16 ms·
Assignment 5: Cars and Key Fobs (2021)
- trishmapow2 1y agoDid a high school project on the jam and replay attack mentioned here: https://github.com/trishmapow/rf-jam-replay https://github.com/trishmapow/rf-jam-replay. Low cost SDRs have been a real game changer in letting the average Joe get started in this space. Good to see that more unis have courses with this type of hands on experimentation.
- spacebanana7 1y agoOne thing I would’ve liked about an Apple car is the security. Imagine FaceID, secure enclaves and MFA. An iPhone on wheels would be immune to most, if not all, of these attacks.
- jimktrains2 1y agoAnd then how do I loan it to a friend without the rigamarole of adding them as an authenticated user? What if I'm not able to add them as an authenticated user or authentic myself to let them drive, e.g. I'm injured or very drunk?
- krisoft 1y ago> And then how do I loan it to a friend without the rigamarole of adding them as an authenticated user? By making adding an authenticated driver not a rigamarole, but easy and intuitive. > What if I'm not able to add them as an authenticated user or authentic myself to let them drive, e.g. I'm injured or very drunk? They call you an ambulance.
- jimktrains2 1y ago> By making adding an authenticated driver not a rigamarole, but easy and intuitive. We'll have to agree to disagree. I don't believe that this will be possible in many situations. What if I'm not near my car? What if my phone is dead? What if my car's battery is dead and it needs jumped? I'm also just cynical that the automakers or app developers are able to not enshittify the process. What if when I set my wife up I added her as a user but not admin and now she can't share with someone without having to involve me, which may not be physically possible in all circumstances. > They call you an ambulance. You don't call an ambulance to take a drunk person home. Calling a taxi when there is someone able to drive is a waste of money and a huge inconvenience the next day to retrieve the car. You also can't call an ambulance in the wilderness. I also meant injured in a more broad sense. What if I just have a bad headache or migraine? I don't want to be fumbling with my phone or car electronics trying to navigate adding someone.
- RandomBacon 1y agoIn the future? They call 911, and they read the license plate number and the authorities send an override signal that turns on the car and only allows it to be driven to the nearest hospital that appears on the screen on the console. If they go off course, they have 30 seconds to get back on course before it coasts into a 5mph limp mode (to find a safe place to pull over) for 1 minute before it completely stops and shutsdown and locks them inside for the police to come get them. Eh, the car will probably be self-driving at that point, so probably only the first half.
- mschuster91 1y agoThe last thing I want to see on any car is the ability for the government to just remotely hijack random cars. Not just because cops already and routinely abuse their privileges (imagine some crazy police officer doing that to their ex girlfriend!), but also because any such capability can and eventually will be abused by malicious actors. Think of the usual "for the lulz" trolls, organized crime rings involved in looting people, or nation-state enemies.
- abenga 1y agoAren't authorities notoriously unable to get into Apple products unless allowed?
- os2warpman 1y agoI imagine the same way you share a key for a HomeKit-enabled smart lock. The only scenarios where one is so injured and/or drunk as to not be able to complete the non-rigamarolish process of sharing a HomeKit home key either by doing it themselves or walking someone through the process are ones where the key holder is so incapacitated that they would be unable to share a physical key. All of that is someone irrelevant because Express Mode is enabled by default, so if you are unconscious all a person has to do is pull your phone out of your pocket and use it to unlock and start your car the exact same way physical keys work in that situation. It even works if the phone's battery is dead. https://support.apple.com/en-us/118271 https://support.apple.com/en-us/118271 Also, every implementation of CarKit Car Keys I have seen is the same as HomeKit home keys: there is a backup. Either a physical key, PIN, fob, or card.
- jimktrains2 1y ago> non-rigamarolish process of sharing a HomeKit home key I have not used homekit, but from some searches it only seems to be a non-rigamarole process to add someone as a homekit user if the other person has an apple device? Also, is the Internet required to enroll someone? > ones where the key holder is so incapacitated that they would be unable to share a physical key. I don't need to be conscious or my phone have battery (or reception) to have someone take a key from my pocket. > Also, every implementation of CarKit Car Keys I have seen is the same as HomeKit home keys: there is a backup. Either a physical key, PIN, fob, or card. I was responding to gp who wanted none of this as it all defeats the security they desired. A 1-factor physical authentication token as a backup would be suitable for nearly all edge cases I can think of. As long as the person carries it, but then we are at worst where we are today, at best I could potentially authenticate or add someone from afar. I'm not saying that smart locks aren't useful, just that they can't only be "smart", which I assume you would agree with since you brought up things currently having backup methods?
