Live data from Hacker News

Keyless BMW cars prove to be very easy to steal

hackaday.com

81–90 of 111 posts

Re: Keyless BMW cars prove to be very easy to steal

#81

Earlier quoted context omitted.

I'm not sure that would help. It just means the thieves need to steal the car in two steps instead of one.

It should also activate a big red sign in the controls that means: "The new key will be usable in 3 hours"; so if you actually didn't changed the keys, something is wrong.

I know the GM Passlock II system works this way - not only do you have to wait, but you have to put the car in 'run' a few times during specific times during the waiting process.

Re: Keyless BMW cars prove to be very easy to steal

#82
post #69

Earlier quoted context omitted.

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

> In the US, many car manufacturers take a different approach. The security key is provided by the manufacturer, not the on-board computer, so you can't simply walk up and re-program a key. And the consequence is that a replacement key costs $150. No joke.

Try 500$. BMW owner. This was my quote from the Dealer when I thought I lost my key.

Re: Keyless BMW cars prove to be very easy to steal

#83
post #71

Earlier quoted context omitted.

It's not keyless entry, it's the electronic keys used for push-to-start (which is also an unavoidable option, but it's one I like).

illamint: the feature is sold as "comfort access keyless entry," and it allows the driver to start the engine without inserting the electronic key. (Without this feature, the default setup for BMWs is that the driver must insert the electronic key before starting the engine -- a form of two-step authentication that isn't susceptible to the attack described in the article.) FWIW, I know about this firsthand because I…

Having the comfort access feature, and having a car stolen many years ago, there's no way I would trade one of my most enjoyed features for a lower risk of car theft.

The reality is that if someone wants your car they're going to get it.

Why get rid of an awesome convenience feature for the risk of something that is a) unlikely and b) won't cost you anything (absent a small deductible) if it does happen?

Re: Keyless BMW cars prove to be very easy to steal

#84

I remember the good old days, where my key opened the doors of my friends car and his key could not open mine yet it would start my car. Where my Aunt drove her car to the mall, locked the doors, and when she came out could get in as she had the keys to her husbands car. Needless to say in both cases there were the same brand, within a year or so. You did not even need to have same major brand (Ford/Mercury were inte…

My roommate and I both have Toyota trucks. Mine is much more than a decade old, his is almost two decades old, and as a consequence there are parts that are starting to wear down. Like the ignition switch. There have been many times I've called him up (or vice versa) and said "can you bring my truck to me?" Even though the keys are not compatible, that doesn't matter anymore. His could probably be started with a pops…

If you're a thief and you can't drive a manual car then something is wrong with you.

Re: Keyless BMW cars prove to be very easy to steal

#85
post #52

Earlier quoted context omitted.

What's wrong a simple "Okay sir, before you can drive away with your new car you need to pick a password. And before anybody can service the car they'll need your password so please don't forget it, but if you do you can always provide proof of ownership to your nearest dealer and they'll help you reset your password."? That way non-franchise garages can still do repairs, as well.

They'd have to provide the 'password restore' functionality to non-franchise garages as well, I guess. Otherwise they could do this except without the password: 'Okay sir, here's your key. Anybody can service the car, but they'll need the key. If you lose it, provide proof of ownership to nearest dealer and they'll make you a new one'.

Good point; a physical key is just as good as a password and has the benefit that people will treat it properly.

Re: Keyless BMW cars prove to be very easy to steal

#86
Right now it is not possible (that I'm aware of) to do asynchronous PKI-like encryption without the contact-type SmartCards. Meaning that all of the contactless RFID/(passive) NFC systems are vulnerable to attack and cloning.

In 3 years, do this, but with a smartphone and an active NFC app that can perform async encryption challenges. Without stealing the phone and the PIN, you can't steal the car.

Re: Keyless BMW cars prove to be very easy to steal

#87
post #75

Cars aren't secure. Most things aren't. The main thing that stops a theft is putting it in a place that's harder to get to (again, nothing is secure) just so that no one sees it, or has the opportunity to steal it. I'm at a coffee shop right now, and my BMW motorcycle is parked right outside the window. Me keeping an eye on it is better security than any electronics lock system (as I know I could hotwire this bike in…

Heck my car got stolen once with a screwdriver. I'm sure it took all of 30 seconds.

[deleted]

Re: Keyless BMW cars prove to be very easy to steal

#88
post #52

Earlier quoted context omitted.

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

What's wrong a simple "Okay sir, before you can drive away with your new car you need to pick a password. And before anybody can service the car they'll need your password so please don't forget it, but if you do you can always provide proof of ownership to your nearest dealer and they'll help you reset your password."? That way non-franchise garages can still do repairs, as well.

Thieves will help themselves to reset the password too, and they naturally waive the proof of ownership clause.

Re: Keyless BMW cars prove to be very easy to steal

#89

Earlier quoted context omitted.

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

4) Nobody said they had to use the OBDII port for this. 4a) Nobody said that OBDII ports had to work while the alarm is armed.

Regarding 4a: if you lose your key (and thus you have lost the ability to disarm the alarm) the entire vehicle is bricked?

Re: Keyless BMW cars prove to be very easy to steal

#90

If this is because of OBD regulations, perhaps it can be changed somewhat. Give the owner a small electronic device that will be necessary to generate a new key for the car they purchased. That device can be kept separate from the car but when the key is actually lost, the owner can bring it to the mechanic and generate a new one. The thieves would need to steal the device before stealing the car, which would make th…

And what if the owner looses that "small electronic device", or forgets to forward it to the new owner.

The whole point of this feature is that you should be able to get the car running if you loose EVERYTHING apart from the car itself. The only way to stop it is to give the manufacturer (or other trusted third party) exclusive right to issue keys but apparently the regulations say no to that.

Post reply on HN