Live data from Hacker News

Thieves boosting signal from key fobs inside homes to steal vehicles

cbc.ca

421–430 of 449 posts

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#421
post #202

Earlier quoted context omitted.

As someone who turns their car on by inserting their key into a slot in it, all this seems quite convoluted just for the convenience of pushing a button. I don't understand why the car would even let you accelerate at all if the key isn't inside the actual car (even if it's just in your pocket, if you insist on pressing a button).

The key has to be in it to start it, but once started, the key can go away and it will continue to run. (& yes, I still start my car with a key that is inserted, and mine also has a clutch & manual H-pattern 5-speed)

Sorry, perhaps I should've put my commment higher up. I was referring to the general problem of the article, which I understood to be enabled (among other things) by the possibility of unlocking, turning on, and driving a car without the car having a means of verifying the key is inside/very close to the car.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#422

Earlier quoted context omitted.

Exactly. Luckily i've got a Kia which nobody wanted to steal, but it's definitely a well known attack vector. A car on one side got stolen, the other side 'just' had stuff stolen from it.

Wait until bad weather. I had an utterly clapped-out Jeep Cherokee stolen one cold-as-hell winter night. Sure enough, found two neighborhoods over... a fair walking distance from where the last late night bus would have dropped someone off. So, yeah, a stolen beater is just fine when it's freezing cold outside...

Good point. We've got a new (year old) Kia Ceed, and a 15 year old Ford Focus. I'd imagine if somebody needed a ride they'd just take the Focus. Either way we've got the cameras outside which, along with the fact we don't have a Jaguar or a BMW outside probably makes us less likely to be turned over.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#423

Earlier quoted context omitted.

I often don't lock my house. But when I'm not there, there's a dog on the front porch who doesn't like strangers.

I don't get the downvotes for this. A dog who doesn't like strangers is a pretty traditional security system, and is much, much more secure than a locked door.

It really really isn't. That stranger can become an instant friend with some food. There was a show once where an ex-burglar would break into people's homes to show how easy it was. People would say, "there's no way he's getting past my dog!" and the guy would just open up the fridge and throw all the meat on the floor. End of problem.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#424

Earlier quoted context omitted.

How does she unlock her front door?

> How does she unlock her front door? For many people, there's no need to unlock the front door because it's never locked. Having to lock your door just means you're living in a terrible neighborhood.

> Having to lock your door just means you're living in a terrible neighborhood.

Interesting. Is that an American thing? I do recall that most of my American friends don't lock their doors, whereas I can only think of a handful of people not locking their doors in Europe - and those live in remote outposts, where people are scarce and deer are unlikely to use the door handle.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#425
post #356

Earlier quoted context omitted.

Huh? The diagram in the article shows two men ("Thief 1", "Thief 2") between the fob and the car, with arrows showing communications going from fob to thief to car. According to the first sentence of the Wikipedia MITM article, that's the very definition.

the relay is of the radio signal, there is no inspection or tampering of the relayed messages. basically, the extender tricks the car into thinking the fob is closer than it is.

In other words, there's identification, there's authentication, but authorization is replaced by "if in range, then authorized." Two out of three is still game over.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#426

Earlier quoted context omitted.

I'm not sure why we can't have some sort of challenge response protocol to prevent MITM...

Challenge response prevents replay attacks, not real time MITM.

This is not even MITM, the thief just blindly proxies traffic.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#427
post #227

Earlier quoted context omitted.

Please yes. Traditional keys fit on my keyring, can survive the clothes washer, don't unlock doors by accident, can open a car with a dead battery, don't have their own battery issues, and can be brought into restricted work environments where radio transmitters are banned. I want key holes in all doors. I want to insert a key to start the car.

About half of those problems don't really exist, in my opinion. I've washed the keyfob (it is waterproof), it has a built in key if the car battery is ever dead, I've never actually had to replace a fob battery. Personally I don't carry any keys so having a small round-ish object in my pocket that doesn't stab me in the leg when I sit down is a preferable situation.

Counterpoint: much that is touted as waterproof tends to have smallprint saying "applicable in dry water only" (yup, had major warranty hassles on supposedly IP68-certified equipment, how could you tell?), and had to replace car fob batteries (unrelated incident; also needed to resync the token generator in the fobs, who knew there even was one?).

"I'm lucky" is not quite the same as "that's a nonexistent problem".

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#428

Earlier quoted context omitted.

But then my mom would have to dump out her purse every time she wanted to unlock her car.

How does she unlock her front door?

Always lock the doors to my house, gives me time to grab the 12 gauge if necessary.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#429

Earlier quoted context omitted.

>>Why is it transmitting without the user pressing a button? Is that a feature? It's not transmitting anything, it works pretty much the same way NFC works. Both the key and the car have their own public/private key pairs(which were obviously set by the manufacturer) and when you touch the handle the car transmits an unlock request to the key, encrypted with the car key's public key(this is going to get confusing lol…

Can you also boost the nfc to make payments from distance?

Yup, but it's not very lucrative vs. risk, thus rare. This doesn't happen all that often because the payments need to also go somewhere, and following the money is apparently easier in electronic form. Plus there's a safety/security layer - you need to authenticate payments above a certain low limit, bank vouches for what's below the limit, etc.

Re: Thieves boosting signal from key fobs inside homes to steal vehicles

#430

This happened to a family member of mine, here in Toronto. Lost their gorgeous M5. Their kid normally wakes up in the middle of the night, except this time, he freaked right out like he was scared. They were wondering what was going on with him, when one of the parents heard the M5 turn on (it's pretty distinct). "That's my car!" His wife said, "Naw, you're crazy, no way." Sure enough, enough, key fob attack and thef…

> If I were the insurance companies, I'd be putting pressure on the car companies And also give car owners an incentive to keep their keys safer, given how many vehicles out there are vulnerable to this. Just fixing this for new cars is only half the solution. I remember back in the 80s my parents got a discount on their insurance for installing a third brake light in the back window of their old Camaro. If my insura…

> And also give car owners an incentive to keep their keys safer, given how many vehicles out there are vulnerable to this. Just fixing this for new cars is only half the solution.

Why is it always up to us to deal with the consequences of all this poorly thought out new crap?

It sort of reminds me of the way they want us to believe that "identity theft" should be our problem to clean up, when its really caused by banks poor security practices.

Post reply on HN