16 ms·
I expect that remote key amplifier attacks work against Tesla like they do against other cars. I wish automakers weren't in denial about this problem.
by TwoBit 11y ago
I expect that remote key amplifier attacks work against Tesla like they do against other cars. I wish automakers weren't in denial about this problem.
- POiNTx 11y agoIs there anything car manufacturers can do against this attack while still keeping all functionality of the key fob?
- mikeash 11y agoIt's hard to see how it could be fixed. Fundamentally, what is different about a local key fob, and a relay connected to a remote key fob? It seems fundamentally impossible to tell the difference. The one thing that I could see working in theory would be detecting the roundtrip transmission time with a strict ceiling on it. No matter how good your relay is, it can't relay data faster than the speed of light, so you can enforce the fob being close by only listening to it if it responds fast enough. The problem with this is that light moves pretty fast, and internal delays within the fob will dominate. If you want to put the range limit at, say, 30ft, that means your response time ceiling is a mere 60ns. Can you build a fob that responds anywhere close to that fast? Edit: one other possibility is if the fob knows where it is. A GPS receiver on the fob, for example, would allow the fob and the car to securely confirm proximity (absent GPS spoofing). Getting a GPS receiver to run on a wireless fob's battery is left as an exercise for the reader.
- maxerickson 11y agoFrom a previous discussion: https://news.ycombinator.com/item?id=9383462 https://news.ycombinator.com/item?id=9383462 https://en.wikipedia.org/wiki/Distance-bounding_protocol https://en.wikipedia.org/wiki/Distance-bounding_protocol (I don't pretend to have a clue whether it can be effective or not)
- mikeash 11y agoThanks, nice to know that it has a name.
- Dylan16807 11y agoYou can try to detect the amplified signal, and if you put an accurate timer in the fob you can make it take exactly 5000ns to process and then require a signal back within 5020ns.
- TheLoneWolfling 11y agoDetecting the amplified signal won't work. There are these things known as directional antennas... The timer idea is a good one, although a ns-accurate timer is starting to get a bit much for something to put into a key fob. Especially give it's run off of a watch battery (power requirements) and often exposed to heat / cold (thermal drift).
- Dylan16807 11y agoWell for the example timing I gave you only need 1 part per thousand accuracy, and it's easy to get 10ppm or much better. It only needs to run during communication, anyway.
- anologwintermut 11y agoThe timer could be in the car. Protocol looks like fob pings car, car challenges fob, fob responds.
- TheLoneWolfling 11y agoNope. Dylan's comment requires a timer in both the key fob and in the car. The key fob to delay transmission of the challenge response, the car to check if there isn't too much delay in the challenge / response pair. You really need a timer in the key fob, as the processor in the key fob is often so slow (for battery / cost reasons) that an extra couple clock cycles somewhere would throw off the timing enough to make it fail.
- anologwintermut 11y agoThe usual distance bounding protocols only need a nano-second accurate timer on one device called the verifier. For example https://www.usenix.org/legacy/event/sec10/tech/full_papers/Rasmussen.pdf https://www.usenix.org/legacy/event/sec10/tech/full_papers/R... Cool trick in that one, the Prover(i.e. the key fob) does the distance measuring part of the challenge response protocol using analog only components. This means its response time is <1 nano second. So you can do it with only the car having a good timer.
- mbrubeck 11y agoTheoretically you could use quantum key distribution, but in practice this usually requires a fiber-optic connection. https://en.wikipedia.org/wiki/Quantum_key_distribution https://en.wikipedia.org/wiki/Quantum_key_distribution Edit: Nope, I am wrong, as the comments below point out.
- Sir_Cmpwn 11y agoWould it be possible to establish a secure connection and exchange a secret key?
- sp332 11y agoNo. This could relay the challenge to the key, and the response back to the car. The attacker doesn't have to know any secrets to do that attack.
- prsutherland 11y agoIf you put the car's public key on the fob, the fob can validate that it is talking directly to the car over a secure connection and then the car can validate the fob's secret.
- TheLoneWolfling 11y agoPlease elaborate as to how the fob or car would detect the MITM: 1. You place device A near car and device B near fob. 2. Device A relays all Rf transmissions in the target frequency range(s) to device B, which rebroadcasts, and vice versa. Public-key encryption / authentication only ensures that no-one in the middle is reading or editing your connection. It does not prevent someone from relaying your communication. (And a good thing too, else the entire encrypted web wouldn't work.)