- woobar 1y agoI have my BMW key in Apple Wallet. When I was out of town and needed to share the key with another person, all I did use a standard share sheet for the key. It let it share via SMS, email, AirDrop, etc.You can revoke the key later.
- 2rsf 1y agoWhich makes you dependent on a third party, that doesn't necessarily have the motive to keep it updated. Having a mobile as a secondary key is a better idea, my Polestar 2 has keys, but also an app that can use Face ID (or the equivalent Android security measure) to drive the car. Once the app is set up you don't need to carry the physical keys.
- sorenjan 1y agoBMW has a page describing the use of UWB (Ultra Wide Bandwidth) radio in key fobs and how it helps against relay attacks. In short it's because the wide bandwidth allows for very short pulses which lets them measure the distance between the car and the key, and using a relay will inevitably add distance and therefore time between the signal is sent and the reply is received. https://www.bmw.com/en/innovation/bmw-digital-key-plus-ultra-wideband.html https://www.bmw.com/en/innovation/bmw-digital-key-plus-ultra...
- H8crilA 1y agoThe core problem is that older systems never proved distance in any rigorous sense, they only proved connectivity/liveness. Pretending that you're closer than you are is sometimes called in research "the mafia fraud attack".
- pwarner 1y agoI believe this was ratified into a standard so it should show up in more new cars. https://carconnectivity.org/car-connectivity-consortium-publishes-digital-key-release-3-0-businesswire/ https://carconnectivity.org/car-connectivity-consortium-publ...
- relaxing 1y agoOnly two lecture slide decks? Did the professor get tired of uploading the material for students to review post lecture?
- H8crilA 1y agoBTW, car keys (physical keys) are notoriously weak, generally susceptible to simple raking attacks. You can learn how to rake a lock in a few minutes, and the rake+tensioner itself costs around $5. And all cars include a physical key as a backup entry method. This was partially solved by adding another device that cuts off the engine, the immobilizer, which still allows the attacker to get in, but not to drive off.
- XorNot 1y agoThe thing is if you have time to rake a car lock, you can also just break the window if you're going to rob the interior. The key fob attack is superior since no one looks twice if you walk up to a car, it unlocks from a hand held device and then you get in and drive off.
- H8crilA 1y agoIt is superior, but a lot more difficult to pull off. And what if raking takes just 5-15 seconds? Because that's how fast it often is. And in either case you still need to deal with the immobilizer, and turn the core of the ignition lock. Unless your radio device is that comprehensive :)
- Crosseye_Jack 1y agoPresuming its a modern car (and if we are talking about keyless entry/start we are), well then you just plug an "Emergency Start Device" into the OBD port or to the BCM module, and drive away. Heck a lot of these "Emergency Start Devices" can also unlock the car, but often involve pulling panels/lights from the car to get to the can bus to run the attack. So that attack when done on its own is mainly left to stealing cars off drives at night rather than say from a supermarkets car park during the day.
- deleted 1y ago[deleted]
- kevin_thibedeau 1y agoPush-to-start eliminates the need to turn a physical lock. They drop to zero security once their RF is broken.
- myself248 1y agoFor the time being, I just store my keys in a little cast iron dutch oven, sitting on top of the fridge. It's extremely effective as a shield for the 125kHz LF wake-up signal, and I've been unable to elicit a response when they're in there, even with a relay setup that reliably wakes them up from several feet away otherwise.
- stavros 1y agoUnrelatedly, I didn't realize "Dutch oven" had a non-fart-related meaning, thanks for the new word.
- xeromal 1y agohaha, I think the fart connotation is just that you're trapped with the lid (blanket) on.
- stavros 1y agoIt all makes sense now.
- onionisafruit 1y agoI learn something new here every day. - I ain’t cut out to be Jessie James -You don’t go writing hot checks down in Mississippi - Dutch oven has a non fart meaning
- karmajunkie 1y agoMy father used to be a prosecutor in MS, and one of my earliest going-to-work-with-dad memories is watching him sign off on warrants for people writing hot checks. I asked him once if he thought that was a bit heavy-handed and he gave me a very stern lecture about people who write hot checks. So yeah, don't do that in Mississippi.
