Earlier quoted context omitted.
The article isn't about people remotely taking over cars or disabling cars. It's that the anti-theft system has a flaw. That's not nothing, but it doesn't put anyone's safety at risk.
In particular, it's not necessarily worse than the status quo ante. Cars had mechanical locks, which were pickable. A "slim jim" could unlock many cars. Once you were in the door, you could hotwire the ignition. So to be able to defeat a computerized anti-theft system... no gain from the computerization, but is there any loss from it?
VW Has Spent Two Years Trying to Hide a Big Security Flaw
151–160 of 226 posts
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#152Earlier quoted context omitted.
I don't think start/stop belongs in your list of useless knick-knacks that are prone to failure -- the Prius has been in production for about 18 years, and it's used start/stop from the beginning to save fuel. But you don't hear of large numbers of Priuses stuck at red lights when their engine computer forgot how to start the engine. Start-stop can save significant fuel - 3% - 12% by some estimates, and it comes at v…
True. stop-start might have not been the best example in this case. But still, i would be quite apprehensive of buying a 10-year old european car that has stop-start built in - Much more than an equivalent toyota. Japanese are quite slow to follow in implementing new features and as a result (IMO) their implementations seem to be more reliable. I have experienced European cars to develop serious electrical issues ove…
It's like switching a traditional light bulb on and off in a continuous way - it won't last years (some 100+ old light bulbs still work fine, but the were powered-off just a handful times).
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#153Earlier quoted context omitted.
No, my anecdote is more about a data point (well, three actually) indicating we don't really know how many ways there are to break into these cars, and that manufacturers are playing dumb, hence me not being surprised at the news that another one was found. If really the problem was relatively trivial, VW should have warned me on how to avoid it, and they didn't. It can't be a simple amplifier: it's not just proximit…
Well sure, but this is just a RF signal here, the objection to your anecdote is that on the face of it it has nothing whatsoever to do with good crypto
Whether my locks open with an easily-spoofable RF signal or with a bruteforceable key, the bottom line is still that they are not doing good crypto in situations where it's clearly necessary.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#154Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#155Earlier quoted context omitted.
True. stop-start might have not been the best example in this case. But still, i would be quite apprehensive of buying a 10-year old european car that has stop-start built in - Much more than an equivalent toyota. Japanese are quite slow to follow in implementing new features and as a result (IMO) their implementations seem to be more reliable. I have experienced European cars to develop serious electrical issues ove…
The continuous start-stop wears out the engine faster, so it won't last as long as an identical model with the same engine that hasn't that feature. It's like switching a traditional light bulb on and off in a continuous way - it won't last years (some 100+ old light bulbs still work fine, but the were powered-off just a handful times).
Yes, that too. Although I imagine it would wear out certain components of the engine (such as starter-motor, and crankshaft?) and battery rather than the engine as a whole.
Total-Cost-of-Ownership-wise, a stop-start might save more in fuel than it would cost in increased repairs (Or it may not, depending on make and model among other things).
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#156Earlier quoted context omitted.
I don't think start/stop belongs in your list of useless knick-knacks that are prone to failure -- the Prius has been in production for about 18 years, and it's used start/stop from the beginning to save fuel. But you don't hear of large numbers of Priuses stuck at red lights when their engine computer forgot how to start the engine. Start-stop can save significant fuel - 3% - 12% by some estimates, and it comes at v…
True. stop-start might have not been the best example in this case. But still, i would be quite apprehensive of buying a 10-year old european car that has stop-start built in - Much more than an equivalent toyota. Japanese are quite slow to follow in implementing new features and as a result (IMO) their implementations seem to be more reliable. I have experienced European cars to develop serious electrical issues ove…
See for yourself: http://www.nhtsa.gov/staticfiles/nvs/pdf/NASA_FR_Appendix_A_...
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#157Earlier quoted context omitted.
>It wouldn't fill me with warm and fuzzies if I were sold a high-end door lock / alarm system / safe that was only exploitable with 'special gear and know-how far outside the realm of the typical thief.' Then you'd better never buy a high-end door lock / alarm system / safe, they all have that in common.
I'm not familiar with the current state of physical security exploitation, but I get the sense that it would take more than 30 minutes and pushing the button on a black box someone built for me to compromise. Unlike this. The issue with electronic exploitation is that the know-how component is relatively trivially automated. Script kiddies, etc. If I bought an $80k Porche, I'd be bit miffed that it could be stolen fr…
If you bought an $80k Porshe you knowingly bought something you know will be a target for theft, and probably have enough money to have anti-theft insurance and be able to afford the inconvenience which would be your car vanishing. Yes apparently the ease of it being stolen is slightly greater than you thought when you bought it. But if not having your car stolen was a top priority for you then you would not of bought a car which people would want to steal as much.
As they mention in the article this would of been a difficult thing to fix on existing models, they did however change the system so it doesn't apply to new models.
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#158I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back t…
Your anecdote doesn't share anything in common with the article. One of two things are likely - your car wasn't actually locked this nights, or the theirs used a signal amplifier to make the car think your keys inside the house were next to your car. Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it…
Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw
#159Earlier quoted context omitted.
Your anecdote doesn't share anything in common with the article. One of two things are likely - your car wasn't actually locked this nights, or the theirs used a signal amplifier to make the car think your keys inside the house were next to your car. Neither of those things is VW's fault - if you don't like the wireless automatic door unlocking because the signal can be boosted maliciously, then you should disable it…
No, my anecdote is more about a data point (well, three actually) indicating we don't really know how many ways there are to break into these cars, and that manufacturers are playing dumb, hence me not being surprised at the news that another one was found. If really the problem was relatively trivial, VW should have warned me on how to avoid it, and they didn't. It can't be a simple amplifier: it's not just proximit…
I can imagine a design where the RF signal is being generated on a very low voltage/low power device that's always/permanently on, and pressing the button enables an integrated antenna that suddenly boosts the signal to a usable signal strength.
In that case, the attacker just has to simulate a increase in signal strength if they are already tapping your signal.
Electronic design doesn't follow the same rules as physical device designs - for example, that power button on your PC, it doesn't really close any circuit! It just tells the motherboard that it's ok to let voltage through a certain electrical pathway, the computer is already permanently on and is trickling power from AC / Mains.
You can use software to tell the motherboard to activate the same way that "pressing the button" does - ie remote server control over pxe, etc.
Most cars are always on trickling power from their battery waiting to hear that signal, I wouldn't be surprised if dongle design follow the same principle.