Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

211–220 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#211
post #189

Earlier quoted context omitted.

I can think of other, lower tech, DoS attacks against cars -- which are also not much exploited.

People always say this about physical tech, but the difference is ease and scalability. Slashing all the car tires in a block is harder and more traceable than sending out a small RF signal.

Remediating slashed tires is a lot more difficult than waiting for your attacker to get bored and move on.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#213

Earlier quoted context omitted.

To a car owner, that's another security flaw of its own. An attacker can deny an owner access to their car with a simple code spammer hidden nearby.

Surely that's better than having your car stolen, right? Security is about trade-offs, after all.

> Surely that's better than having your car stolen, right?

Stranded in hostile environment (middle of nowhere in the arctic or a desert) could be a death sentence.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#214
post #87
post #77

Earlier quoted context omitted.

Is this a specific feature of VW's implementation of CAN? CAN in general (at least not in 2007 when I last worked in the industry) is not secured. The only real security once you had access to the CAN bus were the separate rings (although several modules bridged). You probably couldn't start the car and keep it started unless you figured out the variant of crypto handshake used between whatever did ignition/skim/rke…

Almost all German manufacturers use these variations of CAN. Bosch recently published how their variants are used to prevent stuff like break-in through the radio. The system is safe against replay attack (by prepending a timing signal to the encrypted message), has seperate rings of trust (so your gas pedal can control acceleration, but your radio can’t), and is in general quite safe. And, well, with a physical kit…

This is how it worked ~2000:

You break door lock, get inside, pop the hood. Alarm starts, you spray polyurethane foam into alarm loudspeaker and it shuts up. You close the hood and go away for 10-20 minutes keeping a lookout on the car. You come back, swap computers, turn on the car and drive away.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#216

Earlier quoted context omitted.

Surely that's better than having your car stolen, right? Security is about trade-offs, after all.

> Surely that's better than having your car stolen, right? Stranded in hostile environment (middle of nowhere in the arctic or a desert) could be a death sentence.

Who is going to DoS your car in the middle of the arctic or a desert?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#217
post #202

Honestly I'm not really bothered about the whole "hacking cars" thing. I've spent enough years in dangerous countries that this seems like a non-issue. I do object to car companies knowing about a safety issue & keeping quiet due to it being "cheaper" to accept a couple of deaths than fix it. That kind of thing should be punished with eye watering fines in my view - not to save those 12 lives but to put the message o…

> "companies need to get it right instead of playing the odds"

Doesn't sound cost-effective.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#218

Earlier quoted context omitted.

1993 Corolla with decayed paint. Utterly, utterly, reliable. Appears undesirable. It will also guarantee that you'll never get laid.

No way. Late-model Toyotas and Hondas get stolen a ton. Spare parts are still useful for tuners and sport compact car ricers. Get an old American junker.

1993 is late model?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#219

Earlier quoted context omitted.

> Surely that's better than having your car stolen, right? Stranded in hostile environment (middle of nowhere in the arctic or a desert) could be a death sentence.

Who is going to DoS your car in the middle of the arctic or a desert?

Eh, I dunno, I guess a very not-nice person could attach the device to your car and activate it remotely/later.

I think a more realistic exploit would be a corrupt tow-truck driver / mechanic targeting an area where tourists stop.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#220

Earlier quoted context omitted.

There is no key as such. The fob for my Hyundai never leaves my pocket. Just by standing next to the car, the unlock button on the door is enabled. So if I walk up and push the button, it unlocks. If I'm not around, the button does nothing. So there's no discernible event from the fob, as far as I can see. It's just a "this is me" signal.

I guess the Hyundais I've driven were different, in that the unlock button was on the fob rather than on the car door. Could you say, if you have multiple cars, does the fob work with all of them? I doubt that's the case, so I don't see why your "this is me" signal couldn't actually be a "this is me, fob 123ABC..., and I can authenticate with the vehicle with VIN# 123abc...".

your "this is me" signal couldn't actually be a "this is me, fob 123ABC..., and I can authenticate with the vehicle with VIN# 123abc..."

You're right, that might be it.

the unlock button was on the fob rather than on the car door

Let me clarify: the fob does have buttons for lock, unlock, panic, and open trunk. But I don't normally use them. My normal usage is as I described: just walk up with the fob in my pocket, and press the button on the door handle.

Post reply on HN