Live data from Hacker News

Keyless BMW cars prove to be very easy to steal

hackaday.com

101–110 of 111 posts

Re: Keyless BMW cars prove to be very easy to steal

#101
post #90

Earlier quoted context omitted.

And what if the owner looses that "small electronic device", or forgets to forward it to the new owner. The whole point of this feature is that you should be able to get the car running if you loose EVERYTHING apart from the car itself. The only way to stop it is to give the manufacturer (or other trusted third party) exclusive right to issue keys but apparently the regulations say no to that.

Nonsense. Why not simply design it so that it's difficult and dangerous to access the "reset button" unless you're a trained mechanic with a Rotary lift? Then it's more difficult to steal than an ordinary car, and you are done. In light of history, the answer is probably a combination of laziness, inertia, and an attempt to steer customers to authorized BMW service centers. Or perhaps the threat model includes theft…

Of course you can always make it safer physically, I'm talking about the cryptographic safety.

About towing, look at the video in the article posted. One guy breaks in and releases the parking break while the other 3 push the car. Doesn't show where they push it to though.

Re: Keyless BMW cars prove to be very easy to steal

#102
post #89

Earlier quoted context omitted.

Regarding 4a: if you lose your key (and thus you have lost the ability to disarm the alarm) the entire vehicle is bricked?

No, you just get the dealer to plug something into the (possibly proprietary) port that's used by the alarm system. The assumption that this kind of thing needs to be done via the OBD-II port is wacky from the get-go. It may have been easier for some lazy system integrators at BMW to do it that way, but it certainly wasn't necessary, or apparently advisable.

I'm not seeing how that will deter thieves. Instead of plugging into the ODB port they will just plug into the alarm system's port. Even if it's proprietary, they'll employ/bribe/coerce an official technician to figure out whatever Rube Goldberg sequence of events that are required to re-enable the vehicle.

Re: Keyless BMW cars prove to be very easy to steal

#103
post #102

Earlier quoted context omitted.

No, you just get the dealer to plug something into the (possibly proprietary) port that's used by the alarm system. The assumption that this kind of thing needs to be done via the OBD-II port is wacky from the get-go. It may have been easier for some lazy system integrators at BMW to do it that way, but it certainly wasn't necessary, or apparently advisable.

I'm not seeing how that will deter thieves. Instead of plugging into the ODB port they will just plug into the alarm system's port. Even if it's proprietary, they'll employ/bribe/coerce an official technician to figure out whatever Rube Goldberg sequence of events that are required to re-enable the vehicle.

Presumably there would be more opportunities for secure handshaking with a proprietary port. It doesn't need to involve security by obscurity -- it just needs not to be barkingly stupid.

The best practices in auto security are probably reflected by whatever the leading Japanese brands are doing these days. Traditionally Hondas have been the biggest theft targets, but a glance at the list of most-stolen cars in America ( http://editorial.autos.msn.com/article.aspx?cp-documentid=43... ) suggests that they've more or less solved the problem, as of the mid-1990s. I seriously doubt there's that much need for further innovation.

Re: Keyless BMW cars prove to be very easy to steal

#104
post #18

Earlier quoted context omitted.

Attackers might work for a dealer or otherwise fully decode the system. The only way to build a system like this securely is to have securely-held keys (cryptographic, not physical; physical locks are all easy to break), and ideally published and reviewed code for the security system, same as any other security system. (I've actually thought about building a secure ignition system for cars, mainly to solve the car bo…

I solved this problem by just leaving my car unlocked with a guy with an AK guarding it, though. How resistant is he to femme fatales?

Already had 3 wives, didn't need another.

Re: Keyless BMW cars prove to be very easy to steal

#105
post #102

Earlier quoted context omitted.

I'm not seeing how that will deter thieves. Instead of plugging into the ODB port they will just plug into the alarm system's port. Even if it's proprietary, they'll employ/bribe/coerce an official technician to figure out whatever Rube Goldberg sequence of events that are required to re-enable the vehicle.

Presumably there would be more opportunities for secure handshaking with a proprietary port. It doesn't need to involve security by obscurity -- it just needs not to be barkingly stupid. The best practices in auto security are probably reflected by whatever the leading Japanese brands are doing these days. Traditionally Hondas have been the biggest theft targets, but a glance at the list of most-stolen cars in Americ…

Yes, secure handshaking via PKI is a well known and already solved problem. However, as mentioned in the post you originally replied to: "Anti-competition legislation in Europe dictates that the manufacturer cannot stand in the way of the transfer of secret keys." Keys, here, referring to the private half of a public/private keypair.

This means that a manufacturer can't be the exclusive source of resetting a key much in the same way that Verisign isn't the exclusive source of SSL certificates. Due to the anti-competition legislation, you should be able to take your vehicle to any local garage and have it fully serviced whether for a tune-up or to get a key reset. And if a local garage can be employed to reset your key because they have access to the private key required to sign the key request, thieves can do it just as easily.

