Live data from Hacker News

Keyless BMW cars prove to be very easy to steal

hackaday.com

91–100 of 111 posts

Re: Keyless BMW cars prove to be very easy to steal

#91

Earlier quoted context omitted.

Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…

>Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? >I'm sure some engineers objected that "this is fundamentally insecure!" but got turned down from someone doing the budgets. You're missing a couple of key points here: 1) This is not a network attack, so the internet is largely irrelevant. 2) This is similar to having an attacker sit down at t…

> Other than a physical lockout on the OBD-II port, I can't think of a good defense against this attack.

Make the key changing process VERY slow, as in 24h+. If you really really lost your key you wouldn't mind leaving the car 24h at a mechanic but a thief would have a much harder time hiding a car that long. At least compared to 2mins at a dark parking lot.

Re: Keyless BMW cars prove to be very easy to steal

#92

Earlier quoted context omitted.

I don't disagree with that, but it's still irrelevant in the context of this particular attack, because there's no main-in-the-middle component required. Yes, you must secure the transport, and the same applies for even basic serial communications, but that's not what's happening here at all. This is an exploit of the implementation constraints at a legislate level. Engineers look at this problem and see the engineer…

> I don't disagree with that, but it's still irrelevant in the context of this particular attack, because there's no main-in-the-middle component required. Non-sequitur. If you can interpose the man in the middle, then most protocols are broken. > What are the chances that legislators understand the internet well enough to craft effective legislation? Not good, I'm afraid. From what I've seen, the average level of se…

> Non-sequitur. If you can interpose the man in the middle, then most protocols are broken.

It does follow. There is no basis for the belief that the transport channel isn't secure! For all we know, it's well-encrypted.

Yes, MITM is a concern with all communications that are intended to be secure. Granted. Established. Not an argument. But, it's not relevant to this attack.

Even using the best crypto available won't save you if the client barfs the security keys to unauthenticated clients upon request. The challenges here are in the authentication and authorization layer, not the transport layer. But there are non-technical constraints at play.

Backing up a bit, this even better illustrates the root of the problem. The way the law is written, you can never build a secure system, because the law mandates that the computer in your car trust all clients. Any system that does not secure the channel between an identified client and server is not secure. Hence, when all clients are permitted, the system is not secure by specification.

Re: Keyless BMW cars prove to be very easy to steal

#93
post #84

Earlier quoted context omitted.

My roommate and I both have Toyota trucks. Mine is much more than a decade old, his is almost two decades old, and as a consequence there are parts that are starting to wear down. Like the ignition switch. There have been many times I've called him up (or vice versa) and said "can you bring my truck to me?" Even though the keys are not compatible, that doesn't matter anymore. His could probably be started with a pops…

If you're a thief and you can't drive a manual car then something is wrong with you.

Thievery comes in many forms. The ones who steal cars that aren't worth anything on the black market aren't really going to be the smartest or most well-connected. Street punks really, and in the US manual transmissions are incredibly uncommon. A hoodlum will only know how to drive stick if he/she has had access to one and someone to teach them. While manuals are more common on cheap cars and street thieves are more likely to drive cheap cars, they're still quite rare.

Basically, if you're a smart thief and you can't drive stick, you have something wrong with you. But then again, if you're smart and also a thief, there's something wrong with you. If you're smart and also a thief and also stealing a rusty, beat up, 5-speed, early-90's Japanese truck, you obviously want it more than I do. I could just buy another one for <$1000.

Re: Keyless BMW cars prove to be very easy to steal

#94
post #89

Earlier quoted context omitted.

4) Nobody said they had to use the OBDII port for this. 4a) Nobody said that OBDII ports had to work while the alarm is armed.

Regarding 4a: if you lose your key (and thus you have lost the ability to disarm the alarm) the entire vehicle is bricked?

No, you just get the dealer to plug something into the (possibly proprietary) port that's used by the alarm system.

The assumption that this kind of thing needs to be done via the OBD-II port is wacky from the get-go. It may have been easier for some lazy system integrators at BMW to do it that way, but it certainly wasn't necessary, or apparently advisable.

Re: Keyless BMW cars prove to be very easy to steal

#95
post #45

Earlier quoted context omitted.

Translated into not-evading-responsibility-esque: The fact that the communication protocol used is openly known, much like all internet communications, means that an attack is easy to craft. Somehow that is a solved problem with internet and all other open security architecture. Why isn't it solved on these cars? This sounds like either NIH combined with piss poor security engineering done in the name of looking fanc…

It isn't solved for computer networks, this is exactly the same as the current debate about secure boot. Secure boot is an open standard, but we've not agreed about who can hold the keys: http://www.fsf.org/campaigns/secure-boot-vs-restricted-boot Here, the EU has effectively said that someone with physical access to the car can generate their own keys (since anyone can pretend to be a mechanic, and all mechanics are…

There is a difference, which is that a car is a physical thing.

Imagine that we had the current process. Except that every time a key gets reprogrammed, a record was made of which mechanic's key was used, and we have a mechanism to revoke particular issued keys.

