Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

111–120 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#111

Earlier quoted context omitted.

It's obviously not a safety recall, but that doesn't mean it isn't serious. Other companies have been known to do voluntary recalls defective locks, why is VAG exempted in your mind? "It barely can even be considered an immobiliser" is almost certainly contrary to reasonable consumer expectations, and it wouldn't surprise me if the EU, at least, had laws regarding this kind of issue.

It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.

You really think someone couldn't automate this, and sell the black box (or executable) to car thieves?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#112
post #74

Earlier quoted context omitted.

People are usually bad understanding counter intuitive notions such as the fact that making security flaws public actually makes consumers more secure, not less.

Detailing how this works publicly makes nobody more secure. Public release of the general problem is still worthwhile as information, but there is a net "security" loss here.

Immediately there is but what about long term? If industries know that researchers will post the vulnerabilities all over the net as soon as they find it, it may change their security behavior in a way that is a net positive to security.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#113

"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." What a nightmare. Car manufacturers have to design more resilient systems. Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side. If so, they will also have to think about…

> If so, they will also have to think about a quick way to deploy security fixes remotely. One way could be working with connectivity solutions for Embedded Systems (e.g. SigFox).

Something tells me giving the car's immobilization system a routable IP address is not the best way to "fix security"

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#114
post #29

Earlier quoted context omitted.

Well, the advantage of VW is that the car itself is pretty secure. All messages on the CANBUS are securely signed, there are multiple rings of security where data can always pass only in one direction, etc. The only thing this exploit enables is that if you already have the car, managed to break the steering wheel lock, managed to replicate the magnetic signature of the key, and managed to start the motor, that you c…

Wait, so VW has an RFID immobilizer and a physical key? I've only ever seen cars having one or the other.

All European cars since 1998 will have both, because immobilizers are required by law in most of Western Europe.

On most cars, you'll never notice the immobilizer as it's RFID based, passive, and requires no batteries. The only way you'd find it is if you take apart the key fob or have to service the ignition lock, at which point you'll find the RFID antenna ring around it, or if you try to get the key replaced.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#115
post #100

I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back t…

Your anecdote doesn't share anything in common with the article. One of two things are likely - your car wasn't actually locked this nights, or the theirs used a signal amplifier to make the car think your keys inside the house were next to your car.

Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it. Otherwise live with the consequences.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#116
post #108

Earlier quoted context omitted.

It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.

> It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief. It wouldn't fill me with warm and fuzzies if I were sold a high-end door lock / alarm system / safe that was only exploitable with 'special gear and know-how far outside the realm of the typical thief.'

>It wouldn't fill me with warm and fuzzies if I were sold a high-end door lock / alarm system / safe that was only exploitable with 'special gear and know-how far outside the realm of the typical thief.'

Then you'd better never buy a high-end door lock / alarm system / safe, they all have that in common.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#117
post #100

I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back t…

Your anecdote doesn't share anything in common with the article. One of two things are likely - your car wasn't actually locked this nights, or the theirs used a signal amplifier to make the car think your keys inside the house were next to your car. Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it…

It doesn't share much in common with the article, but I believe this immediately because the same thing happened three times over the last two years with different people in my street. All with new and rather nice Audi models. Opened without any damage, the dashboard completely rampaged (nav, radio, airbags etc removed)

I won't be surprised if there's another, even more serious vulnerability in Volkswagen locks. The security researcher who found it probably sold it to the bad guys, totally understandable after reading how Volkswagen handles security reports.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#118
post #48

Earlier quoted context omitted.

That could be exploited to produce a trivial denial-of-service attack.

Wouldn’t you need to have a device actively running within a few feet of the vehicle to run such an attack? Couldn’t the car start blaring an alarm or something in that case? We’re not talking about a website here.

..plus a high-gain antenna, and suddenly you have an attack that sets off every car alarm in the city at once.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#119
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

"I see three possible outcomes, in decreasing order of likelihood: status quo, where they just "fix" the bugs as they hit the news; some sort of massive push towards real computer security, in this and other industries; or a massive reduction in features to avoid the flaws."

Only one of those three is the correct answer, and it is the third one.

Your car does not need a wireless network - since you have a newer, nicer one in your pocket every 18 months.

Neither does your refrigerator nor your smoke detector.

These are self-inflicted problems and they're easy to solve - just remove the gratuitous complexity.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#120
post #9

Earlier quoted context omitted.

As far as my limited understanding goes using the the key fob for remote central locking does not expose any risk, instead its the immobiliser part, so manually opening your door with the physical key provides no extra safety, its when the key is present near the ignition barrel, thats where the immobiliser kicks in and where this venerability exists

From what I understand, they have to capture two uses of the key fob to be able to brute force, so if you don't use it then they can't capture anything. Or they just captured two uses from a random car and now it'll work on any car. I wish the article went into more detail.

As bri3d has mentioned, I think you are confused because the key actually has three independent functions and you need to make the distinction between them all.

    - Remote central locking via UHF
    - Immobiliser authentication via RFID (this is what is vulnerable) 
    - Key for the ignition barrel or manual unlocking of doors
Post reply on HN