- Sir_Cmpwn 11y agoWhat if the car sent out the signal and the fob received it, then sent an unlock command?
- TheLoneWolfling 11y agoNote the vice versa: In that case device B picks up on the unlock command and relays is back to device A which rebroadcasts the unlock command to the car.
- halviti 11y agoI think this is an easy problem to fix, no? Why not just make the keys responsible for starting the car again? We've traded too much security for convenience and it's time to take a step back. You can still start the car with the push of a button.. only now that button is on the key. Problem solved.
- TheLoneWolfling 11y agoAgreed. Your opinion is an unpopular one, albeit one I share. There are far too many cases where security is getting removed in the name of convenience, and this is no exception.
- URSpider94 11y agoIt's important to look at this in the context of overall auto theft trends. Auto theft has dropped by more than 50% over the past decade, driven mostly by the broad use of smart keys. (http://www.iii.org/issue-update/auto-theft http://www.iii.org/issue-update/auto-theft). The lion's share of the thefts are of older cars (mentioned in the above cite) -- thefts of 2013 vehicles number in the hundreds. Further, a Tesla has a GPS, sophisticated processor, and a 4G WAN. It would be easy enough to have the car report back to the owner if it's being driven without sensing the key, and give the owner the option to route a theft report and live location of the vehicle to police with one click. That's something I wished for in my revenge fantasies when my car was stolen a decade ago. We could do more, sure -- but it's hard to argue that we are making cars less secure, or even that car security should be a major care-about for the buyer.
- greglindahl 11y agoThe main issue with newer cars is people stealing your stuff from your unlocked car. The Tesla app does show the car location on a map; they don't have a "report to police" option, but they aren't that far away from it. BTW the Tesla modem is 3G.
- mikeash 11y agoThe implied context here was "while keeping wireless keyfobs." Yes, the problem becomes substantially easier if you require a direct physical connection, but that's not such an interesting problem. Also, given that modern cars are vastly more difficult to steal, I object to your characterization of "traded too much security for convenience." If the current state is too insecure, then you must think that cars from 20+ years ago are absolutely appalling.
- lsaferite 11y agoIt took a few minutes for the 'relay' portion of what you just wrote to click. So, in theory, if you wanted to steal a REALLY expensive keyless car you could have two devices connected over a mobile data connection that just relays communication with the keyfob. You put one device near the owner of the fob, so in his office, and you keep the other. Then you can just walk off with the car. Yikes.
- TheLoneWolfling 11y agoYep, that's pretty much it. Although sometimes you can even skip the second device and just have the one near the keyfob.
- mbrubeck 11y agoYep - here's a presentation on these relay/repeater attacks by some researchers who actually build some: http://media.hacking-lab.com/scs3/scs3_pdf/SCS3_2011_Capkun.pdf http://media.hacking-lab.com/scs3/scs3_pdf/SCS3_2011_Capkun....
- birdman3131 11y agoI could see several ways. 1. Use a modified form of triangulation. Have multiple transceivers in the car (At the front and back) and make the remote directional aware. Then have the remote and transceivers ask each other if the angles they are seeing are the same. The only way for the thieve to bypass this would be two remote amps set at almost 180 from each other. 2. stick an ultrasonic speaker in the key fob and have the car send it a random sequence to play back. For those worried about battery life use a wireless charging system. Both of these assume that the transmission is encrypted and the thieves are just boosting the signal.
- mikeash 11y agoI don't believe it's possible to do triangulation in anything like a remotely accurate fashion with anything that'll fit in your pocket. I don't see how ultrasound helps matters at all. You just change the nature of what the attacker has to relay.
- tzs 11y agoUltrasound helps because the speed of sound in air is much lower than the speed of radio waves. This makes it massively easier to do distance measurements. Rather than put an ultrasonic speaker in the fob, I'd put a microphone. The car would send an ultrasonic signal, and the fob would send a radio response indicating it heard it. The car could then calculate how far away the fob is.
- mikeash 11y agoUltrasound also makes it massively easier to spoof distance measurements, because there's nothing that requires the attacker to use ultrasound for his own transmissions. The speed of sound in air is about 1ms/foot, so if you're trying to measure proximity within 30ft, you're looking for a 60ms roundtrip delay, or 30ms for one-way. If the attacker has ultrasonic microphones and speakers connected with radio waves, that means he can spoof your fob from up to 9,000km away for roundtrip ultrasound, and 4,500km away for one-way, under ideal conditions. The speed of light imposes difficult constraints in terms of how fast you have to respond, but at least the attacker can't outrun it (as far as anyone knows).
