Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

121–130 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#121
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

The article isn't about people remotely taking over cars or disabling cars. It's that the anti-theft system has a flaw. That's not nothing, but it doesn't put anyone's safety at risk.

In particular, it's not necessarily worse than the status quo ante. Cars had mechanical locks, which were pickable. A "slim jim" could unlock many cars. Once you were in the door, you could hotwire the ignition. So to be able to defeat a computerized anti-theft system... no gain from the computerization, but is there any loss from it?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#122
post #56

Earlier quoted context omitted.

From what I understand, they have to capture two uses of the key fob to be able to brute force, so if you don't use it then they can't capture anything. Or they just captured two uses from a random car and now it'll work on any car. I wish the article went into more detail.

The paper is right here: https://www.usenix.org/sites/default/files/sec15_supplement.... They captured 2 uses of the RFID-based immobilizer. That gets used every time you start the car, regardless of how you unlocked the car. It's completely separate from the UHF-based keyless entry system which you use to unlock the car. The paper makes this distinction in the first paragraph, but of course the article fails to dist…

Ah okay, yeah I misunderstood what was happening here. Thanks for the info.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#123
post #48

Earlier quoted context omitted.

What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.

That could be exploited to produce a trivial denial-of-service attack.

I can think of other, lower tech, DoS attacks against cars -- which are also not much exploited.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#124
post #119
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

"I see three possible outcomes, in decreasing order of likelihood: status quo, where they just "fix" the bugs as they hit the news; some sort of massive push towards real computer security, in this and other industries; or a massive reduction in features to avoid the flaws." Only one of those three is the correct answer, and it is the third one. Your car does not need a wireless network - since you have a newer, nice…

If they're easy to solve, why hasn't that been done already?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#125
post #42

Happy to see the GTI not listed on there but why would that be any different from the other models? You think they would use the same across the board.

I'm pretty sure they sell them as the Golf GTI in Europe where the research was done, so probably included under the Golf model.

Ah, right. Good point.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#126

Earlier quoted context omitted.

The article isn't about people remotely taking over cars or disabling cars. It's that the anti-theft system has a flaw. That's not nothing, but it doesn't put anyone's safety at risk.

In particular, it's not necessarily worse than the status quo ante. Cars had mechanical locks, which were pickable. A "slim jim" could unlock many cars. Once you were in the door, you could hotwire the ignition. So to be able to defeat a computerized anti-theft system... no gain from the computerization, but is there any loss from it?

No gain implying that lockpicking a car and hacking it is of the same level of difficulty.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#127

Earlier quoted context omitted.

In particular, it's not necessarily worse than the status quo ante. Cars had mechanical locks, which were pickable. A "slim jim" could unlock many cars. Once you were in the door, you could hotwire the ignition. So to be able to defeat a computerized anti-theft system... no gain from the computerization, but is there any loss from it?

No gain implying that lockpicking a car and hacking it is of the same level of difficulty.

True, and they probably aren't. So which do you think is harder?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#128
post #119

Earlier quoted context omitted.

"I see three possible outcomes, in decreasing order of likelihood: status quo, where they just "fix" the bugs as they hit the news; some sort of massive push towards real computer security, in this and other industries; or a massive reduction in features to avoid the flaws." Only one of those three is the correct answer, and it is the third one. Your car does not need a wireless network - since you have a newer, nice…

If they're easy to solve, why hasn't that been done already?

Because the solution precludes the emergence of the multimillion dollar market called "The Internet of Things".

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#129

Earlier quoted context omitted.

In particular, it's not necessarily worse than the status quo ante. Cars had mechanical locks, which were pickable. A "slim jim" could unlock many cars. Once you were in the door, you could hotwire the ignition. So to be able to defeat a computerized anti-theft system... no gain from the computerization, but is there any loss from it?

No gain implying that lockpicking a car and hacking it is of the same level of difficulty.

Its not a matter of difficulty, but of reproducibility.

Mechanical locks imply that each individual thief needs to learn how pick locks. With computerized locks, you only need one hacker to crack the security for each model of car, and then a bunch of two-dime thugs will only need to download the app and get going in with the car-thief franchise.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#130
post #28

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Theft of newer-model cars is extremely rare and I don't think vulnerabilities will change that much. Anything that requires computers at all is going to be beyond the average car thief. If you're worried about safety, buy a car with a good crash safety rating. You're far more likely to get into a normal crash due to bad human drivers or mechanical failures than you are to be hacked. If you're worried about the financ…

You're making the mistake of assuming car thiefs are unintelligent or unorganized. Successful thefts that return a profit require a network of skilled people to pull off and talent can be found within that pool or recruited.

By saying a thief would have to understand how a computer exploit works, it's saying a thief needed the equivalence of an engineering degree to drive away with a car before computers entered the equation. Exploit discovery, maybe, but it doesn't take much to execute packaged tools you bought on the blackmarket.

Post reply on HN