Live data from Hacker News

Thieves boosting signal from key fobs inside homes to steal vehicles

cbc.ca

131–140 of 449 posts

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#131
post #122
post #115

A motion sensor in the remote could mitigate the issue and maintain convenience.

How battery intensive are accelerometers? The last fob I had required a battery change once every year or so already, increasing that frequency could be quite annoying. And I'd rather not have yet another device I need to regularly charge.

Anecdotaly, I have a remote that lights up everytime it's moved (to assist finding it at night as it's a remote for a bed). I've had it for well over a year and haven't changed the batteries yet. Granted, it runs on three AAA batteries. Not entirely sure what tech it uses, but it's not necessarily a full blown accelerometer.

Edit: some / all of the power drain would be offset because the RF transmitter would be off while the sensor is on.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#132
post #74
post #37

Earlier quoted context omitted.

Since most car manufacturers seem to be vulnerable (to my knowledge), I assume all or most buy the same COTS keyfob + electronic lock product. Much like Takata airbags or Bosch ECUs. Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.

The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.

Some links at https://en.wikipedia.org/wiki/Distance-bounding_protocol

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#133
post #125
post #74

Earlier quoted context omitted.

The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.

Can't you stop the car if the key is not present in the car? I guess the thieves could fake it with long distance transmission of the signal, but that would be more difficult and the further the car drives away from the actual key, the easier if becomes to detect the timing delay.

No. Safety-wise you can't just shut the engine off and lock the steering because the RF connection to some keyfob is wonky.

These thefts have been going on for years and they will not stop until key-less go is dropped or changed such that the key requires interaction (like every higher security transponder has for, like, always).

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#134

ive tested a couple of things to see if they would block the signal by putting the keys in the container and then standing next to the car and trying to open the door kids Lunch box would not block, small metal garbage can, would not block, cookie tin would not block. All would block if you lined the edge with aluminum foil before putting the top on. foil lined Potato chip bag would block. Wrapping in enough aluminum…

I just read "Garage opener" and automatically I have to think about Samy Kamkar's OpenSesame Hack [0].

Regarding the keyfobs, I've seen demonstrations on video where the RF signal was relayed. I can search for them, but they were in German.

[0]: https://www.youtube.com/watch?v=iSSRaIU9_Vc

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#136
post #74
post #37

Earlier quoted context omitted.

Since most car manufacturers seem to be vulnerable (to my knowledge), I assume all or most buy the same COTS keyfob + electronic lock product. Much like Takata airbags or Bosch ECUs. Being a step away from the problem probably helps keep that OEM manufacturer from strapping in and solving it. They don't feel any pain from it.

The vulnerability is pretty much inherent to the idea. No amount of encryption can protect you from a relay attack. The only foolproof mitigation is to enforce a short round trip time to ensure the fob is actually close to the car, but with the short distances involved that means the fob has to generate and transmit a response within a few nanoseconds.

[deleted]

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#137
post #105

I imagine improvements to the key fob could be made that would require a mechanical coupling with the car in order to start it. That would circumvent this attack.

I'm not sure if this is a joke about old keys being better, but I'd argue you could have the benefits of new keys and old keys combined if you just made it so that new keys have to be inserted into some compartment inside of cars, where they are authenticated by those cars. You can imagine a fob with a USB that has a different authentication code than the wireless one it sends out, and unless the USB is plugged into…

[deleted]

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#138
post #82

This happened to a family member of mine, here in Toronto. Lost their gorgeous M5. Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way." Sure enough, enough, key fob attack and thef…

What strange is, I can see unlocking the car and even starting it with this attack -- but do the cars not continually (or at least every minute or two) revalidate the presence of the key? Once they got very far away from the house, the car should shut off. Or so I would think.

> Once they got very far away from the house, the car should shut off. Or so I would think.

In the event that the actual owner of the car left their fob at their previous stop and discovers this fact 40 miles down the highway later, if the car were to stop, the driver is now stranded with a car that won't start. As it is now, as long as there is enough gas in the tank, the owner can just drive back and get it.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#139

The car manufacturers are going to need to incorporate a time of flight measurement into the key system. Obviously amplitude can be faked.

Or just use physical contacts on a real key.

Not having to drag keys out of your pockets is a feature.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#140
I think convenience here is fundamentally at odds with security.

The convenience here is that the system requires no confirmation from the driver, no physical interaction with buttons, handles, keys, etc. The driver just opens the door and starts the engine. This allows for a trivial remote sniff-and-replay attack, not unlike copying a key temporarily.

I bet not having a lock on the door would be even more convenient. But for some reason it's not widely practiced.

Post reply on HN