- onionisafruit 1y ago
- DebtDeflation 1y agoThe current gold standard for vehicle theft protection is: IGLA system to block the CAN bus, LIN bus, and ODBII port. It also protects against key fob cloning/relay attacks. + A hidden physical kill switch that cuts off the fuel pump relay (the company 41.22 makes a drop in that doesn't require wire splicing). + A hidden GPS tracker with an onboard backup battery in the event the car battery is disconnected. None of this stops someone with a flatbed from simply towing your vehicle away, but at least the GPS tracker will give you a window to locate them.
- unnouinceput 1y agoIf I have a towing tool for your car, be sure I have a Faraday cage too to block all your GPS trackers while I dismantle the car. Think big truck that is isolated from both sound and electromagnetism and I simply hack at your car with my wrenches, selling your expensive Tesla for parts.
- DebtDeflation 1y agoThat's an issue once the tow truck gets where it's going, but the GPS tracker will record/broadcast the path there.
- exhilaration 1y agoGPS jammers are less than $30 on Alibaba, truck drivers have been using them for over 10 years [1] to defeat their bosses tracking devices. Multi-Band Jammers are $1000, burglary rings are using those to block all Wi-Fi, cell, GPS signals - check out this arrest report from last week in Pennsylvania [2]. If I was a high-end car thief, like in Gone in 60 Seconds, that's what I would use. [1] https://www.theregister.com/2013/08/12/feds_arrest_rogue_trucker_after_gps_jamming_disrupts_newark_airport/ https://www.theregister.com/2013/08/12/feds_arrest_rogue_tru... [2] https://dauphin.crimewatchpa.com/lowerpaxtonpd/3730/cases/organized-crime-ring-arrests https://dauphin.crimewatchpa.com/lowerpaxtonpd/3730/cases/or...
- 1y ago
- ta1243 1y agoI have a physical key which I physically put in a hole in the steering column. This means I know exactly where it is when I come to parking the car, and you need to physically have it in contact to drive the car away. I don't get the appeal of keyless ignition.
- deleted 1y ago[deleted]
- marxisttemp 1y agoPeople with bulky keychains often just throw them in their bag or purse and it can be annoying to fish them out. I personally put a very high value on having a minimal keychain and wallet since I rarely carry a bag with me. The goal is to someday live in a state with Apple Wallet drivers’ license support, in a house with NFC smart locks, driving a car with Apple Car Key, at which point I could finally completely jettison my keys and my MagSafe wallet. I don’t want to carry physical keys when I’m already constantly carrying a device with a Secure Enclave and biometrics.
- brk 1y agoNot sure why you're being downvoted, I'm exactly the same. House locks are already electronic/automated, haven't carried a physical house key in year. Cars use fobs, for newer vehicles there is no option for physical keys anyway. When I leave the house I take my phone, plus the solo fob for whatever vehicle I am driving. I have no desire to have a ring of multiple physical keys and fobs with me.
- cholantesh 1y agoBecause it's a wild rube goldberg solution to a minor inconvenience.
- marxisttemp 1y agoWhat is Rube Goldberg about storing passkeys on a phone? Would you not call a physical lock system based on notches cut into metal a Rube Goldberg machine?
- zero_k 1y agoBroke a few of these for my old work -- HiTag2 and Megamos, some of the code&knowledge used for the attack is online&published, but neither can be used to actually break the ciphers as-is [1][2]. The issue used to be that the cipher employed needed to be low-power, fast, and reliable. With current technology, one could easily use AES, and no serious auto maker should be using HiTag2/Megamos. They were hand-rolled ciphers. The way AES is used (i.e. the protocol itself) could still be wrong, of course, e.g. allowing for replay attacks, etc. [1] Doesn't have some features which you need to use to actually attack HiTag2: https://github.com/msoos/grainofsalt https://github.com/msoos/grainofsalt [2] Used for various pre-processing that is useful (but not neccessary) to break Megamos, but _far_ from the actual attack: https://github.com/meelgroup/bosphorus/ https://github.com/meelgroup/bosphorus/
- gadders 1y agoSo many Range Rovers are being stolen in the UK that the manufacturer has started contributing towards insurance costs: https://www.whatcar.com/news/range-rover-insurance-owners-to-receive-pound1800-towards-cover/n26788 https://www.whatcar.com/news/range-rover-insurance-owners-to...
- Tagbert 1y agoperhaps they should also contribute to a solution to the weak encryption?
- techlatest_net 1y ago[dead]
- mppm 1y agoI'm confused why this is still an unsolved problem. A simple cryptographic challenge with pre-shared keys + button press ought to make key fobs perfectly secure for all practical purposes. Is there something I'm missing here?
