Live data from Hacker News

Police admit they're 'stumped' by mystery car thefts

today.com

41–50 of 139 posts

Re: Police admit they're 'stumped' by mystery car thefts

#41

Earlier quoted context omitted.

Oh, but according to SOMEONE (source for this claim is not given) "That code is encrypted and constantly changing — and should be hackproof." American media at it's best!

How would you describe a challenge based authentication system that uses 128-bit AES? I find the reporter's description reasonable.

Does it use ECB (electronic code book)? Because that would be a system using AES that would be terrible.

How many times do we have to go over this? Crypto is hard to do right.

ECB: http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation...

Re: Police admit they're 'stumped' by mystery car thefts

#42

What's the big mystery here? There have been published articles on the ease of hacking car remotes (and even the onboard electronics) going back at least a couple of years. For example: http://content.usatoday.com/communities/driveon/post/2011/01... http://www.schneier.com/blog/archives/2012/07/hacking_bmws_r... http://reviews.cnet.com/8301-13746_7-20085131-48/remote-unlo... http://news.consumerreports.org/cars/2011/…

If they were using key reprogramming/hacking there's no reason to 'always use' the passenger side front door as claimed in the video. So I don't think it's clear that these thieves are using any of those techniques. I imagine it might be stupider, like maybe there's a way to induce the unlock button or motor to trigger via induction or something. Though I'm pretty poorly informed about that kind of thing scientifical…

I searched for Acura MDX alarm antenna location and a quick glance tells me that the antenna is located behind the glovebox. So I would guess it probably works better from that side of the car...notice they seem to have to get very close to the car.

Re: Police admit they're 'stumped' by mystery car thefts

#43

Earlier quoted context omitted.

If I was a thief then I'd always hit the passenger side front door as it gives me the quickest access to the glove compartment, where valuables are likely to be stored. Not sure what the mystery is here.

Do people actually put valuable things in their glove boxes? I didn't think people put stuff besides proof of insurance and their car manuals in them. I'd think it a lot more likely that valuables were in the center console storage.

The glove box has a lock so it must be a good place for valuables!

Re: Police admit they're 'stumped' by mystery car thefts

#44
post #40

What's the big mystery here? There have been published articles on the ease of hacking car remotes (and even the onboard electronics) going back at least a couple of years. For example: http://content.usatoday.com/communities/driveon/post/2011/01... http://www.schneier.com/blog/archives/2012/07/hacking_bmws_r... http://reviews.cnet.com/8301-13746_7-20085131-48/remote-unlo... http://news.consumerreports.org/cars/2011/…

>What's the big mystery here? The method that the thieves are using is unknown. While those links to may be useful to shed light on this type of crime, they do little to confirm the method that these thieves are employing. Hence, there is mystery.

Agreed, there is a mystery about the exact details. I read TFA as suggesting that the fundamental concept of "car hacking" is unknown. I was responding more to the generalization that I felt like I observed, than to the question of exactly how this specific set of thieves is working. I should have been more clear on that point.

Re: Police admit they're 'stumped' by mystery car thefts

#45

Earlier quoted context omitted.

The article makes it sound exactly like what it seems to be -- that the thieves are using an exploit that they don't know, and thus they want to know. One of the guys quoted makes a profession out of this and he doesn't know what they're doing. But apparently lots of people on HN do.

Nobody here has claimed to know exactly what exploit the thieves are using. But a lot of people are claiming (rightly) that general knowledge that these car systems have vulnerabilities is widespread. And that point is what seemed, to me, to be missing from TFA. If TFA had given some more context, and said "exploits which would allow this type of access were shown at a recent hacker conference, and some cars have kno…

[deleted]

Re: Police admit they're 'stumped' by mystery car thefts

#46
post #15

Why is this so baffling a shocking? I think we all knew this was possible before anybody actually did it. It's not like their using proper crypto. It's the equivalent of a bad house lock give me some good lock picks and 60 seconds and I'm in so why is this so surprising?

There is obviously something broken somewhere, but I'd consider 128-bit AES to be 'proper crypto'.

Re: Police admit they're 'stumped' by mystery car thefts

#47

>Both the transmitter and the receiver use the same pseudo-random number generator. When the transmitter sends a 40-bit code, it uses the pseudo-random number generator to pick a new code, which it stores in memory. On the other end, when the receiver receives a valid code, it uses the same pseudo-random number generator to pick a new one. In this way, the transmitter and the receiver are synchronized. The receiver o…

I'm betting these generators have large sources of entropy, right? You have to move your mouse around a bunch before you lock your doors.

Re: Police admit they're 'stumped' by mystery car thefts

#48

I was intrigued by their mention of this "Jim Stickley" who was cited as a top security expert. I had never heard of him before, so did a quick search to find out a little more about him. He seems to be a pretty legit and well known security guy[1], but it surprises me that he said: This is really frustrating because clearly they've figured out something that looks really simple and whatever it is they're doing, it t…

They should hire someone like Dan Boneh[1] to look for cryptoanalytic attacks. Of course, I'm sure he'll find a whole bunch of attacks. That's going to be a really expensive to repair all that faulty crypto hardware.

[1]:http://en.wikipedia.org/wiki/Dan_Boneh

Re: Police admit they're 'stumped' by mystery car thefts

#49
The advice given in the article sounds ridiculous to my (brazilian) ears.

- "Don't leave valuables in the car". Really? I'd have to deal with smashed windows every single day if I left anything that could possibly be of value sitting overnight (or for a few minutes in some places). Perhaps even an empty shoe box. And that's with tinted windows so dark they are not even supposed to be street legal.

- "Keep your car registration in the wallet". Identity theft with a car registration should not be possible here, as it doesn't contain ID numbers, nor photographs and is no proof of identity (you have to display the driver's licence - which is proof of identity - and the car's documents on demand if requested by authorities). Still, it is a ridiculously bad idea to leave it sitting in a car overnight. If the car is stolen, the crooks would have a much easier time evading minor police checkpoints.

I guess some places have such a low crime rate that people just forget basic security precautions?

Re: Police admit they're 'stumped' by mystery car thefts

#50

I was intrigued by their mention of this "Jim Stickley" who was cited as a top security expert. I had never heard of him before, so did a quick search to find out a little more about him. He seems to be a pretty legit and well known security guy[1], but it surprises me that he said: This is really frustrating because clearly they've figured out something that looks really simple and whatever it is they're doing, it t…

I agree with your skepticism but I disagree with your analysis of Stickley. This looks like the typical security clown out there writing his own wikipedia entry. His article's main point seems to be that he found a buffer overflow. There, he's a security expert. What security professional worth his salt says "that should not be possible"? The entire security profession is about identifying assumptions and then challe…

Well we criminalized (DMCA) this kind of "hacking," so as far as this "security professional" knows it is impossible because he hasn't heard of it. Maybe if we stop preventing security researchers from talking about vulnerabilities we could know about these things before the thieves.
Post reply on HN