Live data from Hacker News

Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

esat.kuleuven.be

1–10 of 35 posts

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#2
Oh dear. Seriously, 24-bit and 40-bit crypto of any variety?

Was it really so hard in the year 2013 to put at least a 128-bit AES key in the card?

With a sufficient directional panel antenna you could impersonate a car and query pocketed fobs in whole crowds of somewhat wealthy individuals. Aim the antenna and rig at the seating area of a trade show for middle/upper management types in the technology industry, for instance.

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#4

There's no excuse in 2018 for using a 40-bit key. Hopefully Tesla gives its customers the upgraded fobs for free.

These cars were made ~5 years ago, but there's still no excuse for using a 40-bit key (which is transformed into a 24-bit response, lol) ~5 years ago.

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#5

There's no excuse in 2018 for using a 40-bit key. Hopefully Tesla gives its customers the upgraded fobs for free.

These cars were made ~5 years ago, but there's still no excuse for using a 40-bit key (which is transformed into a 24-bit response, lol) ~5 years ago.

There was really no excuse even in 2009, nevermind 2013, if you were doing some sort of proximity card public/private key crypto...

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#6

There's no excuse in 2018 for using a 40-bit key. Hopefully Tesla gives its customers the upgraded fobs for free.

These cars were made ~5 years ago, but there's still no excuse for using a 40-bit key (which is transformed into a 24-bit response, lol) ~5 years ago.

Fair enough, I think I mentally substituted "Model 3" for some reason. I wonder if these fobs were designed 20+ years ago when the US crypto export control situation was a bit goofier.

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#7
post #5

Earlier quoted context omitted.

These cars were made ~5 years ago, but there's still no excuse for using a 40-bit key (which is transformed into a 24-bit response, lol) ~5 years ago.

There was really no excuse even in 2009, nevermind 2013, if you were doing some sort of proximity card public/private key crypto...

Actually, a very good excuse was provided precisely in 2009 - https://xkcd.com/538/

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#8
post #5

Earlier quoted context omitted.

There was really no excuse even in 2009, nevermind 2013, if you were doing some sort of proximity card public/private key crypto...

Actually, a very good excuse was provided precisely in 2009 - https://xkcd.com/538/

That doesn't really apply in this situation though, since the crypto can be defeated without taking a wrench to the owner's face.

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#9
post #5

Earlier quoted context omitted.

There was really no excuse even in 2009, nevermind 2013, if you were doing some sort of proximity card public/private key crypto...

Actually, a very good excuse was provided precisely in 2009 - https://xkcd.com/538/

I don't disagree with the premise of that cartoon, but it's more about the concept of putting full disk encryption on your laptop, crossing the border into Uzbekistan, and then refusing to give up the password.

By that logic, anything that is protected by crypto, if you threaten the owner with violence, it can be stolen from them. Which is just about everything on earth, if you're willing to apply sufficient violence.

Re: Tesla Model S Can Be Stolen in Seconds by Cloning Its Key Fob

#10
post #9

Earlier quoted context omitted.

Actually, a very good excuse was provided precisely in 2009 - https://xkcd.com/538/

I don't disagree with the premise of that cartoon, but it's more about the concept of putting full disk encryption on your laptop, crossing the border into Uzbekistan, and then refusing to give up the password. By that logic, anything that is protected by crypto, if you threaten the owner with violence, it can be stolen from them. Which is just about everything on earth, if you're willing to apply sufficient violence…

I was referring mostly to the concept of "A crypto nerd's imagination".

Seriously, it is unlikely someone would put the money and R&D effort required to replicate the researcher's solution with the goal of stealing these camera systems on the wheels that can be disabled remotely.

So I'd rather advocate for Tesla to continue using inexpensive and secure enough solution to unlock doors. And focus their efforts on making the thing actually safer, like not accelerating into and colliding with concrete barriers.

Post reply on HN