3 ms·
Somewhat of a tangent, but I am concerned about the MITM attack on car locks [1]. This kind of attack is being used in my neighborhood in Oakland, California an
by Cymen 11y ago
Somewhat of a tangent, but I am concerned about the MITM attack on car locks [1]. This kind of attack is being used in my neighborhood in Oakland, California and no doubt other places. I read the reports of "someone is breaking into my car but no windows/locks are broken". Then a couple other people on NextDoor chime in with the same thing and one person reports a woman who is walking around the neighborhood and appears to be the one responsible. A coworker explained a method where one can amplify the signal of the car and/or car key so that the car thinks the key is next to the car and the door unlocks.
The cryptographically secure garage door opener is still susceptible to MITM if the MITM attack is being done purely by amplification of signal, right?
It's almost like the key needs a handshake with the car by some method that is not using radio frequency. I wonder what options that leaves open? So far, I have not thought of one that is convenient (at some point, it is easier to go back to using a physical key to open a physical lock after all).
1. I think there was a post about it here already but I couldn't find it.
- cmdrfred 11y agoI don't think so, as far as I know a garage door opener has to be activated (you press the button) so that exact attack won't work.
- mrb 11y agoYeah, a car's passive entry system can definitely be exploited by relay attacks. Here is an academic group who demonstrated it: https://eprint.iacr.org/2010/332.pdf https://eprint.iacr.org/2010/332.pdf The most obvious way to mitigate is to have the car require the key to send the first bit of the response at most N nanoseconds after the last bit of the challenge is sent over the air. Because of the speed of light this assures the key is within a certain distance of the car. Ideally you want to constrain this to ~2 meters since passive entry requires the driver to touch the door handle. This limit is not to be confused with remote keyless entry which should work up to ~100 meters as it requires the driver to actively press a button so, like garage door openers, this is not vulnerable to relay attacks. However power-constrained MCUs, especially in the key, have a hard time computing a strong cryptographic challenge within N nanoseconds with N low enough, hence the problem... After my little foray into garage door openers I am currently looking into implementing relay attacks on the passive entry / passive go system of my car (2012 Audi). Fascinating stuff.
- tptacek 11y agoNeat; Aurelien is my co-chair for USENIX WOOT this year. Now that I know his name, I keep noticing amazing things he's worked on. Thanks for posting this.
- Cerium 11y agoThere are super low power accelerometers with wake on movement. Simply require the key be recently moved about to activate the door. If the key is not awake, it can't answer any challenges.
- twanvl 11y agoYou don't need to compute the challenge in N nanoseconds. Instead, the car could send a challenge, the key can compute it in however much time it likes. Then the car sends a one time pad, the key receives it and xors the otp with the challenge's response. Then it sends that. The cryptographic challenge makes it secure, the XORed one-time-pad allows for fast measurement of the round trip time.