Earlier quoted context omitted.
If the message is encrypted with some time component and a pre-shared secret then it is protected from a replay attack no?
Yes, but a replay attack is quite different from a relay attack.
Thieves boosting signal from key fobs inside homes to steal vehicles
341–350 of 449 posts
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#342Earlier quoted context omitted.
Top Gear did a thing on this during their one road trip: https://youtu.be/-aU09WT5rXg fast forward to the 3 minute mark
Exactly. Luckily i've got a Kia which nobody wanted to steal, but it's definitely a well known attack vector. A car on one side got stolen, the other side 'just' had stuff stolen from it.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#343Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#344Earlier quoted context omitted.
Yes, it’s a feature, so you don’t have to remove the key from a bag or pocket to enter or start the car. In typical designs, the car continually transmits a low-frequency (e.g., 135 kHz) radio signal to wake up any wireless keys within range. When a key receives this signal, it replies with a VHF (e.g., 315 MHz) signal, and the car unlocks or starts when a door is opened or the start button is pressed. The reply sign…
This is insane. Please tell me this is an option that non-insane consumers can get their car without. Fortunately I drive an old car so this does not affect me—yet. If I ever have to replace mine, this looks like yet-another-misfeature I’ll have to look out for to avoid.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#345Earlier quoted context omitted.
An timeout that goes into idle mode until it detects some movement, would be less hassle. It still leaves a small window of opportunity for abuse, but seems like a decent middle ground.
Yes, a MEMS accelerometer would be a very cheap mitigation.
My personal solution is to not drive often, and when I do it's a 1996 Subaru. ;)
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#346Earlier quoted context omitted.
Yes, but a replay attack is quite different from a relay attack.
Hm, good point. I guess I don't really know how these systems work. I assumed there was some kind of rotating value but I have no reason to believe this. Based on these attacks it seems the keys are really just sending the same signal every time. That appears to be a real shortcoming of the design.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#347Earlier quoted context omitted.
How does she unlock her front door?
> How does she unlock her front door? For many people, there's no need to unlock the front door because it's never locked. Having to lock your door just means you're living in a terrible neighborhood.
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#348Earlier quoted context omitted.
Yes, I was making a joke, but I was also semi-serious. I personally wouldn't mind that the car unlocks based on the fob's proximity, but requires insertion of the key for ignition. I currently drive a 2009 car with the usual key fob and my biggest issue with it is not having to insert it to start the car, but unlocking the doors while my hands are full. Once I'm seated in the driver's seat I'm not carrying anything a…
My problem with modern cars is that there’s no good place to put the keys. They’re uncomfy in my pocket when sitting down and I’m too warm for a jacket with pockets. The old ignition hole was the perfect solution. You had a dedicated spot for your keys, you always knew where they are, were unlikely to forget them in the car, and it also happened to start your engine. Perfect
Re: Thieves boosting signal from key fobs inside homes to steal vehicles
#349Earlier quoted context omitted.
I'm not sure if this is a joke about old keys being better, but I'd argue you could have the benefits of new keys and old keys combined if you just made it so that new keys have to be inserted into some compartment inside of cars, where they are authenticated by those cars. You can imagine a fob with a USB that has a different authentication code than the wireless one it sends out, and unless the USB is plugged into…
I'm not sure why we can't have some sort of challenge response protocol to prevent MITM...