12 ms·
Reverse engineering a car key fob signal
- bombela 3y agoI had to reverse engineer some cheap key fob purchased on AliExpress for an electronic project. It was simple enough that thanks to an oscilloscope and wikipedia I was able to do it after persisting long enough. Next time I will try the method from this blog post. And maybe become a better hacker.
- tiagod 3y ago>Note: Transceiver SDR devices do exist of course, but they tend to be very pricey A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.
- stavros 3y ago> A HackRF clone is cheaper than a Flipper Yes, but a "HackRF clone, plus a Proxmark3, plus IR, plus whatever" probably isn't.
- AnarchismIsCool 3y agoThe flipper isn't really a full sdr though, it just has a very minimalist RF IC that has almost non-existent bandwidth. For $400 you can get a limeSDR mini that can read and write 30MHz of spectrum at a time, ie the entire ham 70cm band all at once. If you think a flipper is dangerous, plug in a dummy load and dump noise on L1 then watch your phones GPS stop working, or alternatively decide it's on another continent.
- stavros 3y agoThat's true, but more people want to do a little bit of everything than a lot of something. That's why the Flipper is popular.
- twosdai 3y agoAnd it has a fun dolphin mascot!
- shon 3y agoYeah!
- AnarchismIsCool 3y agoI think it's a case of good marketing and good packaging. Realistically you need a laptop to do serious field stuff with a flipper, but only if you plan on doing any testing and reconfiguration and only initially. The flipper isn't much bigger than the limesdr card, but it's nicely packaged and portable so once you have it ready to go you can throw it in a pocket. The community also helps. The flipper is wildly overpriced for being a glorified happy meal toy but millions of people squeezing every ounce of functional potential out of a happy meal toy is better than a few dozen people writing academic papers with mostly high end industrial (cellular base station) and military applications.
- MuffinFlavored 3y agowhat benefit does being able to read the entire ham 70cm at once bring/what usecases does it unlock? interested in learning
- baby_souffle 3y agoComes in handy when you’re hunting for a signal but don’t know where it is exactly. Think flash light with wide beam versus narrow beam.
- AnarchismIsCool 3y agoDepends very broadly on your area of interest, but to throw out some random numbers and thoughts: If you want to move data between two points, 30MHz of "bandwidth", depending on noise and signal, can be on the order of 30MB/s data rates or more assuming you're good at doing QAM or similar modulation. That's 50x what the CC1101 in the flipper maxes out at If you want to search for a particular signal of interest (ie why does turning on my LED lamp open my garage door), that's more spectrum you can view at once, about 3x wider than what an RTL-SDR can receive. Similarly, you can view the entirety of a 30MHz wide emission as opposed to only seeing pieces of it. You could monitor two different narrow bandwidth signal sources that are within ~30MHz of each other simultaneously, ie the 101.5FM broadcast channel and 121.5 airband guard channel. This provides the capabilities of something like a police radio scanner, covering the entire VHF or UHF land mobile band but without having to stop listening to find another signal and the ability to record the entire spectrum capture to disk so you can review all concurrent transmissions separately at a later time. https://en.wikipedia.org/wiki/Waterfall_plot#/media/File:SDRpp_FM_subcarriers.png https://en.wikipedia.org/wiki/Waterfall_plot#/media/File:SDR... Above is a spectrum plot of an FM broadcast station using wide FM modulation and with some digital sub carriers on either side for song info etc. Other stations will be to the left and right of it and the "bandwidth" of the receiver determines how wide the plot you can view is.
- hex4def6 3y agoKind of a tangent, but websdr.org is one of those sites that you can spend hours searching for interesting radio signals in waterfall plots.
- wallaBBB 3y agoWhy would you need such a stack? Article is analyzing unidirectional fobs, HackRF is half duplex so you could easily capture and analyze and/or replay the signal. Only additional thing you need is a PC. One thing to consider is that the payload will be encrypted so you wont be really able to tell apart what is the rolling code. Hopefully fobs have stronger encryption so collecting enough sniffs and analyzing is insufficient (looking at tesla with their 64bit encryption, hopefully they upgraded). Honda replay myth mentioned in the article is BS, it was popularized by ppl faking a simple replay attack while doing a more complicated one. If you record the fob command and the car never receives it, of course you can immidiatly after replay it to the car and car will accept it since RC is valid. But if you're sniffing while car is receiving it, RC gets updated. If Honda didn't have RC, it would have been far worse than the KIA boys (overriding immobilizer protection and hotwiring the car) issue that did a lot of damage to KIA in US.
- alias_neo 3y ago> I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling I find my FZ most useful, not for the radio stuff, but as a wireless (read: untethered) way to dump and write EEPROMs using a POMONA clip, otherwise, yes, it sits in a drawer.
