Is it possible to steal a modern day car...

iwatchlive said:
Hi all

Here’s my basic technical explanation.

You may or may not be aware that BMW can remotely unlock the E89 (text message) and that the keys you are using are using RfID (somewhat like the chip device in your Credit Card)

I have played around with Tech security over the years (Ethically) and also recently developed an RfID solution for my business. I can confirm it is in fact relatively easy for the technically minded to crack car security if they know how to. However in this case I do not feel that is the explanation, as crackers using this tech are simply not interested in Vauxhalls, more £100K vehicles.

Easy as 1 2 3 4
Scan
Probe
Attack
Result

It’s relatively easy to scan the neighbourhood to intercept both text messages as well as wireless transmissions, whether for networking or for a range of other radio frequencies including mobile telephones, DECT and standard mobiles, or for radio frequencies covering the RfID technology currently used in various security equipment or for key systems that switch off alarms and open doors.

For example, when Beckams X5 was stolen, they hacked a Texas Instruments chip using only a laptop, with an antenna and scanner software to itemise the local RfID chip that controlled the Beemer. It really wasn’t that difficult. The result was that Texas Instruments finally introduced encryption (128 bit)

RfID can be passive or active, by using the tags in ignition systems (at 40 bit) all that was required was to be within vicinity of the transponder (RfID tag in the key or the ignition system) and crack the code, which used to take about 15 minutes using a program designed for the task at hand, but this is now approx 20 to 30 secs.

The industry knows this tech isn’t foolproof but it has still seriously reduced auto theft.

It is in fact easier with keyless entry systems as there is the alarm and door opening to deal with if it’s not keyless entry, however we are talking another minute at most for that.

Here’s how
You have the program on your laptop that replicates a car manufacturers ignition system ( lets say BMW) & you sit close to the owner (with the key in his / her pocket)
You scan the local area and pick up the transponder details (using software)
You decrypt the challenge / response pairs (using software) using at basic what is known as a brute force attack; the system will eventually find a pair that work and you can predict the sequence
You go to the vehicle and send out the correct response pair
Voila
You drive away fast (-;

2nd gen transponders are far better than the first, but it’s still possible.
For those of you with keyless entry, (especially 1st Gen) at the least consider keeping your key in a metal shroud as this minimises active scanning attacks, as wrapping your key in tin foil looks rather chav, don’t you agree?

Bit too basic for me, are the Z4's carburettor or dynamo susceptible to a brute force attack by a pair of transponders? I've got an old Crook Lock in the garage will that help?
 
Ewazix said:
iwatchlive said:
Hi all

Here’s my basic technical explanation.

You may or may not be aware that BMW can re.....

...etc...

....transponders are far better than the first, but it’s still possible.
For those of you with keyless entry, (especially 1st Gen) at the least consider keeping your key in a metal shroud as this minimises active scanning attacks, as wrapping your key in tin foil looks rather chav, don’t you agree?

Bit too basic for me, are the Z4's carburettor or dynamo susceptible to a brute force attack by a pair of transponders? I've got an old Crook Lock in the garage will that help?

Only if you catch them in the act and use it to beat them :P
 
My wife locked the keys in the back of her E46 Touring while away working. The RAC man uses a long wire to pop the bonnet open through the door seal. After this he opened the fuse box and eventially started the engine using a number of wire links. The doors also unlocked at this point.
:?
 
Update from a horses mouth so to speak: I recently caught up with an old mate who works for insurance companies tracing stolen cars and I asked him about this. Yes it's well established that software is being used to crack keyless entry or start systems in particular. One 'large' Police force has identified over 200 examples of BMW thefts happening without keys using this method. Some BMWs have a 'glitch' which is being exploited, BMW officially deny this and are apparently very pi55y that after spending millions on security R&D two spotty geeks with a laptop can beat it! Despite denials BMW are patching software when affected cars come in for service (probably without telling owners specifically what software updates have been done). This is great.... unless your car isn't due a service for a year or two :thumbsdown:

...and used car buyers beware. Bent users of hire, loan and lease cars are introducing extra keys to the vehicle (process varies according to make) and fitting trackers. Months later after the car has been moved on to a new owner they activate 'their' tracker at a time/place to suit them and........ voilà, an empty parking space.

Oh and the inside word is Land/Range Rovers are just about the most likely thing to get nicked and never seen again either ending up abroad and/or in pieces, old ones being worth far more as parts.

..... and there is an easy method to locate BMW (and other OEM) trackers which was not divulged, but the advice if you love your motor is to fit a second (non - OEM) tracker, this has so far fooled the thieves since they stop looking once they find the makers one.

Scary but interesting chat.
 
The problem is the embedded industry has been just that for some time: it largely ignores the outside world. I write very fault-tolerant code but until recently it only needed to consider internal faults - components going wrong, strange answers popping out of a logical sequence of instructions etc. As technology moves on those embedded systems now need to talk to non-embedded ones - laptops and phones running quite crappy code (from a point of view of reliability) so security-holes are introduced. It's taking the embedded industry a long time to catch up with some standard server security methods like virtual machines, firewalls etc being built into systems. As an added bonus, the more complicated the software gets, the more eager the script-kiddies get to be the one to crack it.
 
i still think its safe to say that the days of some crack head thinking he can smash a window and jump a car are gone.

however vaunarable keys are today they are still making imporvements, i had a case at work were someone claimed their vehicle was stolen without the keys, he confirmed he still had both of them. as an insurance company we can send they keys of to a nice chap who has spent that last 25 years simply looking at car keys, even just looking at a key he can tell us how many times its been used and even what milage should be on the vehicle. the new method of this is now the plug the key into a computer and the key tells you how many times its been used, what the last recorded milage was and the date and time of its use! safe to safe, we knew it was him who crashed the car and it had not in fact been stolen ;-)
 
Nova2k7 said:
7 years in the insurance business tells me that there is no way that insignia was taken without the keys, im so confident in this that im willing to call your friend a lier if he says the keys are with him!

most people use this excuse when they have got drunk, got into the car crashed and then run home and called the police to say it was stolen.

