] https://www.eff.org/deeplinks/2015/04/automakers-say-you-don...
What if there is an intractable design flaw that is costly to fix? Will it get swept under the rug as they get litigious with those who attempt to expose it?
The assumption usually is if the bounty is less than the expected reward from exploiting a system, then you're really not doing anything other than a PR stunt.
I don't see a mention of a bounty. I do see a mention of them keeping track of those trying to exploit their system at Defcon. Not sure of what the supposed benefit to those that attempt to break their system is.
It makes a nice headline though.
People find a way in either way, whether you want them to or not.