11 ms·
BMW, Audi and Toyota cars can be unlocked and started with hacked radios
- dang 11y agoAlso https://news.ycombinator.com/item?id=11334241 https://news.ycombinator.com/item?id=11334241.
- pmille5 11y agoThe auto manufacturers (and for that matter all the "IoT" creators) couldn't give two shits about protecting consumers. Building security into this stuff is trivial and a responsibility.
- proksoup 11y agoCould you say more about those things they should be doing? I'm naive but it doesn't seem trivial to me.
- rachelbythebay 11y agoRound trip times? Can't cheat the speed of light, assuming you can't spoof the transmission.
- mirimir 11y agoYes! Also, the link ought to be fully authenticated and end-to-end encrypted. And one could require the user to press a button on the key fob.
- kileywm 11y agoThe car could log the signal strength of all successful auth attempts from the key fob and determine an acceptable range. Anything outside of the acceptable range could then require use of the mechanical key (for those fobs where the mechanical key is built in) as a precaution. Fobs could require a 'wake up' key press after a certain duration of inactivity. Fobs could have a physical switch on them, enabling an airplane mode. These ideas all give up some manner of ease-of-use.
- big_al337 11y agoHow would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)
- xenadu02 11y agoLots of ways. The ECU only goes into pairing mode if it gets a valid challenge-response from the manufacturer. If put into that mode, it provides a nonce encrypted with its own pairing mode public key that only the manufacturer knows (could even base-64 encode it and show it on screen to let people do this over the phone). You could make it two-phase where it requires the first response within 5 minutes of starting, then requires a second response that must come one hour later (also with a 5-minute entry window). This makes social engineering much more difficult and the delay makes it impractical for most car thieves, but it won't impact dealers or legit owners at all. If the registered owner provides a cell phone, the first attempt should send a text message to let them know the ECU will enter pairing mode and allow them to reply with "STOP" to cancel any further requests. Once in pairing mode, the physical key and ECU use standard public-key crypto (ala SSL) to setup a secure connection, then exchange keys. In theory you could allow boot-strapping another key so long as an existing paired key is present which would make the procedure above your failsafe for when all keys are lost/destroyed. If you wanted to take things a step further you could use a form of distributed Kerberos where the manufacturer sets up a physical key with a ticket allowing access to one (or a set) of allowed cars but that makes the manufacturer's systems a massive target for hacks/social engineering which is a problem because thousands of dealer technicians need access to those systems... that's the point of the delays and short acceptance windows above. An evil tech or hacker can't pre-create a bunch of keys on the sly. To unlock or remote start, the key broadcasts a HELLO message, encrypted with the ECU's public key. The ECU responds with an ACK+nonce encrypted with the physical key's public key. The physical key decrypts it and replies with an ACK+nonce encrypted with the ECU's public key. Congrats, you now have a reasonably secure system that prevents replay attacks. Ultimately it would require embedded software engineers and company management who a) understood security and b) gave a shit. Both are in extremely short supply.
- kosievdmerwe 11y ago
- apawloski 11y agoSamy Kamkar had a great talk about radio attacks at DEF CON 23: https://www.youtube.com/watch?v=UNgvShN4USU https://www.youtube.com/watch?v=UNgvShN4USU
- sebular 11y agoNot my BMW, it's 25 years old and the driver's side door doesn't unlock even if you use a key :P All jokes aside (although it's true about my car), it just seems like a fundamental truth that digitally-secured systems always provide convenience at the cost of, well, security.
- majormajor 11y agoIt's worth noting that non-digitally-secured cars (pre chip-in-the-key tech) provided very little security themselves. Slim jims, hotwiring... The wireless bit does seem like a big regression over non-wired digital security, though.
- bcook 11y agoSpeaking from experience (locksmith), you cannot download the skills required to use a slim jim. Well, you kinda can, being that there are books/catalogs that show you where the lock's internal mechanism is, but being able to manipulate it requires more than simply pressing "exploit car radio".
