Comment on Electronic devices or 'signal jammers' used in car thefts to be banned

<- View Parent
sugar_in_your_tea@sh.itjust.works ⁨1⁩ ⁨day⁩ ago

I meant they should have failsafes in place so jamming isn’t an effective attack.

A simple analogy is locks. Instead of making lock picking kits illegal, design better locks to increase the time and knowledge needed to defeat a lock.

Car remote unlock design is lazy: you push the button and it generates a key, which is invalidated when used. There’s nothing more complex here than a defined order. To protect against that, add a time element (like TOTP in Google Authenticator). Your fob and car would keep time independently, so an attacker would have a very narrow window (i.e. under a second) to attack the car, if that. Resync the fob with the car after a successful challenge/response process so they don’t drift too much, and allow resyncing with physical entry.

Car companies should pay when their laziness leads to compromise.

source
Sort:hotnewtop