4 ms·
I guess this attack is against the keeloq protocol. There are no known total breakage of this kind AFAIK, against the cryptography implemented in the chip. This
by antirez 1y ago
I guess this attack is against the keeloq protocol. There are no known total breakage of this kind AFAIK, against the cryptography implemented in the chip. This will be interesting to understand, I mean: what they are exactly doing here.
- doctorpangloss 1y agoA protocol that makes sense would be: mTLS. But. Guess what these fobs do not do? Something that makes sense.
- hulitu 1y agoAnd passkeys. Don't forget passkeys. Trivially to implement in some kB of ROM. /s
- jeroenhd 1y agoYou jest but there's no reason to stick with twenty year old component restrictions in a car that costs forty grand. The real cost will be in the software validation and road safety hardening, but there's no reason why the ROM size should be limited to kilobytes. You can implement full passkey cryptography on a basic esp32 (https://github.com/polhenarejos/pico-fido https://github.com/polhenarejos/pico-fido). Cut out the cruft and you can definitely get a similarly secure algorithm on an actual car key or key receiver. And honestly, with cars now unlocking over Bluetooth and WiFi, standardising that process to something like FIDO wouldn't even be that awful of an idea. It certainly beats the "we can do cryptography at home" many car manufacturers seem to be going for.
- vbezhenar 1y agoESP32 won't work 5 years from cell battery. My Dacia key does. Embedded hardware is limited not just because someone wants to save bytes, but because someone wants to save joules (and PCB size).