Live data from Hacker News

A Dutch first: Ingenious BMW theft attempt

mrooding.me

161–170 of 325 posts

Re: A Dutch first: Ingenious BMW theft attempt

#161

Earlier quoted context omitted.

If you had a receiver with a nanosecond precision you can measure the distance to the key with enough accuracy that the relay attack doesn't work anymore. I don't know why manufacturers don't do that yet - I guess the parts necessary are still not available at scale yet? I personally just keep the keys in a metallic bag at night, blocks all signals perfectly.

I have built an access control system that does a similar thing. Long story short: Time Of Flight is patented and no one can use it. Our system used a nice workaround... We tried to convince car manufacturers to use or license our tech and they seemed happy with their current stuff.

How can one patent something so obvious as measuring how far away something is based on how long the signal takes to bounce back? That principle underlies...so many things.

Edit: I looked up the patent. Here it is: https://patents.google.com/patent/US8930045. I understand that patents protect novel inventions and that under some standard this may be considered "novel". On the other hand, I myself have frequently used the technique of sending a signal, awaiting a response, and then using timing to derive the distance. It seems such an obvious application to this use case that there is nothing novel here.

Re: A Dutch first: Ingenious BMW theft attempt

#162
post #118

Earlier quoted context omitted.

Even more modern cars with "protection" (usually against tuning, not theft) use obvious, simple-to-reverse algorithms. For example, the Simos18 ECUs used in modern VWs use flash files encrypted with AES128. Except, they share the same key and IV across all ECUs on the platform, and the key and IV are stored in plaintext in the "upgrade" routines in the flash ROM. So once you've dumped one ECU's flash memory, you own…

Seems like an easy problem to solve - every ECU generates its own encryption/signing key at first boot and dumps it over the serial port, which then gets recorded somewhere. This is eventually passed down to the car’s owner in the documentation, and the key needs to be presented before any firmware upgrade or configuration change. This isn’t bulletproof either, but surely more than “hey I’m legit, here’s your new fir…

Yes, like I alluded to it's trivial drawing from any other trusted boot chain implementation.

The even better and less user-intensive way to do it would be with asymmetric encryption - the ECU only trusts flashes signed with the vendor public key and to make things even more secure, you could encrypt each flash file server side with a keypair derived each boot on the ECU and sent over the Internet (many manufacturers require online flashing anyway).

Manufacturers dislike tuners because they make warranty claims for tune damaged parts like blown turbos. VW especially are very, very aggressive about detection and enforcement around this. Long term I think giving a few dishonest tuned customers free turbos is probably fine but they seem to disagree and I assume they have access to the metrics driving this decision (which I don't).

Re: A Dutch first: Ingenious BMW theft attempt

#163
post #18

BMW burglars appear to be very skilled. The entire board computer was taking from a friend’s car and the screws and cables etc were all tidily set aside as if it was a professional replacement. And this within an hour, on the front porch..

> The entire board computer was taking from a friend’s car and the screws and cables etc were all tidily set aside as if it was a professional replacement.

Probably the thief didn't want to risk any kind of damage on the board caused e.g. by shorting two wires during cutting the cabling and thus shorting a capacitor on the board.

Re: A Dutch first: Ingenious BMW theft attempt

#164
post #118

Earlier quoted context omitted.

Even more modern cars with "protection" (usually against tuning, not theft) use obvious, simple-to-reverse algorithms. For example, the Simos18 ECUs used in modern VWs use flash files encrypted with AES128. Except, they share the same key and IV across all ECUs on the platform, and the key and IV are stored in plaintext in the "upgrade" routines in the flash ROM. So once you've dumped one ECU's flash memory, you own…

Seems like an easy problem to solve - every ECU generates its own encryption/signing key at first boot and dumps it over the serial port, which then gets recorded somewhere. This is eventually passed down to the car’s owner in the documentation, and the key needs to be presented before any firmware upgrade or configuration change. This isn’t bulletproof either, but surely more than “hey I’m legit, here’s your new fir…

I'm not so sure. The key has to be stored somewhere on the car. Why not desolder that and examine it?

(If we're going with "Theoretically possible," that is.)

