Earlier quoted context omitted.
If they were using key reprogramming/hacking there's no reason to 'always use' the passenger side front door as claimed in the video. So I don't think it's clear that these thieves are using any of those techniques. I imagine it might be stupider, like maybe there's a way to induce the unlock button or motor to trigger via induction or something. Though I'm pretty poorly informed about that kind of thing scientifical…
If I was a thief then I'd always hit the passenger side front door as it gives me the quickest access to the glove compartment, where valuables are likely to be stored. Not sure what the mystery is here.
Police admit they're 'stumped' by mystery car thefts
21–30 of 139 posts
Re: Police admit they're 'stumped' by mystery car thefts
#22Why is this so baffling a shocking? I think we all knew this was possible before anybody actually did it. It's not like their using proper crypto. It's the equivalent of a bad house lock give me some good lock picks and 60 seconds and I'm in so why is this so surprising?
Re: Police admit they're 'stumped' by mystery car thefts
#23What's the big mystery here? There have been published articles on the ease of hacking car remotes (and even the onboard electronics) going back at least a couple of years. For example: http://content.usatoday.com/communities/driveon/post/2011/01... http://www.schneier.com/blog/archives/2012/07/hacking_bmws_r... http://reviews.cnet.com/8301-13746_7-20085131-48/remote-unlo... http://news.consumerreports.org/cars/2011/…
Re: Police admit they're 'stumped' by mystery car thefts
#24Earlier quoted context omitted.
Oh, but according to SOMEONE (source for this claim is not given) "That code is encrypted and constantly changing — and should be hackproof." American media at it's best!
How would you describe a challenge based authentication system that uses 128-bit AES? I find the reporter's description reasonable.
http://ir.atmel.com/releasedetail.cfm?ReleaseID=665225
Where Atmel announced a new transponder chip & microcontroller, which do, indeed, use 128-bit AES. This is from 2012 though, so I'm not sure how widely adopted this particular chip is, or if other, older chips are in widespread use that are 128-bit AES.
But even if everybody is using 128-bit AES, all that means is that the actual encryption itself is probably essentially unbreakable. But, as well all know, cryptographic systems are more than just the raw crypto algorithm. All sorts of systems which use crypto are eventually found to be insecure, so this whole thing should still come as little surprise (well, to people like us anyway. To the average cop, maybe this all sounds like black magic).
Re: Police admit they're 'stumped' by mystery car thefts
#25Earlier quoted context omitted.
Oh, but according to SOMEONE (source for this claim is not given) "That code is encrypted and constantly changing — and should be hackproof." American media at it's best!
How would you describe a challenge based authentication system that uses 128-bit AES? I find the reporter's description reasonable.
In other words, the superlatives don't match the reality.
Re: Police admit they're 'stumped' by mystery car thefts
#26What's the big mystery here? There have been published articles on the ease of hacking car remotes (and even the onboard electronics) going back at least a couple of years. For example: http://content.usatoday.com/communities/driveon/post/2011/01... http://www.schneier.com/blog/archives/2012/07/hacking_bmws_r... http://reviews.cnet.com/8301-13746_7-20085131-48/remote-unlo... http://news.consumerreports.org/cars/2011/…
You ask what the big mystery is, and then link to a lot of unrelated hacks/exploits. Yes, the article is that someone hacked/exploited the remote door open specifically, apparently on seemingly random cars. It is a mystery how they are doing it, though it is painfully obvious that they are exploiting something .
I don't see how you can say that is "unrelated". Even if our "mystery" thieves aren't using those exact exploits, there is NO "mystery" that hackers have demonstrated the ability to break car remote systems. But the article and the quotes from the police make it sound like the police are just staring at the wall, drooling and going "duuuhhh huhhh huhhhh... how'd they do that.. duhhuhhhh huhhhhh." Now that's probably not literally the case, but the article makes it sound like nobody has even the slightest clue that this stuff is possible, or how it's done. And that's just not true.
Re: Police admit they're 'stumped' by mystery car thefts
#27So, if you figure out how these are salted (VIN?) and what pseudo-random generator it uses, you can recreate the signal.
Re: Police admit they're 'stumped' by mystery car thefts
#28The level of security of a car door is presumably a lot higher than that of a garage door, but the technology of using a rolling code is the same and the need to be able to (re)synchronize remote keys/fobs is also there. With the cars I own, there is a procedure in the operator's manual on how to resync your keys. Nominally, it requires physical access - an already unlocked car.
Ref: http://www.programmingkey.com/
My first guess is that the bad guys figured out a timing attack that confuses the lock software if the "right" sequence of codes are sent with the "right" timing.
My alternate guess is that the bad guys figured out a way to mimic the resync mechanism without requiring physical access.
Re: Police admit they're 'stumped' by mystery car thefts
#29Earlier quoted context omitted.
You ask what the big mystery is, and then link to a lot of unrelated hacks/exploits. Yes, the article is that someone hacked/exploited the remote door open specifically, apparently on seemingly random cars. It is a mystery how they are doing it, though it is painfully obvious that they are exploiting something .
You ask what the big mystery is, and then link to a lot of unrelated hacks/exploits. I don't see how you can say that is "unrelated". Even if our "mystery" thieves aren't using those exact exploits, there is NO "mystery" that hackers have demonstrated the ability to break car remote systems. But the article and the quotes from the police make it sound like the police are just staring at the wall, drooling and going "…
Re: Police admit they're 'stumped' by mystery car thefts
#30Earlier quoted context omitted.
If I was a thief then I'd always hit the passenger side front door as it gives me the quickest access to the glove compartment, where valuables are likely to be stored. Not sure what the mystery is here.
Do people actually put valuable things in their glove boxes? I didn't think people put stuff besides proof of insurance and their car manuals in them. I'd think it a lot more likely that valuables were in the center console storage.