Hackers remotely start, unlock Honda Civics with $300 tech
- Reference: 1648220405
- News link: https://www.theregister.co.uk/2022/03/25/honda_civic_hack/
- Source link:
Keyless entry exploits are nothing new. Anyone armed with the right equipment can sniff out a lock or unlock code and retransmit it. This particular issue with some Honda vehicles is just the latest demonstration that auto manufacturers haven't adapted their technology to keep up with known threats.
[1]CVE-2022-27254 , tied to this discovery, was the work of four researchers: Professors Hong Liu and Ruolin Zhou from the University of Massachusetts, computer scientist Blake Berry, and Sam Curry, CSO at Cybereason. [2]Their research suggests that Honda Civic LX, EX, EX-L, Touring, Si, and Type R vehicles manufactured between 2016 and 2020 all have this vulnerability.
[3]
According to the team, "various Honda vehicles send the same, unencrypted RF signal for each door-open, door-close, boot-open and remote start. This allows for an attacker to eavesdrop on the request and conduct a replay attack." The GitHub page created for the vulnerability hosts three separate proof-of-concept videos showcasing their results.
[4]
[5]
Attackers only needed a few easily sourced components to execute their attack: a laptop, the GNURadio development toolkit, Gqrx software-defined radio (SDR) receiver software, access to the FCCID.io website, and a HackRF One SDR. The only cost associated with the attack (besides owning a laptop) is purchasing the [6]HackRF One , which retails in the mid-$300 range. All software used in the attack is free and open source.
A common problem
The CVE page for this vulnerability makes mention of another, [7]CVE-2019-20626 , the same vulnerability found in 2017 Honda HR-V vehicles, which Paraguayan security researcher Victor Casares demonstrated in a 2019 Medium post.
[8]US DoJ reveals Russian supply chain attack targeting energy sector
[9]Distributor dumps Kaspersky to show solidarity with Ukraine
[10]We blocked North Korea's Chrome exploit, says Google
[11]Microsoft Azure developers targeted by 200-plus data-stealing npm packages
An unrelated but similar problem in 2012 Honda Civics allows for a [12]similar attack , but with a different cause: a non-expiring rolling code and counter resync. This isn't just a Honda problem either. In 2016, The Register [13]reported on an experiment in which researchers cloned a Volkswagen key fob and were able to use it to potentially unlock 100 million vehicles.
The researchers involved in this latest discovery said that vehicle owners don't have a lot of protection options as long as manufacturers continue using static codes. Rolling codes that change at each press of the button are "a security technology commonly used to provide a fresh code for each authentication of a remote keyless entry (RKE) or passive keyless entry (PKE) system," the researchers said.
Speaking of PKE systems, the researchers say that those are a significant improvement over RKE systems. Instead of relying on the fob to broadcast, the vehicle itself continually searches for a passive RF fob, like a door keycard, and once close enough the vehicle automatically unlocks. The close proximity required makes this attack far trickier.
[14]
Ultimately, the researchers say the only way to mitigate the problem if you're a victim is to head to the dealership and have them reset the key fob. As for prevention, the researchers go back to basics on this one: put your keys in a Faraday pouch.
We have asked Honda to comment. ®
Get our [15]Tech Resources
[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27254
[2] https://github.com/nonamecoder/CVE-2022-27254
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yj31PlKBVdkPUwZLXr5nGgAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yj31PlKBVdkPUwZLXr5nGgAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yj31PlKBVdkPUwZLXr5nGgAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://greatscottgadgets.com/hackrf/one/
[7] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20626
[8] https://www.theregister.com/2022/03/25/us_indicts_russian_state_hackers/
[9] https://www.theregister.com/2022/03/25/distributor_dicker_data_dumps_kaspsersky/
[10] https://www.theregister.com/2022/03/25/chrome_exploits_north_korea/
[11] https://www.theregister.com/2022/03/24/developers_using_microsoft_azure_targeted/
[12] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46145
[13] https://www.theregister.com/2016/08/11/car_lock_hack/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yj31PlKBVdkPUwZLXr5nGgAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Re: kids
Get off my lawn! [cough, hack, wheeze]
Replay attacks
That cars are subject to replay attacks today when it was a know problem so many decades ago is just plain terrible, amazing.. in a bad way.