- majormajor 11y agoI never had much problem breaking into my old 80s Toyota truck with a clothes hanger back when I was a new driver who would occasionally lock himself out of his car, but valid point - I know 90s cars especially made it a lot harder. Window smashing is still an option, though!
- XorNot 11y agoYou also can't download antennas, SDR hardware or a partner to run the other side of the wireless theft operation.
- bcook 11y agoMy critique was regarding tools vs skills.
- 11y ago
- fernly 11y agoThis was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a restaurant, hears its car's ping, it responds, and the bad guys pick that up and amplify it and the car says, ok, key is here, open the door. [1] https://www.grc.com/sn/sn-508.htm https://www.grc.com/sn/sn-508.htm
- kobayashi 11y agoI used to enjoy listening to Security Now! quite a bit, but then I began to feel and read that Steve is not the security expert he claims to be. I'd like to hear corroborating or opposing views from the HN community. Side note: if you have a great infosec podcast to recommend, please share!
- functionCall 11y agohttp://risky.biz/ http://risky.biz/ is a great security podcast. For me the earlier stuff from SN was far better, but now it is mainly adverts and talk about non security stuff.
- Daneel_ 11y agoA big +1 for risky business - I've been listening to Patrick's podcast for well over five years and will happily advocate for the quality of the coverage.
- surge 11y agoI think they're trying to restart Exotic Liability, that was good back when it was running. I loved the rants. There are a few others out there but none worth mentioning.
- augustl 11y agoWow, that's an interesting hack. I can't think of any workarounds either. EDIT: As pointed out in a comment elsewhere in this thread: > The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.
- edent 11y agoSeems a bit weird. The i3 doesn't have an ignition - it is an electric car. Even if they mean "switch on the electronics which control the motor" - I find that hard the believe. There's nothing on the key fob which can do that. And, even if they did, the battery use of a parked car is negligible.
- ratsbane 11y agoA lot of models were not mentioned in that list: Audi A8, any Mercedes, etc. I wonder if they just weren't tested or if the hack doesn't work with them. (And if that's the case, what is different about those models?)
- TwoBit 11y agoalmost certainly those models are affected too. The Audi A7 wasn't listed, but it's 90% the same as the A6.
- thisrod 11y agoI've never used this type of key, and I don't known if I would have noticed the flaw. But, um, nineteen different manufacturers gave drivers devices that try their best to unlock the car every minute of every day, and not one engineer asked what could possibly go wrong?
- mirimir 11y agoExcellent synopsis! Every x milliseconds, probably ;)
- csours 11y agoMultiple OEMs using systems from 4 or so suppliers[1]. If you carefully examine the list of vehicles affected you will see at least a couple duplicates: Toyota and Lexus, as well as Audi and Volkswagen. This article isn't very good. 1. http://www.syssec.ethz.ch/content/dam/ethz/special-interest/infk/inst-infsec/system-security-group-dam/research/spot/332.pdf http://www.syssec.ethz.ch/content/dam/ethz/special-interest/... See page 13: Part Providers
- edelans 11y agoI guess things like this just happen. How many people where involved in using and testing something as critical as openSSL ? Still, heartbleed was discovered more than 2 years after the flawed code landed in production !
- Qantourisc 11y ago"How can I protect my car?" Some keys have a "sleep" mode. For Toyota: hold down the lock key, press the unlock key twice, the key should blink 2 times, short pause, 2 times (total of 4 blinks).
- andreamazz 11y agoThis kinda defeats the convenience of this kind of key free systems though.
- batiste 11y agoActually it defeat both the convenience and the security, because people will forget to switch it off. This is terrible.
- zurn 11y agoThis seems the obvious threat model when thinking about a "no action requred" wireless token, same thing as contactless payments and RFID passports etc. To be secure against this type of attack, such a device has to be designed assuming the adversary controls the nearby radio spectrum and can do relaying and MITM. To control for distance, a speed of light based latency limit might work, though I don't know how cheaply it could be implemented. Laser based distance meters are cheap now, and light travels just 30cm per 1 GHz clock cycle...
- qrybam 11y agoYou could stick your car keys in a Faraday cage of some sort when at home.
