Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

41–50 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#41
post #34

Earlier quoted context omitted.

> Anything that requires computers at all is going to be beyond the average car thief. Not for long.

Well sure, pretty much by definition. Car thieves who can't handle technology will eventually have to stop stealing cars. There are only so many late 90s Honda Accords out there to be stolen, after all, and they aren't making any more. But I really doubt that all the thieves out there will learn fancy technology so they can steal newer cars. A few will, but most will find other things to steal. Right now, popular new…

Oh, then there is a pretty open market on preconfigured "thief tools".

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#43
post #23

Earlier quoted context omitted.

Not only that - but the 'duh' moment for me was the 96bit key size.

96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.

What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed.

Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#44
post #36

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Don't buy a high end car that has a high theft rate. Research theft rates like you would reliability and resale. Buy a plain vanilla mid-level toyota, honda or the like. Insure your car.

The "plain vanilla" cars are the ones with the highest theft rate: http://www.forbes.com/sites/jimgorzelany/2014/08/18/the-most...

It has been this way for about two decades. It is much easier for thieves to slice-and-dice a common vehicle into hard-to-trace parts, since the hot parts will disappear into a sea of legitimate used and reconditioned parts. High-end cars are comparatively rare, and thus harder to dispose of discreetly.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#45

ITT: nobody so far advocating "responsible disclosure", because this is the sort of vendor abusiveness that made "full disclosure" clearly a good idea, and an essential protection for the interests of the end user . The Internet of Things will recapitulate all the painful experience of how this stuff works out we just spent twenty years getting sorted out in the software field.

Even though these cars aren't a part of the internet of things (yet), situations like these are the exact reasons why I'm not enthusiastic about it. Honestly, I hate it.

In the future, your Internet-enabled fridge will get hijacked by Russian spammers ... if the future is 2013. http://www.bbc.co.uk/news/technology-25780908

Whenever anyone says "Internet of Things", reply "unfixable Heartbleed everywhere forever."

Sysadmins will be in work until we're 100 if we want to be, cleaning up after this rubbish. Like elderly COBOL programmers, making the big bucks after retirement.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#46
post #39

Non issue to me. Typical media and security professionals hyperbole. I have car insurance for my Porsche . According to the list it's vulnerable. Chance of getting stolen? Quite small. If it does insurance pays in my case the full value not the depreciated value (age of car as only one reason). Not something I am worrying about. How many cars are actually stolen as a result of this flaw? Just another example of the s…

It wasn't the "security-industrial complex" that caused a security-incompetent vendor to use legal threats to try to suppress disclosure. That's the story here.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#47
post #2

Besides locking your car into a garage, is there anything a VW owner can do to make it more difficult for these types of thefts to occur?

You could always use a club: http://www.amazon.com/Club-1000-Original-Steering-Wheel/dp/B... But anyone waiting to spend 30 minutes with an electronic crack is also smart enough to use liquid nitrogen to crack this too. The difference is that a keyless hack can look natural since there is no physical force for entry or ignition. A funnel and chisel would raise some eyebrows.

This attack is against the RFID immobilizer for the engine, which means an attacker would have to break into the car, break the steering wheel lock and break the physical ignition lock prior to starting the car.

The full paper here: https://www.usenix.org/sites/default/files/sec15_supplement.... has a lot better detail.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#48
post #23

Earlier quoted context omitted.

96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.

What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.

That could be exploited to produce a trivial denial-of-service attack.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#49
If I read this correctly, the vulnerable vehicles are not really left in a worse state because of this defect. If they did not have cryptographic electronic start, they'd simply be vulnerable to old-fashioned hotwiring. I could be wrong, as I haven't been in a recent model, but I assume there is still a physical steering column lock that needs to be disabled, no?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#50
post #9

Earlier quoted context omitted.

If the article is accurate, avoiding use of the key fob should make it more difficult for the attack to be carried out (which admittedly isn't very useful).

As far as my limited understanding goes using the the key fob for remote central locking does not expose any risk, instead its the immobiliser part, so manually opening your door with the physical key provides no extra safety, its when the key is present near the ignition barrel, thats where the immobiliser kicks in and where this venerability exists

From what I understand, they have to capture two uses of the key fob to be able to brute force, so if you don't use it then they can't capture anything. Or they just captured two uses from a random car and now it'll work on any car. I wish the article went into more detail.
Post reply on HN