6 ms·
Why are so many car manufacturers incapable of using cryptography properly?
by cakealert 1y ago
Why are so many car manufacturers incapable of using cryptography properly?
- the_mitsuhiko 1y agoTo some degree customers love it. It allows you to program your own replacement key without having to go through the manufacturer or an official dealer.
- j1elo 1y agoNo doubt they would charge $100 or more for just clicking a button and having the equivalent of an NFC writer.
- colechristensen 1y agoWhen my favorite quadruped knocked my keys into the trash I had to get my car towed to the dealer for them to program me a new key. One one hand, top notch security as it was impossible to do any other way. On the other hand the total to get this done was something like $500 after everything.
- dylan604 1y agoI did this to myself by placing my keys in a pocket of a bag that I've never used before when returning to the airport parking. I found the keys in the bag after paying to have it re-keyed after paying for the tow from the airport to the closest dealer.
- mh- 1y agoThis is totally something I'd do. I'm very organized when I travel for work and everything has a place. If I absentmindedly slip something into the wrong part of my bag, it might as well be invisible..
- dylan604 1y agoI'm a great example of "for someone supposed to be smart, you do the dumbest things"
- mh- 1y agoHaha, I heard this a lot growing up. And now I have kids of my own..
- imp0cat 1y agoGet a bluetooth tracker (Apple Air Tag, Samsung Smart Tag or the generic Google Find My compatible one for other Android devices), set it up with your phone and attach it to your car keys. Then anytime you misplace your keys, you can look at a map on your phone and it will show you where to go.
- mh- 1y agoYeah, big +1 on this tip. I have AirTags on my bags themselves as well as some other things. Don't have them on my key fob, but you may have inspired me to attach one haha. The map thing when you're nearby and it goes into the sonar-like mode is super cool. Especially combined with the ping noise.
- colechristensen 1y agoAirtag in the glove compartment of your car.
- mh- 1y agoOh this is brilliant. Why haven't I thought of this? I travel a lot for work and always take a pic of my parking space number. A few weeks back I forgot to, realized I forgot before I got in the security line and was like.. nah, I won't forget on a short trip. When I got back later that week I walked the entire floor of the garage, about 25 minutes.
- 1y ago
- pkaye 1y agoI wonder who make more money on this. The car dealer or the manufacturer.
- hungmung 1y agoWell they don't call them stealerships for nothing.
- IshKebab 1y agoWhat does? The article is very unclear about what exactly this does.
- the_mitsuhiko 1y agoThe attacks to rolling code keys are well known but these keys continue to exist. They allow you to pair a key yourself to the car that you buy online. Particularly in the US it's quite common that people buy used cars and then another key online that they pair themselves. You won't be able to do this for instance with VAG cars that have KESSY. First of all the immobilizer is paired to the key, secondly the only way to pair a new key to it is via the manufacturer or a licensed dealership because you need a blob from their central server. But the consequence is that people feel like they are being fleeced when they need another key, because it can cost you hundreds of dollars to pair one. In general these types of attacks are much harder in Europe where immobilizers have a legal minimum standard that manufacturers have to meet. On the other hand in the US immobilizer are entirely optional, which has famously led to KIA and Hyundai cars shipping without them and the Kia Boys TikTok phenomenon.
- fc417fc802 1y ago> But the consequence is that people feel like they are being fleeced when they need another key, because it can cost you hundreds of dollars to pair one. Because the ARE being fleeced. It's an artificial dependency on the vendor on the one hand versus a blatantly insecure approach on the other. Secure pairing that can be done by the end user isn't rocket science.
- the_mitsuhiko 1y agoIt is a bit rocket science because cars stand around. The CAN bus can even be externally accessed if you pop open the right part of the car (common fault are adaptive headlights). It is not as trivial as people make it out to be because cars violate one of the most important principles of having good security: no physical access.
- theamk 1y agoYou can have strong cryptography + ability to self-pair. See bluetooth or wifi or zigbee or many other technologies..
- fc417fc802 1y agoMaybe the car manufacturers should just give up and adopt BTLE. Proper security, and you could unlock with your phone.
- tamimio 1y agoCar manufacturers are like automation/control manufacturers; they existed before cybersecurity and never caught up to the pace. If you ever audited any SCADA system, you will see nightmares. For cars, some new models of popular brands (not specifying any), you can access the CANbus from the headlight where you can reprogram the ECM to your new key. It's that simple to "own" a modern car.
- b112 1y agoI've seen one-manufacturer, 2024 models at least, which requires two keys in range, before a third key may be programmed. Good idea, don't know how effective it is in reality.
