Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

71–80 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#71

"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." What a nightmare. Car manufacturers have to design more resilient systems. Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side. If so, they will also have to think about…

> a quick way to deploy security fixes remotely

Right, what could possibly go wrong?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#72
post #23

Earlier quoted context omitted.

96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.

What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.

What if the car was parked in a handicapped spot near entrance of a football stadium? It could conceivably receive enough incorrect RFID signals to trigger a back-off.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#73
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

The article isn't about people remotely taking over cars or disabling cars. It's that the anti-theft system has a flaw. That's not nothing, but it doesn't put anyone's safety at risk.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#74
post #35
post #27

The "new" (actually 2 years old) thing is the UK courts granting injunctions preventing the publication of security research from a well known UK university. WTF. http://www.theguardian.com/technology/2013/jul/30/car-hackin...

Right, the money quote in the article is: > The research team first took its findings to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013. The car-maker filed a lawsuit to block the publication of the paper - arguing that its vehicles would be placed at risk of theft - and was awarded an injunction in the U.K.'s High Court. But then they don't detail the legal situation that l…

People are usually bad understanding counter intuitive notions such as the fact that making security flaws public actually makes consumers more secure, not less.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#75

Earlier quoted context omitted.

What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.

What if the car was parked in a handicapped spot near entrance of a football stadium? It could conceivably receive enough incorrect RFID signals to trigger a back-off.

Since this is an anti-theft system, not a safety system, I can totally see that VW made a rational decision "it's better for the anti-theft system to let a thief steal the car 50 times than for one person to legitimately get locked out of their car."

You can make up for car thefts with dollars.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#76
post #29

Earlier quoted context omitted.

Well, the advantage of VW is that the car itself is pretty secure. All messages on the CANBUS are securely signed, there are multiple rings of security where data can always pass only in one direction, etc. The only thing this exploit enables is that if you already have the car, managed to break the steering wheel lock, managed to replicate the magnetic signature of the key, and managed to start the motor, that you c…

Wait, so VW has an RFID immobilizer and a physical key? I've only ever seen cars having one or the other.

FWIW my honda has a real physical key with an rfid chip. So just duplicating the key won't work unless I get a key with a chip.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#77
post #29

"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." What a nightmare. Car manufacturers have to design more resilient systems. Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side. If so, they will also have to think about…

Well, the advantage of VW is that the car itself is pretty secure. All messages on the CANBUS are securely signed, there are multiple rings of security where data can always pass only in one direction, etc. The only thing this exploit enables is that if you already have the car, managed to break the steering wheel lock, managed to replicate the magnetic signature of the key, and managed to start the motor, that you c…

Is this a specific feature of VW's implementation of CAN? CAN in general (at least not in 2007 when I last worked in the industry) is not secured. The only real security once you had access to the CAN bus were the separate rings (although several modules bridged). You probably couldn't start the car and keep it started unless you figured out the variant of crypto handshake used between whatever did ignition/skim/rke and the engine (sometimes public key, sometimes symmetric, often with some sketchy cipher implemented by modules that would offer full memory access via debug protocols if you asked the right way). If you had access to the spec for messages for the machines, access to the CAN bus can do some very cool/scary things.

Depending on how the car manufacturer spec'd the engineskim handshake, you might get as lucky as to just be able to isolate the offending skim/rke unit and MITM/replay its messages. If the rke and skim units are separate, there's an outside chance that the beacon that is sent after remote-start that lets the engine know not to turn off doesn't contain a secret key itself and can be replayed. In any event, I'd assume that physical access to the vehicle means that a kit could be deployed in minutes to steal the vehicle without any fuss.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#79
post #13

In VW's defence it sounds like they just sourced the parts from Megamos who is ultimately responsible for the flaw

Unless VW is significantly different than GM and Daimler, Megamos likely had very little control over the protocol and messages being sent. They would be given a simulation of the vehicle bus that they would be expected to duplicate exactly. A full spec would be given providing state diagrams for each message and its handling. Megamos engineers would be able to offer suggestions, but the message structure and overall protocol would have been outside their control.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#80
post #48

Earlier quoted context omitted.

That could be exploited to produce a trivial denial-of-service attack.

Wouldn’t you need to have a device actively running within a few feet of the vehicle to run such an attack? Couldn’t the car start blaring an alarm or something in that case? We’re not talking about a website here.

> Wouldn’t you need to have a device actively running within a few feet of the vehicle to run such an attack?

Nope. Just a high-gain antenna.

> Couldn’t the car start blaring an alarm or something in that case?

It could. But that might not help.

For example: you're driving your Mazerati down the road when it suddenly stops and the alarm goes off. The next day you get a letter saying, "If you don't want yesterday's little incident to become a regular event, send BTC500 to the following address...."

Post reply on HN