Earlier quoted context omitted.
The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.
I disagree. A physical switch on the key itself which opened a circuit to the decryption key would mean the key would need to physically be in the possession of the driver.
Thieves boosting signal from key fobs inside homes to steal vehicles
101–110 of 449 posts
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#102Earlier quoted context omitted.
The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.
I disagree. A physical switch on the key itself which opened a circuit to the decryption key would mean the key would need to physically be in the possession of the driver.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#103Earlier quoted context omitted.
> I also know people who take the exact opposite approach with their expensive vehicles - they leave the key in plain sight near the front door This seems like the best strategy to me. If you have a desirable vehicle and someone decides to break into your house to get hold of the keys they're going to turn the place upside down trying to find them. If you're in at the time you're also putting yourself in a lot of dan…
Criminals seeking to commit property crime generally go to great lengths to avoid possible confrontations with people. Stealing one more BMW that week is not worth the risk of a 9mm hole in your chest. Breaking into someone's home when you are all but sure they are there (because their car is in the driveway and you want their keys) is just begging for a confrontation. Someone breaking into your house with the expect…
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#104Tesla recently added a good workaround. They added a setting where you can turn auto unlock or auto start off, which blocks this remote access hack. You have to use your key fob button at least once, say to unlock the car and then it just works wirelessly without further action. My car is unlocked at night but in my garage. If they got in my garage somehow and had the signal repeater they couldn't drive off unless I…
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#105Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#106Earlier quoted context omitted.
The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.
I disagree. A physical switch on the key itself which opened a circuit to the decryption key would mean the key would need to physically be in the possession of the driver.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#107What's considered a safe distance? How far away can they pick up the signal?
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#108Earlier quoted context omitted.
Since most car manufacturers seem to be vulnerable (to my knowledge), I assume all or most buy the same COTS keyfob + electronic lock product. Much like Takata airbags or Bosch ECUs. Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.
The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.
More efficient for the car to estimate the distance and power of the transmitter.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#109I imagine improvements to the key fob could be made that would require a mechanical coupling with the car in order to start it. That would circumvent this attack.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#110Earlier quoted context omitted.
Yes, it’s a feature, so you don’t have to remove the key from a bag or pocket to enter or start the car. In typical designs, the car continually transmits a low-frequency (e.g., 135 kHz) radio signal to wake up any wireless keys within range. When a key receives this signal, it replies with a VHF (e.g., 315 MHz) signal, and the car unlocks or starts when a door is opened or the start button is pressed. The reply sign…
This is insane. Please tell me this is an option that non-insane consumers can get their car without. Fortunately I drive an old car so this does not affect me—yet. If I ever have to replace mine, this looks like yet-another-misfeature I’ll have to look out for to avoid.