Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

141–150 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#141
post #30

So has VW taken advantage of the time given to them by the courts to release fixed transponders in new vehicles and slowly replace the current defective ones as part of a routine service? Otherwise they've just delayed the information getting out which seems pointless?

Yes, that flaw has been fixed in the latest models.

Source please, as I understand it VW cars themselves are not vulnerable but some other VAG brands still use these vulnerable immobilizers to this day.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#142
post #131

Honestly, everytime I hear about the latest new-and-shiny that car manufacturers try to put in new cars (such as stop-start, keyless ignition) I can't help but roll my eyes at the inevitable fail that this is going to bring. Sure these knick-knacks might look cool now, but what happens eight years down the line, when your electric system goes belly up in middle of the highway or at a traffic signal? VW is one of the…

I don't think start/stop belongs in your list of useless knick-knacks that are prone to failure -- the Prius has been in production for about 18 years, and it's used start/stop from the beginning to save fuel. But you don't hear of large numbers of Priuses stuck at red lights when their engine computer forgot how to start the engine. Start-stop can save significant fuel - 3% - 12% by some estimates, and it comes at v…

True. stop-start might have not been the best example in this case. But still, i would be quite apprehensive of buying a 10-year old european car that has stop-start built in - Much more than an equivalent toyota. Japanese are quite slow to follow in implementing new features and as a result (IMO) their implementations seem to be more reliable. I have experienced European cars to develop serious electrical issues over the years. Couple that with a stop-start system, and you are looking at an undrivable car.

edit: In the past couple of years things seemed to have mixed up a bit in the industry (for example American cars have quite improved in quality). So who knows, maybe today's cars might hold up much better 10 years into their life , than their predecessors. But increasing incorporation of software and electronics into these probably will not help them get there.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#143
Is it just me, or is the peak of stupidity in this episode the fact that the car will verify/reject a few hundred thousand passwords in 30 minutes?

Shouldn't that be security 101, limiting the rate to a couple per minute, max? Why allow such brute force attacks in the first place?

EDIT:

Or in other words, why is the phrase "brute force password attack" still even heard in 2015?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#144

Earlier quoted context omitted.

The article isn't about people remotely taking over cars or disabling cars. It's that the anti-theft system has a flaw. That's not nothing, but it doesn't put anyone's safety at risk.

In particular, it's not necessarily worse than the status quo ante. Cars had mechanical locks, which were pickable. A "slim jim" could unlock many cars. Once you were in the door, you could hotwire the ignition. So to be able to defeat a computerized anti-theft system... no gain from the computerization, but is there any loss from it?

The difference is that physical attacks require 1) individual skills and 2) prolonged physical contact in compromising pose.

Where every single thief had to be a skilled lockpicker before, now you just need a few specialized crackers and then you can mass-produce user-friendly hacking devices or even downloadable software.

Where a thief had to spend several minutes in a compromising pose near the car, often carrying suspicious tools, now he can just sit on a bench nearby, wait for the magic click and then choose the right moment to stroll in. A passerby might as well think he's the owner.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#145
post #132

Earlier quoted context omitted.

Your anecdote doesn't share anything in common with the article. One of two things are likely - your car wasn't actually locked this nights, or the theirs used a signal amplifier to make the car think your keys inside the house were next to your car. Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it…

No, my anecdote is more about a data point (well, three actually) indicating we don't really know how many ways there are to break into these cars, and that manufacturers are playing dumb, hence me not being surprised at the news that another one was found. If really the problem was relatively trivial, VW should have warned me on how to avoid it, and they didn't. It can't be a simple amplifier: it's not just proximit…

Well sure, but this is just a RF signal here, the objection to your anecdote is that on the face of it it has nothing whatsoever to do with good crypto

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#146
post #11

[deleted]

The Thai finance minister, apparently: http://www.smh.com.au/articles/2003/05/13/1052591776195.html "Suchart said he was on his way to give a speech to central bank officials from 17 countries when his ministry-assigned BMW car stalled on a road, not far from his house. The engine stopped, the air conditioning shut down, the doors got locked and the windows wouldn't roll down, he said, adding that he was trapped for…

I'm guessing the "no air" thing was a bit of translation error. Presumably he was referring to the ambient temperature in the car rising to dangerous levels in short order.

Is there no physical lock on the BMW? Unless he had the child safety locks on, there should always be a way to manually open the door (even if the latch is somewhat difficult to operate) when the vehicle loses power. It's a huge safety concern if you can be trapped in the car like that.

Maybe he has a driver and was riding in the back with the child safety locks on?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#147
post #13

In VW's defence it sounds like they just sourced the parts from Megamos who is ultimately responsible for the flaw

Right, because VW should blindly build parts into their vehicles without vetting the security they bring (especially when said part is in fact a security component). Tougher to do when vetting such a part requires expertise in the field, but blindly trusting the supplier is never a good practice.

Isn't the whole reason you farm out parts is because you don't have the expertise internal?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#148
post #109

Earlier quoted context omitted.

Detailing how this works publicly makes nobody more secure. Public release of the general problem is still worthwhile as information, but there is a net "security" loss here.

I disagree. Making a security flaw known forces manufacturers to fix it. As the article states, they went "to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013". Two years later the problem hasn't been fixed, because a recall would be too labor intensive. Meanwhile VWs are still being stolen using this exploit. Now that the exploit is out there VW is forced to act. And it's not…

The specifics of how to exploit it do not contribute to pushing the manufacturers to fix it. Disclosing the general vulnerability does, the specifics does not.

> Meanwhile VWs are still being stolen using this exploit

Holy fucking [CITATION NEEDED] batman!

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#149

Earlier quoted context omitted.

It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.

IDK about "far outside the realm of the typical car thief". Not that the typical car thief is going to be trailblazing the research, but once the research is done, it just takes someone putting a black box VW keyless unlocker together, and then it's in the realm of the typical car thief. In fact, at that point you're talking about the break in being the simplest part of the theft, with fencing being much more difficu…

You really think your typical car thief is going to go find and purchase specialized tools?

As always, relevant XKCD: https://xkcd.com/538/

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#150
post #134

Earlier quoted context omitted.

>It wouldn't fill me with warm and fuzzies if I were sold a high-end door lock / alarm system / safe that was only exploitable with 'special gear and know-how far outside the realm of the typical thief.' Then you'd better never buy a high-end door lock / alarm system / safe, they all have that in common.

I'm not familiar with the current state of physical security exploitation, but I get the sense that it would take more than 30 minutes and pushing the button on a black box someone built for me to compromise. Unlike this. The issue with electronic exploitation is that the know-how component is relatively trivially automated. Script kiddies, etc. If I bought an $80k Porche, I'd be bit miffed that it could be stolen fr…

It takes 10 seconds to bypass a window. Alarm systems are a deterrant, not prevention.
Post reply on HN