Live data from Hacker News

Keyless BMW cars prove to be very easy to steal

hackaday.com

1–10 of 111 posts

Re: Keyless BMW cars prove to be very easy to steal

#4
post #3

Isn't the solution here that only BMW authorized devices should be able to connect to the ODB? Or is that already the case? I guess it just takes one unscrupulous dealer to upload their certificate.

OBD-II is legally required (in the US) to be open to consumers. The idea being that you can get diagnostics about your vehicle without being extorted by the dealer. (Originally for environmental data about emissions, but later expanded.)

http://lobby.la.psu.edu/_107th/093_OBD_Service_Info/frameset...

Re: Keyless BMW cars prove to be very easy to steal

#6
post #2

> It can then be used to program a new keyfob Is he programming the keyfob? or is he adding the key to the car's authorized_keys list?

The keys are generally just passive RFID chips so it's more like an authorized_keys file.

The problem here isn't that there's no physical key, those are usually laughably easy to circumvent. I think the real trick here is the physical attack they used to break into the vehicle and gain access to the OBD port without setting the alarm off.

There's a number of cheap and obvious tricks BMW could have used to make the RFID portion of this attack a lot harder. Including, making the OBD port more difficult to actually get at without actually sitting in the car and not letting the new key start the car for some reasonably long period of time.

Re: Keyless BMW cars prove to be very easy to steal

#8
post #6
post #2

> It can then be used to program a new keyfob Is he programming the keyfob? or is he adding the key to the car's authorized_keys list?

The keys are generally just passive RFID chips so it's more like an authorized_keys file. The problem here isn't that there's no physical key, those are usually laughably easy to circumvent. I think the real trick here is the physical attack they used to break into the vehicle and gain access to the OBD port without setting the alarm off. There's a number of cheap and obvious tricks BMW could have used to make the RF…

[deleted]

Re: Keyless BMW cars prove to be very easy to steal

#9
post #6
post #2

> It can then be used to program a new keyfob Is he programming the keyfob? or is he adding the key to the car's authorized_keys list?

The keys are generally just passive RFID chips so it's more like an authorized_keys file. The problem here isn't that there's no physical key, those are usually laughably easy to circumvent. I think the real trick here is the physical attack they used to break into the vehicle and gain access to the OBD port without setting the alarm off. There's a number of cheap and obvious tricks BMW could have used to make the RF…

I think there is a legal requirement that the ODB-2 port needs to be in a standard location. (Driver's Side, Under dashboard)

Re: Keyless BMW cars prove to be very easy to steal

#10
post #4
post #3

Isn't the solution here that only BMW authorized devices should be able to connect to the ODB? Or is that already the case? I guess it just takes one unscrupulous dealer to upload their certificate.

OBD-II is legally required (in the US) to be open to consumers. The idea being that you can get diagnostics about your vehicle without being extorted by the dealer. (Originally for environmental data about emissions, but later expanded.) http://lobby.la.psu.edu/_107th/093_OBD_Service_Info/frameset...

That makes sense, but I can see the argument that not all features need to be open to consumers.
Post reply on HN