Cops swoop after crooks use wireless keyfob hack to steal cars
- Reference: 1666074426
- News link: https://www.theregister.co.uk/2022/10/18/car_thieves_arrested_keyless_tech/
- Source link:
The alleged crooks preyed on motors from two French automakers, we're told. The thieves were apparently able to update or manipulate the cars' software so that the doors could be opened and engine started without needing the owner's wireless keyfob. Just turn up, get in, drive off.
The European cops [1]didn't provide much detail about the "fraudulent tool" used to pull off these thefts, other than it was marketed as an automotive diagnostic product and was typically used by independent repair shops to reprogram a car's key system without requiring a trip to the dealer.
[2]
It sounds as though there was a way to force these vulnerable vehicles to accept another wireless keyfob, allowing a thief in. It's not entirely clear how it worked – whether it was all wireless or if a physical connection was needed. Officially, the cops said the tool was able to "replace the original software of the vehicles, allowing the doors to be opened and the ignition to be started without the actual key fob."
[3]
[4]
"It was a portable solution that the criminals would connect to the car they wish to steal to open the doors and drive off," a Europol spokesperson told The Register , adding that the car-heist-enabling software was sold on the open web — but "to an informed audience (criminals)."
Europol isn't releasing the names of the suspects nor the software at this stage in the investigation. "Investigations are ongoing in a number of European countries to arrest all the car thieves using this tool," the spokesperson added.
[5]
Those arrested apparently include the software developers, its resellers, and the car thieves who used the tool. In addition to cuffing the 31 suspects, the police searched 22 locations and seized more than EUR 1.1 million ($1.1 million) in assets. It appears a website was also seized and shutdown.
The French Gendarmerie's Cybercrime Centre (C3N) opened the investigation with support from Europol starting in March. In September, French authorities opened the case at the European Union Agency for Criminal Justice Cooperation (Eurojust).
French police, working with Spanish and Latvian officers, made the arrests on October 10. Also on that day, Europol open a mobile office in France to assist that country's police and military authorities with their investigation.
[6]
The European Multidisciplinary Platform Against Criminal Threats (EMPACT) and the Internal Security Fund (ISF) SWORD also provided financial support.
[7]Hackers remotely start, unlock Honda Civics with $300 tech
[8]2-bit punks' weak 40-bit crypto didn't help Tesla keyless fobs one bit
[9]Veedub flub hubbub stubs car-jack hack flap
[10]'Baby Al Capone' to pay $22m to SIM-swap crypto-heist victim
The French car heist follows the emergence earlier this year of a [11]keyfob hijack technique affecting Honda Civics.
This security weakness, tagged [12]CVE-2022-27254 , was discovered by Ayyappan Rajesh, a student at University of Massachusetts Dartmouth, and someone with the handle HackingIntoYourHeart. Their [13]research indicated that Honda Civic LX, EX, EX-L, Touring, Si, and Type R vehicles manufactured between 2016 and 2020 all have this over-the-air vulnerability.
According to the duo, "various Honda vehicles send the same, unencrypted RF signal for each door-open, door-close, boot-open and remote start. This allows for an attacker to eavesdrop on the request and conduct a replay attack."
An unrelated but similar problem in 2012 Honda Civics allows for a [14]similar attack , but with a different cause: a non-expiring rolling code and counter resync.
Additionally, in 2016, The Register [15]reported on an experiment in which researchers cloned a Volkswagen keyfob and were able to use it to potentially unlock 100 million vehicles. There's probably plenty more examples in the archives. ®
Get our [16]Tech Resources
[1] https://www.europol.europa.eu/media-press/newsroom/news/31-arrested-for-stealing-cars-hacking-keyless-tech
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y055OadUjYSNl@NOT8LbeQAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y055OadUjYSNl@NOT8LbeQAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y055OadUjYSNl@NOT8LbeQAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y055OadUjYSNl@NOT8LbeQAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y055OadUjYSNl@NOT8LbeQAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/03/25/honda_civic_hack/
[8] https://www.theregister.com/2018/09/12/tesla_hack/
[9] https://www.theregister.com/2015/08/18/vw_vulnerability_report_usenix/
[10] https://www.theregister.com/2022/10/15/pinsky_terpin_sim_swap/
[11] https://www.theregister.com/2022/03/25/honda_civic_hack/
[12] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27254
[13] https://github.com/nonamecoder/CVE-2022-27254
[14] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46145
[15] https://www.theregister.com/2016/08/11/car_lock_hack/
[16] https://whitepapers.theregister.com/
Re: Security is hard!
