Live data from Hacker News

Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

wired.com

131–140 of 144 posts

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#131
post #98

Earlier quoted context omitted.

The BCM is an ECU. The encryption has been broken already but it’s basically trailing bmw and Mercedes etc by about 13 years, so definitely money related but likely they don’t want to or are unable to negotiate patent rights in their technology

BCM is Body Control Module. ECU is Engine Control Unit. 2 different parts (logically). Both are physically PCB's (Printed Circuit Board) that physically can sit either side by side or in very different sides of the car - that's car maker decision. I can't explain it simpler than this.

[deleted]

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#132

Earlier quoted context omitted.

Phone as key is the future. I was skeptical at first given the general unreliability of Bluetooth but Tesla managed to do it. It's been flawless for me. Key card as backup makes perfect sense although I believe upcoming NFC standards will make even this unnecessary with the ability to have the phone act as a passive NFC tag even when the battery is dead. The key fob is still available if you want it. Tesla even allow…

What we need is a world wide standard that every car manufacturer has to adopt by, say, 10 years from now (or whatever is deemed reasonable).

That would be nice, but what is actually going to happen is that all the cars are going to support an Apple-proprietary standard (there are references to a "CarKey" framework in released iOS beta builds). Certainly Google are now working on their own equivalent for Android.

So there will be two standards, Apple and Google and all cars will support both. Kind of like with CarPlay and Android Auto.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#133
post #119

Earlier quoted context omitted.

As Dylan said, cars come in from any direction, which makes not having the port on the same side in every vehicle a complete mess. From my experience most vehicles have it on the left side, in the US that would be the driver side. If you show-up at a busy gas station with a BMW --which has the port on the right-- well, good luck, it can get ugly. Rather than lining-up behind the car currently fueling-up, you have to…

>Second: Auto manufacturers ought to get together and agree on placing the fuel tank port on the same side. The problem: Today you have cars and trucks with fuel tank refill ports on the left and the right. It can be an absolute nightmare to go to a gas station where most of the cars have ports on the left and you show-up with one on the right. This is one of the reasons for which I hated driving our BMW. Going to th…

That makes sense.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#134

Earlier quoted context omitted.

What we need is a world wide standard that every car manufacturer has to adopt by, say, 10 years from now (or whatever is deemed reasonable).

That would be nice, but what is actually going to happen is that all the cars are going to support an Apple-proprietary standard (there are references to a "CarKey" framework in released iOS beta builds). Certainly Google are now working on their own equivalent for Android. So there will be two standards, Apple and Google and all cars will support both. Kind of like with CarPlay and Android Auto.

Yeah, that’s why I would not be for the standard being based on phones.

As a side note, I stopped buying phone controlled devices a while ago. All of these things are going to end-up on a big pile of trash as technology evolves. I don’t need a phone controlled toaster oven or power drill.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#135

Earlier quoted context omitted.

Yes but I would assume that coming home and putting all your keys somewhere to lay down is a routine for most people.

Lots of people sure. Mine stay on me til I go to sleep typically.

This feature can still protect you if it works for enough people that it's no longer worthwhile to attempt to unlock a car this way.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#136

Call me old but what is so great about the smart key? Not having to pull it out of your pocket? I know this is an old rant already but car have reached the crappyfication curve, when something cannot improve its main purpose anymore it starts adding unneeded features to be able to push a “new” product.

I'm with you and not a good representative of the target market for keyless fobs. slovette and aetherspawn give good use cases for some benefits. I still ask how much of a real-world problem to be solved was sticking a physical key into a steering column? What were the stated goals for developing NFC ignition fobs en re drivers, manufacturers, and the automotive industry?(1) Apart from inevitable consequences like fr…

I locked my keys in the car a few times and had to call for help when I had a mechanical key. This has never happened to me with the fob. When I closed the fob in the car, the car refused to lock and made a very long annoying beep at me until I retrieved the fob.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#137

Earlier quoted context omitted.

> Maybe it can finally be affordable again. I like how some Chrysler products handle this. You can buy a $50 fob online and program it to your car yourself. The catch is, you need two key fobs to do it. This is so the valet attendant (who only has 1 of your key fobs) can't make his own copy. So, you just have to plan ahead and do it asap when you get a vehicle and always keep 2 in storage in case you want to make ano…

That is very forward of Chrysler. I just wish some of the more reputable brands would follow suit.

Extreme programming also came out of Chrysler (Kent Beck). They were the first to build and pilot EV pickup trucks and minivans. The 2020 RAM pickup beat BMW and Mercedes for "Luxury Vehicle of the Year". From consulting work I've done there in the past, they have many small groups that function like internal startups. They are surprisingly forward thinking despite many of the other products that actually make it into production, although that seems to be changing. The new infotainment system looks second to none.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#138

Earlier quoted context omitted.

That is very forward of Chrysler. I just wish some of the more reputable brands would follow suit.

Extreme programming also came out of Chrysler (Kent Beck). They were the first to build and pilot EV pickup trucks and minivans. The 2020 RAM pickup beat BMW and Mercedes for "Luxury Vehicle of the Year". From consulting work I've done there in the past, they have many small groups that function like internal startups. They are surprisingly forward thinking despite many of the other products that actually make it int…

My old coworker bought a 2019 RAM pickup. I was floored by the inside. It was closer to a spaceship than a truck. Glad to see they are turning things around (at least when it comes to infotainment electronics) but I wish I could trust the engine.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#139

The LockPickingLawyer has done a few recent videos on RFID locks and how one can bypass them. They were pretty interesting to me: "[1052] Defeating a RFID System With The ESPKey" => https://youtu.be/0SEHUqkbIjU "[1056] This Black Box Reads RFID Cards in Your Pocket" => https://youtu.be/dTObKtHzroM

tl;dr; without even watching those:

Most popular card/fobs (95%+ of all I've seen) don't use challenge-response, but always transmit the same 26 bytes. I don't have to explain how "secure" is that.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#140
Am I the only one still fuming about those two idiots who turned the engine off on the highway, and the hazard lights as well, with no shoulder to pull into? Then the idiots smugly claim they would never put anyone's life in danger. The author also gives them a wide pass. Why? This is such irresponsible behaviour. They couldn't demo it in some large unused lot?
Post reply on HN