Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

21–30 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#21
"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs."

What a nightmare. Car manufacturers have to design more resilient systems.

Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side.

If so, they will also have to think about a quick way to deploy security fixes remotely. One way could be working with connectivity solutions for Embedded Systems (e.g. SigFox).

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#22
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

The attack vectors available for use against a corporation is infinitely larger than those available for a car. It's not really a fair comparison.

Yeah, that's kind of a weird comparison. You can't really tailgate someone through a car door to gain physical access, or social engineer your way to the car's server closet, or spam the car's employees with phishing e-mails.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#23

Earlier quoted context omitted.

The attack vectors available for use against a corporation is infinitely larger than those available for a car. It's not really a fair comparison.

Not only that - but the 'duh' moment for me was the 96bit key size.

96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#24

So has VW taken advantage of the time given to them by the courts to release fixed transponders in new vehicles and slowly replace the current defective ones as part of a routine service? Otherwise they've just delayed the information getting out which seems pointless?

Not pointless - that is two years of executive compensation which has not been impacted by costly recalls.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#26
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

The attack vectors available for use against a corporation is infinitely larger than those available for a car. It's not really a fair comparison.

It was a general point about the state of computer security. In 2015, if you're connecting a computer to the internet, you're vulnerable. If your computer has non-trivial wireless functionality (in this case, keyless entry), you're vulnerable. The only question is whether someone cares enough to hack you, in particular.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#28

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Theft of newer-model cars is extremely rare and I don't think vulnerabilities will change that much. Anything that requires computers at all is going to be beyond the average car thief.

If you're worried about safety, buy a car with a good crash safety rating. You're far more likely to get into a normal crash due to bad human drivers or mechanical failures than you are to be hacked.

If you're worried about the financial loss from a crash or theft, your best protection is good insurance.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#29

"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." What a nightmare. Car manufacturers have to design more resilient systems. Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side. If so, they will also have to think about…

Well, the advantage of VW is that the car itself is pretty secure.

All messages on the CANBUS are securely signed, there are multiple rings of security where data can always pass only in one direction, etc.

The only thing this exploit enables is that if you already have the car, managed to break the steering wheel lock, managed to replicate the magnetic signature of the key, and managed to start the motor, that you can circumvent the immobilizer that comes after that.

This is a pretty minor flaw compared to the "full control via radio" that competitors had.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#30

So has VW taken advantage of the time given to them by the courts to release fixed transponders in new vehicles and slowly replace the current defective ones as part of a routine service? Otherwise they've just delayed the information getting out which seems pointless?

Yes, that flaw has been fixed in the latest models.
Post reply on HN