Live data from Hacker News

BMW, Audi and Toyota cars can be unlocked and started with hacked radios

telegraph.co.uk

71–80 of 118 posts

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#71
post #29

Earlier quoted context omitted.

How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)

The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.

Theoretically, a attacker can transmit an amplified message 300 m in 1 microsecond. So the car must limit the RTT to only a few dozen nanoseconds. This is fairly easy with modern electronics.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#72
post #13

This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…

Wow, that's an interesting hack. I can't think of any workarounds either.

EDIT: As pointed out in a comment elsewhere in this thread:

> The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#73

Earlier quoted context omitted.

I used to enjoy listening to Security Now! quite a bit, but then I began to feel and read that Steve is not the security expert he claims to be. I'd like to hear corroborating or opposing views from the HN community. Side note: if you have a great infosec podcast to recommend, please share!

http://risky.biz/ is a great security podcast. For me the earlier stuff from SN was far better, but now it is mainly adverts and talk about non security stuff.

A big +1 for risky business - I've been listening to Patrick's podcast for well over five years and will happily advocate for the quality of the coverage.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#74
post #3

The auto manufacturers (and for that matter all the "IoT" creators) couldn't give two shits about protecting consumers. Building security into this stuff is trivial and a responsibility.

How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)

Timing.

Proxying the radio signal over this link introduces a req/res delay. The handshake starts when the car detects fob proximity but there is still a communication with the key for authentication (otherwise you could have a replay attack). So if the car side is programmed to be strict about req/res timing you can defeat a proxy like this (in theory at least) at the expense of a higher false-negative rate.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#75
post #72
post #13

This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…

Wow, that's an interesting hack. I can't think of any workarounds either. EDIT: As pointed out in a comment elsewhere in this thread: > The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.

> Wow, that's an interesting hack. I can't think of any workarounds either.

Don't Have Keyless Entry.

It's getting to the point where I don't think I'll ever buy a car made after the early 2010s.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#76
post #13

This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…

I used to enjoy listening to Security Now! quite a bit, but then I began to feel and read that Steve is not the security expert he claims to be. I'd like to hear corroborating or opposing views from the HN community. Side note: if you have a great infosec podcast to recommend, please share!

I think they're trying to restart Exotic Liability, that was good back when it was running. I loved the rants.

There are a few others out there but none worth mentioning.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#77
post #29

Earlier quoted context omitted.

How would you prevent this type of attack while retaining the keyless start and entry feature? (just curious)

The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.

A good search term is distance bounding protocol.

Wikipedia has an article with links to research:

https://en.wikipedia.org/wiki/Distance-bounding_protocol

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#78
post #15

Earlier quoted context omitted.

Cool. What's it like having a 25 year old car? Why'd you choose to stick with it as opposed to getting something newer?

Not the OP, but having owned a 30 year old car up until recently, I can list a few things I loved about it: 1. It operated on mechanics that I could see and touch and fix with a wrench, as opposed to opaque black box computers. I did not need a code reader to diagnose problems. 2. Thanks to point #1, I had the confidence in the knowledge that it was maintained correctly, the parts were good and soundly installed, tha…

Maybe you could have tuned the carbs super lean (temporarily to pass emission) and installed a catalytic. Might have worked

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#79
post #51

Earlier quoted context omitted.

Harsh reality : cable locks below 4cm diameters are useless (only useful for young kids I guess). Even fat 2kg cable lock are useless, anyone can rob a bike in a street, the bolder the easier. I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.

Or do what the Japanese do: every bike has a serial number etched into the frame and is registered to you (similar to a car). If your bike is ever stolen, the police can trivially find it by the serial number and return it.

I believe every modern bike has a unique frame number stamped. If the police recovered a known-stolen bike it could be returned. However, buyers and bike shops don't make a habit of running frame numbers past the theft database, so it's mostly useless.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#80
post #51

Earlier quoted context omitted.

Harsh reality : cable locks below 4cm diameters are useless (only useful for young kids I guess). Even fat 2kg cable lock are useless, anyone can rob a bike in a street, the bolder the easier. I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.

Or do what the Japanese do: every bike has a serial number etched into the frame and is registered to you (similar to a car). If your bike is ever stolen, the police can trivially find it by the serial number and return it.

Nobody in Japan owns a file?
Post reply on HN