3 ms·
This isn't a replay attack in the traditional sense. The attack works by simultaneously receiving the fob signal while jamming it to the car so it doesnt see i
by ipunchghosts 9y ago
This isn't a replay attack in the traditional sense. The attack works by simultaneously receiving the fob signal while jamming it to the car so it doesnt see it. Then, the car can't roll ahead its table.
To say another way, it exploits the fact that you can be a hundred miles from your car and push the unlock button on your fob but then return next to your car, push the fob, and the car unlocks.
- lucaspiller 9y agoWhy aren't the previous codes invalidated though? If the attacker catches code X, and the owner presses the button again to send code X+1, why is code X still valid?
- lunixbochs 9y agoBoth X and X+1 are jammed, then the attacker replays X. The car never sees X+1 to revoke either.
- ipunchghosts 9y agoYes. There is a rolling code both inside your car rx and the fob tx. They get out of sync (think of pushing your car unlock when your car is not around) but the fob can never be behind the car. By jamming the the rx at the car it never gets code X+1 but the attacker does so the car never rolls ahead. Then, the attacker replays X+1 and the car unlocks. This attack has been known for a quite a long time along with the TPMS hack (made famous but rutgers and U South Carolina http://www.sc.edu/news/newsarticle.php?nid=1202#.WRXDdVXythE http://www.sc.edu/news/newsarticle.php?nid=1202#.WRXDdVXythE) https://www.theregister.co.uk/2010/09/21/car_jammer_vehicle_theft_scam/ https://www.theregister.co.uk/2010/09/21/car_jammer_vehicle_...