Live data from Hacker News

BMW, Audi and Toyota cars can be unlocked and started with hacked radios

telegraph.co.uk

81–90 of 118 posts

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#81
post #51

Earlier quoted context omitted.

Harsh reality : cable locks below 4cm diameters are useless (only useful for young kids I guess). Even fat 2kg cable lock are useless, anyone can rob a bike in a street, the bolder the easier. I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.

Or do what the Japanese do: every bike has a serial number etched into the frame and is registered to you (similar to a car). If your bike is ever stolen, the police can trivially find it by the serial number and return it.

Every car has a serial number in several places, in theory it should be trivial to find a stolen one, yet plenty of cars are stolen each yer. Clearly this does not solve the problem.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#82
post #66
post #56

Earlier quoted context omitted.

I guess they just inverted the concept of the remote control key. Remote control key : you push a button on your key (the transmitter), it sends a signal to a receiver in your car, your car authenticates the key (probably a request/response challenge involving some crypto), and opens the door. Now if you swap the transmitter and the receiver : you put the transmitter button in your car door's handle, and you move the…

The GP's point still stands: if you are within transmitting range of your car, anyone can push the button on the car door and open it. I doubt that the transmitter verifies line of sight between it and the car.

I have a car with that system and in my experience you need to be really close to the car for the system to work. Stand further away than arms length from the handle and the car won't open even if someone else tries to open it. Also it looks like the car has independent antennas on each side - even if I stand very close to the driver side, you can't open the car by pulling the handle on the passenger's side.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#83
post #72
post #13

This was covered in depth on the Security Now podcast in May 2015 (Transcript [1]). The Passive Keyless Entry and Start PKES system relies on the assumption that if the car can "hear" the key, the key is in close proximity. Normally that's true but it is technically trivial to build a radio system that picks up and amplifies the car's continuous "ping" transmissions. So the key, which might be in your pocket in a res…

Wow, that's an interesting hack. I can't think of any workarounds either. EDIT: As pointed out in a comment elsewhere in this thread: > The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.

Remember, light moves at one foot per nanosecond. You need to perform a cryptographically-safe ping with timing drift of less than 15 nanoseconds.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#84

Earlier quoted context omitted.

Sorry to hear that. Reminds me of a "best of craiglist" post where a "free washing machine" was left untouched for weeks.. but as soon as a price went on it, it was stolen that evening.

Harsh reality : cable locks below 4cm diameters are useless (only useful for young kids I guess). Even fat 2kg cable lock are useless, anyone can rob a bike in a street, the bolder the easier. I'm still waiting for a cheap bike gps 'self powered' tagger so I can use a bike again.

If you can read German: https://fahrradjaeger.de/

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#85
post #80
post #51

Earlier quoted context omitted.

Or do what the Japanese do: every bike has a serial number etched into the frame and is registered to you (similar to a car). If your bike is ever stolen, the police can trivially find it by the serial number and return it.

Nobody in Japan owns a file?

No one will buy a bike without a number.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#86
post #72

Earlier quoted context omitted.

Wow, that's an interesting hack. I can't think of any workarounds either. EDIT: As pointed out in a comment elsewhere in this thread: > The simplest defeat is to require the key ping round trip to complete in N microseconds, where N is sufficiently low. Researchers have demostrated that this is a practical solution.

Remember, light moves at one foot per nanosecond. You need to perform a cryptographically-safe ping with timing drift of less than 15 nanoseconds.

I think this is doable: https://en.wikipedia.org/wiki/Distance-bounding_protocol

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#87
post #54

Pardon my ignorance: so how those key fobs work? They have no buttons and the car is automatically opening/closing itself based just on the proximity? That would mean I can not have my car closed when I am drinking beer in a garden over the street, which would be totally nuts, so I guess it's not how they work?

The button is on the car, and it (normally) doesn't work unless you're right next to the car. It won't unlock unless you push the button, and some models will automatically lock if you walk more than a foot away.

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#88
Cars can be "hacked" now to simply program a new key with an ODBII "virtual keyboard" which basically does all the work you normally do to program a new key in under 60 seconds.

So here is what you do, amplify the key ping coming from the house, that gets you into the car. Plug this black box into the ODBII and program a new key. Now you've gone around the alarm, and the immobilizer. And the car is yours.

https://www.youtube.com/watch?v=dvmSOEKfkug

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#89

Earlier quoted context omitted.

Remember, light moves at one foot per nanosecond. You need to perform a cryptographically-safe ping with timing drift of less than 15 nanoseconds.

I think this is doable: https://en.wikipedia.org/wiki/Distance-bounding_protocol

Doable doesn't mean easy though. It's far harder than dealing with microseconds. And how much do analog prover components cost?

Re: BMW, Audi and Toyota cars can be unlocked and started with hacked radios

#90
post #50

Earlier quoted context omitted.

My car seems to be able to tell if the key is inside or outside pretty accurately so I think it can already figure out the distance to the key (though might be using something like RFID for that, which is not very secure).

The whole point is the the car is using signal strength as a proxy for proximity, which is unreliable when you can use an transceiver and/or amplifier to boost the signal strength from a remote key.

Not sure if you've miss-replied, but in case you imply the key location works on signal strength I doubt that very much.
Post reply on HN