Re: Replay attacks
Come on, a car stolen is a car its owner will have to buy again. It's a win-win situation (except for the owner, but who cares about him).
It's a feature, you guys!
That's a totally intended for feature, not a vulnerability! If you ever need to lend your car to a family member, friend or someone else that lacks your keys, they can do so. See, car sharing feature!
Maybe somebody should invent some sort of alternative to all this RF stuff. Something radical like maybe a uniquely shaped metal token of some sort that you fit into some sort of receptacle in the vehicle designed to only accept that uniquely shaped token. You could use the same token to open all the doors and maybe start the engine too.
Just random thoughts really...
Slim jim
Or even a flat metal strip that can slide between the window glass and the door.
You’d have to rip the starter wires out though. Bit messy.
Re: Slim jim
There was a period when cars had physical locks as well as an RFID tag in the key. The security with them was pretty damned good. I had a late 90s Volvo with that set up and no remote fob until fairly recently.
I watched an expert try to "steal" it once as part of a demo. Modern cars he was driving away in seconds. My old Volvo defeated him. He had to admit the only way he was opening the door was would be by causing serious physical damage - breaking the window being the easiest route. But even inside the car he was stumped. With the key in the house (the house was actually the police station where the demo took place) the range on that old RFID tag was so low he couldn't activate it. But even with the RFID tag right next to his reader although he couldn't manage to crack things enough to start the car within the 15 minute limit he'd been set.
With access to the RFID tag - for example if the keys were right next to my front door he could fool the ECU into thinking the key was present, but the physical security was too much for him. He had to admin that in order to steal the car he would need to smash the window and then rip the steering column apart. Not just to hot wire the ignition switch, but to bust the steering lock.
And that's all it takes. If the potential thief has a choice of cars they are always going to go for the easy target. Time taken stealing a car is time at risk of being caught in the act. Also there is the risk from failure. Fail to steal a car and you risk leaving physical evidence on the car which is just another way of getting caught. The thing is that most modern cars are pretty easy to steal so the thief is spoiled for choice. Back in the day of course it was GM products every time because you could steal one as quickly as if you had the key.
Car security has gone backwards massively in the name of convenience. But I never found a physical key an inconvenience in the first place.
uniquely shaped metal token of some sort
People would never go for such a cumbersome method. Its been proven recently , presumably by marketing men , that even pushing button on key fob to remotely open the vehicle is far too much trouble so now we have keyfobs that open the door 24/7 for whoever wants to get in , (and have to be kept in a special faraday cage at night to stop them giving your car away) somewhat bending the definition of a lock , in my opinion.
We had those back in 80s
Back then some manufacturers managed to make their keys less unique than they should have been especially after a couple of years of use, such that you could open them with any key. Keys didn't stop huge numbers of hot hatches going awol in UK during the 80s either
"You could use the same token to open all the doors and maybe start the engine too."
I agree with you about the uniquely shaped piece of metal but having that, let's call it a "key", open all the doors, filler cap and ignition is a very bad idea.
My Mini Cooper S has a different key for each of those functions and that is generally thought that that adds to the security of the car. Lose one key, not nice but it happens, and you have only allowed access to one of the parts of the car.
With one key to rule than all, lose that and you're stuffed.
On the other hand I've never lost a key in my life (any key), so YMMV.
I personally would rather not have to carry along a whole bunch of different keys for the car. I already feel like a prison guard with the 4 house keys, the 3 work keys and the 3 keys for the bike...
almost never use remote key fob features
Since I first heard about these kinds of attacks many years ago I almost never use my remote key fob(at least the buttons on it), of course I have to use it to unlock but I just make sure I am close to the car when I hit the unlock button(on the car not the key fob) so it can sense the proximity of the key fob to authenticate the unlock. I assume that is much harder to sniff out then pressing the unlock or lock buttons on the key fob from a distance anyway.
Re: almost never use remote key fob features
RF transmits as far as RF transmits. If they're in range, you're toast.
