Jump to content

Volkswagen key-less ignition security flaw - 2+ years spent hushing, rather than fixing...

Jasmin

Well, it appears we have yet another car-related security issue.

 

This time Roel Verdult and Baris Ege from Radboud University in the Netherlands and Flavio Garcia from the University of Birmingham, U.K. managed to discover that majority of Volkswagen cars and a fairly high volume of cars from other manufacturers using 'key-less' security chips from EM Microelectronic are easily hackable due to outdated encryption systems.

 

According to the researchers, chip which should prevent the engine from starting if it's not in the near vicinity to the twin-chip built into the car and which according to the company itself should be uncopyable, can be, in fact, easily mapped and reproduced after recording the transmission just twice - one of the core issues is that it uses 96-bit encryption... Apparently we are back in the 90's when it comes to luxurious cars.

 

Now the best part - security flaw was discovered back in 2012 and the chip producer was given 9 months to address the issue. Of course how could we expect the car industry to do anything if they can just sue the researches after the timer ran out, preventing them from publishing the research for over 2 years. Way to go VW, 196,607 possible keys are definitely good enough, good gods, no Amiga A1000 could handle it in a reasonable amount of time after all. I hope IBM is providing you with good maintenance on your RAMAC 305 supercomputer!

 

A VW spokesman responded: "Volkswagen maintains its electronic as well as mechanical security measures technologically up-to-date and also offers innovative technologies in this sector."

 

Yea, sure...

 

List of cars that are affected for 100%:

 

-1x-1.jpg

 

Sauce & the other Sauce

Link to comment
Share on other sites

Link to post
Share on other sites

oooh kinda like the 50 cent GM ignition problem? 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Now this is quite a big problem.

cpu: intel i5 4670k @ 4.5ghz Ram: G skill ares 2x4gb 2166mhz cl10 Gpu: GTX 680 liquid cooled cpu cooler: Raijintek ereboss Mobo: gigabyte z87x ud5h psu: cm gx650 bronze Case: Zalman Z9 plus


Listen if you care.

Cpu: intel i7 4770k @ 4.2ghz Ram: G skill  ripjaws 2x4gb Gpu: nvidia gtx 970 cpu cooler: akasa venom voodoo Mobo: G1.Sniper Z6 Psu: XFX proseries 650w Case: Zalman H1

Link to comment
Share on other sites

Link to post
Share on other sites

oooh kinda like the 50 cent GM ignition problem? 

 

My mom had to get hers fixed lol. They did it free then charged her $50 for a "ding" on the rental car...

blackshades on

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

AHHHH. WE HAVE A SPARK AHHH

 Just because you don't care, doesn't mean other others don't. Don't be a self-centered asshole. -Thank You a PSA from the people who do not say random shit on the internet. 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Wow, this sort of attitude just pisses me off, and I thought Volkswagen was one of the better car manufacturers. 

CPU: i5-4690k GPU: 280x Toxic PSU: Coolermaster V750 Motherboard: Z97X-SOC RAM: Ripjaws 1x8 1600mhz Case: Corsair 750D HDD: WD Blue 1TB

How to Build A PC|Windows 10 Review Follow the CoC and don't be a scrub~soaringchicken

 

Link to comment
Share on other sites

Link to post
Share on other sites

Is the Cvic Hybrid affected as well?

Link to comment
Share on other sites

Link to post
Share on other sites

Wow, this sort of attitude just pisses me off, and I thought Volkswagen was one of the better car manufacturers. 

Volkswagen is good value and it's the largest car manufacturer too.

Location: Kaunas, Lithuania, Europe, Earth, Solar System, Local Interstellar Cloud, Local Bubble, Gould Belt, Orion Arm, Milky Way, Milky Way subgroup, Local Group, Virgo Supercluster, Laniakea, Pisces–Cetus Supercluster Complex, Observable universe, Universe.

Spoiler

12700, B660M Mortar DDR4, 32GB 3200C16 Viper Steel, 2TB SN570, EVGA Supernova G6 850W, be quiet! 500FX, EVGA 3070Ti FTW3 Ultra.

 

Link to comment
Share on other sites

Link to post
Share on other sites

My mom had to get hers fixed lol. They did it free then charged her $50 for a "ding" on the rental car...

wow....just....wow   

I have the opposite problem

I can pull my key out of the ignition...and my car will still run 

yay Chrysler 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Volkswagen is good value and it's the largest car manufacturer too.

