Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

91–100 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#91
post #35
post #27

The "new" (actually 2 years old) thing is the UK courts granting injunctions preventing the publication of security research from a well known UK university. WTF. http://www.theguardian.com/technology/2013/jul/30/car-hackin...

Right, the money quote in the article is: > The research team first took its findings to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013. The car-maker filed a lawsuit to block the publication of the paper - arguing that its vehicles would be placed at risk of theft - and was awarded an injunction in the U.K.'s High Court. But then they don't detail the legal situation that l…

It's in the article:

Now, after lengthy negotiations, the paper is finally in the public domain - with just one sentence redacted.

"This single sentence contains an explicit description of a component of the calculations on the chip," Verdult said, adding that by removing the sentence it was much more difficult to recreate the attack.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#92
post #83
post #74

Earlier quoted context omitted.

People are usually bad understanding counter intuitive notions such as the fact that making security flaws public actually makes consumers more secure, not less.

I doubt you'd say that if you owned one of the affected VWs.

but they got the key, so you can safely assume everybody else has or could. publishing it is the kind of pressure the manufacturer need from the public, otherwise people will do the same reasoning, kicking into 'secret = safe' mode even when it's completely pwnd - heck it's not even theoretical there is a paper on it with the extracted keys.

the fact you weren't affected is just because stealing a car is not the hardest part of the ordeal.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#93
post #83
post #74

Earlier quoted context omitted.

People are usually bad understanding counter intuitive notions such as the fact that making security flaws public actually makes consumers more secure, not less.

I doubt you'd say that if you owned one of the affected VWs.

One might, if one had purchased a VW during the years this paper was censored.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#94
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

What's the phrase? "Locks keep honest people honest." This has always been the case.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#95

Earlier quoted context omitted.

They've had the injunction for two years, but haven't initiated a recall in the meantime! "Cover up" sounds accurate to me.

A recall for what? There's no safety issue here. There's no functional loss. Unless they advertised the car as being unstealable or anything close there's not even a marketing point that's not working as one could reasonably expect. Carmakers call this a theft-deterrant feature, they don't even call it anti-theft or similar. The immobilizer is not as secure as one would hope, but nobody ever promised you anything her…

It's obviously not a safety recall, but that doesn't mean it isn't serious.

Other companies have been known to do voluntary recalls defective locks, why is VAG exempted in your mind?

"It barely can even be considered an immobiliser" is almost certainly contrary to reasonable consumer expectations, and it wouldn't surprise me if the EU, at least, had laws regarding this kind of issue.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#96
post #13

In VW's defence it sounds like they just sourced the parts from Megamos who is ultimately responsible for the flaw

Right, because VW should blindly build parts into their vehicles without vetting the security they bring (especially when said part is in fact a security component). Tougher to do when vetting such a part requires expertise in the field, but blindly trusting the supplier is never a good practice.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#97

Earlier quoted context omitted.

What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.

What if the car was parked in a handicapped spot near entrance of a football stadium? It could conceivably receive enough incorrect RFID signals to trigger a back-off.

I don't know anything about the protocols involved, but it would be possible for the first message to be "I'm a key that would like to unlock the vehicle with VIN# 123abc...". In that case there would be no mistaken protocol runs.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#98
post #58

Earlier quoted context omitted.

No, it's also an attack on the actual wireless key which is used to open and start the car. It's just making the car "think" that the key is inside, so you just press the Start button and the car starts, after which you drive it away like normal.

Fair, but only on cars which have only passive security (that is - where you don't need to use the fob to unlock the car and you don't need to use a physical key to turn the ignition).

Which is of course the stock configuration on most modern luxury vehicles.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#99

"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." What a nightmare. Car manufacturers have to design more resilient systems. Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side. If so, they will also have to think about…

I almost want my next car to have a physical key, but a digital one. Back after mechanical keys but before wireless entry/start, there was a short period where you had to plug the entire keyfob into the dash to start the car... I want that back. Mechanical keys have the "photograph" problem (i.e. a single photograph can be used to reproduce them). Wireless start has the wireless hacking problem (i.e. if you broadcast…

The mechanical keys used in VWs today can not be reproduced with photographing. They have non-standard cut-ins on both sides and also activate magnetical bolts inside the lock.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#100
I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back to me.

I'm not surprised in the slightest, I think this sort of news will keep popping up all over the place and manufacturers will keep trying hard to suppress it. We know it will never end: good crypto is hard and inconvenient, so it's unlikely that car manufacturers will ever implement it properly. Bad guys get all the info they need, eventually, so it's just a matter of time before any digital lock is broken.

Post reply on HN