Live data from Hacker News

Keyless BMW cars prove to be very easy to steal

hackaday.com

31–40 of 111 posts

Re: Keyless BMW cars prove to be very easy to steal

#31
post #27
post #22

Earlier quoted context omitted.

Um, it's a GBP 40K car; I don't care.

OBD-II is used on loads of vehicles. If the regulation didn't mandate that this was an open protocol in 10 years every $500 beater is going to be a write off as soon as you lose the keys.

Well, if that means an end to keyless / smart fob systems, I'm all for it; they are nothing but trouble in my opinion. Right now, I think the OBD port should be read-only unless a registered key is present, and recoding the ECU to accept a new key should require more than just physical access.

People don't expect to be able to recode their front door to accept a new blank key - why should a car be different?

Re: Keyless BMW cars prove to be very easy to steal

#32
According to PistonHeads, this isn't limited to BMWs alone:

A quick internet trawl reveals it's not just BMWs that are vulnerable. Devices similar to that used on BMWs are also available for Opel, Renault, Mercedes, Volkswagen, Toyota and Petrol-engined Porsche Cayennes.

The reason this form of theft is currently so rife - and admittedly this issue is not limited to BMWs - is that European competition rules require diagnostic and security reprogramming devices to be available to non-franchised garages. As we understand it, this effectively means that car companies cannot restrict access to or use of OBD ports.

http://pistonheads.com/gassing/topic.asp?h=0&f=23&t=...

Re: Keyless BMW cars prove to be very easy to steal

#33
post #23

Earlier quoted context omitted.

If the alarm system is ultrasonic, I can envision breaking into the car by blasting several watts of power at the same frequency at the car. Loss of receiver dynamic range due to gain compression or transducer saturation == loss of ability to detect changes in the phase of the transmitted signal consistent with someone opening a door and climbing in. What in the world was wrong with plain old car keys -- especially w…

You might be over-thinking this. It's possible to disable the factory alarm motion sensor by double-pressing the lock button on the key fob. This is a feature for people (like me) who take their car on ferries, and who don't enjoy listening to a cacophony of car alarms while on the ferry (I appear to be in minority here, if recent trips were anything to go by) Apparently a fair few owners don't know this feature exis…

Wow, that is horrible UI.

Re: Keyless BMW cars prove to be very easy to steal

#34
I remember the good old days, where my key opened the doors of my friends car and his key could not open mine yet it would start my car.

Where my Aunt drove her car to the mall, locked the doors, and when she came out could get in as she had the keys to her husbands car.

Needless to say in both cases there were the same brand, within a year or so. You did not even need to have same major brand (Ford/Mercury were interchangeable)

Kids these days have it easy, cannot wait for the smart phone app for stealing a ride.

Re: Keyless BMW cars prove to be very easy to steal

#35
post #31
post #27

Earlier quoted context omitted.

OBD-II is used on loads of vehicles. If the regulation didn't mandate that this was an open protocol in 10 years every $500 beater is going to be a write off as soon as you lose the keys.

Well, if that means an end to keyless / smart fob systems, I'm all for it; they are nothing but trouble in my opinion. Right now, I think the OBD port should be read-only unless a registered key is present, and recoding the ECU to accept a new key should require more than just physical access. People don't expect to be able to recode their front door to accept a new blank key - why should a car be different?

A skilled locksmith or someone with a serious interest in locks will have no problem [1] to open your front door without any damage using a lock pick tool [2]. If there's no need for said lock to survive, a selection of power tools make it even easier.

[edit] Which is not to say that cars should be easy to pry open of course ...

[1] in most cases, high-end specialized locks can be an exception. [2] see http://www.lockpicks.com/ for examples.

Re: Keyless BMW cars prove to be very easy to steal

#36
Alas, BMW buyers often cannot opt out of keyless entry, because for some models BMW includes it in popular bundled packages, such that it's impossible for the consumer to avoid buying it without losing other worthwhile features.

This consumer-unfriendly bundling results in BMW buyers often facing what can only be described as ridiculous choices ("which one do I want: a rear-view camera that reduces the risk of accident, OR non-keyless entry that reduces the risk of theft?").