This will not stop my car from being stolen. But we can identify which mechanic's key was used to do it, and I'm able to brick that car remotely.

You've just increased the cost of stealing a car this way, and reduced the cost of having it stolen. That may well be enough to convince thieves to move on to an easier type of target.

Re: Keyless BMW cars prove to be very easy to steal

#96

I remember the good old days, where my key opened the doors of my friends car and his key could not open mine yet it would start my car. Where my Aunt drove her car to the mall, locked the doors, and when she came out could get in as she had the keys to her husbands car. Needless to say in both cases there were the same brand, within a year or so. You did not even need to have same major brand (Ford/Mercury were inte…

No need to wait:

    http://www.viper.com/SmartStart/
Wake me up when it lets me drive the car from the smartphone, James Bond-style (IIRC the Bond car that supported this was a BMW, so not entirely off-topic).

Re: Keyless BMW cars prove to be very easy to steal

#97
How about the following schema for adding a new key to the list of Authorized Keys when NO AUTHORIZED KEY IS PRESENT:

* the procedure requires a module produced and sold by the manufacturer() to any garage that can verify its identity and satisfy manufacturer's specified security requirements (e.g. owning a safe and having no history with local police);

each such module is unique. It contains unique public/private keys and its public key is singed by the manufacturer;

* the procedure of adding the key to the list of Authorized Keys requires the car (actually, its ECU) to only accept incoming requests signed by such modules whose public keys are signed by the manufacturer. When the key is added, the ECU stores:

the key info;

the module's unique ID (IMPORTANT);

timestamp + lat/long;

* if there are no old authorized keys present (very rare scenario, since most of the time the owners want to replace just one lost/stolen key, but not both), the ECU requires 15 minute grace period with the module attached at all times, during which the car is flashing its hazard lights and honks. It makes a small nuisance in the garage once in a while, but attracts enough attention in the middle of the night if somebody is stealing it.

Now, if the car is stolen and then recovered, the police would dump the list of authorization requests and identify the module used. If this module was stolen or copied, the garage who owned the module becomes responsible for the damage to the car's owner. The ID of the module is placed on the revocation list. The revocation list is broadcasted via Sirius/XM/FM/BMW Assist/OnStar/Intelsat/etc.

This allows independent garages working on the cars, but places enough responsibility on them for keeping the system secure, with the override mechanism in form of revocation lists.

This method would NOT prevent all types of thefts (thugs can put the car on the flatbed and do the swap in the middle of the desert, or they can swap the ECU unit completely, or do some manipulations with the stolen "good" key), but it makes it significantly more difficult to authorize a new key and drive away.

(*) in case the manufacturer ceases to exist, some other company (another car manufacturer, perhaps) inherits the master key and will be responsible for authorizing garages to do key management.

Re: Keyless BMW cars prove to be very easy to steal

#98
When do I get encrypted Bluetooth access to my car? I'd bet if we did that, we'd get more tech security hackers involved in making things more secure.

But I guess it all boils down to a single issue: remove the physical token and it's got the same problems as attempting to secure access to your online bank account.

Re: Keyless BMW cars prove to be very easy to steal

#99
post #97

How about the following schema for adding a new key to the list of Authorized Keys when NO AUTHORIZED KEY IS PRESENT: * the procedure requires a module produced and sold by the manufacturer( ) to any garage that can verify its identity and satisfy manufacturer's specified security requirements (e.g. owning a safe and having no history with local police); each such module is unique. It contains unique public/private k…

> the procedure requires a module produced and sold by the manufacturer

So now the manufacturer has yet another method of extorting would-be mechanics. You'd have to regulate pricing or aggressively prosecute attempts at anticompetitive tactics.

> in case the manufacturer ceases to exist...

And who goes to jail when the company folds and, in the fire sale, the master key is on a system that gets wiped when being transferred to the new owner? Key escrow sounds like a better idea to me. Perhaps legislation should specify the creation of a public agency, or maybe we could leave it to private competition.

As for the remainder of your points, I believe you're thinking in the right direction.

Re: Keyless BMW cars prove to be very easy to steal

#100
post #90

If this is because of OBD regulations, perhaps it can be changed somewhat. Give the owner a small electronic device that will be necessary to generate a new key for the car they purchased. That device can be kept separate from the car but when the key is actually lost, the owner can bring it to the mechanic and generate a new one. The thieves would need to steal the device before stealing the car, which would make th…

And what if the owner looses that "small electronic device", or forgets to forward it to the new owner. The whole point of this feature is that you should be able to get the car running if you loose EVERYTHING apart from the car itself. The only way to stop it is to give the manufacturer (or other trusted third party) exclusive right to issue keys but apparently the regulations say no to that.

Nonsense. Why not simply design it so that it's difficult and dangerous to access the "reset button" unless you're a trained mechanic with a Rotary lift? Then it's more difficult to steal than an ordinary car, and you are done.

In light of history, the answer is probably a combination of laziness, inertia, and an attempt to steer customers to authorized BMW service centers. Or perhaps the threat model includes theft by tow truck? (not kidding; perhaps this is common in some places, at least for high-end vehicles?)

Post reply on HN