Live data from Hacker News

Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

wired.com

31–40 of 144 posts

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#31

One related and another unrelated though... First: Auto manufacturers ought to get together and agree on one common key + entry system standard. It can be a combination of physical key and remote key if necessary. The problem: If you have multiple vehicles (and many families do) you end-up with a keychain full of horrendously large and unnecessarily inconvenient keys, key-fobs, whatever. Some manufacturers seem inten…

>was always a game of chicken with cars entering in the other direction

Uh, other direction? Almost always there are hoses from both side of pillar. Is it some regional thing?

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#32
Quote: "By contrast, the cloning attack the Birmingham and KU Leuven researchers developed requires that a thief scan a target key fob with an RFID reader from just an inch or two away."

Story time: Back in 2005/2006 when I worked for Siemens Automotive on Immobilizer feature (was involved in Mazda and Ford projects) I got my hands on the highly secret crypto source...and much to my surprise I've seen they implemented a Vigenere style of cipher. I was astounded by this. Having some crypto background as pet projects on previous years I knew this class of ciphers are at least 1.5 centuries obsolete and they are thought only from historical perspective. Therefore I prepared and called a panel of higher-ups (managers, group leaders and even including the hardware department chief) showing to them that the source code implementation is very dangerous and that for a criminal group to mass steal cars would be very easy. Including telling them exactly what the article is talking about - put an RF recorder under the handle door (how many car owners will check there?), record sessions of radio communications between key fob and the car, analyze that, extract the crypto key and steal the car with a duplicate no more then maximum a week after. Their reply? : "standard in industry call that we also allow mechanical keys to open doors/start the car, so a criminal group can do them as well much easier", and that was the end of that meeting.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#33

The LockPickingLawyer has done a few recent videos on RFID locks and how one can bypass them. They were pretty interesting to me: "[1052] Defeating a RFID System With The ESPKey" => https://youtu.be/0SEHUqkbIjU "[1056] This Black Box Reads RFID Cards in Your Pocket" => https://youtu.be/dTObKtHzroM

[ Edited to insert: 1056 sort-of covers this, that's what I get for not having seen his latest video ]

The lesson in 1052 sort of misses the point. LPL (his videos are a lot of fun by the way and I recommend them to anyone who is curious about lock picking) says:

> So, if you are installing an access control system like this it is really important to use one that only transmits encrypted data

This would defeat the ESPKey demonstrated, but of course that product exists precisely because it's all you need for common systems today. If "encrypted data" was common the ESPKey's successor would probably be a product that sits next to the reader and gets its own copy of the raw RFID signal. Not as convenient, and less fun for doing cool demos, but still plenty effective enough for crooks.

What you actually need to do to defeat this is a bit more expensive. You need the token (keyfob, card, etcetera) to be smart enough to use the tiny surge of power to do local computation, and then produce one-time-only access codes. That would actually fix the problem, because to get the current code a bad guy needs to steal the token and that's an ordinary physical security consideration that humans are used to dealing with. This way an ESPKey gets the one-time code you just used, but neither replaying it nor copying it to a card to try later will do anything useful.

Unfortunately this smarter token would be significantly more expensive. We saw with EMV cards (payment cards) that the smart and secure option (DDA with changing cryptograms) is expensive enough that providers would often rather take a risk and give you an insecure cheaper alternative which looks identical, especially if they believe regulators, courts etc. won't realise they took the cheap option and so the risk actually lands on their customers not on them.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#34

Quote: "By contrast, the cloning attack the Birmingham and KU Leuven researchers developed requires that a thief scan a target key fob with an RFID reader from just an inch or two away." Story time: Back in 2005/2006 when I worked for Siemens Automotive on Immobilizer feature (was involved in Mazda and Ford projects) I got my hands on the highly secret crypto source...and much to my surprise I've seen they implemente…

Hopefully that's in writing somewhere for when the lawsuits happen. Financial consequences tend to motivate large companies to change their ways.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#35

My reaction: Great! Reproducing these keys costs hundreds of dollars and a trip to the dealer. Maybe it can finally be affordable again. I'm less concerned about someone stealing my car. The local police department takes it seriously, no less because stolen cars are used to commit other crimes.

Wait, what are you advocating? Return to keys without an immobiliser??? You do realise that that's the feature that has single-handedly destroyed car theft that was so rampant by the 90s? That is what made cars so difficult to steal, but also what makes keys cost what they do and require an approved dealer to code the keys. Return to the old keys where you only had the key and nothing else would be......crazy, really.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#36

Great! The dealership charges inordinately for a new key so I would love to be able to do it myself.

I am married to someone who has lost her keys several times so far. Upgrading from a car with a $50 fob to one with a $200 fob was not fun.

Key insurance is a thing if this is a legitimate issue for you.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#37

One related and another unrelated though... First: Auto manufacturers ought to get together and agree on one common key + entry system standard. It can be a combination of physical key and remote key if necessary. The problem: If you have multiple vehicles (and many families do) you end-up with a keychain full of horrendously large and unnecessarily inconvenient keys, key-fobs, whatever. Some manufacturers seem inten…

Phone as key is the future. I was skeptical at first given the general unreliability of Bluetooth but Tesla managed to do it. It's been flawless for me. Key card as backup makes perfect sense although I believe upcoming NFC standards will make even this unnecessary with the ability to have the phone act as a passive NFC tag even when the battery is dead.

The key fob is still available if you want it. Tesla even allows adding and removing keys at home. It's an underrated part of the Model 3. Phone key could have been a disaster but they nailed it.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#38

Call me old but what is so great about the smart key? Not having to pull it out of your pocket? I know this is an old rant already but car have reached the crappyfication curve, when something cannot improve its main purpose anymore it starts adding unneeded features to be able to push a “new” product.

Not having the key scratch your smartphone, for one. For another, it just reduces the steps to get you from point A to point B. All these little things add up.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#39
post #7

Earlier quoted context omitted.

https://www.thetileapp.com/en-us/store/tiles/pro If she loses her keys just once it pays for itself many times over.

I assume this person must be losing their keys in public or somewhere unknown. Otherwise their house must have quite the bonanza of keys waiting for them.

Those types of systems like tile work in public as well, they use a network of other users that will inevitably walk by the lost item.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#40

Call me old but what is so great about the smart key? Not having to pull it out of your pocket? I know this is an old rant already but car have reached the crappyfication curve, when something cannot improve its main purpose anymore it starts adding unneeded features to be able to push a “new” product.

Today’s it’s mostly smart keys. Tomorrow it will all be driven from your phone. I can’t wait when I never have to carry a key again. This is a stepping stone.
Post reply on HN