I think in the old days of purely mechanical locks, manufacturers did eventually hire people to test their physical security.
Nowadays, I bet a lot of it is actually bought it, so the manufacturer trusts their supplier and the supplier just wants to keep their costs as low as possible.
Re: Security is hard!
Yeah, but we're talking about French auto makers . . .
They have enough trouble making cars that don't break down after a year.
motors from two French automakers
That'll be Citroen/Peugot and Renault/Nissan then?
Not happy if they have a 'can connect to reprogram the ECU' with the doors locked (implied but not stated in the article) and I have to admit I'm curious as to how the criminals managed that trick (as well as moderately worried since I own a recent - though poverty spec - Renault).
Re: motors from two French automakers
It's the reprogramming without opening that's the scary part.
Many years ago I owned a Citroen and was surprised that the garage would connect the computer to the OBD port on the car and get the car to reprogram the keyfob.
Re: motors from two French automakers
I'm not surprised that the keyfob can be reprogrammed - or rather, the security system can be told to accept a different fob; I don't think the fob would change its RFID chip value though that's possible for some chips - from inside the vehicle.
Like A Mouse above, my concern is why the access is available from outside a locked vehicle - if indeed I read the article correctly and that is what happened.
Re: motors from two French automakers
Hard to believe that any of those brands would be such desirable targets, don't these thieves usually go for Porsches, Mercs or Lexuses (Lexi?)
Re: motors from two French automakers
I guess there are different market segments in car theft just as in any other sector. Mass market cars might be easier to sell on to criminals looking for unidentifiable cars. Stripping them for parts might also be more lucrative for popular models than rarer ones. If thieves have a relatively automated 'get and go' system it could work low-margin high-volume, just like Amazon
Re: motors from two French automakers
Hard to believe that any of those brands would be such desirable targets, don't these thieves usually go for Porsches, Mercs or Lexuses (Lexi?)
Different market, these thefts are for parts, next stop, chop shop!
An alternative
My car (admittedly almost a vintage motor) has a physical metal key that I push into a physical lock. In order to get a spare duplicate, I had to present my ownership document at the dealership to be given the key code and then had to present this and my identity document at the key cutting shop. They also actually asked to see the original key as well. I have a funny feeling that's more secure than any remote locking gadget, particularly as this is by [1]far not the only attack vector on recent record .
[1] https://www.theregister.com/2022/03/25/honda_civic_hack/
Re: An alternative
Reminds me of last time I had a key cut for my old Mitsubishi.
The conversation went like this...
Him: "Sorry Mate, can't copy this key, my machine can't read the transponder"
Me: "It doesn't have a transponder"
Him: "It's for security. There's a chip in the key that talks to the immobiliser"
Me: "I know, but this is an old car, it doesn't have an immobiliser"
Him (scoffing): "Of course it does, you can't just turn the key and start the engine"
Me: "Yes you can, that's exactly how it works"
Him:"Trust me mate, it's not going to work"
Me: "Please could you just cut it for me anyway?"
Progress of car security
When my friend's Vauxhall Viva was stolen around 1980, the police found it abandoned and managed to get into it with a Ford Cortina key. Pretty much any small flat piece of metal would unlock it. On top of which, it was possible to open the Viva's bonnet from the outside, and under the bonnet was a button labelled 'push to start engine'. Since then car security has steadily improved, with proper keys, alarms, deadlocks, immobilisers and so on. Until recently, that is, when technology seems to be returning us to the 'push to start engine' stage.
Re: Progress of car security
My first car was a Vauxhall Cavalier... A 1983 1.6L that I owned around 1995.
The door handles kept breaking, as did the window winders... So I was always at the local scrap yard looking for spares.
One day the key broke... and because of a break in a few months earlier... I'd had to replace the ignition barrel... Which meant I had 2 keys, one for the doors, one for the ignition.
I tried the ignition key in the door lock, and it opened.
As a curious little bugger... I tried other items... all of them worked.