I had my 335 nicked twice, when both keys were still safely in my house, or on my person.

How you ask? fuckwit at the dealer ordering replacement keys for a professional gang.
Was in the news for Peterborough four years back and happened for about 10 customers from the same dealer.

Not saying that's what happened here, but you never know.
I'd still say pics of keys, or GTFO tho :P
 
sk93 said:
I had my 335 nicked twice, when both keys were still safely in my house, or on my person.

How you ask? fuckwit at the dealer ordering replacement keys for a professional gang.
Was in the news for Peterborough four years back and happened for about 10 customers from the same dealer.

Not saying that's what happened here, but you never know.
I'd still say pics of keys, or GTFO tho :P

I saw that in a film once... IIRC it ended up with a dog crapping Mercedes keys :D
 
BMWZ4MC said:
sk93 said:
I had my 335 nicked twice, when both keys were still safely in my house, or on my person.

How you ask? fuckwit at the dealer ordering replacement keys for a professional gang.
Was in the news for Peterborough four years back and happened for about 10 customers from the same dealer.

Not saying that's what happened here, but you never know.
I'd still say pics of keys, or GTFO tho :P

I saw that in a film once... IIRC it ended up with a dog crapping Mercedes keys :D

This is also true.. however, I believe in that film, they drove the cars across town.
In my case, they simply drove it into a truck decalled with the BMW group logos..
 
sk93 said:
BMWZ4MC said:
sk93 said:
I had my 335 nicked twice, when both keys were still safely in my house, or on my person.

How you ask? fuckwit at the dealer ordering replacement keys for a professional gang.
Was in the news for Peterborough four years back and happened for about 10 customers from the same dealer.

Not saying that's what happened here, but you never know.
I'd still say pics of keys, or GTFO tho :P

I saw that in a film once... IIRC it ended up with a dog crapping Mercedes keys :D

This is also true.. however, I believe in that film, they drove the cars across town.
In my case, they simply drove it into a truck decalled with the BMW group logos..


I expect they missed out the extra step involving canine giblets too... :P
 
On the M3 Cutters forum a few years back, there was a post about M3s and other RWD performance cars being stolen from rail station car parks...

The gang would rock up with a fully-marked, genuine looking recovery truck, all in hi-vis jackets with phone numbers on van etc, clearly taking the 'we look like we're in a position of authority, noone will question us' stance.

They would simply tow away the cars they wanted - if the tilt alarm goes off, "sorry, it happens a lot in our job, but this guy has no valid ticket" or whatever, so "his car is being impounded". Station staff don't give a damn, almost better for them if the driver has 'parked illegally'.

In the end, police and CCTV realised what was happening - recommended drivers of RWD cars parked boot first against walls.

Apparently, the problem simply disapeared - the gang's recovery truck could only TOW cars by lifting two of the wheels. Boot-in, they had to lift by the front wheels, meaning the rear either wouldn't move or would be uncontrollable in tow and fall off.

Urban myth?
Maybe, but I ALWAYS park boot-in now... :?

Si
 
Just to reopen this thread with a recent story from a friend

In short he bought a 2010 530D from a mutual friend who had originally purchased BMW assist with the car, but not registered the service with BMW. From laziness of the seller and incompetence from the dealer he had bought it from the new owner was able to register BMW Assist in his name which then allows him to 1. Open the car from his iPhone remotley 2. Turn on Aircon 3. Upload maps/directions to onboard sat nav to name a few.

Series of events

I picked up Steve’s car still in Steve’s name/ private plates and hadn’t even sent the V5 back. Steve just signed it and left it to me to sort out.

When I got home I was looking on BMW forums etc and came across some info on BMW Assist called “Connected Drive”

Went to BMW connected drive website and noted that you had to fill an online form (says 4 years free blah blah so thought may as well try)

I gave my name, address, mobile number, VIN and registration (had not even been to DVLA to swap to my plates yet so still had Steve’s plates on) and submitted the form

About 2 days later I got 2 text messages giving my username and password which I could then user to download and use the iPhone app.

From what I gather on the forums this process should be done as part of the post sales process and should therefore be done by the dealer in the first instance for the customer. As the car was originally owned by the BMW dealership (MD’s of dealers car probably) it never got activated at that time. Steve also didn’t realise he needed to register anything so he didn’t do it either, hence I still have 4 years free



The key information given was the VIN and registration details all of which could have been obtained from the outside of the car. Yes the above is a fluke as the orginal owner had never registered the Assist service and it was a friend to friend sale, but it does make you think what is possible
 
ranski said:
If Iran can remote patch into a american stealth million $ un-maned plane and land it. Then I'm confident your modern day thief can nick any car that is parked up.


Sent from my iPad using Tapatalk
You have a very limited knowledge about Iran then... :roll:
 
Back
Top Bottom