Live data from Hacker News

Thieves boosting signal from key fobs inside homes to steal vehicles

cbc.ca

311–320 of 449 posts

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#311
post #61
post #46

Earlier quoted context omitted.

Yes, it’s a feature, so you don’t have to remove the key from a bag or pocket to enter or start the car. In typical designs, the car continually transmits a low-frequency (e.g., 135 kHz) radio signal to wake up any wireless keys within range. When a key receives this signal, it replies with a VHF (e.g., 315 MHz) signal, and the car unlocks or starts when a door is opened or the start button is pressed. The reply sign…

Is there any type of encryption between the car and the key? Or are the signals always constant? Could you just record the relay signal and play it back whenever, essentially replicating the key?

It might not matter. If the point of the amp is to reduce the effective distance between the car and the fob, whatever messages are exchanged will look right to the car and the door will open.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#312

This happened to a family member of mine, here in Toronto. Lost their gorgeous M5. Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way." Sure enough, enough, key fob attack and thef…

So... Free cars? Whats the yield on the secondary markets for these hot vehicles since the VIN is compromised, a new license plate is needed and a thorough scrubbing has to happen

Get it to a chop shop for parts and/or get it out of the country and I can imagine it's pretty high.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#313
post #223
post #139

Earlier quoted context omitted.

Not having to drag keys out of your pockets is a feature.

You meant a solution in search of a problem.

Not really, for some people it saves very little time, for most it's a small convenience, and for others it saves a lot of time, especially women who have their keys in their purse and don't have to search for them. Just because it's not useful to you doesn't mean that it isn't for others. Car manufacturers aren't going to change something for no reason unless people actually want it.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#314

Earlier quoted context omitted.

And what problem does keyless entry/start aim to solve?

It is a convenience feature -- you don't have to fish your keys out of your pocket/handbag and press a button to unlock your car doors or to start the car. So long as you have the key somewhere on you (bag/handbag/pocket), you can unlock and start the car.

Is getting your keys out of your bag or pocket really that hard? In comparison to the security risks?

To think of it another way: before keyless entry was a thing - how many people were thinking 'damn I wish I didn't have to get these annoying keys out of my pocket?'

To think of it yet another way: How many people buy the upgraded trim on their car mainly for the keyless entry?

(Not having a go - genuinely curious)

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#315
post #227

Earlier quoted context omitted.

Ah, yes, let's put the burden back on the user after we promised them something easier. We should just go back to traditional keys if this is the case.

Please yes. Traditional keys fit on my keyring, can survive the clothes washer, don't unlock doors by accident, can open a car with a dead battery, don't have their own battery issues, and can be brought into restricted work environments where radio transmitters are banned. I want key holes in all doors. I want to insert a key to start the car.

Most vehicles have hidden physical keyslots somewhere, often under the plastic cover of the door handle, but usually not all door handles.

Source: worked for a valet company

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#316

This happened to a family member of mine, here in Toronto. Lost their gorgeous M5. Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way." Sure enough, enough, key fob attack and thef…

That's no problem for the insurance company. Everybody has to pay a bit more, problem solved.

Sure, if a car theft for one car spread the cost to _all_ insurance companies, but it doesn't. So to stay competitive, companies have to 1) insure good drivers so the rates stay low and 2) invest in customers who have good car security (note the discount one gets for having their car garaged).

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#318

> Key fobs are constantly broadcasting a signal that communicates with a specific vehicle, he said, and when it comes into a close enough range, the vehicle will open and start. It's a poor design for the system to take any access-escalating action without an explicit command from the user that initiates a secured transaction that is resistant to MITM. It's poor design to assume that the range is based on raw signal…

RTT measurements can give proof-of-proximity (due to relavity), but I think they're quite hard to get right (you'd need nanosecond RTT resolution in a cheap keyfob) -- I think analog signal repeaters would't add significant RTT. It's not impossible though, GPS decoders work in a similar fashion. Requiring user iniciation seems like the adequate solution here...

The Apple Watch manages to handle RTT measurements to prevent exactly this attack.

You don't need complexity in the FOB; the car starts the clock, sends the signal, measures the time taken to reply. If it exceeds some threshold ignore the response.

There is no way to spoof this if the request/response itself is using proper cryptography.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#319
post #289

Earlier quoted context omitted.

Is it true that encryption cannot proetect from a relay attack? If the encrypted payload is passed based on some kind of pre-shared secret (pairing) then each message should be unpredictable to a third party right?

The third party doesn’t need to predict it, just repeat it. The relay doesn’t need to understand or modify the message, just pass it along.

If the message is encrypted with some time component and a pre-shared secret then it is protected from a replay attack no?

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#320
post #286

My car was recently “broken into”, it’s a Mercedes C400, i thought it to be fairly secure so my assumption has been that i forgot to lock the car. I just double checked, and the car has an “auto-lock” feature and it is already turned on...so...did this happen to me? I just want an off switch in my fob, so i can disable it at night. More fancy solutions would be a motion sensor on the fob to only power it when had rec…

You can turn off keyless-go by double pressing the close button. The LED on the key will light up (short - long) as a confirmation.

Ha, that’s an interesting one! I am sure I’ve done that by accident given how unreliable i find pulling the handle to be.
Post reply on HN