Re: Keyless BMW cars prove to be very easy to steal

#37
post #31

Earlier quoted context omitted.

Well, if that means an end to keyless / smart fob systems, I'm all for it; they are nothing but trouble in my opinion. Right now, I think the OBD port should be read-only unless a registered key is present, and recoding the ECU to accept a new key should require more than just physical access. People don't expect to be able to recode their front door to accept a new blank key - why should a car be different?

A skilled locksmith or someone with a serious interest in locks will have no problem [1] to open your front door without any damage using a lock pick tool [2]. If there's no need for said lock to survive, a selection of power tools make it even easier. [edit] Which is not to say that cars should be easy to pry open of course ... [1] in most cases, high-end specialized locks can be an exception. [2] see http://www.loc…

That's not the point; I don't expect to be able to walk up to your front door with a random Yale key, jam it in and out a few times and have your lock reconfigured to accept my key instead of yours. That's what's happening here - it's not as sophisticated as a lock pick attack, nor as brute force as smashing the dashboard and shorting the appropriate wires.

It's a blind spot in the system that shouldn't exist if the car was locked. The OBD port simply shouldn't be physically connected if the doors are locked. A relay on the CAN bus pins trigged from the central locking might be a start.

Re: Keyless BMW cars prove to be very easy to steal

#38

According to PistonHeads, this isn't limited to BMWs alone: A quick internet trawl reveals it's not just BMWs that are vulnerable. Devices similar to that used on BMWs are also available for Opel, Renault, Mercedes, Volkswagen, Toyota and Petrol-engined Porsche Cayennes. The reason this form of theft is currently so rife - and admittedly this issue is not limited to BMWs - is that European competition rules require d…

Translated into not-evading-responsibility-esque:

The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft.

Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars?

This sounds like either NIH combined with piss poor security engineering done in the name of looking fancy, result of financial constraints or both.

I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets.

Re: Keyless BMW cars prove to be very easy to steal

#39
post #10
post #4

Earlier quoted context omitted.

OBD-II is legally required (in the US) to be open to consumers. The idea being that you can get diagnostics about your vehicle without being extorted by the dealer. (Originally for environmental data about emissions, but later expanded.) http://lobby.la.psu.edu/_107th/093_OBD_Service_Info/frameset...

That makes sense, but I can see the argument that not all features need to be open to consumers.

Amusingly enough most of them aren't - OBD access to interesting features (as opposed to a very limited standard set) usually costs a LOT of money. $10K one-off charge plus an update subscription for example.

OBD-II has essentially failed by allowing so-called "extended" PIDs - which all manufacturers define in their own specific ways. See the Torque forum for endless threads of people wanting extended PIDs for specific models to use with the Torque OBD app.

I suspect this is one reason why good OBD scan tools cost a lot more than the parts cost of an ELM chipset and a few sockets - a trivial adapter costs £20, but a Bavarian Tech scan tool for BMW costs £200, presumably to recoup the costs of buying access to the extended PIDs.

Re: Keyless BMW cars prove to be very easy to steal

#40

According to PistonHeads, this isn't limited to BMWs alone: A quick internet trawl reveals it's not just BMWs that are vulnerable. Devices similar to that used on BMWs are also available for Opel, Renault, Mercedes, Volkswagen, Toyota and Petrol-engined Porsche Cayennes. The reason this form of theft is currently so rife - and admittedly this issue is not limited to BMWs - is that European competition rules require d…

Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…

Somehow that is a solved problem with internet and all other open security architecture.

Just to play devil's advocate, I'm not sure that's entirely true; would you say that every computer user on the entire planet is 100% secured? The vast malware landscape would very much disagree.

I think that it is harder with cars, if only because they have to have an open gate to the heart of their system. Plug in, turn on laptop, access! Apparently that's enshrined in both EU and US law, so not very easy to overcome in the near future.

I do agree with the heart of your message though: this is the year 2012, and whilst as a non-security bod it's easy for me to say, these things really shouldn't be happening.

Post reply on HN