- bayindirh 1y agoNeeding two keys for a third one is not new. My 25 year old car needs two keys for adding the third, old Fiats has “red master” keys which are also required during adding keys.
- serf 1y agoHonda/Acura/Toyota have used similar systems for years; this is one of the reasons why cloning a key costs less flagged hours than making a new one for an owner that lost all of them : when you lose all of them you need to get the actual computer out and pair it with the ecm directly, when you clone them there is a ritual that can be done with the other keys+ the new one.
- tonyarkles 1y ago> ritual I cannot think of a better word to describe the process. The ritual may involve some chanting. Thank you for that :D
- pastage 1y agoCeremony like what is done for the DNS root signing.
- sneak 1y agoThey're not. There is AFAIK an ssh key infrastructure for OnStar that's modern and well-run, for example. Things like key fobs are most likely very incremental changes on "this is the way we've always done it". These organizations are behemoths and steer with all of the inertia of a containership.
- VoidWhisperer 1y agoAnd tend to get stuck in their ways like a container ship stuck in the suez canal
- cindyllm 1y ago[dead]
- dylan604 1y agoProper security is a total pain in the ass, and makes things nigh impossible to use in the manner people want to use them. This naturally makes things more expensive to recover from oopsies. This is why YubiKeys will only ever work for people technical enough to understand them. Normies will loose it at the first chance, and then be locked out of everything. At that point, YubiKeys will be banned by Congress from all of the people writing in demanding something be done about their own inabilities to not be an ID10T
- theamk 1y agoAs far as car security is affected, "normies" really don't care what the algorithm is. The entire UX is "press button to open car, go to dealership if you need new key" and it allows a wide variety of choices re algorithms. The only reason they use KeeLoq (with whopping 32 bits of security!) instead of something normal, like I dunno, AES-128 or something, is because they are trying to save $0.50 in parts on the item they sell for $100. Oh, and because they don't like any change and don't have organizational ability to use anything recent, like other poster says.
- dylan604 1y ago> (with whopping 32 bits of security!) Ha! DVDs at least had 48 bits. /s
- fc417fc802 1y ago> The entire UX is "press button to open car, go to dealership if you need new key" Ironically proper security in this case would likely improve the user experience as well. The car provides a 64 bit (or larger) secret value and you manually program a standardized fob with it. No need for custom parts that are only available from the dealer.
- Terr_ 1y agoI wonder if it's less about the cost of silicon, and more about the energy budget for a device that uses a button-cell battery. Even if it's a problem with off-the-shelf stuff, I imagine a car-manufacturer could easily get something all nice and tiny and special-purpose.
- kube-system 1y agoThe reason these vulnerabilities affect many brands is because they don’t use cryptography. They buy these electronics from other suppliers.
- nullc 1y agoCryptography is actually difficult for the requirements of a key fob. The principle issue is that requiring two way communication greatly increases hardware cost and lowers range/reliability. You also would prefer to minimize or eliminate any volitile storage on the devices. Also you very much want to absolutely minimize the data sent, both for battery life and range/reliability reasons. And whatever volatile storage the devices have you need to have some way of handling it being reset when its lost due to a dead battery or replaced device. So standard replay resistant protocols like "door sends a random challenge, fob signs/decrypts/encrypts it and sends the result" are excluded due to the two-way requirement. The next obvious set is along the lines of "device sends an encrypted counter, door enforces that the counter only goes up" requires nonvol storage in both devices, and then gets tripped up when the fobs counter goes back down due to being reset. (also harder to implement multiple fobs, as they each need unique state).
- SoftTalker 1y agoIf only almost everyone carried a computer with a radio and local storage and a good battery with them almost everywhere
- nullc 1y agowith a battery life of two years? and durable against going through the washing machine?
- SoftTalker 1y agoIf you want simplicity and ruggedness we should never have moved away from steel keys.
- hollerith 1y agoVery few keys are made of steel. Brass is the most common material.
- 1y ago
- brk 1y agoIt's not like the systems they used for physical keys were ever very robust either.
- downrightmike 1y agoLike when just putting in a usb-A anything into the steering column and letting the car drive away? Nah man, no one will figure it out. We're good. Our backdoors are the best
- ronsor 1y agoYou can ask this question about almost every non-software company. Hell, you can ask this question about most software companies. The real question is "why are most people and companies incapable of using cryptography properly?"; and the answer is that doing cryptography right is hard, especially if your use case isn't a common one.