Comments on: Gone in 60 seconds--the high-tech version
How a keyless car gets stolen isn't a secret. The funny thing is, device makers don't seem to care.
How a keyless car gets stolen isn't a secret. The funny thing is, device makers don't seem to care.
December 28, 2009 7:15 AM PST
December 28, 2009 6:41 AM PST
December 28, 2009 6:27 AM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
From the National Insurance Crime Bureau;
http://www.nicb.org/public/newsroom/hotwheels/index.cfm
It has nothing to do with how easy or hard it is to crack. It is like the theater charging you $5 for $0.25 worth of popcorn.
OMGZ!!!!!!111oneone
getting drunk and eating here, then as the night was getting to
an end, he went to fetch his pullover from the car.
He realised that he left his keys on the front seat of his HSV
holden, which has this feature. He came up again and said
"guess what? I've locked my bloody keys in my car!!" he said
"Gee Im so stupid!, what a dick I am!" "how in hell am I gonna
get home Chris?" I told him that I remembered hearing on the
net, whilst searching into RSA/encryption etc etc, for a software
project I had to do for work, and I came across an article about
this matter, which did concern the hell out of me, because I have
one of these bloody cars myself." so I went and did a search for
this again, and to try and find the software, and one that would
work on a PowerBook G4 laptop. as the Desktop I have would be
out of range of our units carpark. I compiled up the software,
while he watched. He said I hope this works, I bet you can do it.
Well... guess what guys... to his delight and his relief, after me
and him sitting there on fold up chair's with the PowerBook G4
on knee, it took us about 3 minutes to find the right Challenge
and reponse codes, then I hit enter and CLICK up went the
central locking on his HSV holden! He just laughed and laughed,
and yelled in the carpark "hurray for Macintosh software
developers! yeee haaaaa!" it was really quite funny, and we
laughed about this at work on monday morning..
That was a nice legit use of this knowledge to help out a
forgetful mate. I also helped read the cars manual, to change the
setting's that the car does not use it 'autolocking' feature. I
disabled that feature on my capri, for this reason!! because Im
known to be a little 'pre-occupied' at times and I wanted to
prevent this happening to me!
his car and mine has that feature and a few of the girls were I
work has it too. Did yours have that??
I hate that bloody 'auto-lock' feature!! I reccomend disabling it,
if your the forgetful type!
Chris J, in Australia.
amusing... lets just hope that was a type-o, after all the the "X"
and "S" keys are pretty close. Oh, and lets not forget the fact
that X5 and S5 sound similar when you say it to your Speech-
To-Text computer. You'd think someone who types a bunch of,
well, ******** about keyless car thiefs would actually have
probably towed the cars away and parted them off. Having the
time it takes to wake in to Starbucks, drink a grande latte and
eat you scone and walk out some 10-15 minutes later to go
through a trillion 40-bit codes, the keyless chip makers
probably reailize that your more likely to have been struk by
lighting and have your social security and credit card numbers
stolen all in the same day. And if you actually watch the videos
Johns Hopkins University put out you'd see there was more than
15 minutes involved, it was well planned and it involved DST
chips, not remote keyless entry/ignition like used in say... BMWs
for one. Not to mention the fact that even with keyless ignition
you still need to break the streering lock, which from experience
can be pretty hard to do without the knowledge of the specific
car model and the proper tools.
Okay, everyone else, lets cross our fingers and hope that we
don't see someone standing next to are car with a laptop, when
we do come out of Starbucks, that comfrontation might be a
little akward. "Mind if I get my tent out of the trunk while you
finsh with that?"
giving a good excuse like my computer screwed up, lets just say I
thought more people would read it this way. :)
Oh, and that ******** is a compound word that begins with a "B"
and ends with a "T", that is, if anyone was curious.
For starters, BMW doesn't make an S5 - Beckham had two X5s stolen from him. That would normally be a minor detail except for the fact that the X5 doesn't come with Comfort Access (n.b. BMW's new 3er, 5er, 6er, and 7er all have the Comfort Access keyless system) - even though the story positions the Beckham thefts as if they were due to Comfort Access.
I saw a similar article on leftlanenews.com days ago - also citing the X5 thefts as if they were due to Comfort Access - so it sounds as if this is just going to make the rounds despite faulty reporting by all parties.
How? Since the key doesn't need any action from the user to open the car, they are active all the time waiting for a signal from the car. And since the keys are passive, the car is always sending that signal. So if someone wanted to just open the car, the only thing that's needed is a two way wireless amplifier or repeater. Just put one end of the repeater pair near the car, and the other end near the owner witht he keys in starbucks. The car broadcasts its signal, it gets relayed by the amplifier to the repeater at starbucks and that unit sends the signal to the keys in the owner's pocket. The key, hearing a call from the car, responds its signal which is then relayed to the car, which opens the door an unlocks everything.
From there, the tieve should be able to start the engine with a traditional key (which should not be a problem for an expert car thieve).
This whould work regardless of the protocol, technology or code bit lenght. It would fail only if the key was extremely time sensitive, but since we are talking about nanosecond delays and this is digital cryptography this is unlikely.
Of course, then the thieves, after getting away with the car, need to replace the necessary electronics in order to be able to start the car again, but they could do so from the safety of their hideouts.
The only way to prevent this is to use keys that require that the user presses a button for the security to be disengaged. Laziness never pays.
How? Since the key doesn't need any action from the user to open the car, they are active all the time waiting for a signal from the car. And since the keys are passive, the car is always sending that signal. So if someone wanted to just open the car, the only thing that's needed is a two way wireless amplifier or repeater. Just put one end of the repeater pair near the car, and the other end near the owner witht he keys in starbucks. The car broadcasts its signal, it gets relayed by the amplifier to the repeater at starbucks and that unit sends the signal to the keys in the owner's pocket. The key, hearing a call from the car, responds its signal which is then relayed to the car, which opens the door an unlocks everything.
From there, the tieve should be able to start the engine with a traditional key (which should not be a problem for an expert car thieve).
This whould work regardless of the protocol, technology or code bit lenght. It would fail only if the key was extremely time sensitive, but since we are talking about nanosecond delays and this is digital cryptography this is unlikely.
Of course, then the thieves, after getting away with the car, need to replace the necessary electronics in order to be able to start the car again, but they could do so from the safety of their hideouts.
The only way to prevent this is to use keys that require that the user presses a button for the security to be disengaged. Laziness never pays.
;)
- hackers will follow the technology
- by 209979377489953107664053243186 May 8, 2006 12:11 PM PDT
- Hackers have been affecting the digital business market for years, so it's no surprise that as technology extends to always on communication within the consumer market that hackers will find the same security lapses and take advantage. Business is just now taking security seriously, (statistics on http://www.essentialsecurity.com/educationalfacts.htm) so how long will it be before consumer manufacturers decide to?
- Like this Reply to this comment
-
(29 Comments)