The final item I tried to unlock the car... an ice cream lollypop stick.
It worked.
Re: Progress of car security
Talk about being Cavalier about security!
Re: Progress of car security
I had a company Sierra a while back. It needed a thin physical key with a round cross-section to unlock the central locking. Some oiks tried to steal it one day but the police were on hand and stopped them, leaving me with a dangling ignition switch and nice full-beam-only headlights for my commute home on the M25, the scrotes having broken the stalk.
The policeman told me that to unlock the doors all you need is half a tennis ball. You place it over the keyhole and strike it sharply. The air pressure then unlocks the car.
Re: Progress of car security
At a car ferry close to where I grew up (so we're talking 30+ years ago), it happened occasionally that someone locked their keys in their car.
Legend has it that the ferry staff could unlock any car in a handful of seconds
Re: Progress of car security
Most cars of that vintage could have the doors opened by a key of roughly the right shape and a bit of jiggling simply because of how worn the locks were, always try the drivers door first as that gets at least double the use of any other lock on the vehicle.
Ignition locks tended to fare better as they were used less than door locks and weren't exposed to the outside weather.
Re: Progress of car security
Ford were well known for it.
The reason they were the first manufacturer to fit high-security "disc" locks was that they Needed To Be Seen To Be Doing Something About It.
Rumour has it that there were a grand total of five distinct Cortina keys. There were many shapes, but all you need to open every single one was the five.
I personally opened and started a Ford Cargo truck using the ignition key from an Austin 1100. While less than a third the size and single, rather than double, edged, it fitted and turned like it was the right key. No fiddling or jiggling required.
Another time I was refuelling and there was a bit of a commotion at the next pump. A woman had locked the keys in her Fiesta. I walked over with a bunch of keys and tried each of them, despite scepticism from the assembled crowd. The third one I tried (the fuel filler cap key from a Skoda Rapid 130) did the job.
Re: Progress of car security
A neighbour locked her keys in her Fiesta along with her baby. None of my keys worked, but I had the back window out in about five minutes - in one piece - without even waking the baby.
Re: Progress of car security
My parent's Cortina was stolen and recovered twice in one week due to Ford's comedy locks.
My latest car has this keyless nonsense - keep the fobs in faraday pouches and a substantial, bright yellow lock on the steering wheel to compensate.
Re: Progress of car security
Escorts were known as a "Ford Takeaway" back in the day. My Morris Ital key could open many of them them. Such fun going round a car park, just for laughs.
Re: Progress of car security
Way back my mother had a little red Mazda 323. One day, after coming back from the theatre the previous night she couldn't figure out where the umbrella stashed in the front passenger seat had gone. And the car was a slightly yellower shade of red... we sorted it out, but the people whose car was accidentally stolen were Not Amused.
I call that a successful operation
"Those arrested apparently include the software developers, its resellers, and the car thieves who used the tool"
Well done to the police forces involved.
Good coordination, good cooperation, and the miscreants go down for the count.
Now all that is needed is for the automakers to analyse the fault and correct it.
Why am I skeptical at this point ?
Re: I call that a successful operation
That is more or less expected as it was a Europol operation. Their role is specifically to collect and share intelligence with regular police forces, investigate bigger and border-crossing types of crime, and coordinate pan-European searches and arrests.
They don't have their own 'cops', they leave the searches and arrests to local police forces but they will take the coordinating role (so a dawn raid in Portugal doesn't alert the accomplices in Finland because all raids happen simultaneously).
It tends to take a while before Europol gets involved, petty crime is not their thing, but when they do get involved [1]they tend to be quite impressive operations . What probably triggered Europol involvement is that this wasn't just a local gang who fiddled with some fobs to steal a handful of cars but that it was an organised crime ring that sold their tech and services to local gangs.
[1] https://www.europol.europa.eu/media-press/newsroom
Only way is to go back to the 1980's and the good old steering wheel locks
Remmeber the nice Orange Hook things going over the brake and steering wheel, or are the new yellow ones that look like they attach to the steering wheel any better ?
Security is hard!
I'd have thought that car manufacturers would have invested in teams that actively try to break into their new cars to avoid just this sort of situation arising.
But then I guess that would add a few pounds/dollars/euros to the cost of the car, so the beancounter .... he say "No!"