Live data from Hacker News

Thieves boosting signal from key fobs inside homes to steal vehicles

cbc.ca

391–400 of 449 posts

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#391

Earlier quoted context omitted.

This eliminates all of the convenience of keyless entry/start.

I suspect many people will happily give up such a convenience if it means they won't have their cars stolen so easily.

You suspect that the average person is going to give up a convenience that benefits them multiple times daily to ever so slightly mitigate the risk of an incredibly rare problem? I do not agree.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#392

Earlier quoted context omitted.

Indeed, the last time this attack vector came up on HN, it was pointed out that one company has patented using time of flight to validate keyless entry. Here's the patent: https://patents.google.com/patent/US8930045

`ping`. They were granted a patent for ping. That seems ridiculous.

It also describes RADAR, or even LIDAR for that matter. It doesn't seem like one should be able to patent something that is merely an application of a well known physical principal. Maybe I misunderstand what "novel" means.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#393
post #242

Earlier quoted context omitted.

I do exactly this. I lined a cookie tin with foil, and tested it by holding the closed box (with the keys inside) next to the car. It didn’t unlock. Then I opened the box, and it did unlock. The box has to be closed (lid fully on, no gaps) or the car will still unlock. Of course this only foils overnight theft. I imagine it would be trivial for someone to follow me from a car park to a public location and sit next to…

Does an unlined cookie tin not work? Does having the lid mostly closed (but with some small gaps) at least cut the effective range?

I’m wondering if a tin facing away from the door may be sufficient since the signal will be reflecting in the wrong direction.

Then just a metallized flap for extra protection.

Leakage is fine. As long as it’s in the right direction.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#394

This happened to a family member of mine, here in Toronto. Lost their gorgeous M5. Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way." Sure enough, enough, key fob attack and thef…

So... Free cars? Whats the yield on the secondary markets for these hot vehicles since the VIN is compromised, a new license plate is needed and a thorough scrubbing has to happen

In some countries, they’re worth more than American MSRP.

Some luxury sellers are actively making it difficult to buy for export to arbitrage this.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#395
post #82

Earlier quoted context omitted.

What strange is, I can see unlocking the car and even starting it with this attack -- but do the cars not continually (or at least every minute or two) revalidate the presence of the key? Once they got very far away from the house, the car should shut off. Or so I would think.

In the article, the first car mentioned the car was found in a parking lot, contents emptied. If they wanted to take it to a chop shop, easy enough to take it far enough to put on a flatbed.

Maybe they came across a better car?

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#396
post #277
post #214

Earlier quoted context omitted.

Or to put a combative point on it: "How much money do I get when you abuse this data for any purpose other than your exclusive safety metrics?"

This is an idea that I do not see getting enough attention. “Big Data” has a lot of possible benefits but only if companies collect limited and relevant data. I’m comfortable telling my insurance company where and how I drive as long as they cannot share that or combine it with any other data.

Wait until your insurance suspends their coverage for 24 hours because the road conditions aren’t meeting their requirements, or you didn’t evacuate quickly enough, or there’s a forest fire nearby.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#397
Shower thought: make a system where you unlock and start your car using your iPhone’s Face ID or Touch ID, and you can drive the car via the phone, like in Golden Eye. That would be really cool. I don’t care about security. It just sounds really cool.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#398

Wouldn’t the technology behind thwarting this essentially be a solution to the man in the middle attack?

Yup

no. it’s a relay attack, not a mitm attack. mitm acts at layer 7, relay at layer 2.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#399
post #280

Earlier quoted context omitted.

Why clone? Why replay? You just need signal boosters so the key and the car think they are next to each other.

Following around someone with a 'signal booster' could be very difficult. If you capture and reply, you afford yourself a lot of advantages.

it’s not difficult when you steal it from their house. which is what happens.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#400
post #373
post #354

Earlier quoted context omitted.

I think it would pretty easily differentiate between "keys in your pocket" and "keys sitting on bedside table for several hours" .

Apparently so: https://spectrum.ieee.org/view-from-the-valley/transportatio... But, he may be saying he's vulnerable for long periods because the idle timer won't kick in for him.

Exactly - if I'm in bed for an optimistic 8 hours, then we're talking about a security feature that works for a third of the day. As for that time being at night when people are more likely to steal: https://www.nytimes.com/video/opinion/100000001423494/bike-t...

I'd much rather have a solution that precludes relaying; maybe something that involves a precise turnaround time in the radio signal between the car and key, and so the key physically can't work beyond some relatively short range.

Post reply on HN