Pentester pops open Tesla Model 3 using low-cost Bluetooth module
- Reference: 1652805013
- News link: https://www.theregister.co.uk/2022/05/17/ble_vulnerability_lets_attackers_steal/
- Source link:
Discovered and demonstrated by researchers at NCC Group, [1]the technique involves relaying the Bluetooth Low Energy (BLE) signals from a smartphone that has been paired with a Tesla back to the vehicle. Far from simply unlocking the door, this hack lets a miscreant start the car and drive away, too.
Essentially, what happens is this: the paired smartphone should be physically close by the Tesla to unlock it. NCC's technique involves one gadget near the paired phone, and another gadget near the car. The phone-side gadget relays signals from the phone to the car-side gadget, which forwards them to the vehicle to unlock and start it. This shouldn't normally happen because the phone and car are so far apart. The car has a defense mechanism – based on measuring transmission latency to detect that a paired device is too far away – that ideally prevents relayed signals from working, though this can be defeated by simply cutting the latency of the relay process.
[2]
In a real-life scenario, a victim could be in a building just out of range of their Tesla while standing near a crook with a relay gadget on them. This gadget relays signals from the victim's phone to the Tesla outside via another miscreant with a gadget, who jumps in and steals the unlocked vehicle.
[3]
[4]
In its testing, NCC Group said it was able to perform a relay attack that opened a Tesla Model 3 in which the vehicle's paired device was located in a house approximately 25 metres from the vehicle. Using phone-side and vehicle-side relaying devices made from $50 Bluetooth development modules, the team said it managed to gain full access to the Tesla when the vehicle-side relay was brought within 3 metres.
While NCC only tested the attack on a Tesla Model 3, Sultan Khan, senior security researcher at NCC and the author of the advisory, said the technology used in the Tesla app is the same when connecting to a Model 3 or Y. Khan also theorized that Model 3 and Y key fobs were also likely affected, though those weren't tested either.
[5]
The advisory added:
As the latency added by this relay attack is within the bounds accepted by the Model 3 (and likely Model Y) passive entry system, it can be used to unlock and drive these vehicles while the authorized mobile device or key fob is out of range.
A problem of keys
Tesla hasn't had a good history when it comes to security researchers finding ways to unlock its cars. In 2014, a group of Chinese university students managed an on a attack Model S that allowed them to open doors, sound the horn and more [6]while the vehicle was in motion , and a second Chinese group did [7]much the same in 2016. That same year, the [8]Tesla app was exploited to allow attackers to track, locate, unlock and start vehicles. Two years later, Belgian researchers managed to [9]clone Tesla keyfobs , giving them full control of the affected vehicle.
A problem of Bluetooth
At the same time NCC Group released its Tesla BLE relay advisory, it published [10]a second advisory authored by Khan. In that advisory, he explains how NCC's novel method to hijack a Tesla works against anything relying on BLE to confirm the presence of an authorized user.
In the advisory, Khan states that BLE proximity relay attacks have been known about for years. Fortunately for fans of the protocol, existing relay attacks introduce too much latency. "Products commonly attempt to prevent relay attacks by imposing strict Generic Attribute Protocols (GATT) response time limits and/or using link layer encryption," Khan said.
[11]Tesla sues former engineer, claims he stole Dojo supercomputer trade secrets
[12]Elon Musk flogs $8.4bn of Tesla shares amid Twitter offer drama
[13]Tesla employee: I was fired after sharing video of self-driving car crash
[14]'Boombox' function sparks Tesla recall
The tool developed by NCC Group for its research operates at the link layer, which Khan said reduces latency down to acceptable GATT ranges. By doing so, it's able to circumvent latency bounding and link layer encryption, Khan said.
It's worth noting that the Bluetooth Core Specification makes no claims that BLE proximity signals are secure. In Proximity Profile specification updates from 2015, the Bluetooth Special Interest Group (SIG) stated "the Proximity Profile should not be used as the only protection of valuable assets," and additionally "there is currently no known way to protect against such attacks using Bluetooth technology."
Car owners should disable passive entry
Khan said that the Tesla Product Security team was notified in April of the flaw. Their response was that it was a known limitation of the passive entry system.
Tesla owners concerned about a relay attack should use the [15]PIN to Drive feature in their Tesla, as well as [16]disabling passive entry :
Controls > Settings > Doors & Locks > Passive Entry > OFF
Khan also said adding checks like having the app report the device's last known location and time-of-flight ranging could protect owners, but that's on Tesla to fix, and Khan told Bloomberg the automaker said it has [17]no plans to do so.
Because this attack potentially affects so many devices used to secure so many things, it's a serious issue. Khan said that Bluetooth SIG was notified of the flaw and it told him "more accurate ranging mechanisms are under development."