- mikeash 11y agoI can't edit anymore, but expanding on the GPS idea: I just realized that we pretty much all carry around a GPS-enabled "fob" these days. If you switched away from using a dedicated fob and instead authenticated against a person's phone, you could double-check proximity that way. It would only need a quick check before opening the car, so battery life shouldn't be affected too much.
- hunt 11y agoPerhaps moving to a shorter distance transmission method would work. You could use NFC and then touch the fob against a portion of the door, placing the key in a cup holder (or something similar in the center console) with NFC support when you want to start the engine? It's not the exact same functionality, but is close.
- TheLoneWolfling 11y agoThat just means that the adversary needs to get the repeater closer to you. It mitigates it, but doesn't stop it.
- raisedbyninjas 11y agoCreating a special hole to put the keyfob into sort of negates the already dubious benefit of these keyless entry systems.
- sp332 11y agoRemember the adversary is boosting the signal, so their device doesn't have to be in a cupholder even if your key would.
- stonemetal 11y agoBut if we are going over a very short distance like NFC does then their amplifier is going to have to be close to the key. If my NFC key only works when it is within two inches of the door lock, your amplifier is going to have to be within two inches of my pocket to pickup the signal to amplify it.
- sp332 11y agoWell... they might have a better antenna or just a bigger amplifier than your car does. And if they can just walk past you to unlock your car, that's still pretty unnerving.
- lsaferite 11y agoWould triangulation of the signal not be effective?
- TheLoneWolfling 11y agoEither do something with speed-of-light delay ("fun"), or manually activating the key fob (degrades user interaction).
- Strilanc 11y agoSome half-baked ideas: - If the car was inductively powering the key, that might be harder/more dangerous to amplify. - The car or house could send a false key signal, which would also be amplified, and refuse to open when receiving it. (New attack: lock rich people out of their car with 17$ of equipment!) - If your house/public-buildings/phone+gps could track the key, they could tell the car to disable the system. - Sending the signal with audio or visible light? Something that doesn't pass through walls. - Use a pedometer to deactive the key when it's at rest. - Use a really long key (like... 2 metres long) with transmitters at each end, use crypto and frequency hopping, and use multiple receivers on the car to triangulate both ends. If both transmissions are coming from the same spot, it's an amplifier.
- TheLoneWolfling 11y agoAnything to do with active disabling is easy to prevent via jamming. Inductive power isn't going to really help, I don't think. A false key signal, like you mention, won't help. Also, it'd be relatively easy to stop via a directional antenna. Audio does pass through walls. Visible light would be less convenient than a standard key, I'd think. Disabling the key while at rest would be really annoying for those who tuck it in their purses. A really long key... I hope you're joking.
- Strilanc 11y ago> Anything to do with active disabling is easy to prevent via jamming. Jamming is better than unlocking. Especially if you can fallback to the normal key. > A really long key... I hope you're joking. Obviously you'd have to do something clever with it. Turn it into a walking stick, sew it into clothing, have an anlket+earing combo, or etc. But, like I said, all the ideas were half-baked.
- anu7df 11y agoThis is more of a question . Is it not possible to "listen" for your reflected (there will be some always right?) search pings, and conclude that there is some amplifier attack happening if the signal is much stronger than usual. Even if there is no signal reflected usually, wouldn't this amplifier be more or less omnidirectional (they don't know where your key is right now). If so, a stronger than expected "reflected" ping can still be recognized. What am I missing?
- TheLoneWolfling 11y agoYou can relatively easily set up an amplifier with a directional antenna. Also, that will easily false positive - there are a lot of things that reflect RF in weird ways.
- anu7df 11y agoA lot of things will reflect RF in weird ways, and that is precisely what I was counting on. Surely an amplifier that changes the detection range from 1 feet to 100 feet will be emitting much much higher energy than what is usually experienced under normal operation. I guess, the antenna does not have to be omnidirectional as long as the attacker can search around the direction the key is likely to be.
- mentat 11y agoIt should be able to triangulate the response and normalize for signal strength at a known distance with standard hardware. Of course on could still make an amp to do full emulation but it would become at least more expensive.
