Live data from Hacker News

A Dutch first: Ingenious BMW theft attempt

mrooding.me

151–160 of 325 posts

Re: A Dutch first: Ingenious BMW theft attempt

#151

I used to fix cars for a living. Sometimes it involved “cracking” alarm & immobiliser systems. My clients all claimed they broke/lost their keys to their car - most of the time they were believable (car stuck in front of their driveway, etc). Sometimes less so, but I’d do it anyway because I needed the money and I had no proof of the contrary (innocent until proven guilty right?), although given the sad conditions of…

In Russia and, I guess, similar countries, it's quite rare to encounter a car which isn't protected by an external protection system (not sure how it's called in English, in Russian it's usually called "Сигнализация") which includes shock sensors, alarm system, remote control and car block which protects some vital engine circuits. There are systems with dialog protocol between remote control and car with actual encryption inside, so it might be not so trivial to break it. In practice such cars are either stolen inside trucks or an entire system is by-passed by a separate automobile computer connected directly to necessary engine sensors, ignition coils, etc. Quite clever technique, you don't need to bypass protected electronics if you can bring and connect your own electronics.

Re: A Dutch first: Ingenious BMW theft attempt

#152
post #27

Reading this article is honestly a bit of a domestic culture shock for me, where does this guy live in The Netherlands? Here in downtown Amsterdam we called the police because the rear window of someone's car had just been smashed outside our office, and the police's response was "Has anyone been hurt? Nope? Then we're not coming". Meanwhile, wherever this guy lives they're sending officers because some BMW call cent…

> Here in downtown Amsterdam we called the police because the rear window of someone's car had just been smashed outside our office, and the police's response was "Has anyone been hurt? Nope? Then we're not coming". Amsterdam currently has a big police shortage, that's why. It's not normal, it's just a problem in Amsterdam. https://www.dutchnews.nl/news/2018/07/amsterdam-is-not-lawle...

> Amsterdam currently has a big police shortage, that's why. It's not normal, it's just a problem in Amsterdam.

Or maybe Amsterdam has an excess of crime.

Re: A Dutch first: Ingenious BMW theft attempt

#153
post #27

Reading this article is honestly a bit of a domestic culture shock for me, where does this guy live in The Netherlands? Here in downtown Amsterdam we called the police because the rear window of someone's car had just been smashed outside our office, and the police's response was "Has anyone been hurt? Nope? Then we're not coming". Meanwhile, wherever this guy lives they're sending officers because some BMW call cent…

Why should the police be sent to a smashed window? Not much they can do at that point unless you caught somebody red-handed. "Yup, that window is totally smashed. OK, just file a claim with your insurance company."

Maybe I read too much about fooling fingerprint readers and think this is easier than it really is, but isn't it easy to check for prints in the car? In the general case, a shattered window means someone stole something and must have touched something in the car.

Of course not everyone is in the database, but if they are ever caught with anything they will be.

Re: A Dutch first: Ingenious BMW theft attempt

#154
post #150
post #33

Earlier quoted context omitted.

Maybe you could stop this attack by having an IMU in the key so it only broadcasts the unlock signal while it's being held/moved.

The attacker could just wait outside your house for you to hold or move it as you head off to work in the morning then come back at night to pick the car up

It doesn't work like that. This can't be recorded and replayed later. This attack works by extending the range of the exchange between car and key in real time using handheld repeaters.

Re: A Dutch first: Ingenious BMW theft attempt

#155

It's clear what has happened here... Cutting that wire loom disables the cars 'call home' functionality (probably by cutting it's antenna), as well as conveniently disabling the alarm. The thieves who cut it this time were too slow though. Presumably, the 3G connection takes ~30 secs to boot up, find a cell tower, and connect to BMW servers. The thieves hoped to break the window and cut the loom immediately, before t…

I’m surprised they wouldn’t just arrive with a GSM/3G/LTE jammer to begin with.

Assuming it's not always-on.

Re: A Dutch first: Ingenious BMW theft attempt

#157
post #52
post #16

I've anecdotally heard a lot of stories about the relay/replay attacks on keyless ignition systems used in many BMW models and other cars as well. No need to smash the window at all in some cases. Remarkably simple attack in principle, and probably a nightmare to explain to your insurer given there will be no evidence of a break in. Makes you wonder if you should start storing the key in a metal/RF shielded box at ho…

That's actually not hard to explain to your insurance or the police at all. This happened to me 5 weeks ago. The car was parked directly in front of my entrance door and the key was basically on the other side of that door. The scene of my car not being where it was supposed to be was so surreal that I did not even realize it was missing the first time when I walked out the trash. I basically walked around an invisib…

> Getting the car back (still ongoing) was so much hassle

I'm very curious to know why was it was such a hassle? Unless the police were keeping the car as evidence in a truly major crime, why wouldn't they immediately give back your property?

Re: A Dutch first: Ingenious BMW theft attempt

#158
post #80

Earlier quoted context omitted.

There's a huge difference between the US and EU in this regard. If I steal a car in California and try to sell it in Nevada, I can expect to be arrested. If I have a car stolen in The Netherlands and it's being sold in Romania, and I find out who's selling it and where, I'll be told that I have to travel to Romania and file report with the local police there before they'll do anything. The only inter-state enforcemen…

Interesting because stolen cars are sometimes broken for parts, but perhaps there's no profit in that in US? There was an 'OEM+' car modding craze here a few years back where certain top-end Audis were being targeted solely for their front seats, which would then be fitted to older VWs.

Parts-related theft is here, but it targets a fairly different set of cars - generally somewhat older (so needing replacement parts) highly common cars. See: https://www.statista.com/chart/6551/the-10-most-stolen-cars-...

I suppose these make for less interesting news stories since they aren't nearly as tricky to steal.

Re: A Dutch first: Ingenious BMW theft attempt

#159
post #114

Earlier quoted context omitted.

Why not relay that, too?

Relaying would still require the owner to push a button on the keyfob, right?

No. The point of this whole thread is there is no button so that when you approach the car it unlocks automatically. That's why this attack is possible by extending the range with repeaters. The key likely already has something similar to what you suggested but that can't prevent this attack.

Re: A Dutch first: Ingenious BMW theft attempt

#160
post #107

Earlier quoted context omitted.

Have you taken a look at a Tesla car yet? From PR materials I'm led to believe that they treat their car software seriously. I doubt one can install untrusted firmware on a Tesla car; is that so?

I’ve never worked on a Tesla. I’ve left the trade long ago finding my way in software engineering instead. Tesla is probably the only one I’d trust though. While I don’t expect them to be bulletproof either (at least not at first), I expect them to quickly catch on should this kind of theft appear, and make the necessary fixes. In any case I doubt they’d be stupid enough to accept arbitrary code over a diagnostics po…

I believe Telsas have a minimal OBD-II port (where mandated by law) but mostly use an Ethernet port for debugging/service.
Post reply on HN