Live data from Hacker News

Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

wired.com

81–90 of 144 posts

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#81

Earlier quoted context omitted.

Latest BMW, Audi, VW and Ford (or at least some models from these manufacturers) key fobs stop transmitting after X amount of time (based on motion).

Interesting. So do you have to put your fob in a bowl so it won't be moving to prevent it from being relay attacked, or some such?

Yes but I would assume that coming home and putting all your keys somewhere to lay down is a routine for most people.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#82
post #61

dang, can we get a ruling? These headlines might not violate the letter of the "If the title begins with a number or number + gratuitous adjective" guideline, but they do violate the spirit. "Hackers Can Clone Toyota, Hyundai, and Kia Keys" gets the same point across without the sensationalism. I'm bringing it up because I've seen many of these "millions of [thing that exists in the millions]" headlines recently, and…

I'm not seeing the problem. Your suggested title makes it sound like they could clone all the keys from those manufacturers which isn't true. And if you inserted a word like "some", my first question would be, "Well, how many?" To me "millions" is useful in conveying it isn't just a niche issue, but it isn't everything, either.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#83

Earlier quoted context omitted.

The scratches on my iPhone disagree

They're definitely from keys? And what kind of metal does the key seem to be?

Definitely from keys. Very light scratches, but they are there. No idea which key exactly, I have a handful on my keychain.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#84
post #55

Earlier quoted context omitted.

Doesn't this require the attacker to have the keys?

The relay attack (which is not what this article is about) relies on an erroneous idea in the design of keyless entry and keyless ignition systems. Signals from an RFID device don't travel very far. So, (here's the error) if the keys can receive and respond to a signal from the car they must be very close to the car. But signals can be relayed. Crook A stands next to your car. Crook B walks up to your front door. Cro…

[deleted]

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#85
post #75

Earlier quoted context omitted.

You want a car that stops working when your phone battery dies?

It doesn't work that way. iPhones NFC chips are still powered even if the phone battery dies. That's how transit cards work even when the battery is dead. https://bgr.com/2018/09/18/iphone-xs-vs-iphone-xr-nfc-chip-w...

That's better than nothing, but that doesn't describe "NFC works with dead phone", that describes "phone reserves up to five hours of emergency battery power for only NFC use".

When my current car fob starts displaying a low battery warning I have at minimum weeks to replace the battery. (Not to mention my current car fob is resistant to being dropped, stepped on, etc.)

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#86

One related and another unrelated though... First: Auto manufacturers ought to get together and agree on one common key + entry system standard. It can be a combination of physical key and remote key if necessary. The problem: If you have multiple vehicles (and many families do) you end-up with a keychain full of horrendously large and unnecessarily inconvenient keys, key-fobs, whatever. Some manufacturers seem inten…

Phone as key is the future. I was skeptical at first given the general unreliability of Bluetooth but Tesla managed to do it. It's been flawless for me. Key card as backup makes perfect sense although I believe upcoming NFC standards will make even this unnecessary with the ability to have the phone act as a passive NFC tag even when the battery is dead. The key fob is still available if you want it. Tesla even allow…

What we need is a world wide standard that every car manufacturer has to adopt by, say, 10 years from now (or whatever is deemed reasonable).

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#87

One related and another unrelated though... First: Auto manufacturers ought to get together and agree on one common key + entry system standard. It can be a combination of physical key and remote key if necessary. The problem: If you have multiple vehicles (and many families do) you end-up with a keychain full of horrendously large and unnecessarily inconvenient keys, key-fobs, whatever. Some manufacturers seem inten…

>was always a game of chicken with cars entering in the other direction Uh, other direction? Almost always there are hoses from both side of pillar. Is it some regional thing?

As Dylan said, cars come in from any direction, which makes not having the port on the same side in every vehicle a complete mess.

From my experience most vehicles have it on the left side, in the US that would be the driver side.

If you show-up at a busy gas station with a BMW --which has the port on the right-- well, good luck, it can get ugly. Rather than lining-up behind the car currently fueling-up, you have to line-up in front of them. Which means that someone entering the station with a left fuel vehicle often ends-up behind them --even with you waiting patiently in front way before the third car showed-up. That's where the problems begin. This has happened to me many times.

Because the car that finished fueling drives forward to exit, the car behind it has a natural advantage and the one in front a disadvantage (at the very least you have to allow plenty of room for them to drive out). The car behind them, if they want to deny your rightful turn, just crawls forward as the first car exits. Before you can do anything at all they are in front of you, took control of the pump and you have to choose between waiting, moving or getting into an argument with someone you know isn't likely to be a nice person.

If all fueling ports are on the same side there are no problems.

The alternative is to require that hoses be longer. The problem with this is that it doesn't work at all for trucks.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#88

Earlier quoted context omitted.

Are you sure you aren't misremembering? DST40 https://en.wikipedia.org/wiki/Digital_signature_transponder used in Fords of that period is a Feistel cipher not a Vigenere cipher. Now, I wouldn't choose a Feistel cipher for this problem today but it certainly is not 1.5 centuries obsolete, this type of encryption wasn't even invented until the mid 20th century and a very famous example would be DES.

I am sure yes. Mind you, this was Immobilizer feature, sold by Siemens Automotive to auto-makers. As to what in rest of their car Ford itself was using I have no idea, since I was not working for them at the time. Here is an analogy - Microsoft is Siemens and Ford is IBM. Microsoft sold DOS to IBM to equip their PC's. As for what IBM implemented/used for BIOS, was not Microsoft's job, get it?

An immobilizer simply keeps the ecu from running the fuel pump, thus preventing the car from starting. The challenge-response from the key is used to authenticate the ecu. It’s not so much that it’s bad encryption (it is) it’s just that the access to override such encryption has physical controls (e.g. if one breaks the glass then one typically has complete access to the vehicle). Second the cpu of the time where maybe 4mhz in a good case so it required a system that was fast. This is very similar to the encryption used to immobilize Mercedes and BMW of early 90s.

Also I can tell you on all current and last gen Ford and Mazda’s, the inter-car encryption and authentication has vastly improved.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#89

Call me old but what is so great about the smart key? Not having to pull it out of your pocket? I know this is an old rant already but car have reached the crappyfication curve, when something cannot improve its main purpose anymore it starts adding unneeded features to be able to push a “new” product.

The smart key is literally the best feature in the second hand Lexus I picked up a few years ago. I no longer have to pry the key out of my jeans, or go looking for it in all my bags when I’m travelling.

my favorite use case is when I've left my key in my bag that I've popped into the trunk and closed. my car beeps at me and my trunk pops right open. it's saved me more than once when I've been far away from home.

Re: Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys

#90
post #29

Earlier quoted context omitted.

It should be a construction approximately: first DHE and then the car challenging the fob to MAC a unique message. Exponential backoff after every failed attempt for that token (fob).

Exponential backoff could DoS someone from opening their own car.

You can already DoS people from opening their car by using a jammer, or expoxying the locking mechanism.
Post reply on HN