- derekp7 11y agoHave the key fob beep or buzz when it gets used, along with a panic button that the user could hit on the fob to force the car off and set off the alarm. To defeat against the attacker cuts off the amplifier just after getting the car started, have the car shut off if it loses contact with the key fob within the first 15 seconds. Edit: just thought of another possibility -- use spread spectrum. An amplifier would have to be tuned to a specific frequency. With spread spectrum, the car and key fob switches frequencies every second based on a cryptographic function, therefore defeating the amplifier.
- TheLoneWolfling 11y agoAn amplifier doesn't need to be tuned to a specific frequency. Look at SDRs. You can "tune" an SDR to tunnel an entire large chunk of spectrum.
- Syrup-tan 11y agoAdding on the idea of a specific frequency; what if the car also sends a few ``honeypot'' signals at different frequencies, near the real frequency. If the attack tries to amplify a given range, the honey pot signals will also be amplified, and the car can refuse to be opened.
- TheLoneWolfling 11y agoYou're assuming omnidirectional amplification. It's easy enough to amplify without leaking more signal back to the source than, say, a metal-faced wall would.
- raisedbyninjas 11y agoI think including a keyfob buzzer would be a hard sell. The whole purpose of these keyless entry systems is convenience and asking buyers to hover over their keyfob like a baby monitor is not convenient (nor cheap).
- windsurfer 11y agoThe root of the problem isn't encryption or communication but rather than the key fob's location is data in the clear and easily tampered with. That data is the signal strength and/or triangulation of the fob's signal. The fob has no knowledge of it's own location, so the car must figure it out on it's own, allowing the attack to occur. If you gave the key fob some way of calculating it's position relative to the car, you may be able to transmit that to the car over the existing communication channel and have the car verify it. The question then becomes: how can one give the tiny computer in a key fob independent access to it's location relative to a car? An inertial navigation system[1] would probably be cheapest and most power-efficient. Though they suffer from inertial drift, that could be mitigated by periodic re-calibration while the car is driving and then parks (and the occasional non-keyless entry). The key fob then only transmits a signal when it detects that it's close enough, and the problem is "solved". Now you just need to replace the batteries on your keys every few weeks... [1]:https://en.wikipedia.org/wiki/Inertial_navigation_system https://en.wikipedia.org/wiki/Inertial_navigation_system
- javadocmd 11y agoProvide small Faraday cages in which to keep your keys when not in use.
- guelo 11y agoWhat about using noise? There's probably some math where amplification would change the level of the noise relative to the level of the signal.
- mod 11y agoFor anyone else who didn't know, I looked up what this is [1]. Essentially it boosts the search range for vehicles from a few feet to something more like 100 meters, when searching for wireless key devices. Then the car will unlock as if the device were very close. The devices are very inexpensive and starting to see increased use. [1] http://www.networkworld.com/article/2909589/microsoft-subnet/thieves-can-use-17-power-amplifier-to-break-into-cars-with-remote-keyless-systems.html http://www.networkworld.com/article/2909589/microsoft-subnet...
- rasur 11y agoYou don't even need to buy an amplifier. You can stick the key against your head and the water in your brain will amplify the signal. Bonus points for taking a plastic container of water for even further extension of the range!
- Flockster 11y agoIs there a source for that? I find it hard to believe.
- MiguelHudnandez 11y agoSome googling yields this discussion: http://physics.stackexchange.com/questions/101913/why-does-a-remote-car-key-work-when-held-to-your-head-body http://physics.stackexchange.com/questions/101913/why-does-a...
- deleted 11y ago[deleted]
- i_cannot_hack 11y agoSee this video by Sixty Symbols: https://www.youtube.com/watch?v=0Uqf71muwWc https://www.youtube.com/watch?v=0Uqf71muwWc
- rasur 11y agoI did too, but I saw this video (which is part of the very entertaining Sixty Symbols series, btw) which had a demonstration. https://www.youtube.com/watch?v=0Uqf71muwWc https://www.youtube.com/watch?v=0Uqf71muwWc EDIT: i_cannot_hack got the link in before me. Kudos ;)
- TheLoneWolfling 11y agoAgreed. There are far too many attacks that get ignored because they don't match the company's threat model, in general, and this is no exception.
- netcan 11y agoOf all the gadgety improvements cars have picked up over the last 10 years, keys are both the most "oooh!" invoking and the most useless, IMO. Normal keys work great. I don't see the big advantage of techno-keys that outweighs the (almost inevitable) cost of paying so much for a spare.
- Goronmon 11y agoBeing able to keep your keys in your pocket/purse/etc when entering and driving a car I find to be a pretty big upside. Especially in areas where it can be cold enough to freeze the key mechanism on your car door.
