Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
11–20 of 144 posts
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#12Ceo's BMW X5 was stolen last year.He watched the CCTV later on.The guy came to the car with a laptop and drove away after a minute or so. Police found the car dumped somewhere on a road,as the car ran out of fuel and apparently it had some security feature that prevented the thieves from refiling it.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#13Ceo's BMW X5 was stolen last year.He watched the CCTV later on.The guy came to the car with a laptop and drove away after a minute or so. Police found the car dumped somewhere on a road,as the car ran out of fuel and apparently it had some security feature that prevented the thieves from refiling it.
Sounds like you’re describing a range extender attack on the keyless start. Almost(I don’t know any that aren’t) all cars with the feature are vulnerable to this.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#14Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#15Call me old but what is so great about the smart key? Not having to pull it out of your pocket? I know this is an old rant already but car have reached the crappyfication curve, when something cannot improve its main purpose anymore it starts adding unneeded features to be able to push a “new” product.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#16I'm less concerned about someone stealing my car. The local police department takes it seriously, no less because stolen cars are used to commit other crimes.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#17There are plenty of offline hardware based solutions already on the market especially for unlocking computers with MFA. It needs to be offline generation for computers for NIST DFARS 800-171 compliance.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#18Call me old but what is so great about the smart key? Not having to pull it out of your pocket? I know this is an old rant already but car have reached the crappyfication curve, when something cannot improve its main purpose anymore it starts adding unneeded features to be able to push a “new” product.
I no longer have to pry the key out of my jeans, or go looking for it in all my bags when I’m travelling.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#19First: Auto manufacturers ought to get together and agree on one common key + entry system standard. It can be a combination of physical key and remote key if necessary.
The problem: If you have multiple vehicles (and many families do) you end-up with a keychain full of horrendously large and unnecessarily inconvenient keys, key-fobs, whatever. Some manufacturers seem intent on making the larges and most inconvenient boxes they can possibly imagine. This is entirely unnecessary. In this day and age one ought to be able to have a universal programmable entry system that gets programmed for your vehicles and that's that. One device to rule them all.
Second: Auto manufacturers ought to get together and agree on placing the fuel tank port on the same side.
The problem: Today you have cars and trucks with fuel tank refill ports on the left and the right. It can be an absolute nightmare to go to a gas station where most of the cars have ports on the left and you show-up with one on the right. This is one of the reasons for which I hated driving our BMW. Going to the gas station was always a game of chicken with cars entering in the other direction.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#20The essential problem is that static credentials are transmitted and can be copied. If they used a randomly generated code to unlock the cars (needs to be generated offline) then that would solve this issue. There are plenty of offline hardware based solutions already on the market especially for unlocking computers with MFA. It needs to be offline generation for computers for NIST DFARS 800-171 compliance.
Not necessarily. Relay attacks are very hard to defeat, regardless of your crypto scheme:
https://www.wired.com/2017/04/just-pair-11-radio-gadgets-can...