this post was submitted on 26 Feb 2024
489 points (96.4% liked)

Technology

58144 readers
4513 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Experts ​alerted motor trade to security risks of ‘smart key’ systems which have now fuelled highest level of car thefts for a decade.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 6 months ago

For one, completely remove presence based unlock and start would be a good first move. They are inherently insecure, as they are much too easy to relay attack.

Next, alter fob controls to encrypt the communication with private/public keys tied to the specific car. This way, even if the fob communication is intercepted, the information is functionally impossible to reverse engineer.

Finally, implement two way communication. An initial handshake followed by the command. This would functionally remove any chance of a replay attack. Even if the handshake is recorded, the fob won’t send the command.

These three changes would essentially remove any chance of using a device like a flipper for entry. Yes, it would still technically be susceptible with a relay attack, but the chances are so slim as to be essentially impossible.