Live data from Hacker News

A Dutch first: Ingenious BMW theft attempt

mrooding.me

291–300 of 325 posts

Re: A Dutch first: Ingenious BMW theft attempt

#291

Earlier quoted context omitted.

Is that how contactless payment cards are protected?

No, contactless cards could be hacked in the exact same way cars are, but it's not worth the trouble since you would need an authorized terminal and the most you could steal is £30 - it's just not worth the trouble.

Steal £30 off enough people, though - RFID/NFC has been demonstrated to have a range of several meters under some conditions, so just stick your equipment in a bag and wander through a shopping centre. Probably pickup a dozen or so. I understand those who buy RF-shielded wallets all too well.

Re: A Dutch first: Ingenious BMW theft attempt

#292

Earlier quoted context omitted.

Is that how contactless payment cards are protected?

No, contactless cards could be hacked in the exact same way cars are, but it's not worth the trouble since you would need an authorized terminal and the most you could steal is £30 - it's just not worth the trouble.

If you get a pin number then it’s different. AFAIK there are contactless ATM’s.

Re: A Dutch first: Ingenious BMW theft attempt

#293

Earlier quoted context omitted.

No, contactless cards could be hacked in the exact same way cars are, but it's not worth the trouble since you would need an authorized terminal and the most you could steal is £30 - it's just not worth the trouble.

Steal £30 off enough people, though - RFID/NFC has been demonstrated to have a range of several meters under some conditions, so just stick your equipment in a bag and wander through a shopping centre. Probably pickup a dozen or so. I understand those who buy RF-shielded wallets all too well.

But like I said, only an authorized terminal will process transactions, so you need to figure out how to get one. And then, visa and MasterCard take at least a week to pay out any money from card transactions - so your terminal and likely the entire account will get banned before you get a penny out of that money.

It's not that £30 is little money - it's that it's nearly impossible to secure a working terminal and then once you have that actually get any money out of it.

Re: A Dutch first: Ingenious BMW theft attempt

#294

Earlier quoted context omitted.

No, contactless cards could be hacked in the exact same way cars are, but it's not worth the trouble since you would need an authorized terminal and the most you could steal is £30 - it's just not worth the trouble.

If you get a pin number then it’s different. AFAIK there are contactless ATM’s.

Contactless ATMs still require a pin - one of the defining features of contactless is that you can't get cash with it. If you ask for cashback at the till and use contactless then you also need to enter the pin.

Re: A Dutch first: Ingenious BMW theft attempt

#295

Earlier quoted context omitted.

No, contactless cards could be hacked in the exact same way cars are, but it's not worth the trouble since you would need an authorized terminal and the most you could steal is £30 - it's just not worth the trouble.

Steal £30 off enough people, though - RFID/NFC has been demonstrated to have a range of several meters under some conditions, so just stick your equipment in a bag and wander through a shopping centre. Probably pickup a dozen or so. I understand those who buy RF-shielded wallets all too well.

Like the parent comment said, you need an authorized terminal, which is linked to a merchant account, which is linked to your bank account (and thus your identity). What do you think visa/mastercard is going to do when the fraud reports start flooding in? Chances are, you're going to be caught before your first payment arrives in your bank account.

Re: A Dutch first: Ingenious BMW theft attempt

#296

Hi guys, very cool to see how this is being picked up over here. Shame on me, but I actually forgot to submit it to Hacker News. The key fob method is out of the question for my car. I've known about it for a while and store my keys in special bags. I see quite a few people asking why a sting wasn't organised. I of course shared the M.O. with the police and we actually had a few phone calls from them over the past fe…

You may want to look into rewiring your OBD port so that it doesn’t work without you flipping a switch somewhere, or building a “key” with a male and female port + some wires, then storing the “key” in some hidden location (spare tire?). Or just expose two data lines from the OBD wiring harness and jump them together. Remove the jumper to operationalize the OBD port. FYI: cutting off VCC may not always work since som…

A few days ago, I read on the most reliable source in the world, the internet, that if you have a class 3 alarm system from BMW, the OBD port is blocked as soon as the alarm goes off. I do want to verify this with the dealer once my holiday is over.

I also read about the OBD key cloning, but I'm not sure whether or not that was an issue with the first F30s. I'm unsure whether or not it still works with the F30 LCI from 2017 that I have

Re: A Dutch first: Ingenious BMW theft attempt

#297

Hi guys, very cool to see how this is being picked up over here. Shame on me, but I actually forgot to submit it to Hacker News. The key fob method is out of the question for my car. I've known about it for a while and store my keys in special bags. I see quite a few people asking why a sting wasn't organised. I of course shared the M.O. with the police and we actually had a few phone calls from them over the past fe…

Oh, and get a dashcam with parking mode! Front and rear. Maybe the sides too? They’re increasingly inexpensive, and you can move them car to car as you buy/sell. I originally bought a forward facing, and as i’ve upgraded, my old forward facing is now my rear facing.

I've been thinking about that. A good one with parking mode and cloud support sets you back about 800 euro including installation. It could be worth it but the chances of the cops actually catching someone based on the footage is quite slim.

For hit and run accidents in which you can record a license plate it might be worth it.

Re: A Dutch first: Ingenious BMW theft attempt

#298

I used to fix cars for a living. Sometimes it involved “cracking” alarm & immobiliser systems. My clients all claimed they broke/lost their keys to their car - most of the time they were believable (car stuck in front of their driveway, etc). Sometimes less so, but I’d do it anyway because I needed the money and I had no proof of the contrary (innocent until proven guilty right?), although given the sad conditions of…

In Russia and, I guess, similar countries, it's quite rare to encounter a car which isn't protected by an external protection system (not sure how it's called in English, in Russian it's usually called "Сигнализация") which includes shock sensors, alarm system, remote control and car block which protects some vital engine circuits. There are systems with dialog protocol between remote control and car with actual encr…

I used to work for an insurance company and I got an entertaining presentation from a 3rd party that showed how ingenious thieves went around car block, special keys, etc, by bringing in the entire front panel of the car (thieves had one for each common model they wanted to steal).

"Casual" thieves are finding it harder though, it's more organized mafia in concert with dismantlers (as mentioned on a sibling comment).

Re: A Dutch first: Ingenious BMW theft attempt

#299

Earlier quoted context omitted.

> If BMW ever shares the location data with third parties other than police, I would have major issues with all of this. By that time it would be too late. And the problem with privacy-related info (like location history) is that once revealed, it can’t be re-secured. So the only proper fix is to not collect it in the first place. Also BMW is a car company. Consumer data protection is not their core competency. Then…

Under the GDPR you could force BMW to hand over what data they have on your car. That way you would at least have some idea of what gets stored and for how long.

As a US citizen residing in the US, no I couldn't. (They might voluntarily disclose, applying GDPR globally, but they aren't required to do so.)

Additionally, my interaction is with BMW USA, not BMW AG. If teleservices is instantiated locally in the US for US customers, then it's doubly the case the BMW need not respond to any such inquiry.

Re: A Dutch first: Ingenious BMW theft attempt

#300

Earlier quoted context omitted.

Under the GDPR you could force BMW to hand over what data they have on your car. That way you would at least have some idea of what gets stored and for how long.

As a US citizen residing in the US, no I couldn't. (They might voluntarily disclose, applying GDPR globally, but they aren't required to do so.) Additionally, my interaction is with BMW USA, not BMW AG. If teleservices is instantiated locally in the US for US customers, then it's doubly the case the BMW need not respond to any such inquiry.

> I wonder if GDPR is a factor for new car sales.

You brought the GDPR into it.

Post reply on HN