Reverse engineering a car key fob signal
1–10 of 85 posts
Re: Reverse engineering a car key fob signal
#2Next time I will try the method from this blog post. And maybe become a better hacker.
Re: Reverse engineering a car key fob signal
#3A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.
Re: Reverse engineering a car key fob signal
#4>Note: Transceiver SDR devices do exist of course, but they tend to be very pricey A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.
Yes, but a "HackRF clone, plus a Proxmark3, plus IR, plus whatever" probably isn't.
Re: Reverse engineering a car key fob signal
#5>Note: Transceiver SDR devices do exist of course, but they tend to be very pricey A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.
> A HackRF clone is cheaper than a Flipper Yes, but a "HackRF clone, plus a Proxmark3, plus IR, plus whatever" probably isn't.
For $400 you can get a limeSDR mini that can read and write 30MHz of spectrum at a time, ie the entire ham 70cm band all at once.
If you think a flipper is dangerous, plug in a dummy load and dump noise on L1 then watch your phones GPS stop working, or alternatively decide it's on another continent.
Re: Reverse engineering a car key fob signal
#6Earlier quoted context omitted.
> A HackRF clone is cheaper than a Flipper Yes, but a "HackRF clone, plus a Proxmark3, plus IR, plus whatever" probably isn't.
The flipper isn't really a full sdr though, it just has a very minimalist RF IC that has almost non-existent bandwidth. For $400 you can get a limeSDR mini that can read and write 30MHz of spectrum at a time, ie the entire ham 70cm band all at once. If you think a flipper is dangerous, plug in a dummy load and dump noise on L1 then watch your phones GPS stop working, or alternatively decide it's on another continent.
Re: Reverse engineering a car key fob signal
#7Something I've always wondered about is, how do learning remotes defeat this?
My car has a couple of built-in garage door buttons, and I'm pretty sure I programmed it by just hitting the remote button in the garage while the car was in a learning mode. Is that a much more sophisticated feature than you would assume (e.g. decoding the signal, recognizing the type, then initiating a pairing with the opener, instead of just replaying the signal)?
Re: Reverse engineering a car key fob signal
#8>Note: Transceiver SDR devices do exist of course, but they tend to be very pricey A HackRF clone is cheaper than a Flipper, and way more capable in my opinion. I would bet most flippers either lie in drawers or are used by stupid teenager kiddies for trolling.
I find my FZ most useful, not for the radio stuff, but as a wireless (read: untethered) way to dump and write EEPROMs using a POMONA clip, otherwise, yes, it sits in a drawer.
Re: Reverse engineering a car key fob signal
#9> These keys are generated and tracked using a counter which has to stay in sync between the remote and the car. This ensures that the car doesn’t reuse an old key, and that the remote always generates fresh keys. Something I've always wondered about is, how do learning remotes defeat this? My car has a couple of built-in garage door buttons, and I'm pretty sure I programmed it by just hitting the remote button in th…
Re: Reverse engineering a car key fob signal
#10> These keys are generated and tracked using a counter which has to stay in sync between the remote and the car. This ensures that the car doesn’t reuse an old key, and that the remote always generates fresh keys. Something I've always wondered about is, how do learning remotes defeat this? My car has a couple of built-in garage door buttons, and I'm pretty sure I programmed it by just hitting the remote button in th…
My understanding is that most garage door openers do not use rolling keys, they send the same code each time.