- 2rsf 1y agoBattery life maybe? AFAIK most of the remotes works one way only, they don't have a receiver and very low processing power.
- PinguTS 1y agoThis adds complexity and with complexity there comes a price tag. That would make the key fob more expansive. It also adds higher power requirements this then comes with new requirements for the battery.
- mppm 1y agoRe price tag: you can buy a smartphone for 100$. Surely it is possible to mass produce cheap key fobs with send/receive capability and a tiny crypto module. Re power: Key fobs already do some form of crypto and broadcast. Adding reception capabilities ought not to be that power hungry.
- Iolaum 1y agoEven Better, they can use a smartphone app. We already have a battery-powered device that can emit radio signals in various frequencies!
- ryandrake 1y agoI've got an even better solution: Picture a piece of metal, cut in a specific way as to allow metal "tumblers" inside a small cylinder to turn, engaging and disengaging the locks and/or ignition, whereas other pieces of metal, cut differently, would not allow any motion. I know, it sounds far out there, but we should give it a shot.
- stewx 1y agoWe should just GPS track the cars and arrest the thieves.
- rikkert 1y agoGood luck when the car is stripped for parts within 24h
- Noumenon72 1y agoWe could have the police work 24 hours also.
- Hamuko 1y agoThere's an UK-based company providing anti-theft tracking services for cars, motorcycles, heavy equipment etc. and they have a YouTube channel where they document some recovery operations. It's quite remarkable how fast a car goes from stolen to stripped. They also can't rely on just GPS to actually recover stolen goods. For example: https://www.youtube.com/watch?v=IdGoxDPMv9Y https://www.youtube.com/watch?v=IdGoxDPMv9Y
- madphilosopher 1y agoVulnerabilities like this lead to car thefts. Some models of cars are more susceptible than others, and the manufacturers seem unwilling to fix the problem. The insurance companies know which models are more trouble for them, and so they set higher rates for these, which punishes the driver/owner for something outside of their control. My solution? Require the manufacturers of vulnerable models to pay the insurance on behalf of the driver/owner as long as the vulnerabilities go unfixed.
- emeril 1y agopart of what helps is, at least, before buying a car, to get insurance quotes and then you see the true cost of THAT car
- pinko 1y agoConsumer Reports will also inform you of things like this in advance, if you look. (For this and 100 other reasons, It's worth paying for a digital sub.)
- potato3732842 1y agoConsumer Reports reporting is bought and paid for by the OEMs. They'll make a big issue out of nothing or minimize real issues depending on where the money is coming from. This goes back at least as far as the Samurai rollover scandal. Pretty much all industry journalism where the journalists depend on being in the good graces of the manufacturers to get the access they need to make their content is like this.
- dripton 1y agoConsumer Reports buys all the items they review, anonymously.
- potato3732842 1y agoThat doesn't stop them from doing questionable stuff and playing favorites. All this was aired publicly in the lawsuit Suzuki filed.
- throw0101d 1y agoFor a good modern day automobile security system, at least in the US, get a car with a manual transmission.
- recursive 1y agoHow do people learn to drive manuals in 2025? It used to be that you used your buddy's/parent's beater in the back of the mall parking lot. But no one has one anymore. I tried to learn in the 90s for about an hour, and never managed to get the car moving forward rather than bouncing. At this point, I don't have much desire to try again, but I wouldn't know how to try if I wanted to.
- ge96 1y agoCheap standard cars like a miata are fun to drive edit: if you buy em old I mean me I want an Exige
- cafard 1y agoTwenty years ago, I supervised a beginner in an office parking lot that was generally empty on Saturdays. But you're right, we haven't had a car with a manual transmission in a dozen years now.
- ge96 1y agoSo funny the guy towing my car couldn't drive it so I had to drive it onto the ramp
- SoleilAbsolu 1y agoA patina of filth, slightly faded paint and maybe a few dings and dents also help make a car invisible.
- Ballas 1y agoCode-hopping remotes have existed for a very long time, and I am really surprised that it's not the case here. I have had cars that were made in the 90's that used keeloq, a technology from the mid 80's. In fact, all of my door openers and car remotes have some form of code-hopping and it's certainly not because they were specifically chosen for that aspect. Sure, there are attacks for code-hopping systems as well, but it's a completely different league.
