5 ms·
Ask HN: Why do we still have replay attacks on our cars?
So today my car got stolen in front of my house. It was a 2021's Hyundai Tucson.
We clearly see on some cameras in the street that it took less than 1 minute for the thief to take it.
I was not aware that the "replay" attack (as I understand consists simply in listening to my keys signal through my door and replicating it to open and start the car), so my key was not far at all.
So my question is, why is my worthless github account secured by a free android 2FA app which makes replicating attacks impossible, and my 50K€ car secured by the dumbest only-one-forever-the-same key ever?
Is it not possible in the car keys to make some pgpsign-like technology?
(Also I am now aware of the tiktok trend of stealing these Kia and Hyundai car because their security is so easy to abuse)
- t-3 4y agoWhat incentives do automakers have to provide you with a secure product? "Old-school" key ignitions work perfectly fine, so why were they replaced with the obviously-flawed dongle? How complex would a device have to be to not be trivially defeated by a replay attack? How do you get both ends to reliably communicate without requiring an always-on internet connection in both the dongle and the vehicle to sync timing or some other state? What do you do when the manufacturer no longer exists or doesn't want to pay for servers to enable people to drive "old models"?
- qmsdfjkc 4y agoActually the said car has a continuous internet connection, using a sim card, so I guess syncing time wouldn't be that difficult. Also I remember some Renault Espace in France which had a dongle but then you had to put it somewhere specifically in the car to start it. Adding an NFC/RFID chip could solve part of the problem maybe... But yes you are right this require maintenance.
- c7DJTLrn 4y ago>How complex would a device have to be to not be trivially defeated by a replay attack? Not very. >How do you get both ends to reliably communicate without requiring an always-on internet connection in both the dongle and the vehicle to sync timing or some other state? You don't need an Internet connection or server. TLS would do the job just fine.
- wruza 4y agoHow complex would a device have to be to not be trivially defeated by a replay attack? Around $5 complex (though I lost track of actual prices for few years). How do you get both ends to reliably communicate You choose a suitable networking stack and communicate. Secure messaging is a solved problem and doesn’t require “internet”.
- afiori 4y agoI guess that the major source of complexity would be that both the car need both a transmitter and a receiver, instead on only one each. But it seems like a risible source of complexity.
- toast0 4y ago> Old-school" key ignitions work perfectly fine, so why were they replaced with the obviously-flawed dongle? It's more convenient to leave your keys in your pocket or your bag, then to rummage around for them. There's a terminology problem here. I don't believe this is a replay attack (same open command is replayed later and works), those are largely solved with rolling codes. This is most likely a relay attack, the distance from the car to the key is bridged with a repeater. That's harder to solve --- you could measure distance by round trip time, rather than by limiting tx power, but the distances in question are small, and the timing difference between keys at car door and keys at house door isn't very much. Probably the crypto takes longer and may vary more than the difference in transmission time.
- kypro 4y agoFor anyone interested in replay attacks and ways in which manufacturers protect against them this is an excellent video on the topic, https://www.youtube.com/watch?v=5CsD8I396wo https://www.youtube.com/watch?v=5CsD8I396wo
- Scaevolus 4y agoIt probably wasn't a replay attack. You can steal a Hyundai with a screwdriver and a USB cable. https://www.hotcars.com/kia-boyz-easily-steal-base-kia-hyundais-across-america/ https://www.hotcars.com/kia-boyz-easily-steal-base-kia-hyund...
- deafpolygon 4y agoInsurance.
- qmsdfjkc 4y agoI don't see really how insurance would profit from that. Now they have to give me the value of the car in money
- deafpolygon 4y agoIt's not about insurance profiting from it. Carmakers are able to pass off certain things like this due consumers having more or less mandatory insurance on this. Why do we lock our doors when it's proven doors don't stop thieves (putting aside the fact that locking does prevent people from just simply walking away)? Why haven't we improved our security systems? Because people will still buy homes, and insurance covers loss and damage in case of theft. Without that, we would demand houses that are harder to break into. So it is for cars.
- mecklyuii 4y agoI'm confused. I thought normal replay attacks are solved and the issue here is more to do to forward they key range close to the car to simulate the car.key being close. That's what I can't easily just solve if not needing a button on the key which defeats the purpose of the said feature
- qmsdfjkc 4y agoOH that's clever ! It is probably what they did to start the car and then leave.
- badpun 4y agoI thought these attacks work on a much lower layer - by adding a repeater, which is essentially extending the range of your fob? I.e. they just pass the radio signals back and forth, without analysing their content at all. Can anyone confirm/deny?
- nikau 4y agoYes likely a relay attack, best way to mitigate is to store keys in a RF blocking container.
- badpun 4y agoWhy don't the producers just add a physical button you have to press in order to open the car? It sounds like much less hassle than remembering to store your keys in a proper container always. It looks like it's just marketed to lazy and uninformed people.
- nikau 4y agoBecause people value walking up to the car and just opening it vs finding the fob in their pocket and pressing a button, and that convenience outweighs the small risk their car gets stolen which is replaced anyway via insurance.
- giantg2 4y agoPart of why insurance is so expensive is the mindset that insurance will just cover everything, leading to a lack of vigilance by some.
- rit 4y agoIn point of fact, Insurance companies have been refusing to cover some of these Kia and Hyundai cars because they're "too easy to steal". The lack of immobilizer chip apparently is the culprit. https://www.cnn.com/2023/01/27/business/progressive-state-farm-hyundai-kia/index.html https://www.cnn.com/2023/01/27/business/progressive-state-fa...
- giantg2 4y agoI don't have to worry about this. My car is cheap and doesn't have a wireless key.