Thieves 'could hack VW, Por iot L?sungen sche, Audi cars'

www.inhandnetworks.de
Security researchers have found that many vehicles produced by the Volkswagen group – including some of the world’s biggest luxury brands like Audi and Porsche – have a security flaw that could let hackers access them without a key.

Researchers from the Netherlands and the UK will this week present a paper detailing the flaw in transponders used by Volkswagen (VW) in its Audi, Porsche, Bentley and Lamborghini lines, Bloomberg reported on Friday.

Cars produced by Fiat, Honda, Volvo and Maserati may also be affected.

But rather than publicize and fix the problems, VW took out a courindustrielle Kommunikationt injunction against the researchers in the UK after they showed the company their findings in 2013, preventing publication.

How it works

The loophole, found by Roel Verdult and Baris Ege of Radboud University and Flavio Garcia of the University of Birmingham, targets Megamos Crypto immobilizer transponders, one of the most common brands.

Immobilizers stop the car’s engine from starting unless the correct key fob is close to the car’s sensors and are used in modern cars with a “start engine” button rather than a turn-key ignition.

“We have reverse-engineered all cryptographic mechanisms of Megamos Crypto… furthermore, we have identified several weaknesses in Megamos Crypto which we exploit in three attacks,” the scientists wrote.industrie router wlan

In one of the attacks they developed, the researchers used “brute force” - simply writing a computer program to try every possible combination of cryptographic keys – to break into cars in less than half an hour.

Not yet a widespread method

“This isn’t a very realistic way of stealing cars” at the moment, security expert Dr David Oswald told The Local.

“For every one of these attacks, you have to speak with both the car and the key at least once. You need to get close.”

In most electronically-assisted thefts carried out today, Oswald said, thieves gain physical access to the car before connecting a computer or other device through the vehicle’s On-Board Diagnostics (OBD) port, which provides access to the car’s computer.

However, Oswald warned that “in the long term, it would definitely make sense to change the transponder. One should always make all components secure.”

While private car owners might not be at risk from the technique immediately, Oswald pointed out, there are cases where it would be easier for thieves to access both car and key fob wirelessly – for example, if a criminal rented a car he planned to steal later.

“There are technical solutions that are relatively secure that are available immediately,” Oswald said, although they would require physically changing components on every vehicle currently fitted with the Megamos transponder.

For now, while consumers could avoid buying cars fitted with the affected security system, “many other similar systems are not particularly secure either,” Oswald warned.

VW says risk is low

In an emailed statement on Friday, a VW spokesman told The Local that “the thresholds for protection against theft are always being lifted… the ignition lock on some older models of vehicle doesn’t match that on our current vehicle modules. That’s unavoidable.”

But he added that "even on older models from our product range like the ones the authors’ work addressed, the attacker would need at least one key and notes on at least two successful ignitions.”

Similar cases across many different fields of IT security have seen researchers heavily criticize companies for gagging their colleagues rather than fixing loopholes, as happened in this case with the UK injunction.

“The court proceedings with the universities and the authors before the High Court in London about publication of the article was ended with an amicable compromise,” the VW statement read.

“The authors are permitted to publish a part of their scientific work.”

The paper has now been published with one sentence redacted, which the researchers say contained a detailed description of calculations performed by the Megamos chip.

“Volkswagen always builindustrial iotds the most modern, technically up-to-date security technology into its vehicles,” the statement continued.

But VW added that while it offers software updates where necessary, it is “usually not possible” to update hardware components.

This article was updated on 14/08/2015 with the emailed statement from Volkswagen.

Tags: Industrie Router, LTE Router, Dual-SIM LTE Router, LTE Industrie Router, UMTS Industrie Router, Industrie Router und Modem, M2M Industrie Router, Industrie LTE Router, Industrie Router Hutschiene, industrie router wlan, wlan router hutschiene, Router für die Hutschiene, VPN router, Server maintenance, Website operation and maintenance, Server optimization, Server maintenance, Server Security, Host security, Website security, webdesign, joomla, seo, Smart Grid mit LTE Routern, Ipsec Industrie Router, OpenVPN Industrie Router, L2TP Industrie Router, robust Industrie Router, LAN router, Industrie Router Verkäufer, Hersteller, industrielle Kommunikation, Industrie Router, Industrie Computer, M2M-Kommunikation, industrial iot, industrial m2m, Server maintenance, Website operation and maintenance, Server optimization, webdesign, seo, joomla, Server maintenance, Server Security, Host security, Website security, IoT Kommunikation, industrielle Kommunikation, Industrie Router, iot Lösungen, A Global Leader in Industrial IoT, Industrial IoT, InHand Networks GmbH

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值