4 ms·
Would just like to add that some of the security issues are to do with limitations set by governments. I think China and the US in particular insist on crappy s
by bArray 10y ago
Would just like to add that some of the security issues are to do with limitations set by governments. I think China and the US in particular insist on crappy security and it's cost effective to simply apply that everywhere else. Forbid anyone have something a government can't pry into...
I think for car manufacturers, they are limited to 128 bit encryption and cars only have to stand up to about 15 minutes of hacking - that last one isn't particularly well defined either.
- maccard 10y agoHave you got a source for either of your claims?
- bArray 10y ago"128-bit encryption has now emerged as the standard of illegality.[16]" [1] [1] https://cyber.law.harvard.edu/privacy/Encryption%20Description.html#_ftnref16 https://cyber.law.harvard.edu/privacy/Encryption%20Descripti...
- raesene9 10y agoThat doesn't seem to have much to do with cars... Also properly implemented 128-bit encryption is generally secure for 15 minutes or 15 days or probably years (the largest key I'm aware of having been cracked is 64-bit and that took a lot of computers a looong time)
- enkid 10y agoThis is absolutely true. For example, the US gov depends on 128 bit equivalent crypto to stop quantum factoring attacks for the foreseeable future.
- akshatpradhan 10y agoA google search of "US Government 128 bit quantum factoring". Stop trying to blame the government for corporations not doing due diligence. If anything, the real failure is Government not enforcing agreeable security measures like NIST and ISO across all US Organizations.
- bArray 10y agoIf I remember rightly, it's set as a maximum for the purpose of allowing cracking. I imagine it would take ages if they were using AES, but I think they are using something more arbitrary than that. I'll try to find out. It seems you're interested, I'll see if I can contact them and find out more. I know they mostly adhere to the Ford specs, so it might be worth a hunt through them. I honestly can't seem to find any of the security spec we were given online. Even so, it's worth pointing out that the car companies have the private keys for flashing the vehicles themselves, all stored nicely in a massive database. The dealerships simply plug in a code to a computer and returned is a key to unlock. I know that they bend over backwards to any requests from Government agencies. Also, the only difference in the software is usually just a language setting, something that's a few bits in the config file. Other than that, they are identical. So a hack for one Country is a hack for all - across multiple models and multiple years.
- bArray 10y agoThe other might be an unwritten rule in the automotive industry. They just hire a bunch of hackers and make sure it stands up to 15 minutes.
- celticninja 10y agoIs that 15 minutes of brute force? Because surely as technology improves more can be done in 15 minutes.
- bArray 10y agoHere's the thing, when software goes into a car it will likely have to last 10 years until it's outside of manufacturers warranty (I think that's in the Ford spec). So sure, 128 bit encryption (not sure what protocol they use) is tough to crack today, but in the next 10 years when the car is still on the road, will it still be tough to crack?
- raesene9 10y agoDo you have any evidence for that at all? I'm fairly sure that automotive security testing doesn't have an arbitrary limit on time of attack...
- bArray 10y agoHow long do you set? How much do you test? At some point, you just have to say "enough is enough". It was a few years back, but I think (not entirely sure) the requirement time aligned with the time it took to hack bluetooth or something. I think there was a case about hacking car wheels that reported their tire pressure via bluetooth and that was used as a time to be better than. Perhaps this story [1]. I think they were using it to get people to pull over and hijack their vehicle. But that could be wrong, I just remember there was some discussion about that around the time we were talking about the security requirements. That's the best I can do. [1] http://arstechnica.com/security/2010/08/cars-hacked-through-wireless-tyre-sensors/ http://arstechnica.com/security/2010/08/cars-hacked-through-...
- Retric 10y agoProperly implemented 128 bit encryption is still secure. Don't forget key fobs are not forced to use public key crypto systems.