Live data from Hacker News

3129 numbers that unlock keyless entry cars (2004)

everything2.com

1–10 of 12 posts

Re: 3129 numbers that unlock keyless entry cars (2004)

#4
Some electric door locks (like the Codoor CD3500 [1] used at a place I used to work) are designed so after a certain number of digits without a valid code (16 for the codoor), they require the correct code to be entered twice in succession in order to unlock.

This is transparent to the user - it's just as if you hit a wrong button - but prevents using codes like this.

I don't know if this is common to all keyless entry systems, but you'd hope it would be!

Of course you can still enter every every code, just it would take 80,000 button presses on a 10-digit lock.

[1] http://www.assar.ee/cgi-bin/document.cgi?doc=356 see page 12 'access blocking'

Re: 3129 numbers that unlock keyless entry cars (2004)

#5

Neat analysis. Do keyless entry cars not have some kind of "too many presses" sensor that would slow this process down or render it impossible by making you start over? I don't know, I'm just asking.

Given the huge security holes already known to be present in the median auto electronics system, my guess is "absolutely not".

There may be some additional consideration for luxury-branded models, but for the standard models, the consideration is primarily whether it works for the auto-buyer every time, not how this could be used as an attack vector.

Re: 3129 numbers that unlock keyless entry cars (2004)

#6

Neat analysis. Do keyless entry cars not have some kind of "too many presses" sensor that would slow this process down or render it impossible by making you start over? I don't know, I'm just asking.

Given the huge security holes already known to be present in the median auto electronics system, my guess is "absolutely not". There may be some additional consideration for luxury-branded models, but for the standard models, the consideration is primarily whether it works for the auto-buyer every time, not how this could be used as an attack vector.

"Given the huge security holes already known to be present in the median auto electronics system"

Would you mind listing some?

Re: 3129 numbers that unlock keyless entry cars (2004)

#7
post #6

Earlier quoted context omitted.

Given the huge security holes already known to be present in the median auto electronics system, my guess is "absolutely not". There may be some additional consideration for luxury-branded models, but for the standard models, the consideration is primarily whether it works for the auto-buyer every time, not how this could be used as an attack vector.

"Given the huge security holes already known to be present in the median auto electronics system" Would you mind listing some?

The first thing that comes to mind is the vehicle audio system using the same electronic communication bus as its critical engine electronics.

Re: 3129 numbers that unlock keyless entry cars (2004)

#8

Neat analysis. Do keyless entry cars not have some kind of "too many presses" sensor that would slow this process down or render it impossible by making you start over? I don't know, I'm just asking.

Given the huge security holes already known to be present in the median auto electronics system, my guess is "absolutely not". There may be some additional consideration for luxury-branded models, but for the standard models, the consideration is primarily whether it works for the auto-buyer every time, not how this could be used as an attack vector.

That’s awfully cynical. It also happens to be completely wrong. I extracted the following form a horrible Answers.com FAQ that was spread over 75 slides (barf):

"If the wrong code has been entered 7 times (35 consecutive button presses), the keypad will go into an anti-scan mode. This mode disables the keypad for one minute and the keypad lamp will flash. The anti-scan feature will turn off after one minute of keypad inactivity."

The Ford Explorer is hardly a “luxury-branded model”, and I’d venture that Ford uses this same system on all their models, across brands.

Re: 3129 numbers that unlock keyless entry cars (2004)

#9

Earlier quoted context omitted.

Given the huge security holes already known to be present in the median auto electronics system, my guess is "absolutely not". There may be some additional consideration for luxury-branded models, but for the standard models, the consideration is primarily whether it works for the auto-buyer every time, not how this could be used as an attack vector.

That’s awfully cynical. It also happens to be completely wrong. I extracted the following form a horrible Answers.com FAQ that was spread over 75 slides (barf): "If the wrong code has been entered 7 times (35 consecutive button presses), the keypad will go into an anti-scan mode. This mode disables the keypad for one minute and the keypad lamp will flash. The anti-scan feature will turn off after one minute of keypad…

Except that 35 consecutive button presses is actually the wrong code entered 31 times. That security feature only adds 101 minutes (and about 400 button presses) to the cracking process.

I think I am correct to be cynical.

And why would you subject yourself to answers.com just for that?

Re: 3129 numbers that unlock keyless entry cars (2004)

#10

Earlier quoted context omitted.

That’s awfully cynical. It also happens to be completely wrong. I extracted the following form a horrible Answers.com FAQ that was spread over 75 slides (barf): "If the wrong code has been entered 7 times (35 consecutive button presses), the keypad will go into an anti-scan mode. This mode disables the keypad for one minute and the keypad lamp will flash. The anti-scan feature will turn off after one minute of keypad…

Except that 35 consecutive button presses is actually the wrong code entered 31 times. That security feature only adds 101 minutes (and about 400 button presses) to the cracking process. I think I am correct to be cynical. And why would you subject yourself to answers.com just for that?

Do you think this is an honest assessment?

"That security feature only adds 101 minutes (and about 400 button presses) to the cracking process."

Only adds 101 minutes? I'm incredulous.

The claimed attack time is 20 minutes. By your assertion, this security feature increases the required attack time by a factor of 5. Were this a virtual system, that is trivial, but this attack requires physical presence, or at least the presence of a device.

I think you're cynicism is unjustified, as the extra time makes this an undesirable attack vector in light of the alternatives. Anyone willing to spend 100+ minutes at a car door is just going to use a slim jim or move on to an easier target instead.

Post reply on HN