Re: A Dutch first: Ingenious BMW theft attempt

#165
post #27

Reading this article is honestly a bit of a domestic culture shock for me, where does this guy live in The Netherlands? Here in downtown Amsterdam we called the police because the rear window of someone's car had just been smashed outside our office, and the police's response was "Has anyone been hurt? Nope? Then we're not coming". Meanwhile, wherever this guy lives they're sending officers because some BMW call cent…

> The officer I spoke to was unable to tell me which phone number or external call center it was, but that it was, in fact, a call center. The message they passed on was that there was either a burglary attempt or that my car was involved in an accident.

That last bit is key: "or that my car was involved in an accident." An accident means people could be hurt which is something the police have to respond to.

Re: A Dutch first: Ingenious BMW theft attempt

#166
post #164

Earlier quoted context omitted.

Seems like an easy problem to solve - every ECU generates its own encryption/signing key at first boot and dumps it over the serial port, which then gets recorded somewhere. This is eventually passed down to the car’s owner in the documentation, and the key needs to be presented before any firmware upgrade or configuration change. This isn’t bulletproof either, but surely more than “hey I’m legit, here’s your new fir…

I'm not so sure. The key has to be stored somewhere on the car. Why not desolder that and examine it? (If we're going with "Theoretically possible," that is.)

The solution here is a combination of tamper-proof secure enclave and ephemeral keys, just like it is for trusted boot chains. Obviously it's not 100% secure and just like mobile phones (which, again, are the exact same problem space) it's eventually defeated, but the magnitude of difficulty can be multiplied without much effort.

Re: A Dutch first: Ingenious BMW theft attempt

#167

Earlier quoted context omitted.

I have built an access control system that does a similar thing. Long story short: Time Of Flight is patented and no one can use it. Our system used a nice workaround... We tried to convince car manufacturers to use or license our tech and they seemed happy with their current stuff.

How can one patent something so obvious as measuring how far away something is based on how long the signal takes to bounce back? That principle underlies...so many things. Edit: I looked up the patent. Here it is: https://patents.google.com/patent/US8930045 . I understand that patents protect novel inventions and that under some standard this may be considered "novel". On the other hand, I myself have frequently use…

Hmmm. 2013? I beat them by a year.

http://rachelbythebay.com/w/2012/02/07/ping/

Re: A Dutch first: Ingenious BMW theft attempt

#168

Earlier quoted context omitted.

Can you pull the SIM card?

No, because this is an embedded system and fiddling around with that is maybe going to void your warranty?

Not in the US. So long as your changes don't cause damage your warranty can't be voided.

Re: A Dutch first: Ingenious BMW theft attempt

#169
post #141

Earlier quoted context omitted.

$30k in cash is not the same as a $30k car. A $30k car that's been stolen is not worth $30k, then there's liquidity, risk and a bunch of other things. Having your car parked outside is not at all like having a box containing $30k outside your house.

I have to worry about a $1,000 bicycle. For some reason it's just socially accepted that this will happen to a $1,000 bicycle. But park a car worth an order of magnitude, and the level of worry actually goes down. That's the bit that throws me for a loop. I'm not trying to argue that anyone should live in fear. Just that assumptions of state-sponsored action severely overestimate which ballpark this lives in. This is…

A bicycle is also often more than an order of magnitude easier to steal; you can't just pick up a car, and a bolt cutter won't cut it even for a car worth $5,000.

Re: A Dutch first: Ingenious BMW theft attempt

#170
post #107

Earlier quoted context omitted.

Have you taken a look at a Tesla car yet? From PR materials I'm led to believe that they treat their car software seriously. I doubt one can install untrusted firmware on a Tesla car; is that so?

I’ve never worked on a Tesla. I’ve left the trade long ago finding my way in software engineering instead. Tesla is probably the only one I’d trust though. While I don’t expect them to be bulletproof either (at least not at first), I expect them to quickly catch on should this kind of theft appear, and make the necessary fixes. In any case I doubt they’d be stupid enough to accept arbitrary code over a diagnostics po…

Teslas have been stolen in Europe, their high value for parts makes them well worth stealing. This is primarily Tesla's fault, as they refuse to sell parts to cars that have been in accidents.

Your Tesla is essentially scrap after a non-minor accident, which is why most US insurers refuse to cover vehicles made by Tesla. Its as bad as rolling coal IMO, Tesla has created a massive eWaste problem. Meanwhile, rebuilding any other manufacturers car is doable, even other EVs.

Source: https://electrek.co/2018/07/31/tesla-theft-tips-help-prevent...

Post reply on HN