Live data from Hacker News

Police admit they're 'stumped' by mystery car thefts

today.com

91–100 of 139 posts

Re: Police admit they're 'stumped' by mystery car thefts

#91

The advice given in the article sounds ridiculous to my (brazilian) ears. - "Don't leave valuables in the car". Really? I'd have to deal with smashed windows every single day if I left anything that could possibly be of value sitting overnight (or for a few minutes in some places). Perhaps even an empty shoe box. And that's with tinted windows so dark they are not even supposed to be street legal. - "Keep your car re…

The tint on your windows probably contributes -- they can't see inside, so they break in just in case there might be something worth stealing.

a lot of smash and grab guys use something called a "ninja rock" which is a chunk of porcelain from a spark plug. throw it against the window and it explodes. if you have tint, it is like tape on the glass, so it doesn't break apart as easily and makes the smash and grab operation take longer.

Re: Police admit they're 'stumped' by mystery car thefts

#92

Earlier quoted context omitted.

The article makes it sound exactly like what it seems to be -- that the thieves are using an exploit that they don't know, and thus they want to know. One of the guys quoted makes a profession out of this and he doesn't know what they're doing. But apparently lots of people on HN do.

Nobody here has claimed to know exactly what exploit the thieves are using. But a lot of people are claiming (rightly) that general knowledge that these car systems have vulnerabilities is widespread. And that point is what seemed, to me, to be missing from TFA. If TFA had given some more context, and said "exploits which would allow this type of access were shown at a recent hacker conference, and some cars have kno…

But a lot of people are claiming (rightly) that general knowledge that these car systems have vulnerabilities is widespread.

So you have a device that can open random car doors in seconds? Do you know where to get one? Do you know anyone who has one?

The police apparently don't (and the police almost certainly know far more about crimes and how they are performed than you and most other HNers do). A guy who specializes in car electronics exploits doesn't.

So yes, this is a mystery. The counter-argument seems to be some variation of the too-common world-weary-haughtiness that spreads like an infection on HN.

Bank closes at night like always. The next morning the manager arrives and finds everything seemingly as it was, but when they look in the safe all of the money missing. Would that qualify as a mystery? Even though people have been robbing banks for centuries, even breaking into safes? Yes, of course it would, though I'm sure there'll be that guy who'll point out the obvious that somehow someone got in the safe.

Re: Police admit they're 'stumped' by mystery car thefts

#93
I wonder if they found an exploit for Bluetooth. Newer cars have this feature so the owner doesn't have to use the key. If the Bluetooth service has access to the On Board Diagnostic (OBD), it can get to a lot of the car's info and commands, such as unlock door. I remember working on AutoPC back in the day and we tapped into the OBD and provided a feature to send a message to the car to unlock the doors. Similar to OnStar now a day.

Re: Police admit they're 'stumped' by mystery car thefts

#94
post #74

Earlier quoted context omitted.

How would you describe a challenge based authentication system that uses 128-bit AES? I find the reporter's description reasonable.

I too agree that this "That code is encrypted and constantly changing" is a reasonable description of an authentication system. However, this, "and should be hackproof", is faulty. Nothing is ever inherently secure, though it might be relatively secure at a given moment and circumstance. It's easy to characterize this as the ignorance of American media. However, this kind of "should be X" is common for anyone, be the…

Clearly the journalist doesn't have time to give a lecture on a cryptography primer. I wouldn't call this ignorance, but convenient shortcut

Re: Police admit they're 'stumped' by mystery car thefts

#95

Earlier quoted context omitted.

The article makes it sound exactly like what it seems to be -- that the thieves are using an exploit that they don't know, and thus they want to know. One of the guys quoted makes a profession out of this and he doesn't know what they're doing. But apparently lots of people on HN do.

Nobody here has claimed to know exactly what exploit the thieves are using. But a lot of people are claiming (rightly) that general knowledge that these car systems have vulnerabilities is widespread. And that point is what seemed, to me, to be missing from TFA. If TFA had given some more context, and said "exploits which would allow this type of access were shown at a recent hacker conference, and some cars have kno…

[deleted]

Re: Police admit they're 'stumped' by mystery car thefts

#96
Probably the attack from two years ago: http://www.technologyreview.com/news/422298/car-theft-by-ant...

Essentially, with the newer cars keyless entry cars, it's the car that transmits the signal to the fob (so you can't get stranded with a flat battery).

The protocol itself is secure, but open to a MITM attack. The exploit works essentially like a WiFi booster. Perp #1 places himself near the car, receiving the car's transmission. This is relayed to perp #2, who is near the owner (and the key). The key communicates with the car (via the relay) - the door opens, the car starts, and off you go.

Re: Police admit they're 'stumped' by mystery car thefts

#97
post #86
post #79

Anyone know how much compute time is needed to crack a new BMW or Audi remote?

Seconds I believe. I have no source but I recall seeing a story where people were able to fake a BMW remote by plugging directly into the OBDII port on the cars and running a quick program on an attached arduino. As for remote access I'm sure its equally plausible to crack if you know the right steps to take.

But that was a clear mistake in the ODB port programming on new BMW, which was fixed by the manufacturer. Not something that can be easily done on any car.

Re: Police admit they're 'stumped' by mystery car thefts

#98

Earlier quoted context omitted.

I lived in a town where if someone was running into a store for only a few minutes, they would probably just leave the car unlocked, with the keys in it, and the engine running.

In many jurisdictions, if the car was stolen and used in a crime, you could be charged for negligence.

Which jurisdictions? (Do you have a reference?) I don't think US law works this way, for example, and would be curious to know where it does.

Re: Police admit they're 'stumped' by mystery car thefts

#99

Earlier quoted context omitted.

The tint on your windows probably contributes -- they can't see inside, so they break in just in case there might be something worth stealing.

a lot of smash and grab guys use something called a "ninja rock" which is a chunk of porcelain from a spark plug. throw it against the window and it explodes. if you have tint, it is like tape on the glass, so it doesn't break apart as easily and makes the smash and grab operation take longer.

An all is a way better tool for tempered glass. Corners are always weak. http://io9.com/meet-prince-ruperts-drop-its-about-to-blow-yo...
Post reply on HN