- alexb_ 3y agoOk but do the clones have a cute dolphin? Very important feature
- tibbon 3y agoI've got a Flipper, LimeSDR (non-mini), some old-school ham equipment, a cheapo $10 RTL-SDR receiver, a few cheap HTs, some RFID tools, etc. Each has their use. The Flipper is nice for quick and lightweight checking of things. LimeSDR is incredibly capable, but also a bit of a pain in the ass to use. Not something you'll flip out to quickly check something or run an experiment.
- MuffinFlavored 3y ago> checking of things like what?
- greenavocado 3y agoDoor handles
- diggan 3y agoBiggest value I got from my Flipper was when a security company was installing a security alarm in my business local, and made a claim that their tags were "unhackable" and "unclonable". ~20 seconds and one cloning later, the installer said something like "Wow, guess we need to update the employee handbook" and I no longer felt comfortable with the installation so asked them to leave after that. I also once forgot the garage opener to the public garage I usually use, but had the signal saved on my Flipper, so that saved me like 5 minutes of not having to park, go home, go to the car and then park inside the garage. Otherwise, it's mostly just for fun.
- 0x457 3y agoOut of curiosity - does flipper handle cloning of IC/ID 125khz/13.56Mhz fobs and is smart enough to trick the receiver into accepting it? Reading and cloning of those fobs was easy, but the receiver wasn't accepting reusable fobs. I had to buy a special write-once fob from Lab401.
- byteknight 3y agoI have both. They both enjoy the warmth of my drawer :)
- bongodongobob 3y agoRealest comment here. I have a few drawers full of these kind of toys I used once and forgot about. Right next to my serial cables and bits of wire.
- MikeTheGreat 3y agoYour post inspired a random but genuine question: Does anyone have a good use for obsolete cables? Like, I've got some serial cables, some co-ax, a bunch of old TV cables, some audio cables. I tell myself I'm keeping them because if I ever need them I'll never be able to (or want to) buy them again. Moreover it feels like such a waste to throw them away. Maybe a makerspace could make use of them?
- aareet 3y agoYou could make some sort of art - in the climbing community old ropes often become chalk bags or carpets etc.
- abakker 3y agoYou've made me imagine a doormat made out of old cat5 and usb cables, and I'm horrified in an amused kind of way.
- jonah 3y agoMy local search and rescue team made door mats for their station with old 1/2" ropes. They came out really nicely. Doing so with serial or coax cables seems like an invitation for bits of the plastic sheath breaking off in a few months and polluting the ground around your door though...
- 3y ago
- deleted 3y ago[deleted]
- tivert 3y ago> These keys are generated and tracked using a counter which has to stay in sync between the remote and the car. This ensures that the car doesn’t reuse an old key, and that the remote always generates fresh keys. Something I've always wondered about is, how do learning remotes defeat this? My car has a couple of built-in garage door buttons, and I'm pretty sure I programmed it by just hitting the remote button in the garage while the car was in a learning mode. Is that a much more sophisticated feature than you would assume (e.g. decoding the signal, recognizing the type, then initiating a pairing with the opener, instead of just replaying the signal)?
- seidleroni 3y agoMy understanding is that most garage door openers do not use rolling keys, they send the same code each time.
- jjtheblunt 3y agoThey use rolling frequencies at least our 2021(?) garage opener does, to retry in the presence of narrow band noise from fcc violating devices. We seem to have neighbors blasting rf in the band that our previous builder installed 2014 model used, because it rarely worked unless super close.
- mdip 3y agoThey've been in use since the 90s, actually[0]. My understanding is that the earlier rolling code systems are easily defeated and I think this can be done (possibly with stock firmware) using a Flipper Zero. Prior to that, garage doors had a set of DIP switches (16, or 32, I can't remember). You matched the switch configuration on your opener with the switch configuration on the controller. And as you might imagine, in a typical suburban area about 80% of the garage doors are set to all zeros. Because the range of the devices was "lucky if you can open the door from the bottom of your driveway", most people didn't notice this. Of course that meant you could open a large number of garage doors by sending the "0" signal for each manufacturer with enough wattage. Compatible models are made by reverse engineering each individual model's rolling code implementation (in the early days) and making an accessory that had the necessary seed value or other component to allow it to be "paired" with a compatible door head unit. Considering it wasn't uncommon for the higher-end models to charge $150 for an accessory remote, manufacturers had a bit of incentive to roll their own slightly incompatible implementations. This is from memory and minimal memory at that, but -- late 90s or early 00s, I think, "HomeLink" was created, which basically allowed car manufacturers to integrate a door opener into the car. If you bought a higher-end model, your visor might have the buttons in it. I believe licensing allowed third-parties to easily create fully compatible accessories at that point (pay a fee, get the patent license/datasheets sort of arrangement). [0] Genie thinks they were first in 1995 but I seem to recall we had a rolling code door installed as early as 1993.
- 0xfeba 3y agoWhat a refreshing article. One I can understand for a change.
