Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

191–200 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#191
post #114

Earlier quoted context omitted.

Wait, so VW has an RFID immobilizer and a physical key? I've only ever seen cars having one or the other.

All European cars since 1998 will have both, because immobilizers are required by law in most of Western Europe. On most cars, you'll never notice the immobilizer as it's RFID based, passive, and requires no batteries. The only way you'd find it is if you take apart the key fob or have to service the ignition lock, at which point you'll find the RFID antenna ring around it, or if you try to get the key replaced.

Doesn't help you much if you don't live in Europe. I have a 2015 audi that doesn't require the key to be inserted.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#192
Off topic but a point about the persistence of cults around unreliable vehicles:

As owner of an 1985 Westfalia, I have nothing but contempt for the inconsistent and poor engineering of this beast. Even with the factory Digijet pro training materials and factory service manual and several mechanics later, this thing still won't idle right when cold or warm. Systemically went through each system (fuel, air, electrical, mechanical, vacuum) individually and triple-checked per procedures and looked at general stuff like grounds and wiring too. Maybe the community factor akin to Mini Cooper owners: ostensible value built on hazing by ostentatious, expensive repairs due to substandard engineering. Sure VW has/had the hippie thing too, perhaps also due to them being difficult/expensive to maintain or being less powerful.

I'm grateful though the beastie doesn't have OBDII or keyless entry. (Like most German vehicles of this vintage, the drivers' side door doesn't lock without the key to avoid locking oneself out.)

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#193
post #36

Earlier quoted context omitted.

Don't buy a high end car that has a high theft rate. Research theft rates like you would reliability and resale. Buy a plain vanilla mid-level toyota, honda or the like. Insure your car.

The "plain vanilla" cars are the ones with the highest theft rate: http://www.forbes.com/sites/jimgorzelany/2014/08/18/the-most... It has been this way for about two decades. It is much easier for thieves to slice-and-dice a common vehicle into hard-to-trace parts, since the hot parts will disappear into a sea of legitimate used and reconditioned parts. High-end cars are comparatively rare, and thus harder to dispose…

Insurance should be cheaper on a plain vanilla car.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#194
post #36

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Don't buy a high end car that has a high theft rate. Research theft rates like you would reliability and resale. Buy a plain vanilla mid-level toyota, honda or the like. Insure your car.

I don't always buy new cars, but when I do, I don't let car thieves pick the make and model.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#195
post #186

Earlier quoted context omitted.

If I get out of my car with the engine still running it starts beeping. I don't know if it will actually turn the engine off, but it obviously knows that the key has departed the vehicle.

Or it detected your bum leaving its seat.

No, because if I toss the key into the seat it stops beeping even if I'm not there.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#196
post #186

Earlier quoted context omitted.

If I get out of my car with the engine still running it starts beeping. I don't know if it will actually turn the engine off, but it obviously knows that the key has departed the vehicle.

Or it detected your bum leaving its seat.

My car also beeps when it detects that the key has left the car. The engine keeps running, but you obviously cannot turn it on again once you turn it off.

I had it happen without me leaving the seat (e.g. my wife has the keys in her bag/pocket, I had been driving, and she gets off the car to unarm the home alarm). The car is turned on by pressing a button, not by turning the key.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#197

Earlier quoted context omitted.

Or it detected your bum leaving its seat.

My car also beeps when it detects that the key has left the car. The engine keeps running, but you obviously cannot turn it on again once you turn it off. I had it happen without me leaving the seat (e.g. my wife has the keys in her bag/pocket, I had been driving, and she gets off the car to unarm the home alarm). The car is turned on by pressing a button, not by turning the key.

That seems like a reasonable setup. I'm having difficulty imagining how that could be hacked into the blackmail situation described above, since the sure way to avoid the beep is to keep the fob in the car.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#198
post #2

Besides locking your car into a garage, is there anything a VW owner can do to make it more difficult for these types of thefts to occur?

You could always use a club: http://www.amazon.com/Club-1000-Original-Steering-Wheel/dp/B... But anyone waiting to spend 30 minutes with an electronic crack is also smart enough to use liquid nitrogen to crack this too. The difference is that a keyless hack can look natural since there is no physical force for entry or ignition. A funnel and chisel would raise some eyebrows.

Ummmm....you don't defeat 'the club' with liquid nitrogen. You just saw through the steering wheel with a small hacksaw.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#199

Earlier quoted context omitted.

You're making the mistake of assuming car thiefs are unintelligent or unorganized. Successful thefts that return a profit require a network of skilled people to pull off and talent can be found within that pool or recruited. By saying a thief would have to understand how a computer exploit works, it's saying a thief needed the equivalence of an engineering degree to drive away with a car before computers entered the…

I'm basing it off the observation that newer cars are essentially never stolen, while popular older cars are stolen in vast numbers. Whatever the reason, stealing newer cars is harder. That increased difficulty translates into decreased theft rates.

> while popular older cars are stolen in vast numbers

For now. Once they get out of circulation only newer cars will be left and at that time it might be that thieves could buy devices to hack into these cars just as you can rent botnets today.

Post reply on HN