Earlier quoted context omitted.
A skilled locksmith or someone with a serious interest in locks will have no problem [1] to open your front door without any damage using a lock pick tool [2]. If there's no need for said lock to survive, a selection of power tools make it even easier. [edit] Which is not to say that cars should be easy to pry open of course ... [1] in most cases, high-end specialized locks can be an exception. [2] see http://www.loc…
That's not the point; I don't expect to be able to walk up to your front door with a random Yale key, jam it in and out a few times and have your lock reconfigured to accept my key instead of yours. That's what's happening here - it's not as sophisticated as a lock pick attack, nor as brute force as smashing the dashboard and shorting the appropriate wires. It's a blind spot in the system that shouldn't exist if the…
Keyless BMW cars prove to be very easy to steal
41–50 of 111 posts
Re: Keyless BMW cars prove to be very easy to steal
#42According to PistonHeads, this isn't limited to BMWs alone: A quick internet trawl reveals it's not just BMWs that are vulnerable. Devices similar to that used on BMWs are also available for Opel, Renault, Mercedes, Volkswagen, Toyota and Petrol-engined Porsche Cayennes. The reason this form of theft is currently so rife - and admittedly this issue is not limited to BMWs - is that European competition rules require d…
Everyone wants the keys to be kept outside the car.
The future of personal freedom will be decided based on whether our fix is to give the keys to the car owner to keep in their home, so that they can unlock their car if they loose their fob (or allow a mechanic of their choosing to generate a new fob), or whether to give the keys to the car manufacturers, so that only approved dealers (and criminals who hack into the dealers' electronic networks) will be able to generate new fobs.
Re: Keyless BMW cars prove to be very easy to steal
#43Earlier quoted context omitted.
A skilled locksmith or someone with a serious interest in locks will have no problem [1] to open your front door without any damage using a lock pick tool [2]. If there's no need for said lock to survive, a selection of power tools make it even easier. [edit] Which is not to say that cars should be easy to pry open of course ... [1] in most cases, high-end specialized locks can be an exception. [2] see http://www.loc…
That's not the point; I don't expect to be able to walk up to your front door with a random Yale key, jam it in and out a few times and have your lock reconfigured to accept my key instead of yours. That's what's happening here - it's not as sophisticated as a lock pick attack, nor as brute force as smashing the dashboard and shorting the appropriate wires. It's a blind spot in the system that shouldn't exist if the…
Re: Keyless BMW cars prove to be very easy to steal
#44Earlier quoted context omitted.
That's not the point; I don't expect to be able to walk up to your front door with a random Yale key, jam it in and out a few times and have your lock reconfigured to accept my key instead of yours. That's what's happening here - it's not as sophisticated as a lock pick attack, nor as brute force as smashing the dashboard and shorting the appropriate wires. It's a blind spot in the system that shouldn't exist if the…
There's no evidence the OBD port was actually used in this attack. The programmer could have been directly connected to an easily accessible CAN connected component such as the wing mirrors.
Re: Keyless BMW cars prove to be very easy to steal
#45According to PistonHeads, this isn't limited to BMWs alone: A quick internet trawl reveals it's not just BMWs that are vulnerable. Devices similar to that used on BMWs are also available for Opel, Renault, Mercedes, Volkswagen, Toyota and Petrol-engined Porsche Cayennes. The reason this form of theft is currently so rife - and admittedly this issue is not limited to BMWs - is that European competition rules require d…
Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…
Here, the EU has effectively said that someone with physical access to the car can generate their own keys (since anyone can pretend to be a mechanic, and all mechanics are allowed to generate keys), and the car manufacturers are saying that they should have the root keys, so that only approved dealers can create new ones. Much like Microsoft saying to ARM tablet manufacturers that they have to allow only Microsoft's keys in ARM tablets, blocking end users from installing their self-signed OS.
tl;dr: the problem is not protocols, it is key management.
Re: Keyless BMW cars prove to be very easy to steal
#46Isn't the solution here that only BMW authorized devices should be able to connect to the ODB? Or is that already the case? I guess it just takes one unscrupulous dealer to upload their certificate.
The security loophole here seems to be that someone could extract information out of the OBD port to generate a new key. That should only be available from the factory port.
Re: Keyless BMW cars prove to be very easy to steal
#47Earlier quoted context omitted.
You might be over-thinking this. It's possible to disable the factory alarm motion sensor by double-pressing the lock button on the key fob. This is a feature for people (like me) who take their car on ferries, and who don't enjoy listening to a cacophony of car alarms while on the ferry (I appear to be in minority here, if recent trips were anything to go by) Apparently a fair few owners don't know this feature exis…
Wow, that is horrible UI.
Re: Keyless BMW cars prove to be very easy to steal
#48So "very easy to steal" is when "sophisticated criminals" "somehow" manage to circumvent multiple security features? And the person claiming that it is "very easy" apparently doesn't even know how it's done. This is sensationalist rubbish.
Re: Keyless BMW cars prove to be very easy to steal
#49Earlier quoted context omitted.
Regular car keys are a pain in a lot of ways, and not all that secure, either. To really do this correctly, you need to have cryptographic challenges between a key and an ECU, and to prevent the ECU from just getting swapped, you probably want to have several processors in various parts of the car, such that replacing them all quickly is too hard. Then you still have the problem of someone driving the car into a fara…
> To really do this correctly, you need to have cryptographic challenges between a key and an ECU, Nonsense. The problem isn't cloning the key, the problem is that you are reprogramming the lock to accept this new key you happen to have with you. No amount of crypto is going to save you when your verifier is full of holes. You can't even use signing to only accept approved programming devices since OBD regulations en…
I think you could get openness with signing. You have a central, non-profit authority that blesses, records, and publishes all signings in real time. When a car turns up missing, you see if anybody re-keyed it and the police have a discussion with them. You could recoup expenses with a modest charge per re-key.
Re: Keyless BMW cars prove to be very easy to steal
#50According to PistonHeads, this isn't limited to BMWs alone: A quick internet trawl reveals it's not just BMWs that are vulnerable. Devices similar to that used on BMWs are also available for Opel, Renault, Mercedes, Volkswagen, Toyota and Petrol-engined Porsche Cayennes. The reason this form of theft is currently so rife - and admittedly this issue is not limited to BMWs - is that European competition rules require d…
Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…
>I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets.
You're missing a couple of key points here:
1) This is not a network attack, so the internet is largely irrelevant.
2) This is similar to having an attacker sit down at the physical computer they're attacking (a much harder problem).
3) Legislation in Europe forces car manufacturers to use an insecure design.
Anti-competition legislation in Europe dictates that the manufacturer cannot stand in the way of the transfer of secret keys. This means that the entire security communication must occur between the on-board computer and the OBD-II tool. Other than a physical lockout on the OBD-II port, I can't think of a good defense against this attack.
In the US, many car manufacturers take a different approach. The security key is provided by the manufacturer, not the on-board computer, so you can't simply walk up and re-program a key. I don't know if this is true of all manufacturers though.