Live data from Hacker News

Thieves boosting signal from key fobs inside homes to steal vehicles

cbc.ca

71–80 of 449 posts

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#71

I already put mine in a metalic bag for the night, or just press the "lock" button twice which disables the keyless entry system entirely. Manufacturers really need to hurry up and implement more accurate timing detection in the keys - it should be absolutely trivial to detect how far away the key is based on the response time, but for some reason manufacturers don't do this yet. Edit: I also know people who take the…

> I also know people who take the exact opposite approach with their expensive vehicles - they leave the key in plain sight near the front door This seems like the best strategy to me. If you have a desirable vehicle and someone decides to break into your house to get hold of the keys they're going to turn the place upside down trying to find them. If you're in at the time you're also putting yourself in a lot of dan…

Criminals seeking to commit property crime generally go to great lengths to avoid possible confrontations with people. Stealing one more BMW that week is not worth the risk of a 9mm hole in your chest. Breaking into someone's home when you are all but sure they are there (because their car is in the driveway and you want their keys) is just begging for a confrontation. Someone breaking into your house with the expectation of a confrontation with you is probably after more than just your keys.

People who's threat model does not include home invasion can generally leave their keys wherever is convenient in your home with immeasurably little additional risk. If you feel your threat model includes home invasion then where your keys are if the least of your issues.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#72
This happened to a family member of mine, here in Toronto. Lost their gorgeous M5.

Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way."

Sure enough, enough, key fob attack and theft. Caught on their video cameras. Filed the police report, claimed insurance, cried internally about the loss of a gorgeous vehicle. In all seriousness though, it's just a car, so no big deal, but nothing will fix the violation you feel, and the fact that you were being targeted.

If I were the insurance companies, I'd be putting pressure on the car companies, but hey, maybe it's just the cost of doing business for them. Better to pay out for a vehicle theft, vs. actual injuries from a collision. That's probably why there's little incentive to fix it, especially if fixing it makes your product less convenient.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#73
post #15

I wonder how hard it is to measure the delay between challenge and response... Any distance extension would increase the signal flight time that should be measurable.

This has been proposed in the past yet I haven't seen any implementation of it - perhaps because of increased power consumption of accurate timing components needed? Any EEs able to comment on this?

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#74
post #37

Nothing new, has been going on for a while now. Market is already providing your own "cage of Faraday[0]" for your fob. [0] https://www.amazon.com/faraday-cage-key-fob/s?page=1&rh=i%3A...

Since most car manufacturers seem to be vulnerable (to my knowledge), I assume all or most buy the same COTS keyfob + electronic lock product. Much like Takata airbags or Bosch ECUs. Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.

The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#75
post #37

Earlier quoted context omitted.

Since most car manufacturers seem to be vulnerable (to my knowledge), I assume all or most buy the same COTS keyfob + electronic lock product. Much like Takata airbags or Bosch ECUs. Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.

Before the keyfobs become poplar there were transponder keys with embedded RFIDs. While still attackable, they aren't actively pinging their car and revealing their presence like the fobs do.

> Before the keyfobs become poplar there were transponder keys with embedded RFIDs.

Tesla is using an NXP Athena OS based smartcard that uses the Java Card 2.2 platform for it's NFC Key on the Model 3.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#76
post #29
post #24

It's useful to note that less sophisticated methods still work as well. I used to lease a 2015 Toyota Auris(facelift). One year into the lease someone broke into it smashing the rear-left window and just drove away.

Curious how they started it?

If it has an immobilizer? You can find immobilizer bypasses on sale online, who knows if they work, or you can create your own and disable it yourself: https://www.youtube.com/watch?v=ispXq4EMrsY#t=24m45s https://github.com/fjvva/ecu-tool/wiki (see also https://ioactive.com/pdfs/IOActive_Adventures_in_Automotive_... and http://opengarages.org/handbook/ebook/)

So besides relaying the key, you can just hack via the CAN bus. There's also a trick to use a second ECU to bypass the immobilizer, but that's probably too time consuming.

Many manufacturers (inc. Toyota) also allow bypassing immobilizers and other features using TechStream and a maintenance tool. If they claim you have to buy a new ECU if you lose your master keys, call bullshit: https://attachments.priuschat.com/attachment-files/2015/10/9...

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#77
post #61
post #46

Earlier quoted context omitted.

Yes, it’s a feature, so you don’t have to remove the key from a bag or pocket to enter or start the car. In typical designs, the car continually transmits a low-frequency (e.g., 135 kHz) radio signal to wake up any wireless keys within range. When a key receives this signal, it replies with a VHF (e.g., 315 MHz) signal, and the car unlocks or starts when a door is opened or the start button is pressed. The reply sign…

Is there any type of encryption between the car and the key? Or are the signals always constant? Could you just record the relay signal and play it back whenever, essentially replicating the key?

Every run of the mill garage door opener using rotating keys or nonces to prevent replay attacks. I assume any fob design worth its salt would implement something similar.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#78
post #46
post #6

> Key fobs are constantly broadcasting a signal that communicates with a specific vehicle, he said, and when it comes into a close enough range, the vehicle will open and start. Why is it transmitting without the user pressing a button? Is that a feature? As you walk up to the car it automatically starts like magic? I'm not familiar with these newer cars.

Yes, it’s a feature, so you don’t have to remove the key from a bag or pocket to enter or start the car. In typical designs, the car continually transmits a low-frequency (e.g., 135 kHz) radio signal to wake up any wireless keys within range. When a key receives this signal, it replies with a VHF (e.g., 315 MHz) signal, and the car unlocks or starts when a door is opened or the start button is pressed. The reply sign…

This is insane. Please tell me this is an option that non-insane consumers can get their car without. Fortunately I drive an old car so this does not affect me—yet. If I ever have to replace mine, this looks like yet-another-misfeature I’ll have to look out for to avoid.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#79
post #6

> Key fobs are constantly broadcasting a signal that communicates with a specific vehicle, he said, and when it comes into a close enough range, the vehicle will open and start. Why is it transmitting without the user pressing a button? Is that a feature? As you walk up to the car it automatically starts like magic? I'm not familiar with these newer cars.

>>Why is it transmitting without the user pressing a button? Is that a feature? It's not transmitting anything, it works pretty much the same way NFC works. Both the key and the car have their own public/private key pairs(which were obviously set by the manufacturer) and when you touch the handle the car transmits an unlock request to the key, encrypted with the car key's public key(this is going to get confusing lol…

Can you also boost the nfc to make payments from distance?

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#80
post #74
post #37

Earlier quoted context omitted.

Since most car manufacturers seem to be vulnerable (to my knowledge), I assume all or most buy the same COTS keyfob + electronic lock product. Much like Takata airbags or Bosch ECUs. Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.

The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.

As long as the fob's own delay is very consistent, I don't see why you couldn't time the signal.

Edit: there's a discussion down the page somewhere. The issue seems to be that (for power reasons) they use low-freq radio, on which it's hard to get timing accurate enough for 10m distance changes.

Post reply on HN