Live data from Hacker News

A surprisingly simple way to foil car thieves

news.umich.edu

501–510 of 576 posts

Re: A surprisingly simple way to foil car thieves

#501
post #388

Earlier quoted context omitted.

Are you suggesting that locks would have prevented this?

Certainly kill switches would Every TV show has a self destruct mechanism to prevent a ship from falling into enemy hands and blabla etc

So... you're basing your opinion about machines used by soldiers in combat.... on fictional television shows?

Just a question, have you ever worked with soldiers before?

Re: A surprisingly simple way to foil car thieves

#502

Earlier quoted context omitted.

I'm curious in how many jurisdictions simply "showing criminal intent" is sufficient to mean they're legally a target to be shot at, potentially fatally. I'd be pretty horrified to know I was living in such a jurisdiction. Whereas somebody walking through my open door while clearly posing a threat to my life, or the life of family members (e.g. holding a weapon) I would have no hypothetical qualms over aiming a gun a…

Are you sure you can run all those calculations while breaking and entering is occurring in your home? It varies quite a bit from place to place, as you can see... https://en.wikipedia.org/wiki/Castle_doctrine But the basic idea is that the natural right of self-defense extends to certain areas, including one's home. (That is, you do not have to wait until the intruder has his hands around your neck in order to defen…

Thanks for that link, that is pretty interesting and I can't honestly say I know exactly what the law is where I live (in Australia, but not in the state that gets a special mention in that article). And absolutely, if I happened to have access to a lethal weapon and I was sufficiently fearful I might well be tempted to use it on an intruder even well before they posed an immediate threat. But if I really were responsible for taking an intruder's life and the courts determined that they were never a realistic threat to anyone, nor was there any good reason for me to believe they were (e.g. I had a clear view of them, could see that had no weapon, and they weren't acting in any sort of hostile manner), I'd fully expect to go to jail for it.

Re: A surprisingly simple way to foil car thieves

#503
post #314
post #170

Earlier quoted context omitted.

> What about a classical mechanical key? can be picked >The problem is relay theft, where thief's relay the signal of your fob key inside the house to the car via a simple antenna and amplifier system. Cryptographical signing won't help. AFAIK the attack you describe only applies to keyless entry systems (ie. you can open and start a car without having to pull your key out), which is related but not the same as an im…

The modern versions of these keys cannot be cloned, they are challenge response. So you need to relay the challenge from the key, and then relay the response from the key back to the car. This is often used by thiefs who bring the relay close to the front door, hoping for the keys to be in a bowl or a hook near the door. Then they can open and start the car using the relay. The car then won't turn off when it loses c…

> The modern versions of these keys cannot be cloned

The persistent rumor, of course, is that this has been cracked for specific models from specific manufacturers, with the help of someone at the dealership, maybe someone who owes large amounts of drug or gambling money to local criminal syndicate types. "All" you'd need to do then is use a valid challenge response pairs off as a cryptographic oracle to brute force the challenge-response algorithm and recover the seed value computation algorithm for the key and the car. Then "all" you need to do is record a challenge-response pair from the real key talking to the vehicle, and maybe the VIN, in order to duplicate the key, in order to steal the vehicle.

If this has been been done, the algorithm and seed-value recovery technique have not been publicly shared over the Internet, so it's only a rumor that it's been done, but given how high-tech thieves are these days, I don't consider it outside the realm of possibility.

What isn't outside the realm of possibility is the Rolling-PWN attack, which can be done with a $32 device and has been demonstrated against 10 years of Honda vehicles, up to 2022.

https://rollingpwn.github.io/rolling-pwn/

Re: A surprisingly simple way to foil car thieves

#504
post #472

Earlier quoted context omitted.

In the UK in WW2 for a period of time everyone had to disable their vehicles when unattended by removing the rotor arm https://www.britishpathe.com/asset/47622/

A local Chevy dealer once got a Silverado pickup with the 454 (7.5 liters) V8 in it. As an anti-theft measure, they disconnected four of the spark plug wires when they parked it on the lot. It got stolen anyway - it turns out that a 454 will still run on half it's cylinders.

