Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

161–170 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#161
post #8

My question is if VW has switched the affected stuff in newer models since they found out about the issues?

Yes, as people mentioned above. It’s long fixed, and only a tiny set of cars (only high-end models with keyless entry) were even affected at all.

Source please, as I understand it current VW cars themselves are not vulnerable but some other VAG brands still use these vulnerable immobilizers to this day. That might be bad reporting though. The only reliable detail I have found is from the paper itself. "We understand that measures have been taken to prevent the weak key and partial key update attacks when the transponder was improperly configured."

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#162
post #83

Earlier quoted context omitted.

I doubt you'd say that if you owned one of the affected VWs.

One might, if one had purchased a VW during the years this paper was censored.

Except that VW at somepoint quit using the transponder in question because of this issue so new cars made are no longer susceptible.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#163
So why were the researchers willing to publish a redacted version now, but were not willing to publish the redacted version 3 years ago when they were researching the issue?

I am actually curious because this is the only part of this whole thing that does not make sense to me. Even if I disagree with Volkswagon's decision to not notify existing owners that there was a vulnerability known or eventually provide them with a fix, the decision at least makes sense because it probably was deemed more profitable for VW.

"The scientists wanted to publish their paper at the well-respected Usenix Security Symposium in Washington DC in August, but the court has imposed an interim injunction. Volkswagen had asked the scientists to publish a redacted version of their paper – Dismantling Megamos Crypto: Wirelessly Lockpicking a Vehicle Immobiliser – without the codes, but they declined."

http://www.theguardian.com/technology/2013/jul/26/scientist-...

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#164
post #5

To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry. It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasin…

Most people do not have a background in security so this is anything but a 'duh' moment for them. The more news like this that makes it to the mainstream media, the more hopeful I am that regular folks will learn the state of security today.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#165

Earlier quoted context omitted.

What if the car was parked in a handicapped spot near entrance of a football stadium? It could conceivably receive enough incorrect RFID signals to trigger a back-off.

I don't know anything about the protocols involved, but it would be possible for the first message to be "I'm a key that would like to unlock the vehicle with VIN# 123abc...". In that case there would be no mistaken protocol runs.

There is no key as such. The fob for my Hyundai never leaves my pocket. Just by standing next to the car, the unlock button on the door is enabled. So if I walk up and push the button, it unlocks. If I'm not around, the button does nothing.

So there's no discernible event from the fob, as far as I can see. It's just a "this is me" signal.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#166
For an analogy you can look inside a car engine take it appart verify its components. But if you take a look inside the software and take it apart you are suddenly potentially breaking license agreements. This agreements violate free speech if you find something you may not tell others about it or risk getting sued.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#167
post #144

Earlier quoted context omitted.

In particular, it's not necessarily worse than the status quo ante. Cars had mechanical locks, which were pickable. A "slim jim" could unlock many cars. Once you were in the door, you could hotwire the ignition. So to be able to defeat a computerized anti-theft system... no gain from the computerization, but is there any loss from it?

The difference is that physical attacks require 1) individual skills and 2) prolonged physical contact in compromising pose. Where every single thief had to be a skilled lockpicker before, now you just need a few specialized crackers and then you can mass-produce user-friendly hacking devices or even downloadable software. Where a thief had to spend several minutes in a compromising pose near the car, often carrying…

a thief had to spend several minutes in a compromising pose near the car

A couple of weeks ago I saw someone using a slimjim, and I did nothing. I have never done anything in reaction to a car alarm. I'm not sure that thief's pose is sufficiently compromising.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#168

Earlier quoted context omitted.

IDK about "far outside the realm of the typical car thief". Not that the typical car thief is going to be trailblazing the research, but once the research is done, it just takes someone putting a black box VW keyless unlocker together, and then it's in the realm of the typical car thief. In fact, at that point you're talking about the break in being the simplest part of the theft, with fencing being much more difficu…

You really think your typical car thief is going to go find and purchase specialized tools? As always, relevant XKCD: https://xkcd.com/538/

Uhm... these sort of tools are being developed and purchased all the time in black markets.

See http://krebsonsecurity.com/ for plenty of examples.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#169
post #100

I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back t…

I saw a report a while back that if you put your car keys in the freezer or something it blocks enough of the signal from your keys so that someone can't use this signal repeater to unlock your car, it's supposed to act like a Faraday cage (somewhat). I know it sounds stupid but I remember seeing it on HackerNews a while back. I'm not sure if it was debunked or not.

I can't find the HN link, but I think this is the article you are referring to:

http://www.networkworld.com/article/2909589/microsoft-subnet...

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#170

Articles like this make me love my 2000 Subaru even more. I'm gonna hate getting a newer car one day, but maybe by then manufacturers will better secure their cars.

You should look at crash tests results of your 2000 Subaru and a car more modern than 2013 and decide which you'd rather be in in the result of a crash. I'm less scared of a potential hacker cutting power to my car than I am of the millions of poor drivers cutting lanes and changing lanes without signals (or even looking) resulting in an auto accident.

Things started improving in the 90's (falling from 143m to 115m). In 2000 it was at 112m. 2008 saw the sharpest decline - down to 78m. In 2012 it was 65m.

The difference between 112m and 65m is staggering - and is largely due to newer, safer cars being on the road.

All figures above are driver deaths per million for registered vehicles taken from: http://www.iihs.org/iihs/sr/statusreport/article/50/1/1

E:

Although Subaru has a good track record of safety. I just think the fear is misplaced. For most people driving older cars, I'd be far more scared about my safety during a crash than my safety from a potential hacker.

Both are of concern, of course.

Post reply on HN