Live data from Hacker News

Thieves boosting signal from key fobs inside homes to steal vehicles

cbc.ca

31–40 of 449 posts

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#32
post #23

I already put mine in a metalic bag for the night, or just press the "lock" button twice which disables the keyless entry system entirely. Manufacturers really need to hurry up and implement more accurate timing detection in the keys - it should be absolutely trivial to detect how far away the key is based on the response time, but for some reason manufacturers don't do this yet. Edit: I also know people who take the…

I don't think it's the distance really, it's the relaying and the additional steps that adds latency. If the data rate is low, and the data is not trivially small (ie over some 10s or 100s of bytes), you are in the milliseconds area, which should be very easily tracked. Perhaps if the keyfob needs to do some additional conditioning on the data (eg some decryption+encryption), or is very slow, the extra overhead of th…

If you are measuring response time in nanoseconds then you have enough precision to tell how far away from you the key is, down to a metre. Even at the speed of light, the signal will travel slightly longer if the key is 10m away from you compared to a key that is 1m away from you.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#34
post #11
post #6

> Key fobs are constantly broadcasting a signal that communicates with a specific vehicle, he said, and when it comes into a close enough range, the vehicle will open and start. Why is it transmitting without the user pressing a button? Is that a feature? As you walk up to the car it automatically starts like magic? I'm not familiar with these newer cars.

With my car, as soon as you touch the door handle (with the keyfob in your pocket, or within a couple feet of the door) it unlocks, and to start the car you push a button. It doesn't work from even 4' away (eg, someone else touches the door handle while you're close) and it doesn't work from the other side (eg, when the keyfob close enough to driver's side door, the passenger side won't unlock). The really nice featu…

> the downside of this feature is my wife's car does not have it -- and so at least half of the time when I am driving it I forget and leave it unlocked in parking lots.

My brother in law did this on a ski trip with a borrowed Range Rover. It was only at the end of the week he realised he'd left his keys in a jacket pocket in the car the entire time and it had been sitting unlocked in the car park half a mile down the road from the apartment. Thankfully it was fine but stealing it would've been a case of getting in, pressing the start button and driving away.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#35
post #20

Earlier quoted context omitted.

> it should be absolutely trivial to detect how far away the key is based on the response time Is that true? Accurate, very low power distance detection has a lot of potential applications (e.g. your phone straying too far away) but BLE (for example) doesn't really work for measuring distance--through signal strength--at all. If it's possible, I'd be very curious how to build such a distance detector.

If you are processing data with nanosecond precision(which is not difficult with modern microchips) then you can tell the distance to the key by just measuring the number of nanoseconds elapsed since the request was sent(accounting for amount of time taken to calculate the response). If you can measure the time in nanoseconds that's good enough to tell the difference between the key being 1m and 10m away.

What about reflections?

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#36
post #20

Earlier quoted context omitted.

> it should be absolutely trivial to detect how far away the key is based on the response time Is that true? Accurate, very low power distance detection has a lot of potential applications (e.g. your phone straying too far away) but BLE (for example) doesn't really work for measuring distance--through signal strength--at all. If it's possible, I'd be very curious how to build such a distance detector.

If you are processing data with nanosecond precision(which is not difficult with modern microchips) then you can tell the distance to the key by just measuring the number of nanoseconds elapsed since the request was sent(accounting for amount of time taken to calculate the response). If you can measure the time in nanoseconds that's good enough to tell the difference between the key being 1m and 10m away.

I think that assumes that all the processing the key fob does internally is reliable constant-time down to the nanosecond. I don't know if that's true but my first guess is that it's doubtful.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#37

Nothing new, has been going on for a while now. Market is already providing your own "cage of Faraday[0]" for your fob. [0] https://www.amazon.com/faraday-cage-key-fob/s?page=1&rh=i%3A...

Since most car manufacturers seem to be vulnerable (to my knowledge), I assume all or most buy the same COTS keyfob + electronic lock product. Much like Takata airbags or Bosch ECUs.

Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#38
post #20

Earlier quoted context omitted.

> it should be absolutely trivial to detect how far away the key is based on the response time Is that true? Accurate, very low power distance detection has a lot of potential applications (e.g. your phone straying too far away) but BLE (for example) doesn't really work for measuring distance--through signal strength--at all. If it's possible, I'd be very curious how to build such a distance detector.

If you are processing data with nanosecond precision(which is not difficult with modern microchips) then you can tell the distance to the key by just measuring the number of nanoseconds elapsed since the request was sent(accounting for amount of time taken to calculate the response). If you can measure the time in nanoseconds that's good enough to tell the difference between the key being 1m and 10m away.

I know how the mechanism would work. I am just not aware of what hardware would be needed to support this type of digital tether using only a small battery for perhaps a year.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#39
post #20

I already put mine in a metalic bag for the night, or just press the "lock" button twice which disables the keyless entry system entirely. Manufacturers really need to hurry up and implement more accurate timing detection in the keys - it should be absolutely trivial to detect how far away the key is based on the response time, but for some reason manufacturers don't do this yet. Edit: I also know people who take the…

> it should be absolutely trivial to detect how far away the key is based on the response time Is that true? Accurate, very low power distance detection has a lot of potential applications (e.g. your phone straying too far away) but BLE (for example) doesn't really work for measuring distance--through signal strength--at all. If it's possible, I'd be very curious how to build such a distance detector.

I think the timing method relies on a challenge response. In short, one side sends something and the other side expects a reply within some amount of time.

If you just simply add distance to the system with no additional overhead. The time it takes for the ack should go up in a measurable amount of time.

And if you did anything more -- like some of the system do today -- where they make a generic pipe that pipes it over the internet via LTE and back -- then for sure we would have a ack way out of the time tolerance.

Method 1

(car){signal amplifier}{signal amplifier}(keyfob)

Method 2

(car){transceiver}[LTE][LTE]{transceiver}(keyfob)

To my knowledge most of these systems work but using some sort of out of band transmission over other wireless means such as WIFI/LTE/or simply another band.

The second method they use has to do with rolling codes. Where they jam the signal and intercept your keyfob code, preventing it from reaching the car. They store this and when the target realizes they did not actually lock/unlock they car they attempt to unlock it again. This time they jam the signal from the keyfob to the car, but replay the code they intercepted the first time, and saving the last code sent from the keyfob for later when the target is not around. This method works for more than just cars, it can be used for most rolling code systems.

Post reply on HN