Live data from Hacker News

Keyless BMW cars prove to be very easy to steal

hackaday.com

51–60 of 111 posts

Re: Keyless BMW cars prove to be very easy to steal

#51
post #45

Earlier quoted context omitted.

Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…

It isn't solved for computer networks, this is exactly the same as the current debate about secure boot. Secure boot is an open standard, but we've not agreed about who can hold the keys: http://www.fsf.org/campaigns/secure-boot-vs-restricted-boot Here, the EU has effectively said that someone with physical access to the car can generate their own keys (since anyone can pretend to be a mechanic, and all mechanics are…

It isn't solved for computer networks, this is exactly the same as the current debate about secure boot.

I would disagree. To me this sounds like a perfect scenario for asymmetric encryption, which would solve this in a secure fashion.

Obviously someone should have a secure repository for official keys issued, so that duplicates can be made, upon request, upon owners' authorization. It might be bothersome and cumbersome, but the point is it should be a possible process, even for third party mechanical shops.

And for me the car-manufacturer sounds like a natural holder of this repo.

On the other hand, if you have access to the car and the key, it should be open enough to allow you to (re-)program it with your own keys if you like.

As far as I can see, that should satisfy everyone involved, while maintaining a secure architecture.

Re: Keyless BMW cars prove to be very easy to steal

#52

Earlier quoted context omitted.

Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

What's wrong a simple "Okay sir, before you can drive away with your new car you need to pick a password. And before anybody can service the car they'll need your password so please don't forget it, but if you do you can always provide proof of ownership to your nearest dealer and they'll help you reset your password."? That way non-franchise garages can still do repairs, as well.

Re: Keyless BMW cars prove to be very easy to steal

#53

Earlier quoted context omitted.

Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

1) This is not a network attack, so the internet is largely irrelevant.

Security protocols that can be used on two points on the Internet can also be used between two pieces of hardware, like a programmer/diagnostic tool and an embedded computer.

Re: Keyless BMW cars prove to be very easy to steal

#54
post #24
post #20

Earlier quoted context omitted.

> To really do this correctly, you need to have cryptographic challenges between a key and an ECU, Nonsense. The problem isn't cloning the key, the problem is that you are reprogramming the lock to accept this new key you happen to have with you. No amount of crypto is going to save you when your verifier is full of holes. You can't even use signing to only accept approved programming devices since OBD regulations en…

1) The cryptographic challenges are a necessary but not sufficient part of building a secure car access control system. All the active components in a car are horrible from a security perspective, usually huge libraries from third-party manufacturers, and all kind of duct-taped together. So bad that a malformed audio cd in the entertainment system could actually totally pwn the car, including driving controls. 2) The…

You should call them and negotiate!

Re: Keyless BMW cars prove to be very easy to steal

#55
post #36

Alas, BMW buyers often cannot opt out of keyless entry, because for some models BMW includes it in popular bundled packages, such that it's impossible for the consumer to avoid buying it without losing other worthwhile features. This consumer-unfriendly bundling results in BMW buyers often facing what can only be described as ridiculous choices ("which one do I want: a rear-view camera that reduces the risk of accide…

It's not keyless entry, it's the electronic keys used for push-to-start (which is also an unavoidable option, but it's one I like).

Re: Keyless BMW cars prove to be very easy to steal

#56
post #18
post #10

Earlier quoted context omitted.

That makes sense, but I can see the argument that not all features need to be open to consumers.

Attackers might work for a dealer or otherwise fully decode the system. The only way to build a system like this securely is to have securely-held keys (cryptographic, not physical; physical locks are all easy to break), and ideally published and reviewed code for the security system, same as any other security system. (I've actually thought about building a secure ignition system for cars, mainly to solve the car bo…

I solved this problem by just leaving my car unlocked with a guy with an AK guarding it, though.

How resistant is he to femme fatales?

Re: Keyless BMW cars prove to be very easy to steal

#58
post #45

Earlier quoted context omitted.

It isn't solved for computer networks, this is exactly the same as the current debate about secure boot. Secure boot is an open standard, but we've not agreed about who can hold the keys: http://www.fsf.org/campaigns/secure-boot-vs-restricted-boot Here, the EU has effectively said that someone with physical access to the car can generate their own keys (since anyone can pretend to be a mechanic, and all mechanics are…

It isn't solved for computer networks, this is exactly the same as the current debate about secure boot. I would disagree. To me this sounds like a perfect scenario for asymmetric encryption, which would solve this in a secure fashion. Obviously someone should have a secure repository for official keys issued, so that duplicates can be made, upon request, upon owners' authorization. It might be bothersome and cumbers…

[deleted]

Re: Keyless BMW cars prove to be very easy to steal

#59
post #52

Earlier quoted context omitted.

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

What's wrong a simple "Okay sir, before you can drive away with your new car you need to pick a password. And before anybody can service the car they'll need your password so please don't forget it, but if you do you can always provide proof of ownership to your nearest dealer and they'll help you reset your password."? That way non-franchise garages can still do repairs, as well.

They'd have to provide the 'password restore' functionality to non-franchise garages as well, I guess. Otherwise they could do this except without the password: 'Okay sir, here's your key. Anybody can service the car, but they'll need the key. If you lose it, provide proof of ownership to nearest dealer and they'll make you a new one'.

Re: Keyless BMW cars prove to be very easy to steal

#60
post #52

Earlier quoted context omitted.

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

What's wrong a simple "Okay sir, before you can drive away with your new car you need to pick a password. And before anybody can service the car they'll need your password so please don't forget it, but if you do you can always provide proof of ownership to your nearest dealer and they'll help you reset your password."? That way non-franchise garages can still do repairs, as well.

That's a great idea, but IANAL, so I can't say if it passes muster for EU anti-anti-competition laws. I'm going to go out on a limb and venture two guesses:

1) Any mechanism that requires manufacturer intervention is going to draw the eye of these legislators, which would likely mean some means of resetting that password for third-parties, which significantly diminishes the security utility.

2) If you've ever worked with consumers and "passwords", you know that they don't remember them. I think this bolsters support for regulations that require the reset procedure to be accessible by third-parties.

Post reply on HN