Live data from Hacker News

BMW, Audi and Toyota cars can be unlocked and started with hacked radios

telegraph.co.uk

61–70 of 118 posts

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#61

Earlier quoted context omitted.

It's worth noting that non-digitally-secured cars (pre chip-in-the-key tech) provided very little security themselves. Slim jims, hotwiring... The wireless bit does seem like a big regression over non-wired digital security, though.

Not only this but many cars of the same make had very little variation in their keys meaning that on a dealer lot or even a very busy mall there was a chance you could unlock or start; rarely both; a car other than your own. Personally I had seen this twice in action. First was back in the early nineties I could unlock my friends Escort GT with my key and he could unlock my EXP. Neither could start it. Now my Aunt an…

As I recall, we discovered back in the day that my dads ford key would lock almost any ford he came across, but not unlock them.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#62
post #3

The auto manufacturers (and for that matter all the "IoT" creators) couldn't give two shits about protecting consumers. Building security into this stuff is trivial and a responsibility.

How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)

>How would you prevent this type of attack while retaining the keyless start and entry feature

I get that regular keys could be copied and locks picked, but I feel that if you can't securely do wireless unlock and keyless start, then don't put it in.

The car industry has a lot to learn about security. I almost refuse to believe the stories where hackers take over the onboard computers via the entertainment systems in a car, because I can't believe that anyone would be stupid enough to link the two system. Yet, companies like Jeep seems to believe there's a reason that the computer running the GPS and radio needs access to the breaks.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#63

"How can I protect my car?" Some keys have a "sleep" mode. For Toyota: hold down the lock key, press the unlock key twice, the key should blink 2 times, short pause, 2 times (total of 4 blinks).

This kinda defeats the convenience of this kind of key free systems though.

Actually it defeat both the convenience and the security, because people will forget to switch it off. This is terrible.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#64
post #13

This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…

I used to enjoy listening to Security Now! quite a bit, but then I began to feel and read that Steve is not the security expert he claims to be. I'd like to hear corroborating or opposing views from the HN community. Side note: if you have a great infosec podcast to recommend, please share!

http://risky.biz/ is a great security podcast.

For me the earlier stuff from SN was far better, but now it is mainly adverts and talk about non security stuff.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#65

Earlier quoted context omitted.

How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)

>How would you prevent this type of attack while retaining the keyless start and entry feature I get that regular keys could be copied and locks picked, but I feel that if you can't securely do wireless unlock and keyless start, then don't put it in. The car industry has a lot to learn about security. I almost refuse to believe the stories where hackers take over the onboard computers via the entertainment systems in…

> The car industry has a lot to learn about security.

Not only security; with GPS and radio having access to the breaks, the car industry has a lot to learn about safety.

The entire industry that allowed this kind of terrible design needs to study the lessons of the Therac-25. Nobody seems to understand what "fail safe" means anymore.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#66
post #56
post #54

Pardon my ignorance: so how those key fobs work? They have no buttons and the car is automatically opening/closing itself based just on the proximity? That would mean I can not have my car closed when I am drinking beer in a garden over the street, which would be totally nuts, so I guess it's not how they work?

I guess they just inverted the concept of the remote control key. Remote control key : you push a button on your key (the transmitter), it sends a signal to a receiver in your car, your car authenticates the key (probably a request/response challenge involving some crypto), and opens the door. Now if you swap the transmitter and the receiver : you put the transmitter button in your car door's handle, and you move the…

The GP's point still stands: if you are within transmitting range of your car, anyone can push the button on the car door and open it. I doubt that the transmitter verifies line of sight between it and the car.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#67
post #15
post #5

Not my BMW, it's 25 years old and the driver's side door doesn't unlock even if you use a key :P All jokes aside (although it's true about my car), it just seems like a fundamental truth that digitally-secured systems always provide convenience at the cost of, well, security.

Cool. What's it like having a 25 year old car? Why'd you choose to stick with it as opposed to getting something newer?

I've had two - Mazda Miata, fine, no real problems, cheap to run. Ferrari 308GTS looked cool but endless breakdowns, bills, rust.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#68
post #51

Earlier quoted context omitted.

Harsh reality : cable locks below 4cm diameters are useless (only useful for young kids I guess). Even fat 2kg cable lock are useless, anyone can rob a bike in a street, the bolder the easier. I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.

Or do what the Japanese do: every bike has a serial number etched into the frame and is registered to you (similar to a car). If your bike is ever stolen, the police can trivially find it by the serial number and return it.

In Sweden we use our personal number etched into the frame but the thiefs just files it away and sells it as second hand.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#69
post #65

Earlier quoted context omitted.

>How would you prevent this type of attack while retaining the keyless start and entry feature I get that regular keys could be copied and locks picked, but I feel that if you can't securely do wireless unlock and keyless start, then don't put it in. The car industry has a lot to learn about security. I almost refuse to believe the stories where hackers take over the onboard computers via the entertainment systems in…

> The car industry has a lot to learn about security. Not only security; with GPS and radio having access to the breaks, the car industry has a lot to learn about safety . The entire industry that allowed this kind of terrible design needs to study the lessons of the Therac-25. Nobody seems to understand what "fail safe " means anymore.

And yet cars have got both dramatically safer and much harder to steal

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#70

Earlier quoted context omitted.

I've always wanted to build a spring loaded 30cm titanium spike that would shoot from the seat pole through the seat if not disarmed. Obviously completely illegal, but a satisfying mental exercise.

When I was in college, like many struggling students, I didn't have much money, my means of transportation was a 3 speed Stermy-Archer 3 speed bike that had the best security system ever, I never locked it. It had something wrong with the 3 speed and if you stood up on the pedals it would slip and the rider would end up with their taint on the center bar, ouch. It was fine if you were not in a hurry and took your tim…

The classic reason for that fault in an old 3-speed SA is minor misadjustment of the gear change cable. The gear lever basically pulls a chain further and further out of the hub, going from 3 at minimum pull to 2 to 1. Unfortunately there's a "neutral" between 3 and 2, so the cable needs to be carefully adjusted so that the 3/2/1 positions of the lever give you all three gears and avoid the neutral section. This design defect was apparently rectified in later versions of the 3-speed hub at some point after SA were bought by Sun Race.

Still, I wouldn't personally ever stand up to pedal on an SA 3-speed unless I personally owned it and knew its maintenance condition...

Post reply on HN