Earlier quoted context omitted.
It's obviously not a safety recall, but that doesn't mean it isn't serious. Other companies have been known to do voluntary recalls defective locks, why is VAG exempted in your mind? "It barely can even be considered an immobiliser" is almost certainly contrary to reasonable consumer expectations, and it wouldn't surprise me if the EU, at least, had laws regarding this kind of issue.
It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.
VW Has Spent Two Years Trying to Hide a Big Security Flaw
111–120 of 226 posts
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#112Earlier quoted context omitted.
People are usually bad understanding counter intuitive notions such as the fact that making security flaws public actually makes consumers more secure, not less.
Detailing how this works publicly makes nobody more secure. Public release of the general problem is still worthwhile as information, but there is a net "security" loss here.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#113"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." What a nightmare. Car manufacturers have to design more resilient systems. Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side. If so, they will also have to think about…
Something tells me giving the car's immobilization system a routable IP address is not the best way to "fix security"
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#114Earlier quoted context omitted.
Well, the advantage of VW is that the car itself is pretty secure. All messages on the CANBUS are securely signed, there are multiple rings of security where data can always pass only in one direction, etc. The only thing this exploit enables is that if you already have the car, managed to break the steering wheel lock, managed to replicate the magnetic signature of the key, and managed to start the motor, that you c…
Wait, so VW has an RFID immobilizer and a physical key? I've only ever seen cars having one or the other.
On most cars, you'll never notice the immobilizer as it's RFID based, passive, and requires no batteries. The only way you'd find it is if you take apart the key fob or have to service the ignition lock, at which point you'll find the RFID antenna ring around it, or if you try to get the key replaced.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#115I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back t…
Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it. Otherwise live with the consequences.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#116Earlier quoted context omitted.
It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.
> It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief. It wouldn't fill me with warm and fuzzies if I were sold a high-end door lock / alarm system / safe that was only exploitable with 'special gear and know-how far outside the realm of the typical thief.'
Then you'd better never buy a high-end door lock / alarm system / safe, they all have that in common.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#117I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back t…
Your anecdote doesn't share anything in common with the article. One of two things are likely - your car wasn't actually locked this nights, or the theirs used a signal amplifier to make the car think your keys inside the house were next to your car. Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it…
I won't be surprised if there's another, even more serious vulnerability in Volkswagen locks. The security researcher who found it probably sold it to the bad guys, totally understandable after reading how Volkswagen handles security reports.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#118Earlier quoted context omitted.
That could be exploited to produce a trivial denial-of-service attack.
Wouldn’t you need to have a device actively running within a few feet of the vehicle to run such an attack? Couldn’t the car start blaring an alarm or something in that case? We’re not talking about a website here.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#119To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…
Only one of those three is the correct answer, and it is the third one.
Your car does not need a wireless network - since you have a newer, nicer one in your pocket every 18 months.
Neither does your refrigerator nor your smoke detector.
These are self-inflicted problems and they're easy to solve - just remove the gratuitous complexity.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#120Earlier quoted context omitted.
As far as my limited understanding goes using the the key fob for remote central locking does not expose any risk, instead its the immobiliser part, so manually opening your door with the physical key provides no extra safety, its when the key is present near the ignition barrel, thats where the immobiliser kicks in and where this venerability exists
From what I understand, they have to capture two uses of the key fob to be able to brute force, so if you don't use it then they can't capture anything. Or they just captured two uses from a random car and now it'll work on any car. I wish the article went into more detail.
- Remote central locking via UHF
- Immobiliser authentication via RFID (this is what is vulnerable)
- Key for the ignition barrel or manual unlocking of doors