Earlier quoted context omitted.
The article makes it sound exactly like what it seems to be -- that the thieves are using an exploit that they don't know, and thus they want to know. One of the guys quoted makes a profession out of this and he doesn't know what they're doing. But apparently lots of people on HN do.
Nobody here has claimed to know exactly what exploit the thieves are using. But a lot of people are claiming (rightly) that general knowledge that these car systems have vulnerabilities is widespread. And that point is what seemed, to me, to be missing from TFA. If TFA had given some more context, and said "exploits which would allow this type of access were shown at a recent hacker conference, and some cars have kno…
Police admit they're 'stumped' by mystery car thefts
61–70 of 139 posts
Re: Police admit they're 'stumped' by mystery car thefts
#62Earlier quoted context omitted.
Oh, but according to SOMEONE (source for this claim is not given) "That code is encrypted and constantly changing — and should be hackproof." American media at it's best!
How would you describe a challenge based authentication system that uses 128-bit AES? I find the reporter's description reasonable.
Re: Police admit they're 'stumped' by mystery car thefts
#63What's the big mystery here? There have been published articles on the ease of hacking car remotes (and even the onboard electronics) going back at least a couple of years. For example: http://content.usatoday.com/communities/driveon/post/2011/01... http://www.schneier.com/blog/archives/2012/07/hacking_bmws_r... http://reviews.cnet.com/8301-13746_7-20085131-48/remote-unlo... http://news.consumerreports.org/cars/2011/…
Re: Police admit they're 'stumped' by mystery car thefts
#64What happens in the event that you loose your fob?
Re: Police admit they're 'stumped' by mystery car thefts
#65I never understood why keyfobs work in a UDP style, when communication between the remote and car would be infinitely better. For instance, instead of just sending "12345" and having the doors open since the code was expected, What about if the remote said "hey car, whats your random number" - the car then transmits back "54321" at which point the transmitter sends a hashed reply sha512(54321 + unique-random-id-set-p…
Re: Police admit they're 'stumped' by mystery car thefts
#66I never understood why keyfobs work in a UDP style, when communication between the remote and car would be infinitely better. For instance, instead of just sending "12345" and having the doors open since the code was expected, What about if the remote said "hey car, whats your random number" - the car then transmits back "54321" at which point the transmitter sends a hashed reply sha512(54321 + unique-random-id-set-p…
Re: Police admit they're 'stumped' by mystery car thefts
#67Earlier quoted context omitted.
I would assume that they use the passenger side front door because that is where the storage compartment is located.
They use the passenger side door because its the one facing the sidewalk.
Re: Police admit they're 'stumped' by mystery car thefts
#68Earlier quoted context omitted.
I would assume that they use the passenger side front door because that is where the storage compartment is located.
They use the passenger side door because its the one facing the sidewalk.
Re: Police admit they're 'stumped' by mystery car thefts
#69What's the big mystery here? There have been published articles on the ease of hacking car remotes (and even the onboard electronics) going back at least a couple of years. For example: http://content.usatoday.com/communities/driveon/post/2011/01... http://www.schneier.com/blog/archives/2012/07/hacking_bmws_r... http://reviews.cnet.com/8301-13746_7-20085131-48/remote-unlo... http://news.consumerreports.org/cars/2011/…
Oh, but according to SOMEONE (source for this claim is not given) "That code is encrypted and constantly changing — and should be hackproof." American media at it's best!
Versus the amazing quality of Chinese or Russian media? Brazilian media? Romanian media? Or maybe it's the French that have outstanding journalistic integrity and never make mistakes!
Re: Police admit they're 'stumped' by mystery car thefts
#70Earlier quoted context omitted.
How would you describe a challenge based authentication system that uses 128-bit AES? I find the reporter's description reasonable.
You have no proof that Honda/Acura use 128-bit AES. In fact, being familiar with some research in the security of electronic car locks, I would wager they do not use AES.
This is the worst possible design, and not far from what late 90's cars use. Even though it is the dumbest possible solution it still works reasonably well, because you have to have access to the key to start the car. You can clone the key in a second, but you still must get within inches of the key.