The problem here is, that VW makes cars I'd actually want to buy. There might be great deals for used Volkswagen though :D

My biggest problem is that they haven't bloody fixed the problem. You don't run around for two years, fucking people after being diagnosed with AIDS, and the only other person who knows it isn't allowed to tell anybody. Dishonesty like that makes me really angry. And the fact, that with all the electronics we have in our cars now a days there is no way to have software updates over the air. Because at some point there will be a security issue and then we'll have a GM ignition 2

Molex to SATA, lose all your data

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

The problem here is, that VW makes cars I'd actually want to buy. There might be great deals for used Volkswagen though :D

My biggest problem is that they haven't bloody fixed the problem. You don't run around for two years, fucking people after being diagnosed with AIDS, and the only other person who knows it isn't allowed to tell anybody. Dishonesty like that makes me really angry. And the fact, that with all the electronics we have in our cars now a days there is no way to have software updates over the air. Because at some point there will be a security issue and then we'll have a GM ignition 2

As far as I can tell this only ever changes anything if someone is trying to steal your car. And trust me, with or without this, if someone decides to steal your car it's gone, changes nothing. If you are afraid of theft get insurance, that's about all you can do.

 

Only security flaws you should be concerned with are the ignition kill switches and stuff.

Location: Kaunas, Lithuania, Europe, Earth, Solar System, Local Interstellar Cloud, Local Bubble, Gould Belt, Orion Arm, Milky Way, Milky Way subgroup, Local Group, Virgo Supercluster, Laniakea, Pisces–Cetus Supercluster Complex, Observable universe, Universe.

Spoiler

12700, B660M Mortar DDR4, 32GB 3200C16 Viper Steel, 2TB SN570, EVGA Supernova G6 850W, be quiet! 500FX, EVGA 3070Ti FTW3 Ultra.

 

Link to comment
Share on other sites

Link to post
Share on other sites

You don't run around for two years, fucking people after being diagnosed with AIDS, and the only other person who knows it isn't allowed to tell anybody. 

 

Well, that's a new one. 

 

 

 

OT: Automakers better pull their heads out of their behinds because the world is no longer stupid when it comes to electronics from the last decade. 

Spoiler

Corsair 400C- Intel i7 6700- Gigabyte Gaming 6- GTX 1080 Founders Ed. - Intel 530 120GB + 2xWD 1TB + Adata 610 256GB- 16GB 2400MHz G.Skill- Evga G2 650 PSU- Corsair H110- ASUS PB278Q- Dell u2412m- Logitech G710+ - Logitech g700 - Sennheiser PC350 SE/598se


Is it just me or is Grammar slowly becoming extinct on LTT? 

 

Link to comment
Share on other sites

Link to post
Share on other sites

As far as I can tell this only ever changes anything if someone is trying to steal your card. And trust me, with or without this, if someone decides to steal your car it's gone, changes nothing.

The key isn't the problem here. VW is. First they dare to use a 96-Bit encryption and then they can't come up with a solution when it inevitably fails. 

Molex to SATA, lose all your data

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

 And the fact, that with all the electronics we have in our cars now a days there is no way to have software updates over the air.

Unless you have a Tesla, but we all know how the competition thinks of them.

 

OT: This should be regulated by law. If one finds an exploit, he/she should report it to the car manufacturer who must then test it and fix it, either via an OTA update or with a recall, within, lets say 6 months. Cars are jammed with technology these days, so manufacturers should treat them like your every day computer, meaning that once an exploit is found, they should fix it.

Ye ole' train

Link to comment
Share on other sites

Link to post
Share on other sites

Volkswagen is good value and it's the largest car manufacturer too.

Wasn't saying that it wasn't, both of my parents own volkswagens and they're both mostly great. It's just the lazy attitude that these massive car manufacturers have in regard to these types of issues pisses me off.

CPU: i5-4690k GPU: 280x Toxic PSU: Coolermaster V750 Motherboard: Z97X-SOC RAM: Ripjaws 1x8 1600mhz Case: Corsair 750D HDD: WD Blue 1TB

How to Build A PC|Windows 10 Review Follow the CoC and don't be a scrub~soaringchicken

 

Link to comment
Share on other sites

Link to post
Share on other sites

wow car companies are soooo behind 

Dont they have any common sense at all?

