Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

181–190 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#181
post #78

Earlier quoted context omitted.

True, but it might be handy for kidnappers.

We're veering into movie-plot territory here.

(not original responder)

That's true. On the subject of movies, though, a plot point based on an actual vulnerability would be way better than typical Hollywood hacking.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#182
FTA:

"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." ... "A VW spokesman responded: 'Volkswagen maintains its electronic as well as mechanical security measures technologically up-to-date and also offers innovative technologies in this sector.'"

Since they haven't recalled the vehicles and replaced the chips, that would be... not precisely true?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#183
post #23

Earlier quoted context omitted.

96 bits by itself probably isn't within reach of brute forcing - I assume the algorithm itself had flaws.

What I want to know is why the car will continue to accept 100 trial keys per second after the first 100,000 attempts failed. Shouldn’t there be some kind of exponential back-off after failures? If after the first 1000 failed keys it would only accept e.g. one new try every few seconds, it would then take 2–3 orders of magnitude more time to brute force.

To a car owner, that's another security flaw of its own. An attacker can deny an owner access to their car with a simple code spammer hidden nearby.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#185
post #134

Earlier quoted context omitted.

I'm not familiar with the current state of physical security exploitation, but I get the sense that it would take more than 30 minutes and pushing the button on a black box someone built for me to compromise. Unlike this. The issue with electronic exploitation is that the know-how component is relatively trivially automated. Script kiddies, etc. If I bought an $80k Porche, I'd be bit miffed that it could be stolen fr…

It takes 10 seconds to bypass a window. Alarm systems are a deterrant, not prevention.

True, but isn't the whole point of an alarm system to draw attention to the thieves? If a thief can bypass the alarm system or other security measures, it may not look they are stealing the car. This gives them a significant amount of time before law enforcement can be informed and greatly lessens the chance of them being caught.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#186
post #80

Earlier quoted context omitted.

> Wouldn’t you need to have a device actively running within a few feet of the vehicle to run such an attack? Nope. Just a high-gain antenna. > Couldn’t the car start blaring an alarm or something in that case? It could. But that might not help. For example: you're driving your Mazerati down the road when it suddenly stops and the alarm goes off. The next day you get a letter saying, "If you don't want yesterday's li…

If the car responds to RFID keys at all when driving, that is a flaw.

If I get out of my car with the engine still running it starts beeping. I don't know if it will actually turn the engine off, but it obviously knows that the key has departed the vehicle.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#187
post #173

Earlier quoted context omitted.

Yes, as people mentioned above. It’s long fixed, and only a tiny set of cars (only high-end models with keyless entry) were even affected at all.

> It’s long fixed, and only a tiny set of cars (only high-end models with keyless entry) were even affected at all. Some of the models on the list feature neither keyless entry, nor are high-end (the Audi A2, for example). While the Audi S2 may be considered high-end, it certainly wasn't available with keyless entry, and I wouldn't be suprised if the Audi 80/90 (which the S2 is based on) were affected, too.

Well, that’s nice – you have a car where you now disabled the immobilizer, but you’ll still need at least large tools and half an hour to break the steering wheel lock and the other stopping mechanisms.

Especially in cars without keyless entry the immobilizer is only one of dozens of mechanisms against theft.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#188
post #160

Earlier quoted context omitted.

I can think of other, lower tech, DoS attacks against cars -- which are also not much exploited.

Someone once DoS'd my car, by slashing two tires. On a downtown public street.

That sucks to have happened to you, but that sentence made me lol.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#189
post #48

Earlier quoted context omitted.

That could be exploited to produce a trivial denial-of-service attack.

I can think of other, lower tech, DoS attacks against cars -- which are also not much exploited.

People always say this about physical tech, but the difference is ease and scalability. Slashing all the car tires in a block is harder and more traceable than sending out a small RF signal.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#190
post #186

Earlier quoted context omitted.

If the car responds to RFID keys at all when driving, that is a flaw.

If I get out of my car with the engine still running it starts beeping. I don't know if it will actually turn the engine off, but it obviously knows that the key has departed the vehicle.

Or it detected your bum leaving its seat.
Post reply on HN