Earlier quoted context omitted.
> Anything that requires computers at all is going to be beyond the average car thief. Not for long.
Well sure, pretty much by definition. Car thieves who can't handle technology will eventually have to stop stealing cars. There are only so many late 90s Honda Accords out there to be stolen, after all, and they aren't making any more. But I really doubt that all the thieves out there will learn fancy technology so they can steal newer cars. A few will, but most will find other things to steal. Right now, popular new…
VW Has Spent Two Years Trying to Hide a Big Security Flaw
41–50 of 226 posts
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#42Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#43Earlier quoted context omitted.
Not only that - but the 'duh' moment for me was the 96bit key size.
96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.
Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#44So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?
Don't buy a high end car that has a high theft rate. Research theft rates like you would reliability and resale. Buy a plain vanilla mid-level toyota, honda or the like. Insure your car.
It has been this way for about two decades. It is much easier for thieves to slice-and-dice a common vehicle into hard-to-trace parts, since the hot parts will disappear into a sea of legitimate used and reconditioned parts. High-end cars are comparatively rare, and thus harder to dispose of discreetly.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#45ITT: nobody so far advocating "responsible disclosure", because this is the sort of vendor abusiveness that made "full disclosure" clearly a good idea, and an essential protection for the interests of the end user . The Internet of Things will recapitulate all the painful experience of how this stuff works out we just spent twenty years getting sorted out in the software field.
Even though these cars aren't a part of the internet of things (yet), situations like these are the exact reasons why I'm not enthusiastic about it. Honestly, I hate it.
Whenever anyone says "Internet of Things", reply "unfixable Heartbleed everywhere forever."
Sysadmins will be in work until we're 100 if we want to be, cleaning up after this rubbish. Like elderly COBOL programmers, making the big bucks after retirement.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#46Non issue to me. Typical media and security professionals hyperbole. I have car insurance for my Porsche . According to the list it's vulnerable. Chance of getting stolen? Quite small. If it does insurance pays in my case the full value not the depreciated value (age of car as only one reason). Not something I am worrying about. How many cars are actually stolen as a result of this flaw? Just another example of the s…
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#47Besides locking your car into a garage, is there anything a VW owner can do to make it more difficult for these types of thefts to occur?
You could always use a club: http://www.amazon.com/Club-1000-Original-Steering-Wheel/dp/B... But anyone waiting to spend 30 minutes with an electronic crack is also smart enough to use liquid nitrogen to crack this too. The difference is that a keyless hack can look natural since there is no physical force for entry or ignition. A funnel and chisel would raise some eyebrows.
The full paper here: https://www.usenix.org/sites/default/files/sec15_supplement.... has a lot better detail.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#48Earlier quoted context omitted.
96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.
What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#49Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#50Earlier quoted context omitted.
If the article is accurate, avoiding use of the key fob should make it more difficult for the attack to be carried out (which admittedly isn't very useful).
As far as my limited understanding goes using the the key fob for remote central locking does not expose any risk, instead its the immobiliser part, so manually opening your door with the physical key provides no extra safety, its when the key is present near the ignition barrel, thats where the immobiliser kicks in and where this venerability exists