- derekp7 11y agoThe drawback is if you left your keys on the bench in the garage next to your car. You get in, push the button to start, then drive off. Now you can't get back home. At least with the physical key you are guaranteed to have it with you. The other thing -- do the key fobs have an on/off switch? If not, you wouldn't be able to have a spare "hidden" under your car somewhere (yes this is insecure anyway, but it works for most people).
- CPLX 11y agoMost key fobs have some kind of failback system that looks like a real/normal metal key.
- dangrossman 11y ago> do the key fobs have an on/off switch? Pop out the battery. You don't need the battery to use the hidden spare if you lose your key: there's a physical key hidden inside the fob to unlock the door, then a slot on the dash to stick the whole fob into to start the car. It's there so you can't be stuck unable to start your car when the fob's battery dies. http://i.imgur.com/uBeach6.jpg http://i.imgur.com/uBeach6.jpg
- blub 11y agoI think (some) cars actually know whether the key is inside or outside the vehicle and can't be started if it's outside.
- sprkyco 11y agoWouldn't say they are in denial about the issue. Wish I had some better sources, but if I recall the automotive industry has always had issues with security regarding keys and ignitions. My 99 Prizm key would work for most all other Chevy Prizm cars. I know that this "cross keying" would work on quite a few different brands and models as well. Some ignitions can be "popped" and screwdrivers used to start the ignition. My point being that security of starting an automobile or accessing one has been plagues with problems. Break the window etc. Some manufacturers do require the key fob to be present while the motor is running in some cases the feul pump will shut off if the key is not present. It is highly likely that the Tesla demo is for opening the CAN exploitability issue to the convention. Attacks on the CAN remotely are much more serious.
- hn_ 11y ago>My 99 Prizm key would work for most all other Chevy Prizm cars. I know that this "cross keying" would work on quite a few different brands and models as well. Back in the later 80s my parents had a Toyota van. One day my mom accidentally started it with her house key. We then realized that pretty much anything that fit partway into the ignition started it. Many years later the key got lost and we kept a screw driver in the cup holder to start it. It was a little odd driving around without a key in the ignition.... always thought cops would get suspicious.
- knodi123 11y ago> My 99 Prizm key would work for most all other Chevy Prizm cars. I accidentally stole a bike in college, because it was the same brand as mine, and had the same brand of lock. Got all the way back to my dorm before I realized that the reason the seat felt weird was that it wasn't mine. But my key worked! I also used my apartment deadbolt key to let my girlfriend into her house when she accidentally got locked out. She was both horrified and grateful that it worked. (I expected that one to fail, but I figured why not try?) I'm not sure what the trick is to finding locks that aren't vulnerable to this trick. I suspect it's "buy locks at least 50% more expensive than the cheapest option", but that's just a guess.
- Retra 11y ago
- cheald 11y agoCan someone explain how this works? Naively, I'd expect that this is just a signal amplifier, which boosts the signal from the key fob to a level where the car will accept it as close enough (via inverse square law computations and a known transmit power). But the key fob would have to transmit far enough to reach the amplification point, no? If I have my keys in my pocket in my house, how is the key fob going to be putting out enough juice to reach more than a couple of feet, let alone through walls?
- etcet 11y agoStart reading http://media.hacking-lab.com/scs3/scs3_pdf/SCS3_2011_Capkun.pdf http://media.hacking-lab.com/scs3/scs3_pdf/SCS3_2011_Capkun.... at page 16. They were able to perform an attack with a relay 8m from the key. I particularly like this implication they present: Relay on a parking lot One antenna near the elevator Attacker at the car while car owner waits for the elevator Also, the radio jamming attack described on page 10 is so simple but isn't something I've considered before. Basically you just jam the right frequency before the victim presses the 'lock' button and you now have access to their car (if they didn't notice).
- cheald 11y agoWow, I am legitimately shocked that the fob is capable of transmitting that far. I'd have thought that the "is the key in close proximity to the car" transmitters would be intentionally range-limited. Great link, thank you.
- dror 11y agoIf you want to play it safe, I suspect something like http://smile.amazon.com/Anti-tracking-Anti-spying-Blocker-Handset-Function/dp/B00ITR3KCQ/ http://smile.amazon.com/Anti-tracking-Anti-spying-Blocker-Ha... would block the signal.
- takeda 11y agoWhat about just adding a switch to the fob, to disable it?