2 ms·
This is not what they did. They used a relay attack which means that they tunneled the actual keyfob signal over the internet (or a direct connection). Tesla
by arlcode 4y ago
This is not what they did.
They used a relay attack which means that they tunneled the actual keyfob signal over the internet (or a direct connection).
Tesla and others try to mitigate that by making sure that the latency of the signal is not too high.
<Everything you described>
Car: your encrypted authentication looks right but you took 200ms to send it. You are probably not within BLE range.
The researchers contribution was to show that despite that a relay attack is still possible.
- jimmaswell 4y agoSo they could add a power switch to the fob or make it need a button press. Maybe people don't think it's worth it. Could also keep your fob in a radio frequency blocking bag.
- arlcode 4y agoIt's usually working without a dedicated fob and uses the users phone to open and start the car. I believe they have an option where you need a pin to start the engine at least however I'm not an owner
- brewdad 4y agoWait. Does this mean thieves are downloading a car? What a world!