11 ms·
The attack vectors available for use against a corporation is infinitely larger than those available for a car. It's not really a fair comparison.
by CaveTech 11y ago
The attack vectors available for use against a corporation is infinitely larger than those available for a car. It's not really a fair comparison.
- binarymax 11y agoNot only that - but the 'duh' moment for me was the 96bit key size.
- mkj 11y ago96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.
- jacobolus 11y agoWhat I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.
- lisper 11y agoThat could be exploited to produce a trivial denial-of-service attack.
- jacobolus 11y agoWouldn’t you need to have a device actively running within a few feet of the vehicle to run such an attack? Couldn’t the car start blaring an alarm or something in that case? We’re not talking about a website here.
- lisper 11y ago> Wouldn’t you need to have a device actively running within a few feet of the vehicle to run such an attack? Nope. Just a high-gain antenna. > Couldn’t the car start blaring an alarm or something in that case? It could. But that might not help. For example: you're driving your Mazerati down the road when it suddenly stops and the alarm goes off. The next day you get a letter saying, "If you don't want yesterday's little incident to become a regular event, send BTC500 to the following address...."
- jessaustin 11y agoIf the car responds to RFID keys at all when driving, that is a flaw.
- lisper 11y agoIf I get out of my car with the engine still running it starts beeping. I don't know if it will actually turn the engine off, but it obviously knows that the key has departed the vehicle.
- tarpherder 11y agoOr it detected your bum leaving its seat.
- lisper 11y agoNo, because if I toss the key into the seat it stops beeping even if I'm not there.
- bonzini 11y agoMy car also beeps when it detects that the key has left the car. The engine keeps running, but you obviously cannot turn it on again once you turn it off. I had it happen without me leaving the seat (e.g. my wife has the keys in her bag/pocket, I had been driving, and she gets off the car to unarm the home alarm). The car is turned on by pressing a button, not by turning the key.
- stcredzero 11y agoWhich would be of no use at all to car thieves.
- lisper 11y agoTrue, but it might be handy for kidnappers.
- jessaustin 11y agoWe're veering into movie-plot territory here.
- maxwelljoslyn 11y ago(not original responder) That's true. On the subject of movies, though, a plot point based on an actual vulnerability would be way better than typical Hollywood hacking.
- fnordfnordfnord 11y agoCarjackers, and parking lot muggers.
- knowaveragejoe 11y ago...and that achieves?
- mturmon 11y agoI can think of other, lower tech, DoS attacks against cars -- which are also not much exploited.
- beat 11y agoSomeone once DoS'd my car, by slashing two tires. On a downtown public street.
- tbomb 11y agoThat sucks to have happened to you, but that sentence made me lol.
- imh 11y agoPeople always say this about physical tech, but the difference is ease and scalability. Slashing all the car tires in a block is harder and more traceable than sending out a small RF signal.
- lwf 11y agoRemediating slashed tires is a lot more difficult than waiting for your attacker to get bored and move on.
- robmcm 11y agoI assume the software/hardware is so simple and specific that adding something like back off blocking would require memory chips, software, timers etc increasing the complexity dramatically.
- briannickel 11y agoWhat if the car was parked in a handicapped spot near entrance of a football stadium? It could conceivably receive enough incorrect RFID signals to trigger a back-off.
- danielweber 11y agoSince this is an anti-theft system, not a safety system, I can totally see that VW made a rational decision "it's better for the anti-theft system to let a thief steal the car 50 times than for one person to legitimately get locked out of their car." You can make up for car thefts with dollars.
- jessaustin 11y agoI don't know anything about the protocols involved, but it would be possible for the first message to be "I'm a key that would like to unlock the vehicle with VIN# 123abc...". In that case there would be no mistaken protocol runs.
- CWuestefeld 11y agoThere is no key as such. The fob for my Hyundai never leaves my pocket. Just by standing next to the car, the unlock button on the door is enabled. So if I walk up and push the button, it unlocks. If I'm not around, the button does nothing. So there's no discernible event from the fob, as far as I can see. It's just a "this is me" signal.
- jessaustin 11y agoI guess the Hyundais I've driven were different, in that the unlock button was on the fob rather than on the car door. Could you say, if you have multiple cars, does the fob work with all of them? I doubt that's the case, so I don't see why your "this is me" signal couldn't actually be a "this is me, fob 123ABC..., and I can authenticate with the vehicle with VIN# 123abc...".
- CWuestefeld 11y ago
- vilhelm_s 11y agoIt doesn't: according to the paper, when someone turns the ignition key, they car will generate about 20 challenges to the key fob, and if the fob does not successfully authenticate any of them, the car will give up and not start. The attack works by overhearing the exchange between the car and the key fob, and then doing an somewhat brute-force analysis to calculate what the secret key on the fob must have been.
- racecar789 11y agoCould someone explain why there is no delay after each failed attempt? The system allowed 197k brute force attempts in 30 minutes. I just cannot wrap my head around it. I tried reading the paper (not an expert). In the recommendation section, it does not suggest implementing a delay either. Is it just not physically possible with RFID? I mean, a 4 digit pin with a 5 second delay would take 14 hours for all combinations (better than the half hour with Megamos)??? I have to be missing something.....It can't be this easy.....
- bigiain 11y agoAs the previous comment says, there's a requirement to eavesdrop on at least one successful authentication. My guess is that they're then doing the brute-forcing "offline", not against the vehicle's system. If you know the algorithm and the keysize, and you can see one successful authentication, you could ship the work of workig out which key replicates the authentication you just saw off to AWS or custom hardware (I wonder how readily Bitcoin mining ASICs can be tweaked to attack embedded or IoT authentication?) (Though it seems there's flaws somewhere in the crypto anyway - they somehow broke a 96bit key with under 2^18 attempts...)
- racecar789 11y agoThat helps. Thanks.
- TwoBit 11y agoClearly, the fact that listening to an exchange helped them proves that the security is fundamentally flawed.
- fnordfnordfnord 11y agoTo a car owner, that's another security flaw of its own. An attacker can deny an owner access to their car with a simple code spammer hidden nearby.
- enraged_camel 11y agoSurely that's better than having your car stolen, right? Security is about trade-offs, after all.
- venomsnake 11y ago> Surely that's better than having your car stolen, right? Stranded in hostile environment (middle of nowhere in the arctic or a desert) could be a death sentence.
- enraged_camel 11y agoWho is going to DoS your car in the middle of the arctic or a desert?
- fnordfnordfnord 11y agoEh, I dunno, I guess a very not-nice person could attach the device to your car and activate it remotely/later. I think a more realistic exploit would be a corrupt tow-truck driver / mechanic targeting an area where tourists stop.
- paulmd 11y agoAccording to TFA, they "overheard 2 communications between the keyfob and the transponder", which reduced the number of possible keys to 196,607. This was brute-forceable in half an hour. So the answer is both - the algorithm was flawed enough to reduce the strength, but they were brute forcing it the rest of the way. 2 communications isn't much at all. Getting something from your car and locking it back up is all it takes.
- Someone 11y agoWorse, the paper says the cipher has only 56 bits of internal state (made me think of DES, but that isn't at play here) Even worse, they get it down to 48 bits.
- mikeash 11y agoYeah, that's kind of a weird comparison. You can't really tailgate someone through a car door to gain physical access, or social engineer your way to the car's server closet, or spam the car's employees with phishing e-mails.
- coldpie 11y agoIt was a general point about the state of computer security. In 2015, if you're connecting a computer to the internet, you're vulnerable. If your computer has non-trivial wireless functionality (in this case, keyless entry), you're vulnerable. The only question is whether someone cares enough to hack you, in particular.