I'd recommend buying a nice reliable beater with no electronics. :)
Re: almost never use remote key fob features
I don't think it transmits far when used in this manor? because if the key is further away than a couple of feet even I think the door won't unlock(note am not pressing any buttons on the key fob to transmit anything just pressing the unlock button on the car door). And the car recognizes when the key is inside the car or not(fortunately as it prevents me from locking the keys inside the car which I have accidentally tried to do many times).
Re: almost never use remote key fob features
I do exactly the same. Why expend the effort to dig for a key fob in your pocket, just to unlock the door, when you have to grab the door handle anyway? It simply doesn't make much sense to me o.O
Re: almost never use remote key fob features
Buttons are getting more and more rare. It's almost twenty years since I drove a car where you never even had to take the keyfob out of your pocket. The RFID tag in that car was supposedly only effective when you were right next to the car. And we did find if I was standing two metres away somebody next to the car couldn't open the door. However I recently tried a modern equivalent and the doors would audibly unlock when I was more than six feet from the car and wouldn't lock again until I was twice that distance away.
With an RFI reader a thief could easilly read that thing from outside your house unless you were to deliberately find the point in your house least accessible to RF to keep your keys. Or maybe invested in a lead box to keep them in.
Steering Wheel Lock Anyone?
Back when I was a lad it was all the rage to have a big fat bar across your steering wheel to make sure that if someone got into your car, they couldn't actually drive it away.
I've a feeling these will be making a comeback!
I'd certainly be investing in one if I had a big fat expensive car. Or even one of those little Hondas..
Re: Steering Wheel Lock Anyone?
There never was one of those that you couldn't pop the lock in under a minute. Doesn't matter how big and sturdy a security device is if you can open the lock with a ball point pen.
Re: Steering Wheel Lock Anyone?
Or saw through the steering wheel to remove it.
Re: Steering Wheel Lock Anyone?
The point of them wasn't to defeat thieves but to make them steal the next car instead of yours
Faraday pouch
Or an Altoids tin.
Only problem with these is that eventually you will have to take your keys out to use your car. And some ner-do-well hiding in your apartment garage with their sniffer grabs the code then. The tins do work well to prevent key fobs lying on your entry hall table from being sniffed through your front door.
Re: Faraday pouch
On the same basis, keep your car in a shipping container.
Re: Faraday pouch
I use a garage. It might not be rf proof but its got a hell of a door on it
Re: Faraday pouch
Great idea. It will save the thieves having to place it into a container when they take it to the docks.
Re: Faraday pouch
These keys that are opening your car without being asked from the hallway are easily the dumbest invention Ive ever heard of .
All because its too much trouble for the owner to push a button on the fob.
Re: Faraday pouch
Look on the bright side, it helps sell more cars. I guess insurers could intervene by refusing to insure insecure vehicles for theft.
Like vanishing buttons, I miss real keys. Easy to get into the habit of locking, even with a fob and checking the door was locked. Proximity keys just seem dumb if locking means walking away and hoping it works.
Money questions
I question why the purchase of the $300 HackRF One is necessary. The fob is told to operate at 433mHz, and both cheap and a pence a dozen. All you should need to do it interface it with any Linux system who's driver can be set to "promiscuous" (which not too many people either use, or know about). Did that back in the day when I was fooling around with Linux but the WiFi refused to connect.
Re: Money questions
Hmm. Are you a geek, or just visiting? In my case, it's more an iWant than iNeed. Mainly because it looks like this gizmo + antenna switcher would cost a lot less and do more than my aging $10K+ spectrum analyser.
I dont understand how it is not now impossible to steal a car by spoofing the key , now that we have encryption both strong and one way - public / private key etc.
Water
What always makes me laugh is when you see modern cars advertised as part of an active lifestyle. Ever tried taking a modern key fob surfing with you?
Re: Water
Advertisement tries desperately to make you dream. That's why you see cars driving through breathtaking beautiful landscapes, or stylish, clean and most of all empty cities. All those sorts of things they will never see in their real life of creeping along, bumper-to-bumper, through some dirty and quite bland (if not obnoxious) and overcrowded city...
Good. Maybe someone will filch those annoying, loud, obnoxious rice burners the kids drive around here and strip them for parts. :)