Live data from Hacker News

Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

wired.com

101–110 of 144 posts

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#102
post #82

Earlier quoted context omitted.

I'm not seeing the problem. Your suggested title makes it sound like they could clone all the keys from those manufacturers which isn't true. And if you inserted a word like "some", my first question would be, "Well, how many?" To me "millions" is useful in conveying it isn't just a niche issue, but it isn't everything, either.

Why not include a percent? Are we talking about 10% of cars, or more like 80%? Is it mostly recent cars, or are cars from several years ago also affected? It's not a terrible headline, but it could also be improved.

Does it matter at all that this is the original title of the article? How about quoting it if we don't like it?

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#103

The LockPickingLawyer has done a few recent videos on RFID locks and how one can bypass them. They were pretty interesting to me: "[1052] Defeating a RFID System With The ESPKey" => https://youtu.be/0SEHUqkbIjU "[1056] This Black Box Reads RFID Cards in Your Pocket" => https://youtu.be/dTObKtHzroM

[ Edited to insert: 1056 sort-of covers this, that's what I get for not having seen his latest video ] The lesson in 1052 sort of misses the point. LPL (his videos are a lot of fun by the way and I recommend them to anyone who is curious about lock picking) says: > So, if you are installing an access control system like this it is really important to use one that only transmits encrypted data This would defeat the ES…

LPL's recent videos are quite interesting, but the RFID cards he targets are one the 'low hanging fruit's side of the spectrum: very old systems with no encryption that only transmit an ID. The system he demonstrates harkens back to the 1980s. [1]

There are literally hundreds of other protocols and systems that are much better: the DesFire EV2, etc [2] for similar costs (ie 80c vs 70c) [3][4]

Just wanted to point out that the systems that you hypothesize exist already, and are not orders "Significantly" more expensive.

[1] https://en.m.wikipedia.org/wiki/Wiegand_interface

[2] https://en.m.wikipedia.org/wiki/MIFARE#MIFARE_DESFire_EV2

[3] https://www.idcardsdirect.co.uk/nxp-mifare-desfire-ev2-4k-bl...

[4] https://www.amazon.com/100pcs-Proximity-ISOProx-26-Bit-H1030...

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#104

Earlier quoted context omitted.

you dont have children

I'm not saying dealing with the kids is at all easy. But the kids are there either way. So I think you have my argument exactly backwards. I'm not saying something is easy. I think kids plus carried bags sounds completely overwhelming . If you want to say I'm wrong, you're making the argument that kids plus carried bags is easier than I think. So please, elaborate on how that's easier than a cart.

You're basically saying "I cannot, in any way, imagine a situation where the parent's story is the sensible choice, and therefore I'm entitled to make a pedantic comment about a situation I wasn't in". Instead, you should give them the benefit of the doubt.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#105

The LockPickingLawyer has done a few recent videos on RFID locks and how one can bypass them. They were pretty interesting to me: "[1052] Defeating a RFID System With The ESPKey" => https://youtu.be/0SEHUqkbIjU "[1056] This Black Box Reads RFID Cards in Your Pocket" => https://youtu.be/dTObKtHzroM

[ Edited to insert: 1056 sort-of covers this, that's what I get for not having seen his latest video ] The lesson in 1052 sort of misses the point. LPL (his videos are a lot of fun by the way and I recommend them to anyone who is curious about lock picking) says: > So, if you are installing an access control system like this it is really important to use one that only transmits encrypted data This would defeat the ES…

What you are describing is basically MIFARE, which is commonly used by transport cards. Rather than just being an ID, the card is responsible for storing and deducting the balance, and often stores other things like trip history. The allows them to be used without a internet connection on the ticketing machine (e.g. on a bus).

There have been vulnerabilities found in older versions, but as far as I know, later versions are still considered secure.

https://en.m.wikipedia.org/wiki/MIFARE

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#106
For the curious or eagle-eyed, David Oswald, one of the co-authors of this paper is also one of the co-creators of the ChameleonMini [1], an open source RFID emulation device which has become the defacto tool for emulation in the penetrating community.

Well done David, and thank you :)

[1] https://github.com/emsec/ChameleonMini/wiki

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#108
post #29

Earlier quoted context omitted.

It should be a construction approximately: first DHE and then the car challenging the fob to MAC a unique message. Exponential backoff after every failed attempt for that token (fob).

Exponential backoff could DoS someone from opening their own car.

I guess you could backoff based on an ID, but then spoofing IDs would need to be defended against. So that doesn't solve anything either. I think DoS is fine to deny attackers entry because most sensible fobs have a backup key with a chip so the driver could just unlock their car like an animal.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#109
post #90
post #29

Earlier quoted context omitted.

Exponential backoff could DoS someone from opening their own car.

You can already DoS people from opening their car by using a jammer, or expoxying the locking mechanism.

Lol, true that. I prefer all of:

- superglue and baking soda in the lock tumblers

- 10 lbs / 4.5 kg of sugar in the gas tank

- pulling the fuel pump relays and spark plug wires

- unhooking the starter positive solenoid wire

- slashing the tires' sidewalls so they can't be repaired.

DoS complete. :) Maybe a swift kick in the bumper to set off the alarm at that point. ;)

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#110
post #98

Earlier quoted context omitted.

The BCM is an ECU. The encryption has been broken already but it’s basically trailing bmw and Mercedes etc by about 13 years, so definitely money related but likely they don’t want to or are unable to negotiate patent rights in their technology

BCM is Body Control Module. ECU is Engine Control Unit. 2 different parts (logically). Both are physically PCB's (Printed Circuit Board) that physically can sit either side by side or in very different sides of the car - that's car maker decision. I can't explain it simpler than this.

ECU is usually an Electronic Control Unit. Some OME's name one of there ECU's, Engine Control Unit to make stuff more complex. Not app manufacturers have Engine Control Unit or a Body Control Module. The electronic architecture of a Volkwagen, GM, Volvo or Tesla is very different. Hardly any of the ECU's have the same name.

It looks like Wikipedia agrees with me and in addition, the Engine Control Unit article state that they are usually called the Engine Control Module (ECM) to lower confusion. https://en.wikipedia.org/wiki/Electronic_control_unit https://en.wikipedia.org/wiki/Engine_control_unit

Different OEMs vary in architecture and naming. Making it a bit of a hassle working in a teir-1 with multiple customers.

Post reply on HN