The LockPickingLawyer has done a few recent videos on RFID locks and how one can bypass them. They were pretty interesting to me: "[1052] Defeating a RFID System With The ESPKey" => https://youtu.be/0SEHUqkbIjU "[1056] This Black Box Reads RFID Cards in Your Pocket" => https://youtu.be/dTObKtHzroM
Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
111–120 of 144 posts
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#112Quote: "By contrast, the cloning attack the Birmingham and KU Leuven researchers developed requires that a thief scan a target key fob with an RFID reader from just an inch or two away." Story time: Back in 2005/2006 when I worked for Siemens Automotive on Immobilizer feature (was involved in Mazda and Ford projects) I got my hands on the highly secret crypto source...and much to my surprise I've seen they implemente…
Instead of paying $100’s to rekey the car, I stuck the broken key into a machine at Home Depot. It cracked the encryption in a few minutes and produced a duplicate key. The brand on the replacement is “Ilco”. It’s bulkier than the OEM key, but it works great.
Anyway, I’m not at all surprised to hear the car uses an obsolete encryption protocol.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#113Earlier quoted context omitted.
[ Edited to insert: 1056 sort-of covers this, that's what I get for not having seen his latest video ] The lesson in 1052 sort of misses the point. LPL (his videos are a lot of fun by the way and I recommend them to anyone who is curious about lock picking) says: > So, if you are installing an access control system like this it is really important to use one that only transmits encrypted data This would defeat the ES…
What you are describing is basically MIFARE, which is commonly used by transport cards. Rather than just being an ID, the card is responsible for storing and deducting the balance, and often stores other things like trip history. The allows them to be used without a internet connection on the ticketing machine (e.g. on a bus). There have been vulnerabilities found in older versions, but as far as I know, later versio…
MIFARE is not a card type, it's more a family of cards in the 13.56MHz space, produced by NXP.
There are multiple cards under the banner of Mifare, including:
- Mifare Classic 1/4k - UID + Storage space, with individual keys and crypto. Suffers/ed from multiple vulnerabilities. Used mainly in cheaper hotel access systems, gym cards, etc etc. Can be secure, if your security layer relies on strong crypto on card contents, as opposed to the crypto of the card itself. There are no counters in Mifare Classic.
- Ultralight / Ultralight-C / Ultralight EV1 These cards are low cost, reduced storage space, and are / were conceived specifically for the transport industry. They have 'one way' counters that can be used to deduct 'credits' - but these can't be re-written - so they fulfill the task of discardable tickets.
- Mifare DESFire 3DES / EV1 / EV2 The EV2 is the latest generation - ID + Storage + "Applications", with AES encryption. The 3DES was cracked with side-channel power analysis (like the items in this article) - but the EV2 has no practical attacks to this day.
Information aside, most transport systems do not store value on the cards, but allow for offline use by forcing sync the next time the card passes by an online system - IE, limited trust.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#114Earlier quoted context omitted.
I'm not saying dealing with the kids is at all easy. But the kids are there either way. So I think you have my argument exactly backwards. I'm not saying something is easy. I think kids plus carried bags sounds completely overwhelming . If you want to say I'm wrong, you're making the argument that kids plus carried bags is easier than I think. So please, elaborate on how that's easier than a cart.
You're basically saying "I cannot, in any way, imagine a situation where the parent's story is the sensible choice, and therefore I'm entitled to make a pedantic comment about a situation I wasn't in". Instead, you should give them the benefit of the doubt.
Maybe there are no carts at this store for some awful reason. Maybe the story was so focused on how this type of key solved their problem that they didn't give a fair shake to other possible solutions. More information is needed.
There are multiple ways I can/do give benefit of the doubt, but doing so doesn't make the situation any clearer.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#115Earlier quoted context omitted.
An immobilizer simply keeps the ecu from running the fuel pump, thus preventing the car from starting. The challenge-response from the key is used to authenticate the ecu. It’s not so much that it’s bad encryption (it is) it’s just that the access to override such encryption has physical controls (e.g. if one breaks the glass then one typically has complete access to the vehicle). Second the cpu of the time where may…
. Wrong! Immobilizer is just a tiny part of the BCM (Body Control Module), to which the normal folks usually interact with and call it on-board computer. The truth is that you have CAN (Controlled Area Network), used by BCM and ECU to communicate through, at the very least. When you press the start button, ECU asks BCM "hey dude, can I start the car?", and BCM responds with "yes" or "no" based on various factors, one…
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#116Earlier quoted context omitted.
The BCM is an ECU. The encryption has been broken already but it’s basically trailing bmw and Mercedes etc by about 13 years, so definitely money related but likely they don’t want to or are unable to negotiate patent rights in their technology
BCM is Body Control Module. ECU is Engine Control Unit. 2 different parts (logically). Both are physically PCB's (Printed Circuit Board) that physically can sit either side by side or in very different sides of the car - that's car maker decision. I can't explain it simpler than this.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#117My reaction: Great! Reproducing these keys costs hundreds of dollars and a trip to the dealer. Maybe it can finally be affordable again. I'm less concerned about someone stealing my car. The local police department takes it seriously, no less because stolen cars are used to commit other crimes.
I like how some Chrysler products handle this. You can buy a $50 fob online and program it to your car yourself. The catch is, you need two key fobs to do it. This is so the valet attendant (who only has 1 of your key fobs) can't make his own copy. So, you just have to plan ahead and do it asap when you get a vehicle and always keep 2 in storage in case you want to make another.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#118Earlier quoted context omitted.
>was always a game of chicken with cars entering in the other direction Uh, other direction? Almost always there are hoses from both side of pillar. Is it some regional thing?
There are hoses on both sides of the line of pillars, but at the same time cars can approach the line from either end. No matter what side your port is on, you can use any spot. In these stations.
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#119Earlier quoted context omitted.
>was always a game of chicken with cars entering in the other direction Uh, other direction? Almost always there are hoses from both side of pillar. Is it some regional thing?
As Dylan said, cars come in from any direction, which makes not having the port on the same side in every vehicle a complete mess. From my experience most vehicles have it on the left side, in the US that would be the driver side. If you show-up at a busy gas station with a BMW --which has the port on the right-- well, good luck, it can get ugly. Rather than lining-up behind the car currently fueling-up, you have to…
I would say that in EU (German, French, Italian) cars have it on the right (like the BMW), i.e. opposite the driver side, I have now an Opel and it is on the right, and my my previous car was also on the right.
I believe it being on the right is a traditional safety provision, though they are becoming very rare nowadays (and since several years) a number of fueling stations (at least in the cities) were not, like it is common nowadays, in a (large) court, the pumps were simply along the road, at the most in a 3-4 meters enlargement of the road itself.
So it made sense to have it on the right, the only moment where the driver is exposed to the trafic is when he/she gets out of the car, during the refueling he/she can stand on the right of the car, i.e. between the car and the sidewalk (and the same applies to - as it was once most common - to the gas station service personnel).
Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys
#120Great! The dealership charges inordinately for a new key so I would love to be able to do it myself.
I am married to someone who has lost her keys several times so far. Upgrading from a car with a $50 fob to one with a $200 fob was not fun.