Earlier quoted context omitted.
How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)
The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.
BMW, Audi and Toyota cars can be unlocked and started with hacked radios
71–80 of 118 posts
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#72This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…
EDIT: As pointed out in a comment elsewhere in this thread:
> The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#73Earlier quoted context omitted.
I used to enjoy listening to Security Now! quite a bit, but then I began to feel and read that Steve is not the security expert he claims to be. I'd like to hear corroborating or opposing views from the HN community. Side note: if you have a great infosec podcast to recommend, please share!
http://risky.biz/ is a great security podcast. For me the earlier stuff from SN was far better, but now it is mainly adverts and talk about non security stuff.
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#74The auto manufacturers (and for that matter all the "IoT" creators) couldn't give two shits about protecting consumers. Building security into this stuff is trivial and a responsibility.
How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)
Proxying the radio signal over this link introduces a req/res delay. The handshake starts when the car detects fob proximity but there is still a communication with the key for authentication (otherwise you could have a replay attack). So if the car side is programmed to be strict about req/res timing you can defeat a proxy like this (in theory at least) at the expense of a higher false-negative rate.
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#75This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…
Wow, that's an interesting hack. I can't think of any workarounds either. EDIT: As pointed out in a comment elsewhere in this thread: > The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.
Don't Have Keyless Entry.
It's getting to the point where I don't think I'll ever buy a car made after the early 2010s.
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#76This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…
I used to enjoy listening to Security Now! quite a bit, but then I began to feel and read that Steve is not the security expert he claims to be. I'd like to hear corroborating or opposing views from the HN community. Side note: if you have a great infosec podcast to recommend, please share!
There are a few others out there but none worth mentioning.
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#77Earlier quoted context omitted.
How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)
The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.
Wikipedia has an article with links to research:
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#78Earlier quoted context omitted.
Cool. What's it like having a 25 year old car? Why'd you choose to stick with it as opposed to getting something newer?
Not the OP, but having owned a 30 year old car up until recently, I can list a few things I loved about it: 1. It operated on mechanics that I could see and touch and fix with a wrench, as opposed to opaque black box computers. I did not need a code reader to diagnose problems. 2. Thanks to point #1, I had the confidence in the knowledge that it was maintained correctly, the parts were good and soundly installed, tha…
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#79Earlier quoted context omitted.
Harsh reality : cable locks below 4cm diameters are useless (only useful for young kids I guess). Even fat 2kg cable lock are useless, anyone can rob a bike in a street, the bolder the easier. I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.
Or do what the Japanese do: every bike has a serial number etched into the frame and is registered to you (similar to a car). If your bike is ever stolen, the police can trivially find it by the serial number and return it.
Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios
#80Earlier quoted context omitted.
Harsh reality : cable locks below 4cm diameters are useless (only useful for young kids I guess). Even fat 2kg cable lock are useless, anyone can rob a bike in a street, the bolder the easier. I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.
Or do what the Japanese do: every bike has a serial number etched into the frame and is registered to you (similar to a car). If your bike is ever stolen, the police can trivially find it by the serial number and return it.