Live data from Hacker News

Police admit they're 'stumped' by mystery car thefts

today.com

111–120 of 139 posts

Re: Police admit they're 'stumped' by mystery car thefts

#111
post #103
post #54

Earlier quoted context omitted.

In urban areas I don't lock my doors to avoid having my windows smashed for some change.

I wouldn't live in a place like that... unless there were major benefits or I had no choice.

You don't have to live in a place like that for it to happen to you.

This is happened to me in the nice parts of town that are close to public transit. They smash a few windows run across the street and jump on the train. . .

Re: Police admit they're 'stumped' by mystery car thefts

#112
post #90

Earlier quoted context omitted.

"How would you describe a challenge based authentication system that uses 128-bit AES?" How do you know at the RF level that its challenge based, and how do you know that the exploit is not operating in some .gov override mode like "I am NSA, open right now" mode. I used to operate a computer that had a rack mount lock where its extremely well known (to some, anyway) that the mfgr shipped every unit with a tumbler th…

At least you have to be a hacker to boost a car these days. I remember when I was a kid my parents' car keys would open every Ford or Chevy on the block. I had a lot of fun running around the parking lot at my brother's soccer games.

That reminds me of the time my cousin lost his car keys. Luckily his parents had an extra set, so he got new copies made, and went on his merry way. A year later, I found the old set under the backseat of my car. Presumably they fell out of his pocket while he was riding with me, and got lodged up under the seat somehow.

Soooo... what to do with an extra set of keys to your buddy's car? Muwahahahaha... gaslight[1] him, of course! So me and a couple of other buddies would randomly drive to where he worked, and take his truck and do little things... change the direction it was facing, or move it about 3 spots over in the parking lot, or fiddle with the presets on his radio.

For like a month, he was spazzing out over this, while we all did our level best to keep a straight face when we were with him. He was convinced it was his brother messing with him for quite a while. Needless to say, he was a bit pissed when we finally broke down and told him and gave him his keys back. But man, what a laugh riot for a time...

[1]: http://en.wikipedia.org/wiki/Gaslighting

Re: Police admit they're 'stumped' by mystery car thefts

#113
RSA Security and John Hopkins have been able to crack an RFID keyfob in 15 minutes [0] back in 2005. Rumor had it that later on it was something like 30 seconds to crack a Ford key. 40-bit RFID keyspace--combine that with 2013-era technology and this is absolutely no surprise.

http://www.jhu.edu/news/home05/jan05/rfid.html

Re: Police admit they're 'stumped' by mystery car thefts

#115
post #93

I wonder if they found an exploit for Bluetooth. Newer cars have this feature so the owner doesn't have to use the key. If the Bluetooth service has access to the On Board Diagnostic (OBD), it can get to a lot of the car's info and commands, such as unlock door. I remember working on AutoPC back in the day and we tapped into the OBD and provided a feature to send a message to the car to unlock the doors. Similar to O…

I don't think this is done via bluetooth - I believe the remote/app unlocking is all done via cellular.

[deleted]

Re: Police admit they're 'stumped' by mystery car thefts

#116

I never understood why keyfobs work in a UDP style, when communication between the remote and car would be infinitely better. For instance, instead of just sending "12345" and having the doors open since the code was expected, What about if the remote said "hey car, whats your random number" - the car then transmits back "54321" at which point the transmitter sends a hashed reply sha512(54321 + unique-random-id-set-p…

Wouldn't you then be able to determine the fob ID by recording multiple car "random number" requests and fob responses?

I think that's part of how Mifare (NFC) was cracked; the entropy of the card's random number generator was very low. When implemented correctly it's a safe method though.

Re: Police admit they're 'stumped' by mystery car thefts

#117

How about the manufacturers providing a back door? Their own code. What happens in the event that you loose your fob?

If you loose your fob, the workaround is re-programming via the OBDII or other diagnostic ports. Yes, that has a backdoor. But typically there is no remote backdoor.

Re: Police admit they're 'stumped' by mystery car thefts

#118
How about the possibility that the thieves have simply purchased replacement remotes from eBay (or similar), and programmed them when they had access to a compatible vehicle? Maybe the thieves work at a car wash, valet or have organized a larger network of goons (think credit card skimming).

Programming a replacement remote is a simple procedure, requiring only a few moments in the vehicle with the key present... like when parking a car. Paired with an easily accessible address (registration?), you have a crime ready to take place.

This would confirm why multiple vehicles in the same driveway were targeted. Families use the same service providers. It could also make sense of why the "device" occasionally did not work. Maybe they got the remotes / addresses mixed up, the programming did not take or their mule is selling them unprogrammed remotes.

I think this is more logical of a solution considering the facts. Any thoughts?

Re: Police admit they're 'stumped' by mystery car thefts

#119
post #89
post #28

Sounds a lot like the Chamberlain garage door gaping security hole: http://en.wikipedia.org/wiki/The_Chamberlain_Group,_Inc._v._... . The level of security of a car door is presumably a lot higher than that of a garage door, but the technology of using a rolling code is the same and the need to be able to (re)synchronize remote keys/fobs is also there. With the cars I own, there is a procedure in the operator's manua…

If they'd figured out how to invoke resync, the owners' keyfobs would stop working, which would be a dead giveaway.

The "(re)sync" mechanism allows you to add new keys without disturbing the existing keys.

Re: Police admit they're 'stumped' by mystery car thefts

#120

What's the big mystery here? There have been published articles on the ease of hacking car remotes (and even the onboard electronics) going back at least a couple of years. For example: http://content.usatoday.com/communities/driveon/post/2011/01... http://www.schneier.com/blog/archives/2012/07/hacking_bmws_r... http://reviews.cnet.com/8301-13746_7-20085131-48/remote-unlo... http://news.consumerreports.org/cars/2011/…

I'd be willing to bet that someone has stolen some universal unlock codes for a variety of manufacturers and it is now in the wild. Of course, no car company wants to admit this.

I would also put money on something like this. Honda/Acura was the only brand mentioned in the video so I can even guess who lost them.
Post reply on HN