We've asked the Bluetooth SIG to tell us more about those mechanisms and their availability, but have yet to hear back. ®
Get our [18]Tech Resources
[1] https://research.nccgroup.com/2022/05/15/technical-advisory-tesla-ble-phone-as-a-key-passive-entry-vulnerable-to-relay-attacks/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YoQbB-RN8hR5iPJApzH9cAAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoQbB-RN8hR5iPJApzH9cAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YoQbB-RN8hR5iPJApzH9cAAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoQbB-RN8hR5iPJApzH9cAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2014/07/21/chinese_uni_students_pop_tesla_model_s/
[7] https://www.theregister.com/2016/09/20/tesla_model_s_hijacked_remotely/
[8] https://www.theregister.com/2016/11/25/tesla_car_app_hack_enables_car_theft/
[9] https://www.theregister.com/2018/09/12/tesla_hack/
[10] https://research.nccgroup.com/2022/05/15/technical-advisory-ble-proximity-authentication-vulnerable-to-relay-attacks/
[11] https://www.theregister.com/2022/05/09/tesla_sues_engineer/
[12] https://www.theregister.com/2022/04/29/musk_tesla_shares/
[13] https://www.theregister.com/2022/03/21/in_brief_ai/
[14] https://www.theregister.com/2022/02/11/tesla/
[15] https://www.tesla.com/support/car-safety-security-features#:~:text=PIN%20to%20Drive%20allows%20you,create%20your%20four%2Ddigit%20verification.
[16] https://www.tesla.com/support/car-safety-security-features#require-manual-entry
[17] https://www.bloomberg.com/news/articles/2022-05-16/hacker-shows-off-a-way-to-unlock-tesla-models-start-the-engine
[18] https://whitepapers.theregister.com/
Always-on Security Hole
As I understand it, and I'm willing to concede that there may be some subtlety here that I haven't grasped, the root of the problem is that "passive" devices to unlock a car are always going to be open to relay attacks if they're always broadcasting / responding to broadcasts. Relying on limited range is a pretty obvious security weakness.
What's wrong with having a key fob with a button you have to press? At least then the window of opportunity to perform an attack is vastly limited?
Re: Always-on Security Hole
You might as well ask, "Why build a single-car rail transport tunnel?"
Re: Always-on Security Hole
What's wrong with having a key which you have to physically insert into a slot in order to lock/unlock a door? Oh, I know, 'for your convenience'. Like having escalators at the gym.
Re: Always-on Security Hole
What's wrong with having a key fob with a button you have to press?
Agreed. My new car came with keyless entry which must be disabled every time you lock the car if you don't want it. I never use it.
Its one saving grace is that the key is only active for a few seconds after it's been moved. If left sitting on a table it becomes quiescent. That way it works when you're carrying it to the car, but can't be used for an unattended relay, which is quite a neat solution.
Re: Always-on Security Hole
Sounds like a good feature.
My key has to live in a pouch which is a Faraday cage and at home the pouch lives in a steal box. Works for a keyfob but doesn't make much sense for a phone.
Mind there are days when keeping the phone in a Faraday cage sounds like bliss.
Re: Always-on Security Hole
"a steal box."
I saw what you did there! :-)
hacked like any PC
What do they say about personal computers?
"If the bad guy has physical access to your computer, it is no longer your computer."
The same is true of any car with radio/remote access. A physical key or encrypted push-a-button-to-unlock key is essential.
I know someone who never locked their car. There was never anything in there to steal, and they reasoned that it'd save a massive clean up operation from him if the local dickhead smashed a window to discover he had nothing in the car.
One morning in December he went down to the car to drive to work and some dickhead had smashed the window. Didn't even try the door.
So while it's awful that a Tesla can be hacked like this, all cars can be hacked easily with a brick. No matter what the owner does.
the hack lets the attacker start the car and drive away too
I suppose the only saving grace here is that the person who nicks your car this way is probably going to lose it pretty quickly to someone else who can steal it just as easily.
Re: the hack lets the attacker start the car and drive away too
Haven't I seen ads where the owner uses their phone app to have the car drive out of tight parking spaces?
So not only can the thief open the car and drive it away, they can probably persuade the car to drive into the middle of the road without needing to actually get into the car.
Re: the hack lets the attacker start the car and drive away too
You can also cause it to brake check the car behind by (as a pedestrian) trying to walk across the road anywhere near it (see Ashley Neal's latest video)
Re: the hack lets the attacker start the car and drive away too
"Haven't I seen ads where the owner uses their phone app to have the car drive out of tight parking spaces?"
I seem to remember a huge advertising campaign stuck at the start of many VHS tapes and DVDs. IIRC, the strapline was "you wouldn't steal car, would you?". Clearly advertising doesn't work as it doesn't seem to have reduced let alone stopped car theft. Unless, I missed the point of the ad.
defeated by simply cutting the latency of the relay process.
Hmmm. Much of my career involved "cutting latency". It's not simple.
Unless, of course, the latency of the (first implementation) relay device was needlessly much larger than expected, for reasons that were known but ignored.
Re: defeated by simply cutting the latency of the relay process.
"cutting latency"
I think the point was the owner can be _just_ outside the activation range, and the small added relay latency still allows the car to unlock. So in a large carpark you could have a criminal mastermind on a skateboard next to the car, a henchman (likely a him) walking near the owner, and the car could be driven away before the owner reaches the stairs. Convenience indeed.
But where is the market for stolen Teslas? All the features that make them Teslas need the phone-home enabled.
living in a fantasy
In my world I don’t need keys because nobody steals anything. I can write Office macros to be productive because no one hacks anything. But, since I’m living in an unreal world I have to be careful. It starts with using a phone to make phone calls and little else.