Live data from Hacker News

Reverse engineering a car key fob signal

0x44.cc

11–20 of 85 posts

Re: Reverse engineering a car key fob signal

#14
post #6

Earlier quoted context omitted.

The flipper isn't really a full sdr though, it just has a very minimalist RF IC that has almost non-existent bandwidth. For $400 you can get a limeSDR mini that can read and write 30MHz of spectrum at a time, ie the entire ham 70cm band all at once. If you think a flipper is dangerous, plug in a dummy load and dump noise on L1 then watch your phones GPS stop working, or alternatively decide it's on another continent.

That's true, but more people want to do a little bit of everything than a lot of something. That's why the Flipper is popular.

And it has a fun dolphin mascot!

Re: Reverse engineering a car key fob signal

#15
post #3

>Note: Transceiver SDR devices do exist of course, but they tend to be very pricey A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.

Ok but do the clones have a cute dolphin? Very important feature

Re: Reverse engineering a car key fob signal

#16
post #6

Earlier quoted context omitted.

The flipper isn't really a full sdr though, it just has a very minimalist RF IC that has almost non-existent bandwidth. For $400 you can get a limeSDR mini that can read and write 30MHz of spectrum at a time, ie the entire ham 70cm band all at once. If you think a flipper is dangerous, plug in a dummy load and dump noise on L1 then watch your phones GPS stop working, or alternatively decide it's on another continent.

That's true, but more people want to do a little bit of everything than a lot of something. That's why the Flipper is popular.

I think it's a case of good marketing and good packaging. Realistically you need a laptop to do serious field stuff with a flipper, but only if you plan on doing any testing and reconfiguration and only initially. The flipper isn't much bigger than the limesdr card, but it's nicely packaged and portable so once you have it ready to go you can throw it in a pocket.

The community also helps. The flipper is wildly overpriced for being a glorified happy meal toy but millions of people squeezing every ounce of functional potential out of a happy meal toy is better than a few dozen people writing academic papers with mostly high end industrial (cellular base station) and military applications.

Re: Reverse engineering a car key fob signal

#17
post #12

Why bother intercepting, decoding, and encoding your own signal when you can just use a big antenna and MITM the fob and the vehicle and convince them they are closer than they really are?

I find it wild how pervasive passive keyless entry is. Completely form over (security) function.

Re: Reverse engineering a car key fob signal

#18
post #4
post #3

>Note: Transceiver SDR devices do exist of course, but they tend to be very pricey A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.

> A HackRF clone is cheaper than a Flipper Yes, but a "HackRF clone, plus a Proxmark3, plus IR, plus whatever" probably isn't.

Why would you need such a stack? Article is analyzing unidirectional fobs, HackRF is half duplex so you could easily capture and analyze and/or replay the signal. Only additional thing you need is a PC.

One thing to consider is that the payload will be encrypted so you wont be really able to tell apart what is the rolling code. Hopefully fobs have stronger encryption so collecting enough sniffs and analyzing is insufficient (looking at tesla with their 64bit encryption, hopefully they upgraded).

Honda replay myth mentioned in the article is BS, it was popularized by ppl faking a simple replay attack while doing a more complicated one. If you record the fob command and the car never receives it, of course you can immidiatly after replay it to the car and car will accept it since RC is valid. But if you're sniffing while car is receiving it, RC gets updated. If Honda didn't have RC, it would have been far worse than the KIA boys (overriding immobilizer protection and hotwiring the car) issue that did a lot of damage to KIA in US.

Re: Reverse engineering a car key fob signal

#19
post #17
post #12

Why bother intercepting, decoding, and encoding your own signal when you can just use a big antenna and MITM the fob and the vehicle and convince them they are closer than they really are?

I find it wild how pervasive passive keyless entry is. Completely form over (security) function.

I wouldn't be so quick to say that - it's unquestionably more convenient than old-fashioned transponder keys in a few really important ways. You can't lock your keys in the car, you don't need more than one free hand to open a door (and sometimes not even that), and you don't need to deal with a massive bundle of keys jangling against your knees.

Re: Reverse engineering a car key fob signal

#20
post #3

>Note: Transceiver SDR devices do exist of course, but they tend to be very pricey A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.

I've got a Flipper, LimeSDR (non-mini), some old-school ham equipment, a cheapo $10 RTL-SDR receiver, a few cheap HTs, some RFID tools, etc.

Each has their use. The Flipper is nice for quick and lightweight checking of things. LimeSDR is incredibly capable, but also a bit of a pain in the ass to use. Not something you'll flip out to quickly check something or run an experiment.

Post reply on HN