5 ms·
Virtually every key fob is vulnerable to relay attacks. Yes Teslas use Bluetooth but you can do the same with other radio bands even NFC. Only the latest NFC pr
by barbegal 4y ago
Virtually every key fob is vulnerable to relay attacks. Yes Teslas use Bluetooth but you can do the same with other radio bands even NFC. Only the latest NFC protocols such as Mifare Plus implement a proximity check function that can help defeat relay attacks.
https://link.springer.com/chapter/10.1007/978-3-030-10591-4_7 https://link.springer.com/chapter/10.1007/978-3-030-10591-4_...
- jpgvm 4y agoThe main reason NFC is resistant to this is it has incredibly tight timings.
- wallaBBB 4y agoToF + RSSI combination on keys is still to be beaten with good protocol. I say with good protocol since "ghost peak" vulnerability is really a protocol issue, but keys don't fall under CCC, and have proprietary ones.
- AshamedCaptain 4y agoThis is exactly what they are beating in this article. They claim their relay method is not altering ToF significantly and that the RSSI measurement is useless.
- wizee 4y agoNo, it does not beat Time-of-Flight measurement. What it does achieve is keeping GATT response latency within normal ranges, so that the GATT response latency cannot be reliably used as an indication of relay attacks. GATT response latency can vary by tens of milliseconds, whereas Time-of-Flight is usually measured in microseconds or nanoseconds. Unfortunately, Bluetooth LE alone lacks a mechanism for time of flight measurement in secure ranging, hence why technologies like UWB are needed.
- victor106 4y ago> Relay Attacks > A relay attack against two > > legitimate parties A and B is > one whereby a man-in-the-> > > middle C forwards A’s messages to B and/or B’s > > messages to A, unbeknown to them. How is this different from a man in the middle attack?
- johnday 4y agoMITM is more general and includes the case where the MITM alters the information in transit to misrepresent the communications of the two parties to each other.
- victor106 4y agoThank you,
- pbronez 4y agoMy understanding is that Relay Attacks take advantage of the fact that key fobs are weak transmitters. If your car can hear the key fob, it assumes the authorized operator is close enough to interact with the car. A relay attack bridges the physical gap between the transmitter and receiver so that the receiver is tricked into thinking the transmitter is nearby. For example, a thief can scan for key fobs in a fancy restaurant, beam the signals to an accomplice near the valet lot, unlock your BMW, and drive away. IIRC this is mostly a problem with always-on key fobs. Here’s an explainer: https://leasing.com/guides/relay-car-theft-what-is-it-and-how-can-you-avoid-it/ https://leasing.com/guides/relay-car-theft-what-is-it-and-ho...
- BoneZone 4y agoArticles like this feed on the idea that someone could just swoop in and magically steal your car, but magine how difficult it would be to not get caught when stealing an electric car. There are several uniquely identify components, not to mention the car fully understands it's own location. It would take a serious criminal organization to get away with the theft and sell it for profit, and at that point you're gonna lose regardless of the type of exploit invoked. Imagine stealing a smart phone today What's the incentive when the technical overhead of getting away with it is so high?
- eldaisfish 4y agothis misses the point. Theft may not be the sole motivator. If someone moved my car 200 m away, i would then be forced to go get it. If someone moved my car and parked it where parking wasn't allowed, i pay a fine.
- samatman 4y agoSo we've narrowed the threat model to people willing to commit serious felonies to annoy me? I'll take it.
- dfadsadsf 4y agoThere are cheap devices that block mobile networks so car won't be able to transmit coordinates. Then just drive the car to junk yard, remove batteries and sell car for parts. This is what actually happen to majority of stolen cars in US.