(Also, apparently Spidey's preferred search engine is Bing, but I assume that's a paid product placement.)
Keyless BMW cars prove to be very easy to steal
61–70 of 111 posts
Re: Keyless BMW cars prove to be very easy to steal
#62On Doard Biagnostic?
Someone needs a proofreader
Re: Keyless BMW cars prove to be very easy to steal
#63This is just poor design, even given the EU laws and requirements.
Re: Keyless BMW cars prove to be very easy to steal
#64Why don't they just build in a delay before the new key starts working? Even a few hours would be enough to prevent most thefts without being too inconvenient on the rare occasion you lose a key. This is just poor design, even given the EU laws and requirements.
Re: Keyless BMW cars prove to be very easy to steal
#65Re: Keyless BMW cars prove to be very easy to steal
#66Earlier quoted context omitted.
It isn't solved for computer networks, this is exactly the same as the current debate about secure boot. Secure boot is an open standard, but we've not agreed about who can hold the keys: http://www.fsf.org/campaigns/secure-boot-vs-restricted-boot Here, the EU has effectively said that someone with physical access to the car can generate their own keys (since anyone can pretend to be a mechanic, and all mechanics are…
It isn't solved for computer networks, this is exactly the same as the current debate about secure boot. I would disagree. To me this sounds like a perfect scenario for asymmetric encryption, which would solve this in a secure fashion. Obviously someone should have a secure repository for official keys issued, so that duplicates can be made, upon request, upon owners' authorization. It might be bothersome and cumbers…
I suspect that they are already using asymmetric encryption, with some sort of mechanism to allow third party mechanics (and thieves pretending to be mechanics) to sign new fobs.
the point is it should be a possible process, even for third party mechanical shops.
Yes, agreed. The issue seems to be how much faith you put in the manufacturers to play ball. If they have to incur a cost to manage keys, that might lead to legislation around putting limits on the amount they can charge for access. It seems like a rabbit hole full of problems to leave them in charge. What happens when someone who has lost the keys to their second hand car goes to a third party mechanic to unlock the computer in their car built by a manufacturer who has gone out of business?
it should be open enough to allow you to (re-)program it with your own keys
With this strategy, the solution the the above question is to hope that the user added their own key/certificate to the car in advance. I suspect that the people who would do that would intersect strongly with those who are meticulous with keeping a spare key in a secure place anyway, so it would only help a minority of people.
Some of the other ideas, like time locks or falling back to a physical key to create new fobs, sound like they may do a better job of ensuring user freedom. Those solutions might apply to secure boot too, but it still seems unsolved in practice.
Re: Keyless BMW cars prove to be very easy to steal
#67If this is because of OBD regulations, perhaps it can be changed somewhat. Give the owner a small electronic device that will be necessary to generate a new key for the car they purchased. That device can be kept separate from the car but when the key is actually lost, the owner can bring it to the mechanic and generate a new one. The thieves would need to steal the device before stealing the car, which would make th…
Re: Keyless BMW cars prove to be very easy to steal
#68Earlier quoted context omitted.
>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…
1) This is not a network attack, so the internet is largely irrelevant. Security protocols that can be used on two points on the Internet can also be used between two pieces of hardware, like a programmer/diagnostic tool and an embedded computer.
Engineers look at this problem and see the engineering problem, but it's cynical (albeit warranted) to believe that the engineers at BMW didn't see the same problems. I bet they are well aware of this vulnerability, but they're unable to do anything about it.
There's a valuable lesson to be learned. It ties in to the old adage: be careful what you wish for, you might just get it. There's a lot of rumbling about new privacy legislation in the US, but the entire concept makes me really nervous. What are the chances that legislators understand the internet well enough to craft effective legislation? Not good, I'm afraid.
Re: Keyless BMW cars prove to be very easy to steal
#69Earlier quoted context omitted.
Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…
>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…
And the consequence is that a replacement key costs $150. No joke.
Re: Keyless BMW cars prove to be very easy to steal
#70Why don't they just build in a delay before the new key starts working? Even a few hours would be enough to prevent most thefts without being too inconvenient on the rare occasion you lose a key. This is just poor design, even given the EU laws and requirements.
I'm not sure that would help. It just means the thieves need to steal the car in two steps instead of one.