Live data from Hacker News

A Dutch first: Ingenious BMW theft attempt

mrooding.me

101–110 of 325 posts

Re: A Dutch first: Ingenious BMW theft attempt

#101
I used to fix cars for a living. Sometimes it involved “cracking” alarm & immobiliser systems.

My clients all claimed they broke/lost their keys to their car - most of the time they were believable (car stuck in front of their driveway, etc). Sometimes less so, but I’d do it anyway because I needed the money and I had no proof of the contrary (innocent until proven guilty right?), although given the sad conditions of the cars I really doubt anyone would bother stealing them.

Car security is based on obscurity. There is very little cryptography involved (if any), and where there is, the car’s “computers” would happily install new, untrusted firmware through the diagnostics (OBD) port, which means you can do pretty much anything - program new keys, disable the immobiliser or alarm completely (by installing patched firmware) or even rewind the odometer.

I’m frankly surprised it took this long for “high tech” car theft to appear, unless it’s been going on for a while but executed perfectly so nobody would find a trace.

Happy to answer any questions if anyone’s curious.

Re: A Dutch first: Ingenious BMW theft attempt

#102
Amateurs, frankly.

The current modus operandi is to find your BMW/Land Rover/Mercedes. Wait for it to come to your hand carwash, tyre company etc and get uninterrupted access to the OBD port along with the key. Program new key, find the address of the vehicle, walk up a few days later and drive it off at 3am in seconds.

If that's too much like shooting fish in a barrel, then the 'keyless relay theft' is probably more your bag. Using a relay transceiver, if the key is in the house within range, then you can trick the motor into thinking the key is present. Many cars will allow you to continue to drive them even if the key if out of range. Provided you don't turn the engine off, this gives you plenty of scope to get away and clone a new key in the meantime.

Tl;DR, OBD and keyless technology is basically flawed. The best countermeasure is a good old fashioned crook lock.

Re: A Dutch first: Ingenious BMW theft attempt

#104

Earlier quoted context omitted.

If you had a receiver with a nanosecond precision you can measure the distance to the key with enough accuracy that the relay attack doesn't work anymore. I don't know why manufacturers don't do that yet - I guess the parts necessary are still not available at scale yet? I personally just keep the keys in a metallic bag at night, blocks all signals perfectly.

It's coming in the next generation of keyless systems: https://www.3db-access.com/

I’m curious, why not just proper cryptographic challenge-response?

Key sends a “wake up” signal, car hears it and sends a random challenge, key receives it, signs it with its private key and send is back. If the response is correct the car unlocks, otherwise not and the user can try again.

Seems like à solved problem really.

Re: A Dutch first: Ingenious BMW theft attempt

#105

More surprising that the car has some call home feature that the owner doesn't seem to know about.

Having recently gotten a new BMW (in USA), they give you a huge packet of about 30 pages explaining the BMW TeleService and the "SOS" button. They also make you sign a power of attorney-style doc giving them rights to notify police in case they believe your vehicle is in trouble and provide police/EMS with its exact location. Mercedes and Audi have similar systems, as do others via OnStar. This is one of few cases wh…

BMW offers a car-sharing service in some cities in Europe through a joint venture with Sixt, called DriveNow. Some assholes like to take these cars and go for joyrides/street races. One of these idiots ran over a bicyclist and killed them. The court/prosecution asked DriveNow to give them the "black box" data of GPS location/heading/speed, but the company doesn't monitor GPS during trips. The court asked BMW, and BMW could comply. A bit freaky...

(After reading more about it, the black box is only for cars used in this service, and apparently BMW and DriveNow have a "data protection firewall": BMW only tells DriveNow where the trip started and ended, and doesn't know who rented the car, and DriveNow knows who the renter is but doesn't know more other than the start/end of their trip)

Re: A Dutch first: Ingenious BMW theft attempt

#106

Why did they not park the car back and wait with the police on call in order to catch the thieves that would have come back the next night?

I had a phone stolen recently at knifepoint (attempting to sell it on a classifieds site). When I told the police I could make them come back next day (posting another ad, etc) they wouldn’t give a shit.

I suspect this is the same reason.

Re: A Dutch first: Ingenious BMW theft attempt

#107

I used to fix cars for a living. Sometimes it involved “cracking” alarm & immobiliser systems. My clients all claimed they broke/lost their keys to their car - most of the time they were believable (car stuck in front of their driveway, etc). Sometimes less so, but I’d do it anyway because I needed the money and I had no proof of the contrary (innocent until proven guilty right?), although given the sad conditions of…

Have you taken a look at a Tesla car yet? From PR materials I'm led to believe that they treat their car software seriously. I doubt one can install untrusted firmware on a Tesla car; is that so?

Re: A Dutch first: Ingenious BMW theft attempt

#108

It's clear what has happened here... Cutting that wire loom disables the cars 'call home' functionality (probably by cutting it's antenna), as well as conveniently disabling the alarm. The thieves who cut it this time were too slow though. Presumably, the 3G connection takes ~30 secs to boot up, find a cell tower, and connect to BMW servers. The thieves hoped to break the window and cut the loom immediately, before t…

I’m surprised they wouldn’t just arrive with a GSM/3G/LTE jammer to begin with.

Re: A Dutch first: Ingenious BMW theft attempt

#109

Earlier quoted context omitted.

What is this magical land you live in where signal jamming triggers a CAR alarm?

PDF alert: https://automotive.vodafone.co.uk/media/239296/stolen%20vehi...

I wouldn’t trust a mobile carrier with anything - they can’t even protect their mobile customers from basic stuff as SMS spam or eavesdropping via SS7.

Not to mention, I technically can’t see how this thing will be able to phone home if the mobile phone frequencies are being jammed.

Re: A Dutch first: Ingenious BMW theft attempt

#110

I used to fix cars for a living. Sometimes it involved “cracking” alarm & immobiliser systems. My clients all claimed they broke/lost their keys to their car - most of the time they were believable (car stuck in front of their driveway, etc). Sometimes less so, but I’d do it anyway because I needed the money and I had no proof of the contrary (innocent until proven guilty right?), although given the sad conditions of…

Seems like that's all you can ask for if the attacker has physical access to the machine. Would be happy to be corrected though.
Post reply on HN