Live data from Hacker News

When Your Used Car Is a Little Too ‘Mobile’

krebsonsecurity.com

51–60 of 102 posts

Re: When Your Used Car Is a Little Too ‘Mobile’

#52
post #44

Earlier quoted context omitted.

Good luck finding it. And then, good luck getting to it.

While a pain, it isn't impossible. There will be an FCC ID that it has (due to transmitting receiving). Based on that device, you at least know what to look for (a PCI card? An entire board? an Antenna?). Since FCC testing is expensive, I would not doubt that many manufacturers just make one card to install into multiple cars (to lower the FCC testing cost). That would be the best case, as all you need to do is find…

Instead of doing that, I'd simulate "network loss" by substituting a 50 ohm dummy load for the output antenna. This assumes that it is a connector, not soldered right to the board.

This way, there is no "fault" other than not being in a cellular-coverage area.

Re: When Your Used Car Is a Little Too ‘Mobile’

#53
post #13

BMW is also massively insecure. My "secret token" I had to enter on my phone to link it with the car was the VIN number. That number is physically stamped into the engine block and chassis so obviously cannot be changed, even after I sell the car. I also suspect these numbers are sequential. Till this car is scrapped I will be able to locate it, turn on the AC, unlock the doors etc.

Yes, but:

- at least in Germany, you have to give physical signature at the dealer to sign up for CarData

- you need to give consent to every third party in order for them to access the data

- to have the car linked to CarData, you have to get in the car, turn the ignition on, receive activation code displayed which is displayed on the infotainment, type the code back into the CarData platform

Re: When Your Used Car Is a Little Too ‘Mobile’

#54
post #21

Earlier quoted context omitted.

Certainly your 1980s SUV is certainly the thing most likely to be the location of your death, unless you’re older than ~70.

Only if your 1980s SUV is capable of reaching speeds that might kill you. I will simply be maimed horribly and die later in the hospital, screaming "AT LEAST MY DEATH WASN'T TRACKED BY ALEXA". I am, on balance, comfortable with this fate. Alexa: His death was, in fact, tracked by Alexa

I’m hearing that last sentence in the voice of the narrator from arrested development.

Re: When Your Used Car Is a Little Too ‘Mobile’

#55

Earlier quoted context omitted.

Only if your 1980s SUV is capable of reaching speeds that might kill you. I will simply be maimed horribly and die later in the hospital, screaming "AT LEAST MY DEATH WASN'T TRACKED BY ALEXA". I am, on balance, comfortable with this fate. Alexa: His death was, in fact, tracked by Alexa

I’m hearing that last sentence in the voice of the narrator from arrested development.

I wish that voice was an option on echo.

Re: When Your Used Car Is a Little Too ‘Mobile’

#56
post #52
post #44

Earlier quoted context omitted.

While a pain, it isn't impossible. There will be an FCC ID that it has (due to transmitting receiving). Based on that device, you at least know what to look for (a PCI card? An entire board? an Antenna?). Since FCC testing is expensive, I would not doubt that many manufacturers just make one card to install into multiple cars (to lower the FCC testing cost). That would be the best case, as all you need to do is find…

Instead of doing that, I'd simulate "network loss" by substituting a 50 ohm dummy load for the output antenna. This assumes that it is a connector, not soldered right to the board. This way, there is no "fault" other than not being in a cellular-coverage area.

That's a good way too. Didn't think of that.

Re: When Your Used Car Is a Little Too ‘Mobile’

#57

Earlier quoted context omitted.

Can you start a ICE vehicle remotely? With a keyfob for decades, and with an app for years. It's virtually standard equipment in certain states, along with plug-in engine block heaters. I thought it was mostly a EV thing A guy at work likes to start his massive Ford Raptor with his phone at the end of the day and set off the alarms of the cars he's parked between.

Do we work together? (I'm assuming not.) Some guy where I work does the same thing, same truck. Usually he's still thousands of feet away when he starts it too, maybe even still in the office. Or maybe it's just a Houston thing.

I'm not in Texas. I think it's an "I bought a giant truck to carry around six dead leaves in the back when I go shopping at Target" kind of thing.

Re: When Your Used Car Is a Little Too ‘Mobile’

#58
post #16

Earlier quoted context omitted.

On many (all?) modern cars it's also visible at the bottom of driver's side of the windshield. A car's VIN is public information.

I have a small piece of black paper over mine. I am happy to let a law enforcement officer view it if they ask.

I thought about doing that, but if someone wants my VIN, they just have to squat down and look at the VIN that's punched in the frame of my truck.

I haven't checked other vehicles, but I imagine they also have their VINs punched in the frame where it's easily visible.

I don't know if it's against the law to grind that off, but it's probably not against the law to weld a metal plate over it.

Re: When Your Used Car Is a Little Too ‘Mobile’

#59
post #13

BMW is also massively insecure. My "secret token" I had to enter on my phone to link it with the car was the VIN number. That number is physically stamped into the engine block and chassis so obviously cannot be changed, even after I sell the car. I also suspect these numbers are sequential. Till this car is scrapped I will be able to locate it, turn on the AC, unlock the doors etc.

I'm curious, would it be possible for a malicious person to create a bunch of VMs running the app and brute force VINs to get access to thousands of vehicles and do things all at the same time?

As it is, it already sounds like a theif's dream: no special, suspicious tools required: just a burner phone with an app, walk up to a car, enter the VIN, unlock doors, steal stuff.

Re: When Your Used Car Is a Little Too ‘Mobile’

#60
post #13

BMW is also massively insecure. My "secret token" I had to enter on my phone to link it with the car was the VIN number. That number is physically stamped into the engine block and chassis so obviously cannot be changed, even after I sell the car. I also suspect these numbers are sequential. Till this car is scrapped I will be able to locate it, turn on the AC, unlock the doors etc.

I'm curious, would it be possible for a malicious person to create a bunch of VMs running the app and brute force VINs to get access to thousands of vehicles and do things all at the same time? As it is, it already sounds like a theif's dream: no special, suspicious tools required: just a burner phone with an app, walk up to a car, enter the VIN, unlock doors, steal stuff.

No, it’s not possible: https://news.ycombinator.com/item?id=22259046
Post reply on HN