- smith007 11y agoHire a Security Hacker from this Hackers List http://hackerslist.co/ http://hackerslist.co/ This is the largest anonymous and free marketplace for hacking and securing your asset.
- jakub_g 11y agoPardon my ignorance: so how those key fobs work? They have no buttons and the car is automatically opening/closing itself based just on the proximity? That would mean I can not have my car closed when I am drinking beer in a garden over the street, which would be totally nuts, so I guess it's not how they work?
- edelans 11y agoI guess they just inverted the concept of the remote control key. Remote control key : you push a button on your key (the transmitter), it sends a signal to a receiver in your car, your car authenticates the key (probably a request/response challenge involving some crypto), and opens the door. Now if you swap the transmitter and the receiver : you put the transmitter button in your car door's handle, and you move the receiver to your key: you have your magic key fob. From what I understand, the security relies on the fact that the power of the radio signals emitted by the transmitter and receiver are very low, so the range of usage is limited to a few meters. The thiefs and researchers exploited this by amplifing the radio signals of both communicating devices to extend the range up to 90+ meters.
- tremon 11y agoThe GP's point still stands: if you are within transmitting range of your car, anyone can push the button on the car door and open it. I doubt that the transmitter verifies line of sight between it and the car.
- gambiting 11y agoI have a car with that system and in my experience you need to be really close to the car for the system to work. Stand further away than arms length from the handle and the car won't open even if someone else tries to open it. Also it looks like the car has independent antennas on each side - even if I stand very close to the driver side, you can't open the car by pulling the handle on the passenger's side.
- 11y ago
- post_break 11y agoCars can be "hacked" now to simply program a new key with an ODBII "virtual keyboard" which basically does all the work you normally do to program a new key in under 60 seconds. So here is what you do, amplify the key ping coming from the house, that gets you into the car. Plug this black box into the ODBII and program a new key. Now you've gone around the alarm, and the immobilizer. And the car is yours. https://www.youtube.com/watch?v=dvmSOEKfkug https://www.youtube.com/watch?v=dvmSOEKfkug
- Cshelton 11y agoCar maker's take note: That list is now a list of cars I will not buy. Many other consumers probably feel the same.
- beeboop 11y agoWhy is this a deal breaker for you, but windows aren't? Someone can break into any car through a window using a rock.
- baq 11y ago1) a broken window is easily noticeable and a giveaway that the car could be stolen. 2) breaking a window creates noise, usually. 3) it still takes time to start the car after you break into it. not so when you hack the radio. all in all, this hack turns something that would take minutes into something that takes a couple of seconds and leaves the vehicle intact, i.e. beyond suspicion.
- beeboop 11y agoPeople are going to be breaking into your car to steal stuff 99% of the time, not trying to steal the car itself. They are often homeless, or have some sort of chemical dependency, or are mentally ill. They are not going to have the foresight, funds, or ingenuity to use some sort of electronic hacking device. They are not going to make the effort to scout out people as they leave their cars (of only certain makes and models) and play secret agent to use some sort of device between the owner and the car. And they break windows in broad daylight all the time - just smash, grab, and run. It's not like anyone is going to try to tackle a meth head running away with some stranger's $90 GPS. Even on the infinitesimal chance they steal the car itself, you have car insurance. It doesn't really matter aside from the inconvenience, and the odds are so low it seems like a silly thing to be an absolute deal breaker for anyone.
- baq 11y agojust for the record, i've got a radio key for my car, the convience factor is much bigger than i anticipated :)
- massemphasis 11y agoUmm... how old is this hack? Over a decade ago, one of my friends used to drive a somewhat nice car that he modded and fixed up on his own. He always threw his keys with the alarm dongle thing, etc... in the freezer and I never asked why. edit: Although his car was still eventually stolen when the thieves used some kind of specialized tools to bend his car's hood. The tool allowed them to bend the hood without triggering the alarm somehow and cut the power sources to the alarms. Then they put it on a repo/tow truck and drove away. I guess he showed his alarm to the wrong hot girl he would always bring around when we all hanged out. When the police found the car everything was gone except for the car's frame and bent hood.