- sureglymop 1y agoBy code hopping do you mean rolling code based remotes? I think what can sometimes be done with these is that one can record one or two codes and then desync the original remote. But I agree, it's a different league.
- deleted 1y ago[deleted]
- bufferoverflow 1y agoWhy can't it be very simple and secure. Car and fob share a secret key. When you click on the open button on the fob, you send SHA256(key) Car responds with a random challenge RND Fob sends SHA256(key XOR RND) Car does the same calculation and compares.
- kilburn 1y agoThere's no car identification in this protocol, meaning that impersonation/mitm attacks are trivial. Try again :)
- bufferoverflow 1y agoI don't see it. Give an example of how this attack can be executed, a practical application. I approach my car, I press the button on the fob to open it, and your attack does what exactly?
- crustycoder 1y agoThis is an old article and whilst there are undoubtedly still vulnerable vehicles, with the advent of UWB it seems to be a solved problem. My car has UWB, there's a LED on the fob that blinks when it is in range and if it's stationary for a short time, it inactivates as well. Some experimentation suggests you need to be within about 5m of the car to open the doors. The localisation seems to be very accurate, even if you can open the car from a distance it won't start unless the fob is physically within it. If I sit in the driver seat the fob has to be less than 10mm away from the outside of driver's window, otherwise it refuses to start.
- mrinterweb 1y agoI have a 2021 Toyota that I lost one of two key fobs. Toyota has a strict policy that only Toyota dealerships can program key fobs for their newer cars, so buying a key fob replacement from a 3rd party was not an option. Total out of pocket expense for getting new key fob, programming that key fob to the car, and making sure the other fob still worked; cost about $550. I feel that is an absurd amount of money to spend because of a lost fob. I appreciate people looking into and exposing weaknesses of car fobs because it might expose ways to circumvent the monopolistic costs associated with replacements. Wish there was a way to retrofit my car to use Ultra Wide Bandwidth as a key.
- throw678937 1y agoUsed to be, you could get a seedy OBD cable off Amazon and it came with instructions on how to "acquire" the dealer software, which let you reprogram the car to accept any fob. Not sure if things have changed in the last 5 years.
- jdietrich 1y agoEssentially all manufacturers have that policy, because key replacement is a profit center for dealerships. Independent auto locksmiths depend on third-party programming tools and keys by companies like Autel and Xhorse. There's a constant game of cat-and-mouse, with manufacturers developing new immobilizer systems and the third-party companies reverse-engineering those systems. An auto locksmith with the right equipment should be able to copy a key, remote or keyless fob for any current US Toyota model.
- mrinterweb 1y agoTwo locks smiths told me that only the dealership can program a fob for a 2021 Toyota Sienna.
- Spooky23 1y agoImprovements in key tech just hurt me. As long as they aren’t trivially exploitable like the Hyundai keys, more expensive keys are my problem. Stolen cars are my insurance company’s problem.
- 1970-01-01 1y agoI HATE to say it, but 'enter your password to unlock your car' is the only reasonable alternative when 'something you have' is pseudo-secure.
- deleted 1y ago[deleted]
- neogodless 1y agoThis is both very relevant and a bit off topic, but for me, quite timely. Today my Polestar app wasn't updating properly. Some things were, but the widget was stuck on manual refresh, and the odometer and location in the app were from the previous location I'd been, not including the trip home. I stupidly deleted the cache and data for the app. Then tried to reconnect to the car. This process requires putting all of the fobs (for me, two) in the car, and then getting to the right step in the car as well as the app. But... here the car claims it cannot find both fobs. While in other parts of the car software, it indicates it can find both fobs. Because of this, I cannot pair the phone and car, and have any of the app features working again. I would, naturally, factory reset, but this also requires both fobs, and also claims it cannot find them. (I've tested each fob and they both fully work otherwise - just in these two instances, the car acts as if it cannot find them.)
- Peanuts99 1y agoDid you put them both in the cupholder? There's an RFID reader in there for that purpose.
- neogodless 1y agoI did. I tried a lot of things. Ultimately the next day (this morning) I unplugged the charger, and hopped in the car and pressed Factory Reset, and it worked like a charm, and everything is fine now. I don't know if charging was blocking pairing but I assume it was blocking the factory reset. (Just wish error messages were... more informative, you know?!) I assume somehow data was... not in an ideal state... in the car's internal database, and the factory reset removed the bad data, allowing normal operation to assume.
- quailfarmer 1y agoThis was a great class when I took it! Hope you’re doing well Dr. Pauly!