{"id":8391,"date":"2018-09-15T14:56:59","date_gmt":"2018-09-15T12:56:59","guid":{"rendered":"http:\/\/blog.netspark.de\/?p=8391"},"modified":"2018-09-12T09:38:09","modified_gmt":"2018-09-12T07:38:09","slug":"tesla-s-car-key-easily-cloned","status":"publish","type":"post","link":"https:\/\/blog.netspark.de\/?p=8391","title":{"rendered":"Tesla S car key easily cloned"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-Post-Thumb wp-image-8111\" src=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2018\/08\/Tesla-64x64.png\" alt=\"\" width=\"64\" height=\"64\" srcset=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2018\/08\/Tesla-64x64.png 64w, https:\/\/blog.netspark.de\/wp-content\/uploads\/2018\/08\/Tesla-150x150.png 150w, https:\/\/blog.netspark.de\/wp-content\/uploads\/2018\/08\/Tesla.png 256w\" sizes=\"auto, (max-width: 64px) 100vw, 64px\" \/>If you thought, a high tech car with a value of over<br \/>\n100&#8217;000 US$ cannot be stolen easily, then you&#8217;d better<br \/>\nnot watch the following video. A team of the catholic<br \/>\nUniversity Leuven in Belgium shows how.<\/p>\n<p><!--more-->With hardware worth 500 US$ you&#8217;ll be equipped for your less-than-a-minute-carjacking<\/p>\n<p>All you need is an antenna (Yard Stick One), an USB-powered minicomputer (Raspberry Pi 3 B+), A software defined radio (Proxmark 3) and a USB powerbank to power it all.<\/p>\n<p>The backend is a server with a 6 terabytes large database containing various pairing keys.<\/p>\n<p>The problem is that the Tesla is constantly sending out a wake up signal to identify nearby keys and unlock itself to allow a quick start and ride experience.<\/p>\n<p>With the antenna you&#8217;re good to go and take the signal from about 1m (3ft) distance most likely unnoticed.<\/p>\n<p>The Raspi is gathering the information about the key and the car and compares them in the database remotely stored on the server.<\/p>\n<p>This is so fast that it takes only a couple seconds to be performed completely. Rendering the car helpless against your &#8220;attack&#8221;<\/p>\n<p>With only little effort you&#8217;re good to hijack a 100&#8217;000 US$ car.<\/p>\n<p>Although Tesla has fixed the security leak by introducing a PIN-to-go system in the car, other vehicles are still suject to being instantly hijacked as they also use the same encryption\/decryption method Tesla uses. So are also cars and bikes from McLaren, Karma and Triumph affected.<\/p>\n<p>The encryption standard DST40 has been declared insecure by 2005 yet it is used in a wide variety of even actual cars, even luxury cars.<\/p>\n<p>Since there&#8217;s no easy fix as the hardware inside the key is too weak to use an alternative encryption system, most companies still rely on DST40 and it&#8217;s insecure encryption power. 40 bits are just too weak to offer a good protection and that&#8217;s the reason why the TMTO attack (TMTO stands for Time\/Memory TradeOff attack) is so successful and quick.<\/p>\n<p>The only workaround for the companies mentioned above is to implement a second security system i.e. to start the vehicle using a passcode. But this passcode has to be entered on the vehicle.s console directly as otherwise even that communication sent from the key might be captured and rendering\u00a0 the passcode obsolete.<\/p>\n<p>So what we learn from this is, that comfort often has a tradeoff with security. The result is what we have now. A rather insecure transmission system for quite expensive vehicles making a theft easier as usual.<\/p>\n<p>In the upcoming years, these companies will have to check on a new encryption method that is on the one hand lightweight and can be run from the transmitter with just a little more processing power. New small-embedded-systems on specially desigened SoCs should make this possible&#8230;<\/p>\n<p>Watch the video here:<\/p>\n<div style=\"width: 640px;\" class=\"wp-video\"><video class=\"wp-video-shortcode\" id=\"video-8391-1\" width=\"640\" height=\"360\" preload=\"metadata\" controls=\"controls\"><source type=\"video\/mp4\" src=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2018\/09\/COSIC-researchers-hack-Tesla-Model-S-key-fob.mp4?_=1\" \/><a href=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2018\/09\/COSIC-researchers-hack-Tesla-Model-S-key-fob.mp4\">https:\/\/blog.netspark.de\/wp-content\/uploads\/2018\/09\/COSIC-researchers-hack-Tesla-Model-S-key-fob.mp4<\/a><\/video><\/div>\n","protected":false},"excerpt":{"rendered":"<p>If you thought, a high tech car with a value of over 100&#8217;000 US$ cannot be stolen easily, then you&#8217;d better not watch the following video. A team of the catholic University Leuven in Belgium shows how.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[55,4,3,2949,150],"tags":[1715,3165,3166,851,2176,127,3167],"class_list":["post-8391","post","type-post","status-publish","format-standard","hentry","category-computer-2","category-curiosities","category-news","category-technology","category-video","tag-encryption","tag-keyless-go","tag-reach","tag-security","tag-tesla","tag-theft","tag-wireless-tapping"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/posts\/8391","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8391"}],"version-history":[{"count":0,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/posts\/8391\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}