- mdip 3y agoJust keep hanging around here and you'll start understanding more of them ;)
- elif 3y agoWhy bother intercepting, decoding, and encoding your own signal when you can just use a big antenna and MITM the fob and the vehicle and convince them they are closer than they really are?
- orra 3y agoI find it wild how pervasive passive keyless entry is. Completely form over (security) function.
- SR2Z 3y agoI wouldn't be so quick to say that - it's unquestionably more convenient than old-fashioned transponder keys in a few really important ways. You can't lock your keys in the car, you don't need more than one free hand to open a door (and sometimes not even that), and you don't need to deal with a massive bundle of keys jangling against your knees.
- elif 3y agotumber locks are built on even more hopes and dreams than security. proper PSK cryptographic locks can (and are) implemented for cars already, just not all cars.
- mmh0000 3y agoHonestly... As an end user, I prefer convenience over security in my everyday life. I have insurance for the rare instance someone steals it. The same goes for my house. I could live in a concrete bunker with no windows and steel doors, but I would much rather live in a home with large windows and a door with a crummy deadbolt. The risk of someone stealing my car or breaking into my house is low. If that risk increases (and thus the area's overall quality decreases), I'll move to a different location.
- hnick 3y agoUltimately, if it were a severe problem, wouldn't insurance premiums reflect this?
- 3y ago
- JosephRedfern 3y agoThere's also a gnu-radio flow graph which serves a similar purpose: https://github.com/bastibl/gr-keyfob https://github.com/bastibl/gr-keyfob. Presentation here: https://www.fleark.de/keyfob.pdf https://www.fleark.de/keyfob.pdf
- pajko 3y agoAnd there's a multiformat receiver block too: https://github.com/merbanan/rtl_433 https://github.com/merbanan/rtl_433
- zzz999 3y agoJust buy a fob from eBay and program it using your car... Instructions can easily be found online
- platz 3y ago429 Too Many Requests = no images lololololol
- lukasm 3y ago> Receiving/analyzing raw signals Stock Flipper can receive raw signal.
- mordae 3y agohttps://www.ti.com/lit/ds/symlink/cc1101.pdf https://www.ti.com/lit/ds/symlink/cc1101.pdf You might be able to get it to output raw demodulated FSK or OOK data without further processing, but I really doubt you are getting raw IQ samples from it.
- gigel82 3y agoI wish car manufacturers would start making tiny (maybe RFID) remotes I could stick in my (minimalist) wallet. Alternatively, looking forward to a tiny Flipper-like (credit-card sized) that can achieve the same result. Seriously, the car fob is the largest thing in my pocket after the phone (thickness-wise at least).
- 0x457 3y agoI think what you wish is your phone to be your car key.
- imp0cat 3y agoAnd you can already have that!
- 0x457 3y agoYes. However, I'm only aware of a Tesla that actually turns your phone/watch into an actual proximity key fob. Not to be confused with what others do: - open an app - login again because devs can't figure out persistence between updates - wait for thing to connect and load slow af UI - click on unlock button in the app - wait - wait - wait - wait - give up - do not renew service after 1 year trial expired because it never worked
- sebk 3y agoThere's a standard for this using NFC and UWB, Digital Car Key; BMW has support for either 2.0 (NFC) or 3.0 (UWB) across their entire range. The Hyundai Motor Company group (Hyundai/Kia/Genesis) is starting to add support as well. See [1] for exact models (look for the little key icon). Several other makes are members of the Car Connectivity Consortium that standardized this protocol so it's reasonable to expect wider compatibility in the near future. The protocol incorporates significant countermeasures against relay and replay attacks like some that are mentioned in other comments here. [1]https://www.apple.com/ios/carplay/available-models/ https://www.apple.com/ios/carplay/available-models/
- rainbowzootsuit 3y agoInteresting related development that access to key programming is being put behind some more "security" due in part to easier access of key programming devices, but it's on the manufacturer to say what's part of the "security" system. Not just keys but can extend to tons of modules. It's arguable if this would have any effect on criminals who are known to follow rules (/s), but will definitely have an impact on some businesses. A criminal record can disallow participation. One way for people who have a record to enjoy success after serving their sentence is to start and run their own business, but I guess they are screwed. <shrug-emoji></shrug-emoji> https://wp.nastf.org/?page_id=367 https://wp.nastf.org/?page_id=367 https://wp.nastf.org/wp-content/uploads/2023/07/ApplicationCheckList.pdf https://wp.nastf.org/wp-content/uploads/2023/07/ApplicationC...
- swamp40 3y agoHe decoded everything, but he didn't actually open a car door. He still has to defeat the rolling code. It's not like you can add 1 to it and resend it. From the outside world, the next rolling code should appear random.
- solaarphunk 3y agoWhat’s more interesting is that if you get into a car now, there are OBD tools that just let you program a new key and drive off, which is wildly insecure.