it4sec,
@it4sec@mastodon.social avatar

Gone in 61 seconds.

The keys were left near the front door.

video/mp4

bhawthorne,

@it4sec @docpop Could be a good way of trapping criminals. Setup the car portion to control a gate closer and lock, and leave a fob just inside. When their device forwards the key fob signal, the gate behind them slams shut and locks, flood lights come on, and a siren blares. No reason this couldn’t be built in to the home security system.

bhawthorne,

@it4sec @docpop
Home surveillance video showing a masked thief holding a wire loop antenna in both arms held wide, and walking near the front door until the car parked there unlocks. An accomplice then gets in the car, starts it, and backs the car out of the driveway while the first thief walks away.

skry,
@skry@mastodon.social avatar

@it4sec @mhoye Smashing Security podcast this week said that the attack distance was 60 feet or so to get the signal from the keyfob. A second person next to the car receives and relays.

Faraday box or the refrigerator [and maybe some microwave ovens] are mitigations. Boxes are easier to self test.

@smashingsecurity

Ertain,
@Ertain@mast.linuxgamecast.com avatar

@it4sec Goddamn 😮

zem,
@zem@conesphere.social avatar

@it4sec
wtf! I thought those keys would send at least permanent status beacons but this really is crazy.
@Cryptomon

Mikal, (edited )
@Mikal@sfba.social avatar

@it4sec

This and CAN attacks are a perfect illustration of "blue team has to be perfect every time, red team only needs to find one mistake." Until car manufacturers become liable for the thefts, they have little incentive to find and fix the vulnerabilities they've created. Being perfect is expensive.

Pro tip: drive an older car and put in a hidden fuel pump cut off switch. (I'm guessing that's probably too complicated in the modern motorized computers called cars.)

I recently crossed paths with an acquaintance in the parking lot who pointed to her new truck and excitedly told me how cool it was that she can control the entire thing with her phone... 😱🤦‍♂️

Ich_halt_,
@Ich_halt_@chaos.social avatar

@it4sec that's another pint on my 'Don't like new cars' list.

Ihazchaos,
@Ihazchaos@chaos.social avatar

@it4sec oh, a new kind of car sharing :-)

kimschulz,
@kimschulz@social.data.coop avatar

@it4sec Why the huge backpack and wire anteanna? It can be done with a keyfob size device these days (available for cheep on the internet). Must be an old video

rowan_johnson,
@rowan_johnson@mas.to avatar

@kimschulz @it4sec it says 2021 in the timestamp.

naturzukunft,
@naturzukunft@mastodon.social avatar

@it4sec Handsfree 😂 This is what happens when people become so comfortable that they prefer to be carried into the car.

masek,

@it4sec Would probably work with my bike lock too (using https://mobil.abus.com/int/Consumer/Bicycle-locks/Folding-Locks/BORDO-One-6500A-110-black-bracket-SH). Luckily those locks are still so rare, they confuse thieves ....

simonzerafa,

@it4sec

Lucky that an anti-terrorist squad didn't see that equipment.

Would give you pause that it's a suicide vest with unfortunate consiquences 🫤🤷‍♂️

jesusmargar,
@jesusmargar@mastodon.social avatar

@it4sec i have a car that requires me to press a button to unlock the doors but I need to put the key in the ignition to start. I've always assumed this kind of trick wouldn't work on it. Am I wrong?

dickon,

@it4sec We need to make the manufacturers liable for this. These attacks have been known about for years -- plenty long enough to enact a fix -- and there's simply no excuse for them doing nothing.

mago,

@it4sec key-less go went to key-less gone

BubblegumYeti,
@BubblegumYeti@mastodon.social avatar

@it4sec But wait... how can you drive out of range of the key? My car stops when you do this.

mxtthxw,
@mxtthxw@mxtthxw.art avatar

deleted_by_author

  • Loading...
  • henrik,
    @henrik@eliitin-some.fi avatar

    @mxtthxw @it4sec

    Wow. So... the keys were inside near the door, the guy located them with the antenna thingie? And then what happened?

    mxtthxw,
    @mxtthxw@mxtthxw.art avatar

    deleted_by_author

  • Loading...
  • henrik,
    @henrik@eliitin-some.fi avatar

    @mxtthxw @it4sec

    Ah, just learned about "Relay Attack" 😬

    xs4me2,
    @xs4me2@mastodon.social avatar

    @it4sec

    Wtf…

    linuxandyarn,

    @it4sec Is he walking around with a big loop of coax as an antenna?

    it4sec,
    @it4sec@mastodon.social avatar

    @linuxandyarn yep, he use the loop if coax and his hands to create a frame antenna.

    linuxandyarn,

    @it4sec Further proof that "Nobody would do that" is always the wrong answer.

    cultdev,
    @cultdev@mastodon.social avatar

    @it4sec i live somewhere robberies aren’t common at all, i have no idea what the heck i’m looking at

    krizzzn,

    @it4sec what will they do once they have the car? Are they able to clone the key from the car alone, or reflash the car to accept a new key?

    it4sec,
    @it4sec@mastodon.social avatar

    @krizzzn.

    In this particular case, I'm pretty sure it will go to parts and the rest to the scrap yard.

    byteborg,
    @byteborg@chaos.social avatar

    @it4sec
    Keyless entry and drive, working as advertised. 🤷

    cccac,
    @cccac@chaos.social avatar

    @it4sec crazy how Keyless Gone is still a thing today.

    https://aachen.ccc.de/keyless-gone/

    tito_swineflu,
    @tito_swineflu@sfba.social avatar

    @it4sec so are they scanning for the code from the keys near the door, then transferring that code to a device in the car? That's pretty amazing.

    AustinB,
    @AustinB@esq.social avatar

    deleted_by_author

  • Loading...
  • it4sec,
    @it4sec@mastodon.social avatar

    @AustinB

    1. Usually - while engine is on.
    2. This is a good advice - unlock is easier than engine start.
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • InstantRegret
  • ethstaker
  • cubers
  • khanakhh
  • Durango
  • rosin
  • tacticalgear
  • magazineikmin
  • thenastyranch
  • DreamBathrooms
  • Youngstown
  • mdbf
  • slotface
  • kavyap
  • JUstTest
  • cisconetworking
  • modclub
  • osvaldo12
  • normalnudes
  • everett
  • GTA5RPClips
  • ngwrru68w68
  • Leos
  • anitta
  • megavids
  • tester
  • provamag3
  • lostlight
  • All magazines