Seems it would be more effective to slightly disconnect the coil wire, in addition to being less work to reverse.

Re: A surprisingly simple way to foil car thieves

#505
post #319

Earlier quoted context omitted.

Huh, never considered valet parking to actually be a real thing. Isn't it annoying having to wait for someone to drive your car? I'd almost pay more not to have to do it.

It's common in denser cities, primarily with two applications: 1. at parking garages so that cars can be double- or triple-parked. This is by far the most common use case for valets today. At these lots, you actually do have to pay more (or arrive early) for a spot that doesn't require valet parking. 2. at high-end restaurants or other similar venues where there is no immediately nearby parking and limited or no stre…

Simplest way to avoid using a valet service is probably to not turn up in a car.

Re: A surprisingly simple way to foil car thieves

#506

Earlier quoted context omitted.

I guess this works if you don’t have immobilizers. In Canada they’re mandated, so the ECU is expecting some kind of digital signal from the key before turning on (but sometimes you can just shuck the rf chip inside they key and glue it in the right spot, or uncode it from the écu).

1996 ford pickups have about the simplest ignition wiring you could possibly imagine. I wouldn't even dream of doing this on anything new enough to have an immobilizer.

> I wouldn't even dream of doing this on anything new enough to have an immobilizer.

It would work great on many Hyundais built as recently as last year!

Re: A surprisingly simple way to foil car thieves

#507
post #450
post #358

Earlier quoted context omitted.

Why not? A 2GHz is very attainable in modern CPUs and translates to 0.0005ns per cycle. This isn't theoretical either. 802.11mc[1] is a real standard and is accurate to 1-2m. [1] https://en.wikipedia.org/wiki/IEEE_802.11mc

Aren’t you off by three orders of magnitude? 2GHz translates to 0.5ns per cycle. Or perhaps you meant to write ms.

Whoops, you're right!

Re: A surprisingly simple way to foil car thieves

#508

Earlier quoted context omitted.

Where are you seeing $44k? The link you gave shows payscales for postdocs, and points to another page [1] showing that predoctoral trainees get $27k. Also, in my field and in my region, $27k is massive funding. I don't know anybody who makes that much, let alone $44k, and we also don't get tuition or benefits covered. Our TA/RA union is currently striking because it's essentially impossible to live off of funding alo…

I'll give you that I misread bullet 2, so the total is a little over 31k. But grants that fund salaries for predoctoral scholars don't just fund the salary itself, they also cover the additional funds listed on that page. You can't partially fund a trainee on a grant. In any case, this wildly misses the forest for the trees - 1.2 mil in grants does not cover 6 years of salary plus research costs for 2 trainees and 2…

Absolutely, 6 years with a 1.2mil grant is ridiculous. I was just hopeful that somewhere there were PhD students making enough money to live from research

Re: A surprisingly simple way to foil car thieves

#509
post #264

Earlier quoted context omitted.

The Fed is the cause of QE/ZIRP, but it's not "funded by taxpayers" in any meaningful sense. The mechanism by which QE is done is that the fed prints money and uses it to buy government bonds and other assets, which pushes bond prices up, and consequently yields (and therefore interest rates) down. All of this doesn't cost the fed anything. The money is printed by them, after all. It's not like they're borrowing mone…

100% of the direct monetary cost of QE is borne by the American people.

And what is the mechanism by which the "direct monetary cost" arises, and is borne by the american people?

Re: A surprisingly simple way to foil car thieves

#510

Earlier quoted context omitted.

Speaking as someone who's reviewed for NSF before, I'd have expected this grant to also include resources to get the product to market, which I'm assuming you haven't done.

I don't think so. NSF Small Business Technology Transfer (STTR) and NSF Small Business Innovation Research (SBIR) grants include getting products to market. But this is a regular research grant from NSF Secure and Trustworthy Cyberspace (SaTC)[1]. The SaTC does have a Transition to Practice (TTP) option. However, this research is CORE (see the text "CORE" in the project title [2]). The objective is to write research…

Thanks for the correction!
Post reply on HN