IntelCorei54670k,Maximus VI Formula,Swift tech H220, 16gigs Corsair Dominator platinums, Asus DCUII GTX 780,1x256 840 evo, 1x 2TB Segate barracuda, Corsair AX 860, 

3 X Noctua NF-F12, 2x Noctua NF A-14, Ducky Shine 3 Blue Leds Blue switches, Razer Death Adder 2012, Corsair vengence 1400  

Link to comment
Share on other sites

Link to post
Share on other sites

Just tried this on a coworker's Daewoo Matiz. Didn't work :( I'm disappoint.

Remember kids, the only difference between screwing around and science is writing it down. - Adam Savage

 

PHOΞNIX Ryzen 5 1600 @ 3.75GHz | Corsair LPX 16Gb DDR4 @ 2933 | MSI B350 Tomahawk | Sapphire RX 480 Nitro+ 8Gb | Intel 535 120Gb | Western Digital WD5000AAKS x2 | Cooler Master HAF XB Evo | Corsair H80 + Corsair SP120 | Cooler Master 120mm AF | Corsair SP120 | Icy Box IB-172SK-B | OCZ CX500W | Acer GF246 24" + AOC <some model> 21.5" | Steelseries Apex 350 | Steelseries Diablo 3 | Steelseries Syberia RAW Prism | Corsair HS-1 | Akai AM-A1

D.VA coming soon™ xoxo

Sapphire Acer Aspire 1410 Celeron 743 | 3Gb DDR2-667 | 120Gb HDD | Windows 10 Home x32

Vault Tec Celeron 420 | 2Gb DDR2-667 | Storage pending | Open Media Vault

gh0st Asus K50IJ T3100 | 2Gb DDR2-667 | 40Gb HDD | Ubuntu 17.04

Diskord Apple MacBook A1181 Mid-2007 Core2Duo T7400 @2.16GHz | 4Gb DDR2-667 | 120Gb HDD | Windows 10 Pro x32

Firebird//Phoeniix FX-4320 | Gigabyte 990X-Gaming SLI | Asus GTS 450 | 16Gb DDR3-1600 | 2x Intel 535 250Gb | 4x 10Tb Western Digital Red | 600W Segotep custom refurb unit | Windows 10 Pro x64 // offisite backup and dad's PC

 

Saint Olms Apple iPhone 6 16Gb Gold

Archon Microsoft Lumia 640 LTE

Gulliver Nokia Lumia 1320

Werkfern Nokia Lumia 520

Hydromancer Acer Liquid Z220

Link to comment
Share on other sites

Link to post
Share on other sites

Looks like we're okay (Q5 in the family.)

Main Rig: CPU: AMD Ryzen 7 5800X | RAM: 32GB (2x16GB) KLEVV CRAS XR RGB DDR4-3600 | Motherboard: Gigabyte B550I AORUS PRO AX | Storage: 512GB SKHynix PC401, 1TB Samsung 970 EVO Plus, 2x Micron 1100 256GB SATA SSDs | GPU: EVGA RTX 3080 FTW3 Ultra 10GB | Cooling: ThermalTake Floe 280mm w/ be quiet! Pure Wings 3 | Case: Sliger SM580 (Black) | PSU: Lian Li SP 850W

 

Server: CPU: AMD Ryzen 3 3100 | RAM: 32GB (2x16GB) Crucial DDR4 Pro | Motherboard: ASUS PRIME B550-PLUS AC-HES | Storage: 128GB Samsung PM961, 4TB Seagate IronWolf | GPU: AMD FirePro WX 3100 | Cooling: EK-AIO Elite 360 D-RGB | Case: Corsair 5000D Airflow (White) | PSU: Seasonic Focus GM-850

 

Miscellaneous: Dell Optiplex 7060 Micro (i5-8500T/16GB/512GB), Lenovo ThinkCentre M715q Tiny (R5 2400GE/16GB/256GB), Dell Optiplex 7040 SFF (i5-6400/8GB/128GB)

Link to comment
Share on other sites

Link to post
Share on other sites

---

I wanted to find the treasure again, forgot how fucking long it takes to read your signature. :lol:

I run my browser through NSA ports to make their illegal jobs easier. :P
If it's not broken, take it apart and fix it.
http://pcpartpicker.com/b/fGM8TW

Link to comment
Share on other sites

Link to post
Share on other sites

If car manufactures don't change their attitudes then they really will be replaced by tech companies like apple/google and car manufactures that actually know the importance of quickly fixing problems.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×