Live data from Hacker News

Toyota runs a car-hacking event to boost security (2024)

toyotatimes.jp

91–100 of 115 posts

Re: Toyota runs a car-hacking event to boost security (2024)

#91

My brother had his car (a sleek AUDI) stolen in front of his house. He left the key in the entry hall, and someone extended the range. Are current electronics (the consumer ones) good enough at scale to limit the time the round-trip car-key-car takes?

How does that work?

Once they have driven 100m what happens?

Re: Toyota runs a car-hacking event to boost security (2024)

#92

Earlier quoted context omitted.

Toyota won't build BEVs in scale, nor will most of the Japanese brands. They can't. Japan can't build the batteries for BEV's at the necessary scale for global production. Yes China controls lithium but they also control some 95% of global battery grade graphite production, and anywhere from 60% to 90% production of manganese, cobalt, and nickle. Not to mention all of the components that those produce like the anodes…

China is in the process of crippling 10% of Japan's GDP in automotive, just by building EVs and EV components and selling them to other nearby countries where Toyota (and other Japanese brands) currently dominate and hae vchosen not to compete in this new format. So we don't need Tom Clancy to generate scenarios where this will be bad for Japan.

[dead]

Re: Toyota runs a car-hacking event to boost security (2024)

#93
post #64

Tangent but I have a 2016 Toyota 4Runner. Great car and fits my family and needs perfectly. The key fob broke so I needed to get a replacement, I got a blank and had a locksmith cut and program the blank. He must have not done it right because it worked and then I got stranded cause it must have lost its pair to the car or something. Nothing wrong with the vehicle, the engine wouldn’t start because of the key. I do r…

You can disable the RFID by manipulating the right bits in the ECU’s anti-theft EEPROM. Something that’s done with imported engines from Japan for sports car engine swap; they usually come with wire harnesses and ECU but no key. I know how its done for the imported 3SGTE engine ECU… I’m sure it’s not too different for the 2013 4Runner. Though, Toyota makes some newer ECUs nearly impossible to open without damaging the circuit board and anti-theft bypass requires physical access to the EEPROM.

Edit: RFID should not need battery…you can reprogram your own key by jumpering the correct OBD2 pins..process takes about 20 minutes…

Re: Toyota runs a car-hacking event to boost security (2024)

#94
post #28
post #14

Earlier quoted context omitted.

The iPhone did everything the Nokia 3310 did, better. Electric cars do not (yet) do better some things hybrids do, such as being able to be fuelled with 400+ miles of range in 5 minutes. I’m nowhere near the point of wanting an electric car to replace my hybrid. The convenience of petrol and the cost of electricity is too high. High electricity costs aren’t going to be fixed in my country any time soon so Toyota will…

Most EVs these days can recharge 300ish miles in 15 mins, but 99% of the time I don’t even have to drive anywhere to refuel as it get recharged overnight in my garage. EVs are waaay more efficient in terms of MPGe so at least for me it is less half in terms of cost to refuel compared to petrol not even considering the external cost of emitting CO2

15 minutes is still not as good as the 2 minutes it takes to fill up a gas tank. Electric cars just aren't there yet for long drives, though they are great for everyday driving around town.

Re: Toyota runs a car-hacking event to boost security (2024)

#95
post #19
post #9

Earlier quoted context omitted.

Are you talking about Toyota or every german automaker ;)

Or even US government? (by removing incentives)

Removing incentives is not "taxing EVs", it's leveling the playing field. If EVs can't compete without the competition being tilted in their favor, they aren't up to scratch yet.

Re: Toyota runs a car-hacking event to boost security (2024)

#96

There's 2 things when it comes to security: Companies are responsible for their own security. You cannot try to hack them without their permission. Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony. Also, companies are not responsible (liable) for their own poor security. If they do something like leak the p…

>Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony.

citation needed

Re: Toyota runs a car-hacking event to boost security (2024)

#97
post #78

Earlier quoted context omitted.

The Stellantis systems I’ve worked on have a nice feature that there is a battery for the proximity use, that you can keep the key in your pocket and press the button to run the car, as long as the key is within the four or five proximity sensors you are fine. When that battery dies, you can press the directly to the start button and it uses a “receiver powered transmitter” RFID close proximity to start and run the v…

This technique of pressing the dead key to the starter button works for quite a lot of brands, not just Stellantis vehicles. Always worth trying if you are in a "keyless" car with a dead key fob battery. In my experience virtually everything made in last 15 years will either support this RFID backup or have a spare physical key hidden inside the keyless fob. Lots of them will even let you press the dead key against s…

What is funny to me is that before the proximity and push https start… the keys had RFID and an antenna at the lock cylinder anyhow.

They just left that same antenna in place (in Chrysler+ anyhow, called SKIM) now as a backup instead of the primary.

Re: Toyota runs a car-hacking event to boost security (2024)

#98
post #82

Earlier quoted context omitted.

No explanation or elaboration on your claim that electric vehicles are theft-proof

I thought it was obvious. Charging (scoping just to US) has some difficulties. First, you need to know how charging works (110V vs 240V vs DC fast charging) and also understand what kind of charging the car you are stealing supports: https://www.power-sonic.com/ev-charging-connector-types . Also understand the various apps that are needed for different cars and how they work. The thief most likely may not have chargi…

You're assuming so much that is wrong. Thieves don't know how to use technology?

They can't use a charger? (I imagine they'd wire one to an also stolen generator)

Then you assume they're gonna be in a car chase? That's not how most stolen vehicles end up.

Afaik most stolen vehicles either get quickly parted out at a chop shop, or are sent across a border (driven across borders or container shipped to another country), or used for other crimes, or they're joy rided around then abandoned. Basically all things you could easily do on a partial charge with a modern car mechanics skills.

Re: Toyota runs a car-hacking event to boost security (2024)

#99
post #19

Earlier quoted context omitted.

Or even US government? (by removing incentives)

Removing incentives is not "taxing EVs", it's leveling the playing field. If EVs can't compete without the competition being tilted in their favor, they aren't up to scratch yet.

If EV costs more you pay more sales tax / gst / vat.

Also most places now tax EV registration with extra fee or per mile so you add fair share towards roads making hybrid TCO lower.

Re: Toyota runs a car-hacking event to boost security (2024)

#100

There's 2 things when it comes to security: Companies are responsible for their own security. You cannot try to hack them without their permission. Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony. Also, companies are not responsible (liable) for their own poor security. If they do something like leak the p…

>Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony. citation needed

> No person shall circumvent a technological measure that effectively controls access to a work

Source: DMCA: https://www.law.cornell.edu/uscode/text/17/1201

I'm sure that spending a few hundred thousand dollars on lawyers might find a legal loophole, but I wouldn't count on it.

Why is it illegal to break the encryption of video game consoles? Whatever the answer is, the same can be applied to breaking the encryption of a car.

Post reply on HN