I work at very large OEM. We've run the numbers, and key fob exploits are _extremely_ rare. (most) Modern keys use rolling keys that are verified by the ECU, making cloning (let alone initial pairing) extremely time consuming. However, Keyless-go key fobs _can_ be captured and replayed (not necessarily exploited). 99.99% of the time that cars are stolen (which we find much more common in Europe due to small jurisdict…
Thieves boosting signal from key fobs inside homes to steal vehicles
211–220 of 449 posts
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#212This happened to a family member of mine, here in Toronto. Lost their gorgeous M5. Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way." Sure enough, enough, key fob attack and thef…
> If I were the insurance companies, I'd be putting pressure on the car companies And also give car owners an incentive to keep their keys safer, given how many vehicles out there are vulnerable to this. Just fixing this for new cars is only half the solution. I remember back in the 80s my parents got a discount on their insurance for installing a third brake light in the back window of their old Camaro. If my insura…
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#213There is a lot of great technical discussions here of ways to possibly solve the issue. The real problem points back to the lackluster security the auto industry is used to. Only if some sort of accountability or software security testing requirements are enforced this will get fixed. They have to have a mandatory recall if your Audi accelerates quickly by itself (that was in the early 80's i think), but no recall fo…
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#214Earlier quoted context omitted.
Insurance companies pressure drivers who have these misfeatures, drivers pressure car manufactures. See also: discounts for anti-theft tech and airbags.
The latest insurance "incentive" is a tracking device in your car that tracks when and where you drive, how fast, how hard you corner and stop, etc. I've declined this but expect that insurers will push for it to become mandatory. They would love to be able to charge unsafe drivers more money, and in the abstract I don't have a problem with that, but the tracking is creepy.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#215Earlier quoted context omitted.
Leaving a car unlocked is sometimes safer, while not foolproof it reduces the likelihood of getting your window smashed to loot the vehicle for valuables (and non valuable items)
Leaving car doors unlocked is SOP in urban corridors with high incidence of petty theft. I.e. don't leave attractive objects in your vehicle, and leave it unlocked so that would-be thieves can learn it themselves w/o smashing a window. The problem here being able to start the engine wirelessly, not simply getting in.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#216> Key fobs are constantly broadcasting a signal that communicates with a specific vehicle, he said, and when it comes into a close enough range, the vehicle will open and start. It's a poor design for the system to take any access-escalating action without an explicit command from the user that initiates a secured transaction that is resistant to MITM. It's poor design to assume that the range is based on raw signal…
I see I made a naive statement here. Let's consider the access-reducing action of the vehicle locking itself when the fob becomes distant. That is also open to exploit; if the attackers boost the signal when they spot a driver walking away from the car, then the locking neglects to take place as the driver enters a building and goes out of sight.
However, auto locking a car based on proximity is justifiable as a fall-back measure to explicit locking with a button. The rationale is that if the user forgot to lock, it is probably better to do it for them than to do nothing.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#217Earlier quoted context omitted.
> All you have to do is keep the fob inside a shielded case at home and you're fine. Because we all have Faraday cages in our homes, and I'm sure the salesman who sold the car also made the customer aware of this vulnerability. /sarcasm.
>Because we all have Faraday cages in our homes Yes, most people who own cars new enough to have this vulnerability own microwave ovens.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#218Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#219This happened to a family member of mine, here in Toronto. Lost their gorgeous M5. Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way." Sure enough, enough, key fob attack and thef…
> Better to pay out for a vehicle theft, vs. actual injuries from a collision. What do you mean? It's not as if anyone will be driving less... the insurance company will pay for a new car, the family will buy a new car (presumably they need it), and still be just as statistically likely to collide with the new car.