Re: Keyless BMW cars prove to be very easy to steal

#106
post #105

Earlier quoted context omitted.

Presumably there would be more opportunities for secure handshaking with a proprietary port. It doesn't need to involve security by obscurity -- it just needs not to be barkingly stupid. The best practices in auto security are probably reflected by whatever the leading Japanese brands are doing these days. Traditionally Hondas have been the biggest theft targets, but a glance at the list of most-stolen cars in Americ…

Yes, secure handshaking via PKI is a well known and already solved problem. However, as mentioned in the post you originally replied to: "Anti-competition legislation in Europe dictates that the manufacturer cannot stand in the way of the transfer of secret keys." Keys, here, referring to the private half of a public/private keypair. This means that a manufacturer can't be the exclusive source of resetting a key much…

Are you speaking from knowledge of the anti-competition legislation, or just from the summaries we've seen upthread? It strikes me that we're taking a car blog's throwaway description of the law as a presumed engineering constraint.

Re: Keyless BMW cars prove to be very easy to steal

#107
I don't understand this. I have an older BMW which developed starting problems with the immobiliser computer. It doesn't have keyless entry but it is based on rfid.

I did extensive research on the system and there were three parts - the key, the immobiliser and the engine management computer. The key physically turned the ignition, but the security was in a rfid chip inside the key, which was physically matched to the immobiliser via an antenna ring that circles the lock. The immobiliser was physically matched to the computer via a VIN-based code. If you lost the key, you had to order a new one from germany after producing the VIN and proof of ownership to a licensed dealer. They keys cost about $500 from memory - don't lose the key. There is an upper limit of 10 keys to be produced per vehicle, with two of those supplied upon purchase.

In order to replace the immobiliser computer, again both the VIN and proof of ownership had to be supplied to the licensed dealer, who then ordered a new one from the factory in Germany. You cannot swap any of the parts between cars - you can't reprogram keys, reprogram the immobiliser or reprogram the computer.

If you do put a new computer or immobiliser in, it had to be taken into a BMW dealership to re-sync and get all the devices to handshake each other and agree that they were all legitimate. Otherwise - no start.

I know all this because I tried to hotwire the car myself to get it working until the new computer arrived (3 week order period). While I could manually activate the fuel supply and manually activate the starter, the computer refused to tell the spark plugs to ignite and refused to tell the injectors to inject.

What I'm curious about is how have they gone backwards from this seemingly impregnable system to one where you can get the car to reprogram a key? Surely it can't all be the fault of the OBD port - I doubt there is anything in the legislation calling for the ability to reprogram keys via the vehicle itself? Or is it just the fact that someone has come up with software that replicates what the factory does?

Somehow it all seems a retrograde step. Given that the older systems worked with rfid, whether or not you put the key in seems a moot point.

Re: Keyless BMW cars prove to be very easy to steal

#108
post #105

Earlier quoted context omitted.

Yes, secure handshaking via PKI is a well known and already solved problem. However, as mentioned in the post you originally replied to: "Anti-competition legislation in Europe dictates that the manufacturer cannot stand in the way of the transfer of secret keys." Keys, here, referring to the private half of a public/private keypair. This means that a manufacturer can't be the exclusive source of resetting a key much…

Are you speaking from knowledge of the anti-competition legislation, or just from the summaries we've seen upthread? It strikes me that we're taking a car blog's throwaway description of the law as a presumed engineering constraint.

Every reputable website with details beyond the "scary, scary news" headlines have made mention of the legal aspect. There's a lot of information in this thread over at Bimmerpost.com as well:

http://www.1addicts.com/forums/showthread.php?t=712717

Re: Keyless BMW cars prove to be very easy to steal

#109

Earlier quoted context omitted.

Are you speaking from knowledge of the anti-competition legislation, or just from the summaries we've seen upthread? It strikes me that we're taking a car blog's throwaway description of the law as a presumed engineering constraint.

Every reputable website with details beyond the "scary, scary news" headlines have made mention of the legal aspect. There's a lot of information in this thread over at Bimmerpost.com as well: http://www.1addicts.com/forums/showthread.php?t=712717

Are you sure you linked to the right thread? I didn't see any discussion of the legal aspect at all - other than "can we sue BMW?"

Re: Keyless BMW cars prove to be very easy to steal

#110
post #107

I don't understand this. I have an older BMW which developed starting problems with the immobiliser computer. It doesn't have keyless entry but it is based on rfid. I did extensive research on the system and there were three parts - the key, the immobiliser and the engine management computer. The key physically turned the ignition, but the security was in a rfid chip inside the key, which was physically matched to th…

[deleted]
Post reply on HN